Sensitive data identification method and device
By presetting the sensitive tags corresponding to the sensitive fields of the API interface, combined with the cache module and expert rules, the problem of low recognition accuracy of sensitive tags is solved, and more accurate sensitive data protection is achieved.
Patent Information
- Application Number
- CN202410122041.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-29
- Publication Date
- 2025-07-29
AI Technical Summary
In the prior art, when reliing on expert rules to identify sensitive data on API interfaces, there is a problem of low accuracy in identification of sensitive tags, resulting in improper protection of sensitive data and increasing the risk of leakage.
Through the preset API interface, the preset sensitive tags corresponding to the sensitive fields transmitted within the preset period, the preset sensitive tags for the sensitive fields are set in advance, and the cache module and expert rules are combined to identify and match sensitive data to ensure the accuracy of the sensitive tags.
Improve the accuracy of sensitive data identification, reduce the misoperation of sensitive data protection activities, and reduce the risk of sensitive data breaches.
Smart Images

Figure CN120387182A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technologies, and in particular, to a method and device for identifying sensitive data. Background Art
[0002] Interface messages of API interfaces usually involve a large amount of sensitive data. Once the sensitive data is leaked and maliciously used, it will bring serious adverse effects. Therefore, it is necessary to identify the sensitive labels of the sensitive data included in the interface messages (for example, labels such as mobile phone numbers and names that describe the types of sensitive data), so as to carry out corresponding sensitive data protection activities for the sensitive data based on the sensitive labels.
[0003] Currently, it is usually relied on expert rules to identify the sensitive labels of sensitive data. Expert rules are rules formed by summarizing the laws of data, field dictionaries, or text features for identifying sensitive labels. However, limited by the writing level of expert rules, it often occurs that for the same sensitive data in interface messages transmitted by the same API interface at different times, different sensitive label recognition results are given, resulting in a low accuracy of identifying the sensitive labels of sensitive data. Inaccurate identification of sensitive labels will lead to inappropriate sensitive data protection activities for sensitive data, thus bringing the risk of leakage of sensitive data. Summary of the Invention
[0004] In view of this, this application proposes a method and device for identifying sensitive data, and the main purpose is to more accurately determine the sensitive labels of the sensitive data transmitted by the API interface.
[0005] To achieve the above purpose, this application mainly provides the following technical solutions:
[0006] In a first aspect, this application provides a method for identifying sensitive data, and preset sensitive labels corresponding to sensitive fields of at least one API interface, where the preset sensitive labels are obtained based on the sensitive labels corresponding to the transmission of the corresponding sensitive fields by the corresponding API interface within a preset period. The method for identifying sensitive data includes:
[0007] Perform sensitive data identification on the interface message of the API interface to obtain a target sensitive field;
[0008] Match the identified target sensitive field with the sensitive field of the corresponding API interface;
[0009] If the match is successful, it is determined that the sensitive data corresponding to the successfully matched target sensitive field in the interface message has a preset sensitive label.
[0010] In some embodiments of the present application, the sensitive data identification method further includes: if the matching fails, based on the corresponding first expert rule for identifying sensitive tags, determining the sensitive tags of the sensitive data corresponding to the target sensitive field with the matching failure in the interface message.
[0011] In some embodiments of the present application, the sensitive data identification method further includes: obtaining a first interface message transmitted by the API interface within the preset period; performing sensitive field identification on the first interface message; for each identified sensitive field, based on the corresponding second expert rule for identifying sensitive tags, determining the sensitive tags of the sensitive data corresponding to the sensitive field in the corresponding first interface message; based on the determined sensitive tags, counting the first total number of occurrences of each sensitive tag and the second total number of occurrences of all sensitive tags; based on the first total number and the second total number, determining the first occurrence probability corresponding to each sensitive tag; and determining the preset sensitive tag corresponding to the sensitive field as the first sensitive tag corresponding to the maximum first occurrence probability.
[0012] In some embodiments of the present application, the sensitive data identification method further includes: obtaining a second interface message transmitted by the API interface within a new preset period; for each of the sensitive fields, based on the corresponding third expert rule for identifying sensitive tags, determining the sensitive tags of the sensitive data corresponding to the sensitive field in the corresponding second interface message; based on the determined sensitive tags, counting the third total number of occurrences of each sensitive tag and the fourth total number of occurrences of all sensitive tags, and determining the second occurrence probability corresponding to each sensitive tag; determining whether the second sensitive tag corresponding to the maximum second occurrence probability in the second occurrence probabilities is the same as the preset sensitive tag corresponding to the sensitive field; if not, updating the second sensitive tag to the preset sensitive tag corresponding to the sensitive field; if so, keeping the preset sensitive tag corresponding to the sensitive field unchanged.
[0013] In some embodiments of the present application, after determining the maximum second occurrence probability, the sensitive data identification method further includes: determining whether the maximum second occurrence probability is greater than the maximum first occurrence probability when determining the first sensitive tag corresponding to the sensitive field; if it is greater, performing the step of determining whether the second sensitive tag corresponding to the maximum second occurrence probability in the second occurrence probabilities is the same as the
[0014] preset sensitive tag corresponding to the sensitive field; if it is not greater, keeping the preset sensitive tag corresponding to the sensitive field unchanged.
[0015] In some embodiments of the present application, based on the first total number and the second total number, determining the first occurrence probability corresponding to each sensitive tag includes: for each of the sensitive tags, determining the ratio between the corresponding first total number and the second total number as the first occurrence probability corresponding to the sensitive tag.
[0016] In some embodiments of the present application, after identifying sensitive fields in the first interface message, the sensitive data identification method further includes: removing sensitive fields located at non-specified positions in the first interface message.
[0017] In some embodiments of the present application, the preset sensitive tags corresponding to the sensitive fields of at least one API interface are stored through a cache module. Then, matching the identified target sensitive fields with the preset sensitive fields includes: determining whether the identified target sensitive fields hit the preset sensitive tags corresponding to the sensitive fields stored in the cache module; if a hit occurs, determining that the matching is successful; if no hit occurs, determining that the matching fails.
