Early warning method, device and equipment for data leakage and readable storage medium

By obtaining data from core switches and system files, using deep neural network models for data preprocessing and convolutional operations, and generating fusion features for grading and early warning, the problem of incomplete data leakage detection in the existing technology is solved, and more efficient data leakage detection and early warning is achieved.

CN120342646APending Publication Date: 2025-07-18厦门农芯数字科技有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410422064.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-04-09
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

Existing data breach detection methods are difficult to detect various forms of data breach in a comprehensive and accurate manner.

Method used

By obtaining the traffic data generated from the core switch and the system data collected from the system files, after preprocessing, three convolutional neural networks in the deep neural network model are called for convolution operations, fusion features are generated, and leakage risks are classified and warning based on the fusion features.

Benefits of technology

It realizes comprehensive and accurate detection of data leakage, improves the sensitivity and accuracy of early warnings, and can take timely response measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342646A_ABST
    Figure CN120342646A_ABST
Patent Text Reader

Abstract

The invention provides a data leakage early warning method, device and equipment and a readable storage medium, and the method comprises the steps: obtaining traffic data generated from a switch through mirroring, and system data collected from a system file, and carrying out the preprocessing of the traffic data and the system data, the system data comprising file data and picture data; performing convolution operation on the traffic data, the file data and the picture data by using three convolutional neural networks in a deep neural network model to generate a traffic convolution result, a file convolution result and a picture convolution result; then, based on a preset weight, fusing the traffic convolution result, the file convolution result and the picture convolution result to generate a fusion feature; and according to the fusion features, grading leakage risks, and according to a grading result, performing early warning in a corresponding early warning mode. The problem that it is difficult to comprehensively and accurately detect data leakage in an existing data leakage detection mode is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security, and in particular to a data leakage early warning method, device, equipment and readable storage medium. Background Art

[0002] As the level of enterprise informatization continues to increase, data plays an increasingly critical role in enterprise operations. However, enterprises are facing increasingly severe security threats, one of the most prominent of which is data leakage. Data leakage may lead to the leakage of corporate intellectual property rights, customer privacy, etc., which in turn has a serious impact on the company's reputation and business.

[0003] Traditional data leakage detection methods mainly rely on the monitoring and analysis of a single data source, such as file monitoring, network traffic monitoring, etc. However, these methods can often only identify data leakage of a specific type or source, and it is difficult to comprehensively and accurately detect various forms of data leakage.

[0004] In view of this, this application is filed. Summary of the invention

[0005] The present invention discloses a data leakage early warning method, device, equipment and readable storage medium, aiming to solve the problem that existing data leakage detection methods are difficult to be fully and accurately detected.

[0006] The first embodiment of the present invention provides a data leakage early warning method, comprising:

[0007] Acquire traffic data generated by mirroring from a core switch and system data collected from a system file, and pre-process the traffic data and the system data, wherein the system data includes file data and image data;

[0008] Calling three convolutional neural networks in the deep neural network model to perform convolution operations on the preprocessed traffic data, the file data, and the image data, respectively, to generate a traffic convolution result, a file convolution result, and an image convolution result;

[0009] The flow convolution result, the file convolution result, and the image convolution result are fused based on a preset weight to generate a fusion feature;

[0010] The leakage risk is graded according to the fusion characteristics, and an early warning is issued in a corresponding early warning manner according to the classification result.

[0011] Preferably, the preprocessing process of the flow data includes:

[0012] Traverse the network data and extract the target fields, where the target fields include the source IP address, destination IP address, transport protocol, source port, and destination port;

[0013] Aggregate the data packets in the network data based on the target fields.

[0014] Preferably, the preprocessing process of the file data includes: tokenizing the file data, removing stop words, stemming, or lemmatization.

[0015] Preferably, the preprocessing process of the picture data includes: grayscale processing and edge detection of the picture data, and converting the text in the picture into a recognizable text format through optical character recognition.

[0016] Preferably, the model for performing convolution operation on the picture data is:

[0017] f image = CNN image (I)

[0018] where f image is the picture convolution result, and I is the picture data;

[0019] The model for performing convolution operation on the file data is:

[0020] f text = CNN text (T)

[0021] where f text is the file convolution result, and T is the file data;

[0022] The model for performing convolution operation on the traffic data is:

[0023] f traffic = CNN traffic (F)

[0024] where f traffic is the traffic convolution result, and F is the traffic data.

