Sensitive data leakage risk studying and judging method and device for API (Application Program Interface)
By filtering and counting sensitive data logs from the API interface, statistical data reflecting transmission situations are obtained, which solves the problem of inconvenience in risk assessment caused by complex traffic logs in the existing technology, and achieves efficient assessment of the risk of sensitive data leakage.
Patent Information
- Application Number
- CN202410080347.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-19
- Publication Date
- 2025-07-22
AI Technical Summary
In the prior art, the number of traffic logs in the API interface is huge and the information is complicated. It is not convenient to accurately evaluate the risk of sensitive data leakage based on the traffic log.
By filtering out the sensitive data logs of the API interface and performing statistical processing, statistical data reflecting the sensitive data transmission of the API interface is obtained, and risk analysis is conducted based on these data.
The risk assessment process is simplified, which can facilitate the rapid identification of sensitive data leakage risks of API interfaces and reduce the processing burden on massive traffic logs.
Smart Images

Figure CN120354409A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a method and device for analyzing the risk of sensitive data leakage of an API interface. Background Art
[0002] When there is a risk of sensitive data leakage in the API (Application Programming Interface), sensitive data may be leaked through the API. Once the leaked sensitive data is maliciously used, it will bring serious adverse effects. Therefore, it is necessary to determine the risk of sensitive data leakage in the API interface, so as to reduce the possibility of sensitive data leakage in the API interface based on the results of the determination.
[0003] At present, the risk assessment of sensitive data leakage of API interfaces is usually conducted directly based on the traffic logs of API interfaces. However, the number of traffic logs of API interfaces is huge, and the information contained in traffic logs is complicated. It is not convenient to assess the risk of sensitive data leakage of API interfaces directly based on traffic logs. Summary of the invention
[0004] In view of this, the present application proposes a method and device for assessing the risk of sensitive data leakage of an API interface, the main purpose of which is to facilitate the assessment of the risk of sensitive data leakage of an API interface.
[0005] In order to achieve the above objectives, this application mainly provides the following technical solutions:
[0006] In a first aspect, the present application provides a method for assessing the risk of sensitive data leakage of an API interface, the method comprising:
[0007] In response to an API interface having a risk of sensitive data leakage to be determined, determining a sensitive data log, wherein the sensitive data log is a traffic log including sensitive data transmitted by the API interface;
[0008] Performing statistical processing on the sensitive data included in the sensitive data log to obtain statistical data;
[0009] The risk of sensitive data leakage of the API interface is analyzed and judged based on the statistical data.
[0010] In some embodiments of the present application, statistical processing is performed on the sensitive data included in the sensitive data log, including: counting the first cumulative number of occurrences of sensitive data of the same sensitive data type in all sensitive data logs; and determining the first cumulative number of occurrences as statistical data for indicating that the API interface transmits the corresponding sensitive data type.
[0011] In some embodiments of the present application, counting the first cumulative occurrence times of sensitive data of the same sensitive data type in all sensitive data logs includes: for each sensitive data existing in the sensitive data logs, detecting whether the sensitive data is the sensitive data transmitted by the API interface; if so, keeping the current first cumulative occurrence times of the corresponding sensitive data type unchanged; if not, incrementing the current first cumulative occurrence times of the corresponding sensitive data type by one.
[0012] In some embodiments of the present application, counting the first cumulative occurrence times of sensitive data of the same sensitive data type in all sensitive data logs includes: for each sensitive data existing in the sensitive data logs, determining the sensitive data type of the sensitive data and incrementing the current first cumulative occurrence times of the sensitive data type by one.
[0013] In some embodiments of the present application, each sensitive data type has a corresponding first number threshold. Then, based on the statistical data, judging the sensitive data leakage risk of the API interface includes: based on the statistical data, determining whether the sensitive data types transmitted by the API interface include a target sensitive data type, where the first cumulative occurrence times of the target sensitive data type reach the corresponding first number threshold; if so, determining that the API interface has a sensitive data leakage risk; if not, determining that the API interface does not have a sensitive data leakage risk.
[0014] In some embodiments of the present application, after determining that the API interface has a sensitive data leakage risk, outputting the corresponding first cumulative occurrence times of the target sensitive data type, or outputting the corresponding first cumulative occurrence times of each sensitive data type transmitted by the API interface.
[0015] In some embodiments of the present application, performing statistical processing on the sensitive data included in the sensitive data logs includes: counting the second cumulative occurrence times of the same sensitive data in all sensitive data logs; determining the second cumulative occurrence times as the statistical data for indicating that the API interface transmits the corresponding sensitive data.
[0016] In some embodiments of the present application, each sensitive data type has a corresponding second number threshold. Then, based on the statistical data, judging the sensitive data leakage risk of the API interface includes: based on the statistical data, determining whether the sensitive data transmitted by the API interface includes a target sensitive data, where the second cumulative occurrence times of the target sensitive data reach the corresponding second number threshold of the corresponding sensitive data type; if so, determining that the API interface has a sensitive data leakage risk; if not, determining that the API interface does not have a sensitive data leakage risk.
[0017] In some embodiments of the present application, the method for judging the risk of sensitive data leakage of the API interface further includes: after determining that there is a risk of sensitive data leakage in the API interface, outputting the corresponding second cumulative occurrence times of the target sensitive data, or outputting the corresponding second cumulative occurrence times of each sensitive data transmitted by the API interface.