[0018] In some embodiments of the present application, if the sensitive fields and the corresponding sensitive data exist in the interface message in a key-value pair structure, then, identifying sensitive fields in the interface message of the API interface to obtain target sensitive fields includes: parsing the interface message to obtain the target key-value pair structure located at a specified position in the interface message, where the specified position includes at least one of the following: request body, response body; identifying the field corresponding to the key in the target key-value pair structure as the target sensitive field.
[0019] In a second aspect, the present application provides a sensitive data identification device that presets preset sensitive tags corresponding to sensitive fields of at least one API interface, where the preset sensitive tags are obtained based on the sensitive tags corresponding to the transmission of the corresponding sensitive fields by the corresponding API interface within a preset period. The sensitive data identification device includes:
[0020] An identification module, configured to identify sensitive fields in the interface message of the API interface to obtain target sensitive fields;
[0021] A matching module, configured to match the identified target sensitive fields with the sensitive fields of the corresponding API interface;
[0022] A determination module, configured to, if the matching module matches successfully, determine that the sensitive data corresponding to the successfully matched target sensitive fields in the interface message has a preset sensitive tag.
[0023] In a third aspect, the present application provides a computer-readable storage medium, where the storage medium includes a stored program. When the program runs, it controls the device where the storage medium is located to execute the sensitive data identification method of the first aspect.
[0024] In a fourth aspect, the present application provides an electronic device, which includes: a memory for storing a program; and a processor coupled to the memory for running the program to execute the sensitive data identification method of the first aspect.
[0025] For the sensitive data identification method and device provided by the present application, one or more preset sensitive labels corresponding to sensitive fields of API interfaces are preset in advance. The preset sensitive labels are obtained based on the sensitive labels corresponding to the transmission of the corresponding sensitive fields by the corresponding API interfaces within a preset period. When it is necessary to identify sensitive data of an API interface, the interface message of the API interface is identified for sensitive data to obtain target sensitive fields. The identified target sensitive fields are matched with the sensitive fields of the corresponding API interface. If the match is successful, it is determined that the sensitive data corresponding to the successfully matched target sensitive field in the interface message has a preset sensitive label. It can be seen that the solution provided by the present application presets in advance the preset sensitive labels corresponding to the sensitive fields of the API interfaces. In this way, when determining the sensitive labels of the sensitive data in the interface message, it no longer directly depends on expert rules, but based on the prior knowledge of the preset sensitive labels corresponding to the sensitive fields of the API interfaces preset in advance, the sensitive labels of the sensitive data transmitted by the API interfaces can be accurately determined.
[0026] The above description is only an overview of the technical solution of the present application. In order to be able to understand the technical means of the present application more clearly, it can be implemented according to the content of the description. And in order to make the above and other purposes, features and advantages of the present application more obvious and understandable, the following specifically illustrates the specific embodiments of the present application. Description of the Drawings
[0027] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0028] Figure 1 Shows a flowchart of a sensitive data identification method provided by an embodiment of the present application;
[0029] Figure 2 Shows a schematic structural diagram of a sensitive data identification device provided by an embodiment of the present application;
[0030] Figure 3 Shows a schematic structural diagram of a sensitive data identification device provided by another embodiment of the present application. Detailed Embodiments
[0031] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present disclosure can be more thoroughly understood and the scope of the present disclosure can be fully conveyed to those skilled in the art.
[0032] Currently, it is generally dependent on expert rules to identify sensitive tags of sensitive data included in interface messages of API interfaces. However, limited by the writing level of expert rules, for the same sensitive data in interface messages transmitted by the same API interface on different occasions, different sensitive tag identification results are often given. Exemplarily, relying on expert rules, the sensitive tag of the sensitive data "12345678936" in interface message 1 transmitted by API interface 1 is identified as a mobile phone number. Relying on expert rules, the sensitive tag of the sensitive data "12345678936" in interface message 2 transmitted by API interface 1 is identified as an ID number. It can be seen that different sensitive tag identification results are given for the same sensitive data "12345678936" in interface messages transmitted by API interface 1 on different occasions. It can be seen that when identifying sensitive data currently, the accuracy of identifying sensitive tags of sensitive data is low. Low accuracy of sensitive tag identification will lead to inappropriate sensitive data protection activities for sensitive data, thus bringing the risk of leakage of sensitive data.
[0033] The inventors have found through research that the interface messages transmitted by API interfaces are usually semi-structured data in formats such as xml, json, form, etc. In such semi-structured data, the sensitive data transmitted by the API and the corresponding sensitive fields exist in the interface message in a key-value pair structure, and the sensitive fields are used to describe the meaning of the corresponding sensitive data. For the same API interface, within a preset period, the sensitive tags of the sensitive data corresponding to the same sensitive field in the interface messages it transmits are usually unchanged. Therefore, the inventors considered that one or more preset sensitive tags corresponding to the sensitive fields of an API interface can be preset in advance based on the sensitive tags corresponding to the transmission of the corresponding sensitive fields by the API interface within a preset period. In this way, when it is necessary to identify sensitive data of an API interface, first identify the sensitive data of the interface message of the API interface to obtain the target sensitive field. Then, match the identified target sensitive field with the sensitive field of the corresponding API interface. If the match is successful, it is determined that the sensitive data corresponding to the successfully matched target sensitive field in the interface message has a preset sensitive tag. In this way, when identifying the sensitive tags of sensitive data in the interface message, instead of directly relying on expert rules, based on the prior knowledge of the preset sensitive tags corresponding to the sensitive fields of the API interface preset in advance, the sensitive tags of the sensitive data transmitted by the API interface can be accurately determined.
[0034] Based on the above considerations, the embodiments of the present application specifically provide a technical solution for sensitive data recognition, which is as follows: preset at least one preset sensitive label corresponding to the sensitive field of the API interface, and the preset sensitive label is obtained based on the sensitive label corresponding to the transmission of the corresponding sensitive field by the corresponding API interface within a preset period. Perform sensitive data recognition on the interface message of the API interface to obtain the target sensitive field. Match the identified target sensitive field with the sensitive field of the corresponding API interface. If the match is successful, it is determined that the sensitive data corresponding to the successfully matched target sensitive field in the interface message has a preset sensitive label.