[0025] Preferably, the expression for fusing the traffic convolution result, the file convolution result, and the picture convolution result is:

[0026] f usion = W traffic * f traffic + W text * f text + W image * f image

[0027] where fusion is the fusion feature, W traffic is the traffic weight, W text is the file weight, W image is the picture weight, and the sum of the traffic weight, the file weight, and the picture weight is 1.

[0028] The second embodiment of the present invention provides a data leakage warning device, including:

[0029] A preprocessing unit, configured to obtain traffic data mirrored from a core switch and system data collected from system files, and preprocess the traffic data and the system data, where the system data includes file data and picture data;

[0030] A convolution operation unit, configured to call three convolutional neural networks in a deep neural network model to perform convolution operations on the preprocessed traffic data, file data, and picture data respectively to generate a traffic convolution result, a file convolution result, and a picture convolution result;

[0031] A fusion unit, configured to fuse the traffic convolution result, the file convolution result, and the picture convolution result based on a preset weight to generate a fusion feature;

[0032] A warning unit, configured to classify the leakage risk according to the fusion feature, and perform a warning in a corresponding warning manner according to the classification result.

[0033] The third embodiment of the present invention provides a data leakage warning device, including a memory and a processor, where a computer program is stored in the memory, and the computer program can be executed by the processor to implement a data leakage warning method as described in any one of the above.

[0034] The fourth embodiment of the present invention provides a computer-readable storage medium storing a computer program, and the computer program can be executed by a processor of a device where the computer-readable storage medium is located to implement a data leakage warning method as described in any one of the above.

[0035] Based on a data leakage warning method, device, equipment and readable storage medium provided by the present invention, traffic data mirrored and generated from a core switch and system data collected from system files are obtained, and the traffic data and the system data are preprocessed, wherein the system data includes file data and picture data; then, three convolutional neural networks in a deep neural network model are called to perform convolutional operations on the traffic data, the file data and the picture data respectively to generate a traffic convolution result, a file convolution result and a picture convolution result; then, based on preset weights, the traffic convolution result, the file convolution result and the picture convolution result are fused to generate a fused feature; finally, the leakage risk is classified according to the fused feature, and a warning is given in a corresponding warning manner according to the classification result. This solves the problem that existing data leakage detection methods are difficult to detect comprehensively and accurately. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1 FIG. 6 is a schematic flowchart of a data leakage warning method provided by the first embodiment of the present invention;

[0037] Figure 2 FIG. 10 is a schematic diagram of modules of a data leakage warning device provided by the second embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0038] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0039] For a better understanding of the technical solutions of the present invention, the embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0040] It should be clear that the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0041] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms "a", "said" and "the" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.

[0042] It should be understood that the term "and / or" used herein is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Additionally, the character " / " in this text generally represents an "or" relationship between the associated objects before and after.

[0043] Depending on the context, as used herein, the word "if" can be interpreted as "when" or "while" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detecting (stated condition or event)" can be interpreted as "when determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)".

[0044] The "first / second" mentioned in the embodiments is merely to distinguish similar objects and does not represent a specific order for the objects. It can be understood that the "first / second" can be interchanged in a specific order or sequence when permitted. It should be understood that the objects distinguished by the "first / second" can be interchanged appropriately so that the embodiments described herein can be implemented in an order other than those illustrated or described herein.

[0045] The following will describe in detail the specific embodiments of the present invention with reference to the accompanying drawings.

[0046] The present invention discloses a method, apparatus, device, and readable storage medium for early warning of data leakage, aiming to solve the problem that existing data leakage detection methods are difficult to be comprehensively and accurately detected.

[0047] The first embodiment of the present invention provides a method for early warning of data leakage, which can be executed by a data leakage early warning device (hereinafter referred to as the early warning device), and particularly, by one or more processors in the early warning device, to at least achieve the following steps:

[0048] S101, obtain traffic data mirrored from the core switch and system data collected from system files, and preprocess the traffic data and the system data, where the system data includes file data and picture data;

[0049] In this embodiment, the early warning device can be a terminal with data processing capabilities such as a server, a workstation, a desktop computer, a laptop computer, etc. The early warning device can be installed with corresponding operating systems and application software, and the functions required in this embodiment can be achieved through the combination of the operating system and the application software;

[0050] It should be noted that the core switch is the core device of the enterprise network, and all internal network traffic is forwarded through these switches (meanwhile, it does not affect the normal forwarding of the original traffic). A mirror port is configured on the switch so that all traffic passing through the switch can be mirrored. The warning device can establish a communication connection with the core switch and can receive and process a large amount of network traffic data;

[0051] Furthermore, the warning device can establish communication with a local server storing system files or a network shared storage or cloud storage. Specifically, it can be established through the provided APIs, network protocols (such as SMB, NFS, etc.) or other access methods. It can traverse the file system to obtain file information therein, which can include file metadata (such as file name, size, modification time, etc.) and access to the file content.