[0018] In some embodiments of the present application, before statistically processing the sensitive data included in the sensitive data log, the method for judging the risk of sensitive data leakage of the API interface further includes: judging whether the sensitive data log includes sensitive data of a specified sensitive data type; if so, removing the sensitive data of the specified sensitive data type from the corresponding sensitive data log.
[0019] In some embodiments of the present application, if the number of the sensitive data logs is not less than two, then, before statistically processing the sensitive data included in the sensitive data logs, the method for judging the risk of sensitive data leakage of the API interface further includes: setting the statistical processing order of each of the sensitive data logs.
[0020] In a second aspect, the present application provides a device for judging the risk of sensitive data leakage of an API interface, and the device for judging the risk of sensitive data leakage of the API interface includes:
[0021] A determination module, configured to determine a sensitive data log in response to an API interface with a risk of sensitive data leakage to be judged, where the sensitive data log is a traffic log including sensitive data transmitted by the API interface;
[0022] A processing module, configured to statistically process the sensitive data included in the sensitive data log to obtain statistical data;
[0023] A judgment module, configured to judge the risk of sensitive data leakage of the API interface based on the statistical data.
[0024] In a third aspect, the present application provides a computer-readable storage medium, where the storage medium includes a stored program, and wherein, when the program runs, it controls the device where the storage medium is located to execute the method for judging the risk of sensitive data leakage of the API interface described in the first aspect.
[0025] In a fourth aspect, the present application provides an electronic device, and the electronic device includes: a memory, configured to store a program; a processor, coupled to the memory, configured to run the program to execute the method for judging the risk of sensitive data leakage of the API interface described in the first aspect.
[0026] The method and device for judging the risk of sensitive data leakage of the API interface provided by this application, in the case of determining an API interface with a risk of sensitive data leakage to be judged, determine the sensitive data log including sensitive data transmitted by the API interface. Then, statistical processing is performed on the sensitive data included in the sensitive data log to obtain statistical data. Finally, based on the statistical data, the risk of sensitive data leakage of the API interface is judged. It can be seen that the solution provided by this application obtains statistical data for reflecting the situation of sensitive data transmitted by the API interface by means of statistical processing of the sensitive data included in the sensitive data log. In this way, when judging the risk of sensitive data leakage of the API interface, instead of facing a large amount of traffic logs, it is directly based on the statistical data reflecting the situation of sensitive data transmitted by the API interface, so it is convenient to judge the risk of sensitive data leakage of the API interface.
[0027] The above description is only an overview of the technical solution of this application. In order to be able to understand the technical means of this application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of this application more obvious and understandable, the following specific embodiments of this application are specifically given. Brief Description of the Drawings
[0028] In order to more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the following will briefly introduce the drawings required to be used in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0029] Figure 1 Shows the flowchart of a method for judging the risk of sensitive data leakage of an API interface provided by an embodiment of this application;
[0030] Figure 2 Shows the structural schematic diagram of a device for judging the risk of sensitive data leakage of an API interface provided by an embodiment of this application;
[0031] Figure 3 Shows the structural schematic diagram of a device for judging the risk of sensitive data leakage of an API interface provided by another embodiment of this application. Detailed Description of the Embodiments
[0032] The following will describe the exemplary embodiments of the present disclosure in more detail with reference to the drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.
[0033] At present, the risk assessment of sensitive data leakage of API interfaces is usually conducted directly based on the traffic logs of API interfaces. However, the number of traffic logs of API interfaces is huge, and the information contained in traffic logs is complicated. It is not convenient to assess the risk of sensitive data leakage of API interfaces directly based on traffic logs.
[0034] After research, the inventor found that when judging the risk of sensitive data leakage of API interface, it is mainly necessary to clarify the situation of sensitive data transmission of API interface, and judge the risk of sensitive data leakage of API interface through the situation of sensitive data transmission of API interface. Therefore, the inventor considered that the sensitive data logs that include sensitive data in the traffic log of API interface can be screened out, and then the sensitive data included in the sensitive data log can be statistically processed to obtain statistical data, and finally the risk of sensitive data leakage of API interface can be judged based on the statistical data. In this way, when judging the risk of sensitive data leakage of API interface, there is no need to face massive traffic logs. The risk of sensitive data transmission of API interface can be judged through statistical data reflecting the situation of sensitive data transmission of API interface.
[0035] Based on the above considerations, this embodiment specifically provides a technical solution for assessing the risk of sensitive data leakage of an API interface, specifically: in response to an API interface with a risk of sensitive data leakage to be assessed, a sensitive data log including sensitive data transmitted by the API interface is determined. The sensitive data included in the sensitive data log is statistically processed to obtain statistical data. The risk of sensitive data leakage of the API interface is assessed based on the statistical data.
[0036] The technical solution for assessing the risk of sensitive data leakage of an API interface provided in this embodiment can be applied to any API interface in any software product to assess the risk of sensitive data leakage of the API interface. This embodiment does not limit the type of software product.
[0037] Based on the technical solution for sensitive data leakage risk assessment of the above-mentioned API interface, this embodiment specifically provides a method and device for sensitive data leakage risk assessment of an API interface. The method and device for sensitive data leakage risk assessment of the API interface provided in this embodiment are specifically described below.
[0038] like Figure 1 As shown, the embodiment of the present application provides a method for assessing the risk of sensitive data leakage of an API interface. The method for assessing the risk of sensitive data leakage of an API interface mainly includes the following steps 101 to 103:
[0039] 101. In response to an API interface with a risk of sensitive data leakage to be judged, determine sensitive data logs, where the sensitive data logs are traffic logs including sensitive data transmitted by the API interface.