[0035] The technical solution for sensitive data recognition provided by this embodiment can be applied to any software product to recognize the sensitive label of the sensitive data included in the interface message transmitted by the API interface of the software product. The type of the software product is not limited in this embodiment.
[0036] Based on the above technical solution for sensitive data recognition, this embodiment specifically provides a sensitive data recognition method and device. The following specifically describes the sensitive data recognition method and device provided by this embodiment.
[0037] As Figure 1 shown, the embodiments of the present application provide a sensitive data recognition method, and the sensitive data recognition method may include the following steps 101 to 103:
[0038] 101. Perform sensitive data recognition on the interface message of the API interface to obtain the target sensitive field.
[0039] The API interface is an API interface that needs to protect sensitive data. It can be an API interface with a unique API asset number in any software product. The type of the software product is not specifically limited in this embodiment. The interface message of the API interface is semi-structured data in formats such as xml, json, and form. In such semi-structured data, the sensitive data transmitted by the API interface and the corresponding sensitive fields exist in the interface message in a key-value pair structure, and the sensitive fields are used to describe the meaning of the corresponding sensitive data. Exemplarily, the sensitive field is patName, which is used to describe the corresponding sensitive data as the patient's name.
[0040] When the interface message of the API interface is obtained, perform sensitive data recognition on the interface message to obtain the target sensitive field included in the interface message, so as to clarify the sensitive label of the corresponding sensitive data in the interface message based on the target sensitive field.
[0041] The method for performing sensitive data recognition on the interface message of the API interface to obtain the target sensitive field may at least include the following two types:
[0042] First, the specific process of identifying sensitive data in the interface message of the API interface to obtain the target sensitive fields may include the following steps: Use the interface message as the input of a preset sensitive field identification model, and identify the sensitive fields in the interface message through the preset sensitive field identification model; Obtain the identification result output by the preset sensitive field identification model to obtain the sensitive fields included in the interface message. The preset sensitive field identification model is a neural network model that has been pre-trained to identify sensitive fields in interface messages. Further, the preset sensitive field identification model can also specifically specify to identify sensitive fields at specified positions in the interface message, and the specified positions include at least one of the following: request body, response body.
[0043] Second, if the sensitive fields and the corresponding sensitive data exist in the interface message in a key-value pair structure, then the specific process of identifying sensitive data in the interface message of the API interface to obtain the target sensitive fields may include the following steps: Parse the interface message to obtain the target key-value pair structure located at the specified position in the interface message, and the specified positions include at least one of the following: request body, response body; Identify the field corresponding to the key in the target key-value pair structure as the target sensitive field.
[0044] For an API interface, the importance of sensitive data at different positions in its interface message is different. Therefore, in order to be able to protect sensitive data at certain positions in a targeted manner, specified positions can be preset so that only sensitive fields at the specified positions are identified during sensitive data identification. This can not only identify the sensitive fields corresponding to the sensitive data that needs to be protected with emphasis, but also avoid identifying unnecessary sensitive fields and reduce the identification consumption.
[0045] The sensitive fields and the corresponding sensitive data exist in the interface message in a key-value pair structure, where the field corresponding to the key is the sensitive field and the field corresponding to the value is the sensitive data. After determining the specified position, locate the specified position in the interface message and obtain the target key-value pair structure located at the specified position in the interface message, and identify the field corresponding to the key in the target key-value pair structure as the target sensitive field.
[0046] Exemplarily, Table-1 shows the data included in the interface message of an API interface. It can be seen from Table-1 that the interface message includes the API asset code, data format, content data of the API interface, and the position of the content data in the interface message.
[0047] Table-1
[0048]
[0049] After identifying sensitive data in the interface message of the API interface, the target sensitive fields patName and contact are obtained.
[0050] 102. Match the identified target sensitive fields with the sensitive fields of the corresponding API interface.
[0051] For the same API interface, the sensitive label of the sensitive data corresponding to the same sensitive field in the interface messages transmitted within a preset period is usually unchanged. Therefore, in this embodiment, based on the invariance of the sensitive label within the preset period, one or more preset sensitive labels corresponding to the sensitive fields of the API interface are preset in advance based on the sensitive labels corresponding to the transmission of the corresponding sensitive fields by the API interface within the preset period. The preset sensitive label is obtained based on the sensitive label corresponding to the transmission of the corresponding sensitive field by the corresponding API interface within the preset period. In this way, after identifying the target sensitive field, the target sensitive field is matched with the prior knowledge of the sensitive fields of the corresponding API interface to determine whether the target sensitive field is a sensitive field with a corresponding preset sensitive label. Once it is determined that the target sensitive field is a sensitive field with a corresponding preset sensitive label, it is determined that the sensitive data corresponding to the target sensitive field in the interface message has the preset sensitive label corresponding to the corresponding sensitive field.
[0052] In this embodiment, the preset sensitive labels corresponding to the sensitive fields of at least one preset API interface are stored in the cache module to facilitate the matching operation using the preset sensitive labels corresponding to the sensitive fields of the API interface. The specific process of matching the identified target sensitive fields with the preset sensitive fields may include: determining whether the identified target sensitive field hits the preset sensitive label corresponding to the sensitive field stored in the cache module; if it hits, determining that the match is successful; if it does not hit, determining that the match fails.
[0053] For a target sensitive field, if the target sensitive field hits the preset sensitive label corresponding to the sensitive field stored in the cache module, it means that the target sensitive field is stored in the cache module and has the corresponding preset sensitive label, so it is determined that the target sensitive field match is successful. If the target sensitive field does not hit the preset sensitive label corresponding to the sensitive field stored in the cache module, it means that the sensitive field is not stored in the cache module, so it is determined that the target sensitive field match fails.
[0054] 103. If the match is successful, determine that the sensitive data corresponding to the successfully matched target sensitive field in the interface message has a preset sensitive label.
[0055] If the matching is successful, it indicates that there are corresponding prior conclusions for the sensitive labels corresponding to the target sensitive fields that match successfully, specifically the preset sensitive labels corresponding to the corresponding preset sensitive fields. Therefore, in order to accurately and quickly determine the sensitive labels of the sensitive data corresponding to the target sensitive fields in the interface message, after the matching is successful, it is determined that the sensitive data corresponding to the target sensitive fields that match successfully in the interface message has the preset sensitive labels corresponding to the corresponding preset sensitive fields.