[0052] In this embodiment, the preprocessing process of the traffic data includes:

[0053] Traverse the network traffic data packets, and extract information such as source IP address, destination IP address, transport protocol (such as TCP, UDP), source port, and destination port from each packet. The collected traffic data can be aggregated to reduce data complexity and improve analysis efficiency. The aggregation method can include aggregating by keyword fields such as source IP address, destination IP address, and protocol. For example, packets with the same source IP address and destination IP address are merged into one data stream, and its traffic volume and frequency are counted. For large-scale network traffic data, time window sampling can be performed on the traffic data, and only part of the traffic data within each time window is retained to reduce the data volume while retaining key information.

[0054] In this embodiment, the preprocessing process of the file data includes: cutting the text content in the file according to certain rules or patterns and decomposing it into individual words or phrases. The word segmentation method can be determined according to specific requirements and language characteristics, such as word segmentation according to spaces, punctuation marks or other language-specific rules. After word segmentation, stop words in the text are removed. These stop words can be some common words without actual meaning, such as "de", "shi", "zai", etc. Removing stop words can reduce data noise and improve the expression ability of text features. Stemming or lemmatization processing is performed on the segmented words to convert the words into their stems or original forms to reduce the impact of lexical variants on analysis. For example, various forms of words such as tenses, voices, and numbers are unified into their original forms. It can reduce the number of features and improve the accuracy and stability of analysis.

[0055] In this embodiment, the preprocessing process of the picture data includes: converting a color picture into a grayscale image. The aim is to simplify the image processing process and reduce the computational amount of processing. A grayscale image has only one channel, while a color image has three channels (red, green, and blue), and processing a grayscale image is more efficient. Further, an edge detection algorithm is used to identify the edges in the image. Edge detection can quickly find the main features in the image and the areas with obvious changes from the background. The edge detection algorithm can adopt one or more of the Sobel operator or the Canny operator. Even further, the OCR technology can be adopted to convert the text in the picture into a recognizable text format. The OCR technology extracts the text content in the image by performing feature extraction and pattern recognition on the image and converts it into a computer-readable text format. When processing pictures containing text, the OCR technology can extract the text in the pictures for subsequent text analysis, search, and processing.

[0056] S102, call three convolutional neural networks in the deep neural network model to perform convolutional operations on the preprocessed traffic data, file data, and picture data respectively to generate a traffic convolution result, a file convolution result, and a picture convolution result;

[0057] It should be noted that since it involves the model processing and model training of multiple data such as text, network traffic, and pictures. A deep neural network (MIMO) model is adopted to accept multiple inputs and multiple outputs. Among them, by incorporating multiple data types such as text, network traffic, and pictures into the same model for processing and training, the enterprise data can be analyzed more comprehensively to discover potential threats and problems. Compared with the method of processing each data type separately, this comprehensive processing method can better reflect the real enterprise data environment and improve the applicability and accuracy of the model.

[0058] Secondly, the MIMO model can accept multiple inputs and produce multiple outputs, making full use of the correlation and information interaction between different data types. By using multiple convolutional neural network (CNN) branches to process different types of data, the model for performing convolutional operations on the picture data is: f image = CNN image (I); where f image is the picture convolution result, and I is the picture data; the model for performing convolutional operations on the file data is: f text = CNN text (T); where f text is the file convolution result, and T is the file data; the model for performing convolutional operations on the traffic data is: f traffic = CNN traffic (F); where f trafficis the result of traffic convolution, and F is traffic data. Each branch is specifically responsible for processing one of the data types, improving the efficiency and accuracy of the model. The setting of the branch structure enables the model to process different types of data more flexibly and can adaptively learn and adjust to adapt to different data characteristics and changes.