[0040] The API interface with a risk of sensitive data leakage to be judged can be any API interface in any software product, and the type of the software product is not specifically limited in this embodiment. Considering that not all traffic logs of the API interface can be used to judge the risk of sensitive data leakage of the API interface, only the sensitive data logs including sensitive data in the traffic logs can be used to judge the risk of sensitive data leakage of the API interface. Therefore, when it is determined that there is an API interface with a risk of sensitive data leakage to be judged, it is necessary to determine the sensitive data logs of the API interface.
[0041] The method for determining sensitive data logs can include the following two types: One is to set a specified time period, monitor the API interface within the specified time period, and for each traffic log transmitted by the API interface monitored, detect whether the traffic log includes sensitive data. If it does, determine the traffic log as a sensitive data log. The other is to obtain a large number of traffic logs that have been transmitted by the API interface, and determine the traffic logs that meet the preset conditions in the traffic logs as sensitive data logs. The preset conditions can be limited in at least one of the following dimensions: the time when the log is generated, the recipient of the log.
[0042] After determining the sensitive data logs, there is a data basis for judging the risk of sensitive data leakage of the API interface. Therefore, subsequent steps for judging the risk of sensitive data leakage can be continued based on the sensitive data logs.
[0043] 102. Perform statistical processing on the sensitive data included in the sensitive data logs to obtain statistical data.
[0044] The purpose of performing statistical processing on the sensitive data included in the sensitive data logs is to clarify the situation of the API interface transmitting sensitive data and obtain statistical data indicating the situation of the API interface transmitting sensitive data.
[0045] The method for performing statistical processing on the sensitive data included in the sensitive data logs is related to the specific content to be statistically processed. Therefore, the method for performing statistical processing on the sensitive data included in the sensitive data logs can at least include the following two types: One is to perform statistics based on the sensitive data types of the sensitive data; the other is to perform statistics based on the sensitive data. The following will explain these two methods separately:
[0046] First, the specific process of performing statistical processing on the sensitive data included in the sensitive data logs can include the following steps 102A to 102B:
[0047] 102A. Statistically count the first cumulative occurrence times of sensitive data of the same sensitive data type in all sensitive data logs.
[0048] Each sensitive data has a corresponding sensitive data type. For example, the sensitive data type corresponding to the sensitive data "12358966345" is mobile phone number, and for another example, the sensitive data type corresponding to the sensitive data "Zhang San" is name. By statistically counting based on the sensitive data types of sensitive data, it is possible to clarify the transmission situation of sensitive data of the corresponding sensitive data types by the API interface, and thus clarify the magnitude of the leakage risk of sensitive data of the corresponding sensitive data types by the API interface.
[0049] The first cumulative occurrence times of sensitive data of a sensitive data type in all sensitive data logs can reflect the transmission volume of sensitive data of this sensitive data type by the API interface, and this transmission volume can reflect the magnitude of the leakage risk of sensitive data of this sensitive data type by the API interface. Therefore, it is necessary to statistically count the first cumulative occurrence times of sensitive data of the same sensitive data type in all sensitive data logs.
[0050] The specific methods for statistically counting the first cumulative occurrence times of sensitive data of the same sensitive data type in all sensitive data logs can include the following two:
[0051] One is that the specific process for statistically counting the first cumulative occurrence times of sensitive data of the same sensitive data type in all sensitive data logs can include the following steps: For each sensitive data existing in the sensitive data logs, detect whether the sensitive data is the sensitive data transmitted by the API interface; if so, keep the current first cumulative occurrence times of the corresponding sensitive data type unchanged; if not, increment the current first cumulative occurrence times of the corresponding sensitive data type by one. If it is detected that the sensitive data is the sensitive data transmitted by the API interface, it means that the sensitive data has been statistically counted in the corresponding sensitive data type, and it will not be statistically counted this time. Therefore, keep the current first cumulative occurrence times of the sensitive data corresponding to the sensitive data type unchanged. That is, for the same sensitive data, no matter how many times the sensitive data appears in all the sensitive data logs, it is only cumulatively counted once in the first cumulative occurrence times of the corresponding sensitive data type.
[0052] For a piece of sensitive data, if it is detected that the sensitive data is not the sensitive data transmitted through the API interface, it means that the API interface transmits the sensitive data for the first time, and the sensitive data has not been counted in the corresponding sensitive data type. Therefore, the current first cumulative occurrence count of the corresponding sensitive data type of the sensitive data is incremented by one. It should be noted that if the corresponding sensitive data type of the sensitive data is a sensitive data type not transmitted through the API interface, the current first cumulative occurrence count of the corresponding sensitive data type is 0. If the corresponding sensitive data type of the sensitive data is a sensitive data type transmitted through the API interface, the current first cumulative occurrence count of the corresponding sensitive data type is the most recently counted first cumulative occurrence count.
[0053] Exemplarily, for the sensitive data "Zhang San" existing in the sensitive data log, if it is detected that "Zhang San" is sensitive data not transmitted through the API interface, the current first cumulative occurrence count "5" of the corresponding sensitive data type "Name" of "Zhang San" is incremented by one, and the incremented first cumulative occurrence count is "6". For the sensitive data "12358966345" existing in the sensitive data log, if it is detected that "12358966345" is sensitive data transmitted through the API interface, the current first cumulative occurrence count "10" of the corresponding sensitive data type "Mobile Phone Number" of "12358966345" remains unchanged.