[0056] The sensitive data recognition method provided by the embodiments of the present application pre-sets preset sensitive labels corresponding to the sensitive fields of one or more API interfaces. The preset sensitive labels are obtained based on the sensitive labels corresponding to the transmission of the corresponding sensitive fields by the corresponding API interfaces within a preset period. When it is necessary to recognize sensitive data for an API interface, the interface message of the API interface is recognized for sensitive data to obtain target sensitive fields. The recognized target sensitive fields are matched with the sensitive fields of the corresponding API interface. If the matching is successful, it is determined that the sensitive data corresponding to the target sensitive fields that match successfully in the interface message has preset sensitive labels. It can be seen that the solution provided by the embodiments of the present application pre-sets the preset sensitive labels corresponding to the sensitive fields of the API interface in advance. In this way, when determining the sensitive labels of the sensitive data in the interface message, it no longer directly depends on expert rules, but based on the prior knowledge of the preset sensitive labels corresponding to the sensitive fields of the API interface in advance, the sensitive labels of the sensitive data transmitted by the API interface can be accurately determined.
[0057] In some embodiments of the present application, considering the limitations of the prior knowledge of the preset sensitive labels corresponding to the sensitive fields of the preset API interfaces, which may not comprehensively cover all the sensitive fields included in the interface messages of the API interfaces. Therefore, in order to be able to determine the sensitive labels of the sensitive data corresponding to the sensitive fields not covered by the prior knowledge, the sensitive data recognition method may further include the following steps: If the matching fails, then based on the corresponding first expert rule for recognizing sensitive labels, determine the sensitive labels of the sensitive data corresponding to the target sensitive fields that fail to match in the interface message.
[0058] In order to be able to determine the sensitive fields of the sensitive data corresponding to each target sensitive field in the interface message, after the above step 102, if the target sensitive field fails to match the sensitive field of the corresponding API interface, then based on the corresponding first expert rule for recognizing sensitive labels, determine the sensitive labels of the sensitive data corresponding to the target sensitive fields that fail to match in the interface message. The first expert rule is a rule for recognizing sensitive labels formed by inducing the laws of data, field dictionaries, or text features.
[0059] For a target sensitive field that fails to match the sensitive field of the corresponding API interface, the determination method of its corresponding first expert rule can include the following two types: One is to use a unified expert rule to identify sensitive tags, and then determine the unified expert rule as the first expert rule corresponding to the target sensitive field that fails to match. The other is to preset at least one expert rule, each expert rule having a corresponding sensitive field, and the expert rule is applicable to determining sensitive tags for sensitive data of the corresponding sensitive field. Determine the expert rule corresponding to the target sensitive field that fails to match as the first expert rule corresponding to the target sensitive field that fails to match.
[0060] After determining the corresponding first expert rule, based on the corresponding first expert rule, determine the sensitive tag of the sensitive data corresponding to the target sensitive field that fails to match in the interface message. In this way, even if the target sensitive field fails to match the prior sensitive field of the corresponding API interface, the sensitive tag of the sensitive data corresponding to the target sensitive field in the interface message can be determined through the corresponding first expert rule, which will not affect the subsequent corresponding sensitive data protection activities for the sensitive data.
[0061] In some embodiments of the present application, in order to be able to preset the preset sensitive tags corresponding to the sensitive fields of at least one API interface for use in identifying the sensitive tags of the sensitive data in the interface message of the API interface, the sensitive data identification method may further include the following steps 104 to 106:
[0062] 104. Obtain the first interface message transmitted by the API interface within a preset period.
[0063] In this embodiment, there are many API interfaces in the software product, and it is necessary to select in advance the API interfaces for which the preset sensitive tags corresponding to the sensitive fields need to be preset. After selecting the API interfaces, steps 104 to 106 are executed for each API interface to preset the preset sensitive tags corresponding to the sensitive fields of each API interface.
[0064] For an API interface, the sensitive tags of the sensitive data corresponding to the same sensitive field in the interface message transmitted within the preset period are usually unchanged. Therefore, in this embodiment, based on the invariance of the sensitive tags of the sensitive data corresponding to the same sensitive field within the preset period, the first interface message transmitted by the API interface within the preset period is obtained to preset the preset sensitive tags corresponding to the sensitive fields of the API interface based on the sensitive tags corresponding to the sensitive fields in the first interface message.
[0065] 105. Identify the sensitive fields in the first interface message.
[0066] The method for identifying the sensitive fields in the first interface message can include at least the following three types:
[0067] First, the specific process of identifying sensitive fields in the first interface message may include the following steps: Use the first interface message as the input of a preset sensitive field identification model, and identify the sensitive fields in the first interface message through the preset sensitive field identification model; Obtain the identification result output by the preset sensitive field identification model to obtain the sensitive fields included in the first interface message. The preset sensitive field identification model is a neural network model that has been pre-trained to identify sensitive fields in interface messages. Further, the preset sensitive field identification model can also specifically specify to identify sensitive fields at specified positions in the interface message, and the specified positions include at least one of the following: request body, response body.
[0068] Second, if the sensitive fields and the corresponding sensitive data exist in the interface message in a key-value pair structure, then the specific process of identifying sensitive fields in the first interface message may include the following steps: Parse the first interface message to obtain the target key-value pair structure located at the specified position in the first interface message, and the specified positions include at least one of the following: request body, response body; Identify the field corresponding to the key in the target key-value pair structure as the target sensitive field.
[0069] Third, the specific process of identifying sensitive fields in the first interface message may include the following steps: Obtain the configuration information of the API interface, and the configuration information is used to record the sensitive fields corresponding to the API interface; Determine the sensitive fields recorded in the configuration information as the sensitive fields included in the first interface message.
[0070] After the API interface is developed, corresponding configuration information will be set for it to use and maintain the API interface through the configuration information. The configuration information records the sensitive fields corresponding to the API interface so that the API interface can perform corresponding sensitive data transmission based on the sensitive fields. Therefore, the sensitive fields included in the first interface message can be identified based on the corresponding configuration information of the API interface. Further, identify the sensitive fields at the specified positions in the interface message through the configuration information, and the specified positions include at least one of the following: request body, response body.
