Data processing method and device, equipment and storage medium

By calculating the benefit and cost ratio of the target security strategy to all the security strategies that have been launched after they are launched, the problem of inaccurate evaluation results in the existing technology is solved, and a more accurate security strategy evaluation is achieved.

CN120408626APending Publication Date: 2025-08-01TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410144703.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-31
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

In the prior art, the evaluation results of security strategies are not accurate enough due to mutual constraints on accuracy and recall, and the evaluation results of relying solely on one security strategy are not comprehensive enough.

Method used

After the preset time of the target security policy is launched, the evaluation data is read and the benefit ratio and cost ratio to all the security policies currently launched are calculated to comprehensively evaluate the performance of the target security policy.

Benefits of technology

It improves the accuracy of security strategy evaluation, avoids the influence of mutually restrictive indicators, and provides an evaluation method from an overall perspective.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408626A_ABST
    Figure CN120408626A_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a data processing method, apparatus and device, and a storage medium, which can relate to an information security technology, the method comprising: after a target security policy is online for a preset duration, reading evaluation data for evaluating the target security policy; based on the evaluation data, determining at least one of an income ratio of the target security policy to all currently online security policies and a cost ratio of the target security policy to all currently online security policies; a target security policy is evaluated based on at least one of the revenue ratio and the cost ratio. Therefore, the assessment accuracy for the security policy can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the technical field of data processing, and in particular, to a data processing method, apparatus, device, and storage medium. Background Art

[0002] Security policies play a crucial role in the field of information security technology. For example, through security policies, it is possible to detect whether unimodal or multimodal content such as images, texts, audios, and videos carries prohibited content. If such unimodal or multimodal content carries prohibited content, then the dissemination of this content can be prohibited.

[0003] Currently, the accuracy, precision, and recall rate of a security policy are mainly used to evaluate the security policy to support further decision-making by security administrators. For example, taking the security policy offline, adjusting it, or designating it as a key security policy, etc.

[0004] However, on the one hand, precision and recall rate are a pair of indicators that restrict each other and change in opposite directions, resulting in inaccurate evaluation results of the security policy. On the other hand, in fact, security administrators often face more than one security policy. Currently, simply evaluating a security policy through the accuracy, precision, and recall rate of a single security policy leads to inaccurate evaluation results. Summary of the Invention

[0005] Embodiments of the present application provide a data processing method, apparatus, device, and storage medium, thereby improving the evaluation accuracy of security policies.

[0006] Embodiments of the present application provide a data processing method, which includes: after a target security policy is online for a preset duration, reading evaluation data for evaluating the target security policy; based on the evaluation data, determining at least one of the benefit ratio of the target security policy to all currently online security policies and the cost ratio of the target security policy to all currently online security policies; evaluating the target security policy based on at least one of the benefit ratio and the cost ratio.

[0007] Embodiments of the present application provide a data processing apparatus, including: a reading module, a determining module, and an evaluating module. Among them, the reading module is used to read evaluation data for evaluating the target security policy after the target security policy is online for a preset duration; the determining module is used to determine at least one of the benefit ratio of the target security policy to all currently online security policies and the cost ratio of the target security policy to all currently online security policies based on the evaluation data; the evaluating module is used to evaluate the target security policy based on at least one of the benefit ratio and the cost ratio.

[0008] In a third aspect, an embodiment of the present application provides an electronic device, including: a processor and a memory. The memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory to execute the method in the first aspect or its various implementation manners.

[0009] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium for storing a computer program, and the computer program causes a computer to execute the method in the first aspect or its various implementation manners.

[0010] In a fifth aspect, an embodiment of the present application provides a computer program product, including computer program instructions, and the computer program instructions cause a computer to execute the method in the first aspect or its various implementation manners.

[0011] In a sixth aspect, an embodiment of the present application provides a computer program, and the computer program causes a computer to execute the method in the first aspect or its various implementation manners.

[0012] Through the technical solution provided by the present application, an embodiment of the present application proposes to evaluate a security policy according to at least one of the benefit ratio and cost ratio of the security policy relative to all currently online security policies. On the one hand, since the technical solution provided by the embodiment of the present application does not involve indicators that restrict each other and increase and decrease reciprocally; on the other hand, the technical solution provided by the present application evaluates a single security policy from the overall perspective of all currently online security policies. Based on this, the evaluation accuracy can be improved through the technical solution provided by the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0014] Figure 1 It is a schematic diagram of a system architecture related to an embodiment of the present application;

[0015] Figure 2 It is a flowchart of a data processing method provided by an embodiment of the present application;

[0016] Figure 3 It is a flowchart of the data processing method provided by an embodiment of the present application;

[0017] Figure 4 It is a schematic diagram of a data processing device 400 provided by an embodiment of the present application;

[0018] Figure 5It is a schematic block diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0019] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0020] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned accompanying drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or server including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0021] In the embodiments of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of the overall module or unit including the function of the module or unit.

[0022] Before introducing the technical solutions of the present application, the relevant knowledge involved in the present application will be elaborated below:

[0023] I. A security policy refers to a series of rules and measures formulated to ensure information security.