[0059] S103, fuse the traffic convolution result, the file convolution result, and the picture convolution result based on a preset weight to generate a fused feature;

[0060] In this embodiment, the expression for fusing the traffic convolution result, the file convolution result, and the picture convolution result is:

[0061] f usion =W traffic *f traffic +W text *f text +W image *f image

[0062] where f usion is the fused feature, W traffic is the traffic weight, W text is the file weight, W image is the picture weight, and the sum of the traffic weight, the file weight, and the picture weight is 1.

[0063] It should be noted that by fusing the different models output in step three, the feature information of different data types can be comprehensively utilized to further improve the accurate evaluation and early warning capabilities for the sensitivity of enterprise data leakage. The fusion process involves weighted summing the features of three different branches of network traffic, files, and pictures according to certain weights to comprehensively consider the contributions of each data type to leakage early warning.

[0064] In the fusion process, a set of weights need to be defined, which respectively represent the weights of the three data types of network traffic, files, and pictures, to ensure that the contributions of each data type can be reasonably considered. These weights can be adjusted and optimized according to the actual situation and empirical knowledge so that the fused features can better reflect the situation of enterprise data leakage.

[0065] S104, classify the leakage risk according to the fused feature, and issue an early warning in a corresponding early warning manner according to the classification result.

[0066] It should be noted that in this embodiment, the classification results may include: critical level, high risk, medium risk, and low risk. For the critical level leakage risk, a telephone warning method can be used for notification. Telephone warning is the most direct and urgent notification method, which can ensure that the recipient receives the warning information in time and can immediately take actions to respond to the risk. It is applicable to situations with extremely high leakage risks and situations where immediate actions need to be taken to avoid serious consequences. For high-risk leakage risks, a text message warning method is used for notification. Text message warning is a fast and convenient notification method, which can convey the warning information to the recipient in the first time, reminding them to pay attention and take necessary countermeasures. For medium-risk leakage risks, an email warning method is used for notification. Email warning is a stable and reliable notification method, which can send detailed warning information to the recipient and leave enough time for them to conduct further analysis and processing. For low-risk leakage risks, a pop-up warning method is used for notification. Pop-up warning is a lightweight notification method that does not disturb the user's operation. It can immediately display the warning information in the recipient's working environment, reminding them to pay attention to the risk and take appropriate measures.

[0067] The second embodiment of the present invention provides a data leakage warning device, including:

[0068] A preprocessing unit, configured to obtain traffic data mirrored from a core switch and system data collected from system files, and preprocess the traffic data and the system data, where the system data includes file data and picture data;

[0069] A convolution operation unit, configured to call three convolutional neural networks in a deep neural network model to perform convolution operations on the traffic data, the file data, and the picture data respectively, so as to generate a traffic convolution result, a file convolution result, and a picture convolution result;

[0070] A fusion unit, configured to fuse the traffic convolution result, the file convolution result, and the picture convolution result based on a preset weight to generate a fusion feature;

[0071] A warning unit, configured to classify the leakage risk according to the fusion feature, and perform a warning in a corresponding warning manner according to the classification result.

[0072] The third embodiment of the present invention provides a data leakage warning device, including a memory and a processor, where a computer program is stored in the memory, and the computer program can be executed by the processor to implement a data leakage warning method as described in any one of the above.

[0073] The fourth embodiment of the present invention provides a computer-readable storage medium storing a computer program that can be executed by a processor of a device where the computer-readable storage medium is located to implement the method for warning of data leakage as described in any one of the above.

[0074] Based on the method, device, equipment and readable storage medium for warning of data leakage provided by the present invention, by acquiring traffic data mirrored from a core switch and system data collected from system files, and preprocessing the traffic data and the system data, wherein the system data includes file data and picture data; then, calling three convolutional neural networks in a deep neural network model to perform convolutional operations on the traffic data, the file data and the picture data respectively to generate a traffic convolution result, a file convolution result and a picture convolution result; then, fusing the traffic convolution result, the file convolution result and the picture convolution result based on a preset weight to generate a fused feature; finally, grading the leakage risk according to the fused feature and giving a warning in a corresponding warning manner according to the grading result. The problem that the existing data leakage detection methods are difficult to be detected comprehensively and accurately is solved.