[0054] Another way is that the specific process of counting the first cumulative occurrence count of sensitive data of the same sensitive data type in all sensitive data logs may include the following steps: For each sensitive data existing in the sensitive data log, determine the sensitive data type of the sensitive data, and increment the current first cumulative occurrence count of the sensitive data type by one.
[0055] For each sensitive data in the sensitive data log, every time the sensitive data appears in the sensitive data log, the current first cumulative occurrence count of the corresponding sensitive data type of the sensitive data is incremented by one.
[0056] Exemplarily, for the sensitive data "Zhang San" existing in the sensitive data log, if the sensitive data type of "Zhang San" is determined to be "Name", the current first cumulative occurrence count "6" of the corresponding sensitive data type "Name" of the sensitive data "Zhang San" is incremented by one, and the incremented first cumulative occurrence count is "7".
[0057] The above two methods of counting the first cumulative occurrence count of sensitive data of the same sensitive data type in all sensitive data logs can be used alone or in combination, and this embodiment does not make any limitations in this regard.
[0058] 102B. Determine the first cumulative occurrence count as the statistical data for indicating that the API interface transmits the corresponding sensitive data type.
[0059] After obtaining the first cumulative occurrence count, the quantity of sensitive data of the corresponding sensitive data type transmitted by the API interface can be determined. The first cumulative occurrence count can reflect the magnitude of the leakage risk of the sensitive data of the corresponding sensitive data type transmitted by the API interface. Therefore, the first cumulative occurrence count is determined as the statistical data for indicating that the API interface transmits the corresponding sensitive data type.
[0060] Second, the specific process of statistically processing the sensitive data included in the sensitive data log may include the following steps 102C to 102D:
[0061] 102C. Statistically calculate the second cumulative occurrence count of the same sensitive data in all sensitive data logs.
[0062] The second cumulative occurrence count of a sensitive data in all sensitive data logs can reflect the total quantity of the sensitive data transmitted by the API interface, and this total quantity can reflect the magnitude of the leakage risk of the sensitive data by the API interface. Therefore, it is necessary to statistically calculate the second cumulative occurrence count of the same sensitive data in all sensitive data logs.
[0063] The specific process of statistically calculating the second cumulative occurrence count of the same sensitive data in all sensitive data logs may include the following steps: For each sensitive data existing in the sensitive data log, every time the sensitive data appears, the current second cumulative occurrence count of the sensitive data is incremented by one. It should be noted that if the sensitive data has not been transmitted by the API interface, the current second cumulative occurrence count is 0. If the sensitive data has been transmitted by the API interface, the current second cumulative occurrence count is the most recently statistically obtained second cumulative occurrence count.
[0064] Exemplarily, if it is detected that the sensitive data "Zhang San" exists in the sensitive data log, then the current second cumulative occurrence count "6" of the sensitive data "Zhang San" is incremented by one, and the incremented second cumulative occurrence count is "7".
[0065] 102D. Determine the second cumulative occurrence count as the statistical data for indicating that the API interface transmits the corresponding sensitive data.
[0066] The second cumulative occurrence count can reflect the total quantity of the corresponding sensitive data transmitted by the API interface, and its magnitude can reflect the magnitude of the leakage risk when the API interface transmits the corresponding sensitive data. Therefore, the second cumulative occurrence count is determined as the statistical data for indicating that the API interface transmits the corresponding sensitive data type.
[0067] The above two methods for statistically processing the sensitive data included in the sensitive data logs can be used alone or in combination, and this embodiment does not make specific limitations.
[0068] After statistically processing the sensitive data included in the sensitive data logs, statistical data for indicating the situation of the API interface transmitting sensitive data can be obtained. This statistical data can reflect the risk level of the API interface leaking sensitive data. Therefore, the statistical data obtained after statistical processing can be used as the basis for judging the sensitive data leakage risk of the API interface.
[0069] 103. Judge the sensitive data leakage risk of the API interface based on the statistical data.
[0070] The statistical data can clarify the specific situation of the API interface transmitting sensitive data. Therefore, the sensitive data leakage risk of the API interface can be judged based on the statistical data.
[0071] The method for judging the sensitive data leakage risk of the API interface based on the statistical data is related to the specific content of the statistical data. Therefore, the judging method can at least include the following two types:
[0072] First, the statistical data for indicating the situation of the API interface transmitting sensitive data includes the first cumulative occurrence times of the corresponding sensitive data types. Each sensitive data type has a corresponding first number threshold. Then, the specific process of judging the sensitive data leakage risk of the API interface based on the statistical data can include the following steps 103A to 103C:
[0073] 103A. Based on the statistical data, judge whether the sensitive data types transmitted by the API interface include a target sensitive data type, where the first cumulative occurrence times of the target sensitive data type reach the corresponding first number threshold; if included, execute step 103B; if not included, execute step 103C.
[0074] If it is determined that the sensitive data types transmitted by the API interface include the target sensitive data type, it indicates that the sensitive data of the target sensitive data type is transmitted in large quantities by the API interface, and the risk of the API interface leaking the sensitive data of the target sensitive data type is relatively high. Therefore, execute step 103B to clarify that there is a sensitive data leakage risk in the API interface.