[0071] The above three methods for identifying sensitive fields in the first interface message can be used alone or in combination. When used in combination, the three methods have the functions of mutual verification and complementation to more accurately identify the sensitive fields included in the first interface message.
[0072] Furthermore, since the importance of sensitive data at different locations in the API interface message is different, in order to provide targeted protection for sensitive data at certain locations, a designated location can be preset so that only sensitive data in sensitive fields at designated locations are subject to sensitive label identification during sensitive data identification. Therefore, after identifying the sensitive fields of the first interface message, the sensitive data identification method may further include the following steps: removing sensitive fields at non-designated locations in the first interface message to avoid additional sensitive label identification of sensitive data corresponding to the sensitive fields at these non-designated locations. Designated locations may include, but are not limited to, request bodies and response bodies.
[0073] 106. For each identified sensitive field, perform the following steps 106A to 106D:
[0074] 106A. Based on the corresponding second expert rule for identifying sensitivity labels, determine the sensitivity label of the sensitive data corresponding to the sensitive field in the corresponding first interface message.
[0075] The second expert rule is a rule for identifying sensitive labels formed by summarizing data patterns, field dictionaries, or text features. For a sensitive field, there are two methods for determining the corresponding second expert rule: one is to use a unified expert rule to identify sensitive labels, and then determine the unified expert rule as the second expert rule corresponding to the sensitive field. The other is to preset at least one expert rule, each expert rule has a corresponding sensitive field, and the expert rule is applicable to determining sensitive labels for sensitive data in the corresponding sensitive field. The expert rule corresponding to the sensitive field is determined as the second expert rule corresponding to the sensitive field.
[0076] After determining the second expert rule corresponding to the sensitive field, the sensitivity label of the sensitive data corresponding to the sensitive field in the corresponding first interface message is determined based on the corresponding second expert rule. The purpose of determining the sensitivity label of the sensitive data corresponding to the sensitive field in the corresponding first interface message based on the corresponding second expert rule for identifying the sensitivity label is to take into account the limitations of the writing level of the expert rules, and the reliance on the expert rules to determine the sensitivity label of the sensitive data has a certain false positive rate. By determining the sensitive labels of the sensitive data corresponding to the sensitive fields in a large number of first interface messages, the false positive rate of the sensitivity labels of the sensitive data corresponding to the sensitive fields in the interface messages can be clarified.
[0077] 106B. Based on the determined sensitive labels, count a first total number of occurrences of each sensitive label and a second total number of occurrences of all sensitive labels.
[0078] For the same sensitive label, the total number of times it appears among the identified sensitive labels reflects the recognition of the sensitive label of the sensitive data corresponding to the sensitive field by the second expert rule. Therefore, among the determined sensitive labels, count the first total number of times each sensitive label appears and the second total number of times all sensitive labels appear, so as to clarify the recognition of the sensitive label of the sensitive data corresponding to the sensitive field by the second expert rule based on the corresponding first total number of times and second total number of times of each sensitive label.
[0079] 106C. Based on the first total number of times and the second total number of times, determine the first appearance probability corresponding to each sensitive label.
[0080] The specific process of determining the first appearance probability corresponding to each sensitive label based on the first total number of times and the second total number of times may include: for each sensitive label, determine the ratio between the corresponding first total number of times and the second total number of times as the first appearance probability corresponding to the sensitive label. The first appearance probability is used to reflect the probability that the second expert rule recognizes the sensitive data corresponding to the sensitive field as the corresponding sensitive label.
[0081] Exemplarily, for the API interfaces shown in Table - 1, based on the corresponding second expert rule for identifying sensitive labels, determine the sensitive labels of the sensitive data corresponding to the sensitive field "contact" in each first interface message within the preset period. Among the determined sensitive labels, count that the first total number of times the sensitive label "phone number" appears is C1, and the first total number of times the sensitive label "ID number" appears is C2. The second total number of times all sensitive labels appear is "C = C1 + C2". Determine that the first appearance probability corresponding to the sensitive label "phone number" is "P1 = C1 / C", and determine that the first appearance probability corresponding to the sensitive label "ID number" is "P2 = C2 / C".
[0082] 106D. Determine the first sensitive label corresponding to the maximum first appearance probability among the first appearance probabilities as the preset sensitive label corresponding to the sensitive field.
[0083] The greater the first appearance probability, the greater the probability that the sensitive data corresponding to the sensitive field in the corresponding first interface message is recognized as having the corresponding sensitive label. Therefore, determine the maximum first appearance probability among the first appearance probabilities as the preset sensitive label corresponding to the sensitive field.
[0084] For example, for the sensitive field "contact", the first occurrence probability corresponding to the sensitive label "mobile phone number" is "P1=C1 / C", and the first occurrence probability corresponding to the sensitive label "ID number" is determined to be "P2=C2 / C". Then, through the determination of the function MAX(P1, P2), P1 is the maximum first occurrence probability, and the sensitive label "mobile phone number" corresponding to P1 is determined as the preset sensitive label corresponding to the sensitive field "contact".
[0085] It can be seen from the above steps 104 to 106 that this embodiment fully utilizes the invariance of the sensitive labels of the sensitive data corresponding to the same sensitive field of the same API interface within a preset period, and presets prior knowledge such as preset sensitive labels corresponding to the sensitive fields of one or more API interfaces to assist in determining the sensitive labels of the sensitive data in the interface message of the API interface. This not only can more accurately determine the sensitive labels of the sensitive data transmitted by the API interface, but also can improve the efficiency of determining the sensitive labels.
[0086] In some embodiments of the present application, in order to continuously improve the preset sensitivity labels corresponding to the sensitive fields of the API interface, the sensitive data identification method may further include the following steps 107 to 108:
[0087] 107. Obtain a second interface message transmitted by the API interface within a new preset period.
[0088] In order to continuously improve the preset sensitive labels corresponding to the sensitive fields of the API interface, so that the preset sensitive labels corresponding to the sensitive fields are more closely aligned with the real sensitive labels corresponding to the sensitive fields transmitted by the corresponding API interface, the preset sensitive labels corresponding to the sensitive fields of the API interface can be continuously updated based on the changes in the preset period.