[0075] Exemplarily, the computer program described in the third and fourth embodiments of the present invention can be divided into one or more modules. The one or more modules are stored in the memory and executed by the processor to complete the present invention. The one or more modules can be a series of computer program instruction segments capable of completing specific functions, and the instruction segments are used to describe the execution process of the computer program in the device for warning of data leakage. For example, the device described in the second embodiment of the present invention.

[0076] The so-called processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the method for warning of data leakage, and uses various interfaces and lines to connect all parts of the method for warning of data leakage.

[0077] The memory can be used to store the computer program and / or module. By running or executing the computer program and / or module stored in the memory, and invoking the data stored in the memory, the processor realizes various functions of a data leakage warning method. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, a text conversion function, etc.); the data storage area can store data created according to the use of the mobile phone (such as audio data, text message data, etc.). In addition, the memory can include high-speed random access memory, and can also include non-volatile memory, such as a hard disk, memory, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one magnetic disk storage device, flash device, or other volatile solid-state storage devices.

[0078] Among them, if the implemented module is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-mentioned embodiment methods of the present invention, it can also be completed by instructing relevant hardware through a computer program. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned various method embodiments can be realized. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file, or some intermediate form, etc. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disc, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. It should be noted that the content included in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, the computer-readable medium does not include electrical carrier signals and telecommunication signals.

[0079] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the attached drawings of the device embodiments provided by the present invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0080] As mentioned above, the above are only the preferred specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A method for warning of data leakage, characterized in that, including: Obtain traffic data mirrored from a core switch and system data collected from system files, and preprocess the traffic data and the system data, where the system data includes file data and picture data; Call three convolutional neural networks in a deep neural network model to perform convolutional operations on the preprocessed traffic data, file data, and picture data respectively to generate a traffic convolution result, a file convolution result, and a picture convolution result; Fuse the traffic convolution result, the file convolution result, and the picture convolution result based on a preset weight to generate a fused feature; Classify the leakage risk according to the fused feature, and give an early warning in a corresponding warning manner according to the classification result.

2. The early warning method for data leakage according to claim 1, characterized in that, The preprocessing process of the traffic data includes: Traverse the network data and extract target fields, where the target fields include source IP address, destination IP address, transport protocol, source port, and destination port; Aggregate the data packets in the network data based on the target fields.

3. The early warning method for data leakage according to claim 1, wherein The preprocessing process of the file data includes: performing word segmentation, removing stop words, stemming, or lemmatization on the file data.

4. A method for warning of data leakage according to claim 1, characterized in that, The preprocessing process of the picture data includes: performing grayscale processing and edge detection on the picture data, and converting the text in the picture into a recognizable text format through optical character recognition.

5. The early warning method for data leakage according to claim 1, characterized in that The model for performing the convolutional operation on the picture data is: fimage = CNN Nimage(I) Among them, fima g e is the result of image convolution, and I is the image data; The model for performing the convolutional operation on the file data is: ftext = CNN text((T) where f text is the result of file convolution, and T is the file data; The model for performing the convolutional operation on the traffic data is: ftraffiicc = CNN Ntraffic(F) where f traffic is the flow convolution result, and F is the flow data.

6. The early warning method for data leakage according to claim 1, wherein The expression for fusing the traffic convolution result, the file convolution result, and the picture convolution result is: f f usionWttraffici mage Among them, f usion is the fusion feature, Wtraffic is the traffic weight, Wteet is the file weight, Wima g e is the image weight, and the sum of the traffic weight, the file weight, and the image weight is 1.

7. An early warning device for data leakage, characterized in that, including: A preprocessing unit for obtaining traffic data mirrored from a core switch and system data collected from system files, and preprocessing the traffic data and the system data, where the system data includes file data and picture data; A convolutional operation unit for calling three convolutional neural networks in a deep neural network model to perform convolutional operations on the preprocessed traffic data, file data, and picture data respectively to generate a traffic convolution result, a file convolution result, and a picture convolution result; A fusion unit for fusing the traffic convolution result, the file convolution result, and the picture convolution result based on a preset weight to generate a fused feature; An early warning unit for classifying the leakage risk according to the fused feature, and giving an early warning in a corresponding warning manner according to the classification result.

8. An early warning device for data leakage, characterized in that, Including a memory and a processor, where the memory stores a computer program that can be executed by the processor to implement a method for early warning of data leakage according to any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, A computer program is stored, and the computer program can be executed by a processor of a device where the computer-readable storage medium is located to implement a method for warning of data leakage as described in any one of claims 1 to 6.