[0075] If it is determined that the sensitive data types transmitted by the API interface do not include the target sensitive data type, it indicates that the quantity of the sensitive data of the corresponding sensitive data types transmitted by the API interface is within the acceptable range, and the risk of the API interface leaking sensitive data is relatively small. Therefore, execute step 103C to clarify that there is no sensitive data leakage risk in the API interface.
[0076] 103B. Determine that there is a risk of sensitive data leakage in the API interface.
[0077] The risk of the API interface leaking sensitive data of the target sensitive data type is relatively high. Therefore, in order to enable business personnel to be aware of the fact that there is a risk of sensitive data leakage in the API interface, it is determined that there is a risk of sensitive data leakage in the API interface.
[0078] Furthermore, after determining that there is a risk of sensitive data leakage in the API interface, in order to facilitate business personnel to handle the risk of sensitive data leakage in the API interface, the method for judging the risk of sensitive data leakage in the API interface may further include any of the following execution processes: First, output the first cumulative occurrence times corresponding to the target sensitive data type. Sensitive data of the target sensitive data type is transmitted in large quantities by the API interface, and the risk of the API interface leaking sensitive data of the target sensitive data type is relatively high. Therefore, output the first cumulative occurrence times corresponding to the target sensitive data type so that business personnel can more specifically handle the risk of the API interface leaking sensitive data of the target sensitive data type based on these outputs. Second, output the first cumulative occurrence times corresponding to each sensitive data type transmitted by the API interface. Considering that while sensitive data of the target sensitive data type is transmitted in large quantities by the API interface, there may be other risks of sensitive data leakage in the API interface that have not been discovered. Therefore, in order to comprehensively handle the risk of sensitive data leakage in the API interface, it is necessary to output the first cumulative occurrence times corresponding to each sensitive data type transmitted by the API interface so that business personnel can comprehensively eliminate the risk of sensitive data leakage in the API interface based on these outputs.
[0079] 103C. Determine that there is no risk of sensitive data leakage in the API interface.
[0080] If it is determined that the sensitive data types transmitted by the API interface do not include the target sensitive data type, it indicates that the quantity of sensitive data of the corresponding sensitive data types transmitted by the API interface is within the acceptable range, and the risk of the API interface leaking sensitive data is relatively small. Therefore, it is determined that there is no risk of sensitive data leakage in the API interface.
[0081] Furthermore, after determining that there is no risk of sensitive data leakage in the API interface, in order to facilitate business personnel to understand the specific situation of judging the risk of sensitive data leakage in the API interface, the first cumulative occurrence times corresponding to each sensitive data type transmitted by the API interface can be output.
[0082] Second, the statistical data used to indicate the situation of the API interface transmitting sensitive data includes the second cumulative occurrence times of the corresponding sensitive data, and each sensitive data type has a corresponding second occurrence threshold. Then, the specific process of judging the risk of sensitive data leakage in the API interface based on the statistical data may include the following steps 103D to 103F:
[0083] 103D. Based on statistical data, determine whether the sensitive data transmitted by the API interface includes the target sensitive data, where the second cumulative occurrence count of the target sensitive data reaches the corresponding second count threshold for the corresponding sensitive data type; if it includes, execute step 103E; if it does not include, execute step 103F.
[0084] If it is determined that the sensitive data transmitted by the API interface includes the target sensitive data, it indicates that the target sensitive data is transmitted in large quantities by the API interface, and the risk of the API interface leaking the target sensitive data is relatively high. Therefore, execute step 103E to identify that there is a risk of sensitive data leakage in the API interface.
[0085] If it is determined that the sensitive data transmitted by the API interface does not include the target sensitive data, it indicates that the quantity of the corresponding sensitive data transmitted by the API interface is within the acceptable range, and the risk of the API interface leaking sensitive data is relatively low. Therefore, execute step 103F to identify that there is no risk of sensitive data leakage in the API interface.
[0086] 103E. Determine that there is a risk of sensitive data leakage in the API interface.
[0087] The risk of the API interface leaking the target sensitive data is relatively high. Therefore, in order to enable the research and judgment personnel to be aware of the fact that there is a risk of sensitive data leakage in the API interface, it is determined that there is a risk of sensitive data leakage in the API interface.
[0088] Furthermore, after determining that there is a risk of sensitive data leakage in the API interface, in order to facilitate the business personnel to handle the risk of sensitive data leakage in the API interface, the method for researching and judging the risk of sensitive data leakage of the API interface may further include any of the following execution processes: First, output the second cumulative occurrence count of the target sensitive data. The target sensitive data is transmitted in large quantities by the API interface, and the risk of the API interface leaking the target sensitive data is relatively high. Therefore, output the second cumulative occurrence count of the target sensitive data so that the business personnel can handle the risk of the API interface leaking the target sensitive data more pertinently based on these outputs. Second, output the second cumulative occurrence count of each sensitive data transmitted by the API interface. Considering that while the target sensitive data is transmitted in large quantities by the API interface, there may be other risks of sensitive data leakage in the API interface that have not been discovered. Therefore, in order to comprehensively handle the risk of sensitive data leakage in the API interface, it is necessary to output the second cumulative occurrence count of each sensitive data transmitted by the API interface so that the business personnel can comprehensively eliminate the problem of sensitive data leakage in the API interface based on these outputs.
[0089] 103F. Determine that there is no risk of sensitive data leakage in the API interface.
[0090] If it is determined that the sensitive data transmitted by the API interface does not include the target sensitive data, it indicates that the quantity of the corresponding sensitive data transmitted by the API interface is within the acceptable range, and the risk of the API interface leaking sensitive data is relatively small. Therefore, it is determined that there is no risk of sensitive data leakage in the API interface.