[0089] When updating the preset sensitive label corresponding to the sensitive field of the API interface, it is necessary to obtain the second interface message transmitted by the API interface within a new preset period to update the preset sensitive label corresponding to the sensitive field based on the identification result of the sensitive label corresponding to the sensitive field in the second interface message.
[0090] 108. For each sensitive field, perform the following steps 108A to 108D:
[0091] 108A. Based on the corresponding third expert rule for identifying sensitivity labels, determine the sensitivity label of the sensitive data corresponding to the sensitive field in the corresponding second interface message.
[0092] The third expert rule is the rule newly formed by inducing the laws of data, field dictionaries, or text features for identifying sensitive tags. It is the latest rule refined over time to ensure more accurate determination of sensitive tags. For a sensitive field, the method for determining its corresponding third expert rule can refer to the method for determining the first expert rule or the second expert rule, so it will not be elaborated here.
[0093] After determining the corresponding third expert rule, determine the sensitive tags of the sensitive data corresponding to the sensitive field in the corresponding second interface message based on the corresponding third expert rule. The purpose of determining the sensitive tags of the sensitive data corresponding to the sensitive field in the corresponding second interface message based on the corresponding third expert rule is that, considering the limitations of the writing level of expert rules, there is a certain false positive rate in determining the sensitive tags of sensitive data relying on expert rules. By determining the sensitive tags of the sensitive data corresponding to the sensitive field in a large number of second interface messages, clarify the false positive situation of the sensitive tags of the sensitive data corresponding to the sensitive field in the interface message.
[0094] 108B. Based on the determined sensitive tags, count the third total number of times each sensitive tag appears and the fourth total number of times all sensitive tags appear, and determine the second occurrence probability corresponding to each sensitive tag.
[0095] For the same sensitive tag, the total number of times it appears among the identified sensitive tags reflects the recognition of the sensitive tags of the sensitive data corresponding to the sensitive field by the third expert rule. Therefore, among the determined sensitive tags, count the third total number of times each sensitive tag appears and the fourth total number of times all sensitive tags appear, so as to clarify the recognition of the sensitive tags of the sensitive data corresponding to the sensitive field by the third expert rule based on the corresponding third total number of times and fourth total number of times of each sensitive tag.
[0096] 108C. Judge whether the second sensitive tag corresponding to the maximum second occurrence probability in the second occurrence probability is the same as the preset sensitive tag corresponding to the sensitive field; if not, update the second sensitive tag to the preset sensitive tag corresponding to the sensitive field; if so, keep the preset sensitive tag corresponding to the sensitive field unchanged.
[0097] Judge whether the second sensitive tag corresponding to the maximum second occurrence probability in the second occurrence probability is the same as the preset sensitive tag corresponding to the sensitive field to clarify whether the preset sensitive tag corresponding to the sensitive field needs to be updated.
[0098] If it is determined that the second sensitive label corresponding to the maximum second occurrence probability in the second occurrence probabilities is the same as the preset sensitive label corresponding to the sensitive field, it indicates that the recognition of the sensitive label of the sensitive field this time is consistent with the previous recognition result, the preset sensitive label corresponding to the sensitive field is determined relatively accurately, and the preset sensitive label corresponding to the sensitive field does not need to be updated. Therefore, the preset sensitive label corresponding to the sensitive field remains unchanged.
[0099] If it is determined that the second sensitive label corresponding to the maximum second occurrence probability in the second occurrence probabilities is different from the preset sensitive label corresponding to the sensitive field, it indicates that the recognition of the sensitive label of the sensitive field this time is inconsistent with the previous recognition result. Considering that the third expert rule used to recognize the sensitive label of the sensitive field this time is usually optimized compared to the expert rule used to recognize the sensitive label of the sensitive field previously, and the sensitive label recognized by it is more credible. Therefore, the second sensitive label corresponding to the maximum second occurrence probability is updated to the preset sensitive label corresponding to the sensitive field.
[0100] Furthermore, considering that there may be a certain false alarm probability in the recognition of the sensitive label of the sensitive field by any expert rule, after determining the maximum second occurrence probability, the sensitive data recognition method may further include the following steps: determining whether the maximum second occurrence probability is greater than the maximum first occurrence probability when determining the first sensitive label corresponding to the sensitive field; if it is greater, then execute the step of determining whether the second sensitive label corresponding to the maximum second occurrence probability in the second occurrence probabilities is the same as the preset sensitive label corresponding to the sensitive field; if it is not greater, then keep the preset sensitive label corresponding to the sensitive field unchanged.
[0101] If it is determined that the maximum second occurrence probability is greater than the maximum first occurrence probability when determining the first sensitive label corresponding to the sensitive field, it indicates that the accuracy of the recognition of the sensitive label of the sensitive field this time is higher than the previous recognition result. At this time, the step of determining whether the second sensitive label corresponding to the maximum second occurrence probability in the second occurrence probabilities is the same as the preset sensitive label corresponding to the sensitive field can be executed to further clarify whether to update the preset sensitive label corresponding to the sensitive field based on the sameness of the sensitive labels.
[0102] If it is determined that the maximum second occurrence probability is not greater than the maximum first occurrence probability when determining the first sensitive label corresponding to the sensitive field, it indicates that the accuracy of the recognition of the sensitive label of the sensitive field this time is not higher than the previous recognition result, and the recognition result this time may be inaccurate. Therefore, the preset sensitive label corresponding to the sensitive field remains unchanged.
[0103] Further, to facilitate the update of the preset sensitive labels corresponding to the sensitive fields of the API interfaces, after presetting the sensitive labels corresponding to the sensitive fields of at least one API interface, the occurrence probability of the preset sensitive labels corresponding to the sensitive fields of at least one API interface can also be recorded. The purpose of recording is to explain the preset reasons for the preset sensitive labels corresponding to the sensitive fields of the API interfaces with the corresponding occurrence probabilities. The recording can be based on a map structure. The map structure includes a key name, a preset sensitive label, and an occurrence probability.
[0104] Exemplarily, as shown in Table-2, the key name in Table-2 is composed of the API asset code of the API interface and the corresponding sensitive field.