[0091] Further, after determining that there is no risk of sensitive data leakage in the API interface, in order to facilitate business personnel to understand the specific situation of judging the risk of sensitive data leakage in the API interface, the second cumulative occurrence times corresponding to each sensitive data can be output.
[0092] The method for judging the risk of sensitive data leakage in the API interface provided by the embodiment of the present application, in the case of determining an API interface with a risk of sensitive data leakage to be judged, determines a sensitive data log including sensitive data transmitted by the API interface. Then, statistical processing is performed on the sensitive data included in the sensitive data log to obtain statistical data. Finally, the risk of sensitive data leakage in the API interface is judged based on the statistical data. It can be seen that the solution provided by the embodiment of the present application obtains statistical data for reflecting the situation of the API interface transmitting sensitive data by means of statistical processing of the sensitive data included in the sensitive data log. In this way, when judging the risk of sensitive data leakage in the API interface, instead of facing a large amount of traffic logs, it is directly based on the statistical data reflecting the situation of the API interface transmitting sensitive data, so it is convenient to judge the risk of sensitive data leakage in the API interface.
[0093] In some embodiments of the present application, considering that even if some sensitive data of a sensitive data type is leaked and maliciously used, it will not cause losses to the enterprise or users. Therefore, in order to reduce the data processing volume, before performing statistical processing on the sensitive data included in the sensitive data log in the above step 102, the method for judging the risk of sensitive data leakage in the API interface may further include the following steps: determining whether the sensitive data log includes sensitive data of a specified sensitive data type; if it includes, removing the sensitive data of the specified sensitive data type from the corresponding sensitive data log.
[0094] The specified sensitive data type is a sensitive data type for which no damage will be caused even if the corresponding sensitive data is leaked. The specified sensitive data type can be flexibly set based on the business, and this embodiment does not limit it. Exemplarily, the specified sensitive data type is name.
[0095] For each sensitive data log, if it is determined that the sensitive data log includes sensitive data of a specified sensitive data type, then in order to reduce data processing, the sensitive data of the specified sensitive data type is removed from the corresponding sensitive data log to avoid performing statistical processing on the sensitive data of the specified sensitive data type, thereby reducing the processing volume consumed by judging the risk of sensitive data leakage in the API interface.
[0096] In some embodiments of the present application, in order to more comprehensively evaluate the sensitive data leakage risk of the API interface, a large number of sensitive data logs are usually used, and the use of a large number of sensitive data logs may cause chaos in the evaluation process. Therefore, in order to avoid chaos, if the number of sensitive data logs is not less than two, the method for evaluating the sensitive data leakage risk of the API interface may further include the following steps: setting the statistical processing order of each sensitive data log to statistically process the sensitive data included in the sensitive data log based on the processing order.
[0097] The purpose of setting the statistical processing order is to avoid chaos in the statistical process and improve the accuracy of statistics. The methods for setting the statistical processing order of each sensitive data log may include the following several types: One is to set the statistical processing order of each sensitive data log according to the chronological order of the generation time of the sensitive data log. The second is to set the statistical processing order of each sensitive data log according to the quantity size of the sensitive data included in the sensitive data log. The third is to set the statistical processing order of each sensitive data log according to the importance level of the recipient corresponding to the sensitive data log. The fourth is to randomly sort the sensitive data logs to obtain the statistical processing order of each sensitive data log.
[0098] After setting the statistical processing order of each sensitive data log, statistically process the sensitive data included in the sensitive data log in sequence according to the statistical processing order. After all the sensitive data logs have been statistically processed, the corresponding statistical data is obtained.
[0099] Furthermore, another embodiment of the present application also provides a device for evaluating the sensitive data leakage risk of an API interface, as Figure 2 shown. The device for evaluating the sensitive data leakage risk of the API interface includes:
[0100] A determination module 21, configured to determine sensitive data logs in response to the existence of an API interface for which the sensitive data leakage risk is to be evaluated, where the sensitive data logs are traffic logs including sensitive data transmitted by the API interface;
[0101] A processing module 22, configured to statistically process the sensitive data included in the sensitive data logs to obtain statistical data;
[0102] A judgment module 23, configured to evaluate the sensitive data leakage risk of the API interface based on the statistical data.
[0103] The sensitive data leakage risk judgment device for the API interface provided by the embodiment of the present application, in the case of determining an API interface with a sensitive data leakage risk to be judged, determines a sensitive data log including sensitive data transmitted by the API interface. Then, statistical processing is performed on the sensitive data included in the sensitive data log to obtain statistical data. Finally, the sensitive data leakage risk of the API interface is judged based on the statistical data. It can be seen that the solution provided by the embodiment of the present application obtains statistical data for reflecting the situation of the API interface transmitting sensitive data by means of statistical processing of the sensitive data included in the sensitive data log. In this way, when judging the sensitive data leakage risk of the API interface, instead of facing a large amount of traffic logs, it is directly based on the statistical data reflecting the situation of the API interface transmitting sensitive data, so it is convenient to judge the sensitive data leakage risk of the API interface.
[0104] In some embodiments of the present application, as Figure 3 shown, the processing module 22 includes:
[0105] A first statistical unit 221, configured to count the first cumulative occurrence times of sensitive data of the same sensitive data type in all sensitive data logs;
[0106] A first determination unit 222, configured to determine the first cumulative occurrence times as statistical data for indicating that the API interface transmits the corresponding sensitive data type.