[0105] Table-2
[0106]
[0107]
[0108] Further, another embodiment of the present application also provides a sensitive data recognition device, which presets sensitive labels corresponding to sensitive fields of at least one API interface. The preset sensitive labels are obtained based on the sensitive labels corresponding to the transmission of the corresponding sensitive fields by the corresponding API interfaces within a preset period. As Figure 2 shown, the sensitive data recognition device includes:
[0109] An identification module 21, configured to identify sensitive fields in the interface message of the API interface to obtain target sensitive fields;
[0110] A matching module 22, configured to match the identified target sensitive fields with the sensitive fields of the corresponding API interface;
[0111] A determination module 23, configured to, if the matching module matches successfully, determine that the sensitive data corresponding to the successfully matched target sensitive field in the interface message has a preset sensitive label.
[0112] The sensitive data recognition device provided by the embodiment of the present application pre-sets preset sensitive tags corresponding to sensitive fields of one or more API interfaces. The preset sensitive tags are obtained based on the sensitive tags corresponding to the transmission of the corresponding sensitive fields by the corresponding API interfaces within a preset period. When it is necessary to recognize sensitive data of an API interface, sensitive data recognition is performed on the interface message of the API interface to obtain target sensitive fields. The recognized target sensitive fields are matched with the sensitive fields of the corresponding API interface. If the match is successful, it is determined that the sensitive data corresponding to the successfully matched target sensitive field in the interface message has a preset sensitive tag. It can be seen that the solution provided by the embodiment of the present application pre-sets the preset sensitive tags corresponding to the sensitive fields of the API interface in advance. In this way, when determining the sensitive tags of the sensitive data in the interface message, it no longer directly depends on expert rules, but can accurately determine the sensitive tags of the sensitive data transmitted by the API interface based on the prior knowledge of the preset sensitive tags corresponding to the sensitive fields of the API interface preset in advance.
[0113] In some embodiments of the present application, as Figure 3 shown, the determination module 23 is further configured to, if the matching module 22 fails to match, determine the sensitive tag of the sensitive data corresponding to the target sensitive field that fails to match in the interface message based on the corresponding first expert rule for identifying sensitive tags.
[0114] In some embodiments of the present application, as Figure 3 shown, the sensitive data recognition device further includes:
[0115] The first acquisition module 24 is configured to acquire a first interface message transmitted by the API interface within the preset period and perform sensitive field recognition on the first interface message;
[0116] The setting module 25 is configured to, for each identified sensitive field of the first acquisition module 24, determine the sensitive tag of the sensitive data corresponding to the sensitive field in the corresponding first interface message based on the corresponding second expert rule for identifying sensitive tags; based on the determined sensitive tags, count the first total number of occurrences of each sensitive tag and the second total number of occurrences of all sensitive tags; based on the first total number and the second total number, determine the first occurrence probability corresponding to each sensitive tag; and determine the first sensitive tag corresponding to the maximum first occurrence probability among the first occurrence probabilities as the preset sensitive tag corresponding to the sensitive field.
[0117] In some embodiments of the present application, as Figure 3 shown, the sensitive data recognition device further includes:
[0118] The second acquisition module 26 is configured to acquire a second interface message transmitted by the API interface within a new preset period;
[0119] An update module 27, configured to, for each of the sensitive fields, determine, based on a third expert rule for identifying sensitive labels, a sensitive label of sensitive data corresponding to the sensitive field in a corresponding second interface message; based on the determined sensitive label, count a third total number of occurrences of each sensitive label and a fourth total number of occurrences of all sensitive labels, and determine a second occurrence probability corresponding to each sensitive label; determine whether a second sensitive label corresponding to a maximum second occurrence probability among the second occurrence probabilities is the same as a preset sensitive label corresponding to the sensitive field; if not, update the second sensitive label to the preset sensitive label corresponding to the sensitive field; if so, keep the preset sensitive label corresponding to the sensitive field unchanged.
[0120] In some embodiments of the present application, as Figure 3 shown, the update module 27 is further configured to, after determining the maximum second occurrence probability, determine whether the maximum second occurrence probability is greater than a maximum first occurrence probability when determining a first sensitive label corresponding to the sensitive field; if it is greater, execute the step of determining whether a second sensitive label corresponding to the maximum second occurrence probability among the second occurrence probabilities is the same as a preset sensitive label corresponding to the sensitive field; if it is not greater, keep the preset sensitive label corresponding to the sensitive field unchanged.
[0121] In some embodiments of the present application, as Figure 3 shown, the setting module 25 is specifically configured to, for each of the sensitive labels, determine a ratio between a corresponding first total number and the second total number as a first occurrence probability corresponding to the sensitive label.
[0122] In some embodiments of the present application, as Figure 3 shown, the first obtaining module 24 is further configured to, after identifying sensitive fields in the first interface message, remove sensitive fields located at non-specified positions in the first interface message.
[0123] In some embodiments of the present application, as Figure 3 shown, the sensitive data identification device further includes:
[0124] A cache module 28, configured to store preset sensitive labels corresponding to sensitive fields of the at least one API interface;
[0125] Then, the matching module 22 is specifically configured to determine whether a recognized target sensitive field hits a preset sensitive label corresponding to a sensitive field stored in the cache module; if it hits, determine that the matching is successful; if it does not hit, determine that the matching fails.
[0126] In some embodiments of the present application, as Figure 3As shown, the sensitive fields and the corresponding sensitive data exist in the interface message in a key-value pair structure. Then, the recognition module 21 is specifically configured to parse the interface message, obtain the target key-value pair structure located at a specified position in the interface message, where the specified position includes at least one of the following: request body, response body; and identify the field corresponding to the key in the target key-value pair structure as the target sensitive field.
[0127] In the sensitive data recognition device provided by the embodiments of the present application, the detailed explanations adopted during the operation of each functional module can refer to the corresponding explanations in the above embodiments of the sensitive data recognition method, which will not be elaborated here.
[0128] Furthermore, another embodiment of the present application also provides a computer-readable storage medium, where the storage medium includes a stored program, and when the program runs, it controls the device where the storage medium is located to execute the above-mentioned sensitive data recognition method.
[0129] Furthermore, another embodiment of the present application also provides an electronic device, which includes: a memory for storing a program; a processor coupled to the memory for running the program to execute the above-mentioned sensitive data recognition method.