[0107] In some embodiments of the present application, as Figure 3 shown, the first statistical unit 221 is specifically configured to, for each sensitive data existing in the sensitive data log, detect whether the sensitive data is sensitive data transmitted by the API interface; if so, keep the current first cumulative occurrence times of the corresponding sensitive data type unchanged; if not, add 1 to the current first cumulative occurrence times of the corresponding sensitive data type.
[0108] In some embodiments of the present application, as Figure 3 shown, the first statistical unit 221 is specifically configured to, for each sensitive data existing in the sensitive data log, determine the sensitive data type of the sensitive data and add 1 to the current first cumulative occurrence times of the sensitive data type.
[0109] In some embodiments of the present application, as Figure 3 shown, each sensitive data type has a corresponding first number threshold, then, the judgment module 23 includes:
[0110] The first determination unit 231 is configured to determine, based on the statistical data, whether the sensitive data types transmitted by the API interface include a target sensitive data type, where a first cumulative occurrence count of the target sensitive data type reaches a corresponding first count threshold; if so, trigger the second determination unit 232 to determine that there is a risk of sensitive data leakage in the API interface; if not, trigger the third determination unit 233 to determine that there is no risk of sensitive data leakage in the API interface.
[0111] In some embodiments of the present application, as Figure 3 shown, the research and judgment module 23 further includes:
[0112] The first output unit 234 is configured to, after the second determination unit 232 determines that there is a risk of sensitive data leakage in the API interface, output the first cumulative occurrence count corresponding to the target sensitive data type, or output the first cumulative occurrence count corresponding to each sensitive data type transmitted by the API interface.
[0113] In some embodiments of the present application, as Figure 3 shown, the processing module 22 includes:
[0114] The second statistics unit 223 is configured to count a second cumulative occurrence count of the same sensitive data in all sensitive data logs;
[0115] The fourth determination unit 224 is configured to determine the second cumulative occurrence count as statistical data for indicating that the API interface transmits the corresponding sensitive data.
[0116] In some embodiments of the present application, as Figure 3 shown, each sensitive data type has a corresponding second count threshold, then the research and judgment module 23 includes:
[0117] The second judgment unit 235 is configured to determine, based on the statistical data, whether the sensitive data transmitted by the API interface includes target sensitive data, where the second cumulative occurrence count of the target sensitive data reaches the corresponding second count threshold of the corresponding sensitive data type; if so, trigger the fifth determination unit 236 to determine that there is a risk of sensitive data leakage in the API interface; if not, trigger the sixth determination unit 237 to determine that there is no risk of sensitive data leakage in the API interface.
[0118] In some embodiments of the present application, as Figure 3 shown, the research and judgment module 23 further includes:
[0119] A second output unit 238, configured to output the corresponding second cumulative occurrence times of the target sensitive data, or output the corresponding second cumulative occurrence times of each sensitive data transmitted by the API interface, after a fifth determination unit 236 determines that there is a risk of sensitive data leakage in the API interface.
[0120] In some embodiments of the present application, as Figure 3 shown, the sensitive data leakage risk judgment device of the API interface further includes:
[0121] A judgment module 24, configured to judge whether the sensitive data log includes sensitive data of a specified sensitive data type before a processing module 22 performs statistical processing on the sensitive data included in the sensitive data log; if so, trigger an elimination module 25 to eliminate the sensitive data of the specified sensitive data type from the corresponding sensitive data log.
[0122] In some embodiments of the present application, as Figure 3 shown, the sensitive data leakage risk judgment device of the API interface further includes:
[0123] A setting module 26, configured to set the statistical processing order of each of the sensitive data logs before the processing module 22 performs statistical processing on the sensitive data included in the sensitive data log if the number of the sensitive data logs is not less than two.
[0124] In the sensitive data leakage risk judgment device of the API interface provided by the embodiments of the present application, the detailed explanations adopted during the operation of each functional module can refer to the corresponding explanations in the above embodiments of the sensitive data leakage risk judgment method of the API interface, which will not be elaborated here.
[0125] Furthermore, an embodiment of the present application further provides a computer-readable storage medium, where the storage medium includes a stored program, and during the running of the program, the device where the storage medium is located is controlled to execute the above-mentioned sensitive data leakage risk judgment method of the API interface.
[0126] Furthermore, an embodiment of the present application further provides an electronic device, where the electronic device includes: a memory for storing a program; a processor coupled to the memory for running the program to execute the above-mentioned sensitive data leakage risk judgment method of the API interface.
[0127] In the above embodiments, the descriptions of the various embodiments have their own focuses. For parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0128] It can be understood that the relevant features in the above methods and devices can be referred to each other. Additionally, the "first", "second", etc. in the above embodiments are used to distinguish the embodiments, rather than representing the superiority or inferiority of each embodiment.
[0129] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0130] The algorithms and displays provided herein are not inherently related to any particular computer, virtual system, or other device. Various general-purpose systems can also be used in conjunction with the teachings herein. The structure required to construct such systems is obvious from the above description. In addition, this application is not directed to any specific programming language. It should be understood that the content of this application described herein can be implemented using various programming languages, and the description of the specific language above is to disclose the preferred embodiments of this application.
[0131] In addition, the memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash RAM, and the memory includes at least one storage chip.
[0132] Those skilled in the art should understand that the embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0133] This application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of this application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows or multiple flows and / or blocks Figure 1 one or more of the blocks or multiple blocks.
[0134] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufacture including an instruction device that implements the functions specified in one or more processes and / or blocks Figure 1 in one or more processes and / or blocks Figure 1 specified in the block or blocks.
[0135] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operational steps are performed on the computer or other programmable device to produce a computer-implemented process, thereby providing steps for implementing the functions specified in one or more processes and / or blocks Figure 1 in one or more processes and / or blocks Figure 1 specified in the block or blocks.
[0136] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0137] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of computer-readable media.
[0138] Computer-readable media includes both permanent and non-permanent, removable and non-removable media implemented by any method or technology for storing information. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0139] It should also be noted that the term "comprise", "include" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.
[0140] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0141] The above are only the embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.
Claims
1. A method for judging the risk of sensitive data leakage in an API interface, characterized in that, The method includes: In response to the existence of an API interface with a risk of sensitive data leakage to be judged, determining sensitive data logs, where the sensitive data logs are traffic logs including sensitive data transmitted by the API interface; Performing statistical processing on the sensitive data included in the sensitive data logs to obtain statistical data; Judging the risk of sensitive data leakage of the API interface based on the statistical data.
2. The method according to claim 1, wherein Performing statistical processing on the sensitive data included in the sensitive data logs includes: Counting the first cumulative occurrence times of sensitive data of the same sensitive data type in all sensitive data logs; Determining the first cumulative occurrence times as statistical data for indicating that the API interface transmits the corresponding sensitive data type.
3. The method according to claim 2, characterized in that Counting the first cumulative occurrence times of sensitive data of the same sensitive data type in all sensitive data logs includes: For each sensitive data existing in the sensitive data logs, detecting whether the sensitive data is sensitive data transmitted by the API interface; if so, keeping the current first cumulative occurrence times of the corresponding sensitive data type unchanged; if not, adding 1 to the current first cumulative occurrence times of the corresponding sensitive data type.
4. The method according to claim 2, wherein Counting the first cumulative occurrence times of sensitive data of the same sensitive data type in all sensitive data logs includes: For each sensitive data existing in the sensitive data logs, determining the sensitive data type of the sensitive data and adding 1 to the current first cumulative occurrence times of the sensitive data type.
5. The method according to claim 2, wherein Each sensitive data type has a corresponding first number threshold. Then, judging the risk of sensitive data leakage of the API interface based on the statistical data includes: Based on the statistical data, judging whether the sensitive data types transmitted by the API interface include a target sensitive data type, where the first cumulative occurrence times of the target sensitive data type reach the corresponding first number threshold; If so, determining that the API interface has a risk of sensitive data leakage; If not, determining that the API interface does not have a risk of sensitive data leakage.
6. The method according to claim 5, wherein The method further includes: After determining that the API interface has a risk of sensitive data leakage, outputting the first cumulative occurrence times corresponding to the target sensitive data type, or outputting the first cumulative occurrence times corresponding to each sensitive data type transmitted by the API interface.
7. The method according to claim 1 or 2, characterized in that, Performing statistical processing on the sensitive data included in the sensitive data logs includes: Counting the second cumulative occurrence times of the same sensitive data in all sensitive data logs; Determining the second cumulative occurrence times as statistical data for indicating that the API interface transmits the corresponding sensitive data.
8. The method according to claim 7, characterized in that Each sensitive data type has a corresponding second number threshold. Then, judging the risk of sensitive data leakage of the API interface based on the statistical data includes: Based on the statistical data, judging whether the sensitive data transmitted by the API interface includes target sensitive data, where the second cumulative occurrence times of the target sensitive data reach the corresponding second number threshold of the corresponding sensitive data type; If included, it is determined that there is a risk of sensitive data breach on the API interface; If not included, it is determined that there is no risk of sensitive data breach on the API interface.
9. The method according to claim 8, wherein The method further comprises: After determining that the API interface has a risk of sensitive data leakage, the corresponding second cumulative number of occurrences of the target sensitive data is output, or the corresponding second cumulative number of occurrences of each sensitive data transmitted by the API interface is output.
10. The method according to any one of claims 1-6, 8-9, characterized in that, Before statistical processing of sensitive data included in the sensitive data log, the method further comprises: Determine whether the sensitive data log includes sensitive data of the specified sensitive data type; If included, sensitive data of the specified sensitive data type is removed from the corresponding sensitive data log; and / or, If the number of the sensitive data logs is not less than two, the method further comprises: Set the statistical processing order for each of the sensitive data logs.
11. A sensitive data leakage risk judgment device for an API interface, characterized in that, The device comprises: A determination module, configured to determine, in response to an API interface having a risk of sensitive data leakage to be determined, a sensitive data log, wherein the sensitive data log is a traffic log including sensitive data transmitted by the API interface; The processing module is used to statistically process the sensitive data included in the sensitive data log to obtain statistical data; The analysis module is used to analyze and judge the risk of sensitive data leakage of the API interface based on the statistical data.
12. A computer-readable storage medium, characterized in that, The storage medium includes a stored program, wherein when the program is running, the device where the storage medium is located is controlled to execute the sensitive data leakage risk assessment method of the API interface described in any one of claims 1 to 10.
13. An electronic device, characterized in that, The electronic device comprises: Memory, used to store programs; A processor coupled to the memory is used to run the program to perform a sensitive data leakage risk analysis method of the API interface as claimed in any one of claims 1 to 10.