[0130] In the above embodiments, the descriptions of each embodiment have their own focuses. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0131] It can be understood that the relevant features in the above methods and devices can be referred to each other. In addition, the "first", "second", etc. in the above embodiments are used to distinguish each embodiment, and do not represent the advantages and disadvantages of each embodiment.
[0132] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments, which will not be elaborated here.
[0133] The algorithms and displays provided herein are not inherently related to any specific computer, virtual system, or other device. Various general-purpose systems can also be used in conjunction with the teachings provided herein. The structure required to construct such a system is obvious from the above description. In addition, the present application is not directed to any specific programming language. It should be understood that the content of the present application described herein can be implemented using various programming languages, and the description of the specific language above is for disclosing the preferred embodiments of the present application.
[0134] In addition, the memory may include non-permanent memory in the form of computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0135] Those skilled in the art will appreciate that the embodiments of the present application may be provided as a method, a system, or a computer program product. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0136] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0137] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0138] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.
[0139] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and a memory.
[0140] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0141] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0142] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0143] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0144] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A sensitive data recognition method, characterized in that, Preset a preset sensitive label corresponding to at least one sensitive field of an API interface, where the preset sensitive label is obtained based on the sensitive label corresponding to the transmission of the corresponding sensitive field by the corresponding API interface within a preset period. The method includes: Perform sensitive data recognition on the interface message of the API interface to obtain a target sensitive field; Match the identified target sensitive field with the sensitive field of the corresponding API interface; If the match is successful, determine that the sensitive data corresponding to the successfully matched target sensitive field in the interface message has a preset sensitive label.
2. The method according to claim 1, characterized in that The method further includes: If the match fails, determine the sensitive label of the sensitive data corresponding to the target sensitive field that fails to match in the interface message based on the corresponding first expert rule for identifying sensitive labels.
3. The method according to claim 1, wherein The method further includes: Obtain the first interface message transmitted by the API interface within the preset period; Perform sensitive field recognition on the first interface message; For each identified sensitive field, determine the sensitive label of the sensitive data corresponding to the sensitive field in the corresponding first interface message based on the corresponding second expert rule for identifying sensitive labels; Based on the determined sensitive labels, count the first total number of occurrences of each sensitive label and the second total number of occurrences of all sensitive labels; Based on the first total number of occurrences and the second total number of occurrences, determine the first occurrence probability corresponding to each sensitive label; Determine the first sensitive label corresponding to the maximum first occurrence probability among the first occurrence probabilities as the preset sensitive label corresponding to the sensitive field.
4. The method according to claim 3, characterized in that The method further includes: Obtain the second interface message transmitted by the API interface within the new preset period; For each of the sensitive fields, determine the sensitive label of the sensitive data corresponding to the sensitive field in the corresponding second interface message based on the corresponding third expert rule for identifying sensitive labels; Based on the determined sensitive labels, count the third total number of occurrences of each sensitive label and the fourth total number of occurrences of all sensitive labels, and determine the second occurrence probability corresponding to each sensitive label; Judge whether the second sensitive label corresponding to the maximum second occurrence probability among the second occurrence probabilities is the same as the preset sensitive label corresponding to the sensitive field; If they are not the same, update the second sensitive label to the preset sensitive label corresponding to the sensitive field; If they are the same, keep the preset sensitive label corresponding to the sensitive field unchanged.
5. The method according to claim 4, characterized in that, After determining the maximum second occurrence probability, the method further includes: Judge whether the maximum second occurrence probability is greater than the maximum first occurrence probability when determining the first sensitive label corresponding to the sensitive field; If it is greater, perform the step of judging whether the second sensitive label corresponding to the maximum second occurrence probability among the second occurrence probabilities is the same as the preset sensitive label corresponding to the sensitive field; If it is not greater, keep the preset sensitive label corresponding to the sensitive field unchanged.
6. The method according to claim 3, wherein Based on the first total number of occurrences and the second total number of occurrences, determining the first occurrence probability corresponding to each sensitive label includes: For each of the sensitive tags, the ratio between the corresponding first total count and the second total count is determined as the first occurrence probability corresponding to the sensitive tag.
7. The method according to claim 3, wherein After identifying sensitive fields in the first interface message, the method further includes: Removing sensitive fields located at non-specified positions in the first interface message.
8. The method according to any one of claims 1 to 7, characterized in that, Storing, through a cache module, preset sensitive tags corresponding to sensitive fields of the at least one API interface. Then, matching the identified target sensitive fields with preset sensitive fields includes: Determining whether the identified target sensitive fields hit the preset sensitive tags corresponding to the sensitive fields stored in the cache module; If a hit occurs, determining that the matching is successful; If no hit occurs, determining that the matching fails.
9. The method according to any one of claims 1-7, characterized in that, If the sensitive fields and the corresponding sensitive data exist in the interface message in a key-value pair structure, then identifying sensitive fields in the interface message of the API interface to obtain target sensitive fields includes: Parsing the interface message to obtain the target key-value pair structure located at a specified position in the interface message, where the specified position includes at least one of the following: request body, response body; Identifying the field corresponding to the key in the target key-value pair structure as the target sensitive field.
10. A sensitive data recognition device, characterized in that, Presetting preset sensitive tags corresponding to sensitive fields of at least one API interface, where the preset sensitive tags are obtained based on the sensitive tags corresponding to the transmission of the corresponding sensitive fields by the corresponding API interface within a preset period. The device includes: An identification module, configured to identify sensitive fields in the interface message of the API interface to obtain target sensitive fields; A matching module, configured to match the identified target sensitive fields with the sensitive fields of the corresponding API interface; A determination module, configured to, if the matching module matches successfully, determine that the sensitive data corresponding to the successfully matched target sensitive fields in the interface message has a preset sensitive tag.
11. A computer-readable storage medium, characterized in that, The storage medium includes a stored program, where, when the program runs, it controls the device where the storage medium is located to execute the sensitive data identification method according to any one of claims 1 to 9.
12. An electronic device, characterized in that, The electronic device includes: A memory, configured to store a program; A processor, coupled to the memory, configured to run the program to execute the sensitive data identification method according to any one of claims 1 to 9.