[0024] II. Accuracy is the most commonly used classification performance metric.

[0025] Accuracy = (TP + TN) / (TP + FN + FP + TN)

[0026] Among them, TP (True Positive) represents the number of positive samples predicted by the security policy and actually being positive samples, TN (True Negative) represents the number of negative samples predicted by the security policy and actually being negative samples, FP (False Positive) represents the number of positive samples predicted by the security policy but actually being negative samples, and FN (False Negative) represents the number of negative samples predicted by the security policy but actually being positive samples. Based on this, the accuracy rate represents the proportion of the number of correctly predicted samples to the total number of samples, that is, the number of correctly predicted positive and negative examples / the total number of samples.

[0027] III. Precision, is the most commonly used classification performance metric.

[0028] Precision = TP / (TP + FP)

[0029] Among them, TP (True Positive) represents the number of positive samples predicted by the security policy and actually being positive samples, and FP (False Positive) represents the number of positive samples predicted by the security policy but actually being negative samples. Based on this, the precision represents the number of correctly predicted positive examples / the total number of predicted positive examples.

[0030] IV. Recall, is the most commonly used classification performance metric.

[0031] Recall = TP / (TP + FN)

[0032] Among them, TP (True Positive) represents the number of positive samples predicted by the security policy and actually being positive samples, and FN (False Negative) represents the number of negative samples predicted by the security policy but actually being positive samples. Based on this, the recall represents the number of correctly predicted positive examples / the total number of actual positive examples.

[0033] V. The automatic processing volume of the security policy refers to the number of contents (i.e., samples) that can be automatically identified and processed during the automatic detection and defense process of the security policy.

[0034] VI. The automatic processing accuracy rate of the security policy refers to the proportion of the contents that can be accurately identified and processed to all contents during the automatic detection and defense process of the security policy.

[0035] VII. The manual submission volume for the security policy refers to the number of contents that need to be manually reviewed using this security policy.

[0036] VIII. The manual processing rate for the security policy refers to the proportion of the contents that are manually processed among all the contents sent to manual for the security policy.

[0037] IX. The machine service cost of the security policy is mainly related to the volume of business requests, and refers to the hardware cost, software cost, maintenance cost, etc. incurred during the automatic detection and defense process of the security policy, but not limited to this.

[0038] X. The manual service cost of the content submitted for review includes, but is not limited to: the costs of manual review, manual processing, and manual monitoring, etc.

[0039] The manual review cost refers to the cost of reviewing, analyzing, evaluating, etc. the content submitted for review.

[0040] The manual processing cost refers to the cost of processing problems such as contraband in the content submitted for review, including the investigation, banning, deletion, etc. of the content involving contraband, but not limited to this.

[0041] The manual monitoring cost refers to the cost of real-time monitoring of the content submitted for review to timely discover and handle problems.

[0042] XI. Single-modal content refers to content presented using only one medium or form. For example, text, pictures, audio, video, etc. are all single-modal content.

[0043] XII. Multi-modal content refers to content presented using multiple media or forms simultaneously. For example, short videos are content that simultaneously involves multiple forms such as text, pictures, audio, video, etc.

[0044] Next, the technical problems to be solved, the inventive concept, and the system architecture of the embodiments of the present application will be elaborated:

[0045] As described above, the current data processing method has the problem of inaccurate evaluation results.

[0046] To solve the above technical problems, the embodiments of the present application propose to evaluate the security policy based on at least one of the benefit ratio and cost ratio of the security policy relative to all the currently online security policies. On the one hand, since the technical solution provided by the embodiments of the present application does not involve indicators that restrict each other and increase or decrease reciprocally; on the other hand, the technical solution provided by the present application evaluates a single security policy from the overall perspective of all the currently online security policies. Based on this, the evaluation accuracy can be improved through the technical solution provided by the present application.

[0047] In some realizable ways, the system architecture of the embodiments of the present application is as Figure 1 shown.

[0048] Figure 1 FIG. is a schematic diagram of a system architecture related to the embodiments of the present application. The system architecture includes: a content background server 110, a security control device 120, a database 130, and a security policy evaluation device 140.

[0049] In some implementable ways, the content back-end server 110 can be the back-end server corresponding to single-modal content or multi-modal content. For example, the content back-end server 110 can be the back-end server corresponding to a bank loan system or the back-end server corresponding to short videos.

[0050] In some implementable ways, the content back-end server 110 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, Content Delivery Network (CDN), and big data and artificial intelligence platforms.

[0051] In some implementable ways, the security control device 120 is used to detect whether the content in the content back-end server 110 is prohibited or not by adopting security policies, and can conduct investigations, bans, deletions, etc. on prohibited content.

[0052] In some implementable ways, the security control device 120 can be a terminal device or a security control back-end server. The terminal device can be a smart phone, a tablet computer, a smart watch, Virtual Reality (VR), Augmented Reality (AR), etc., but is not limited thereto. The security control back-end server can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.

[0053] In some implementable ways, the database 130 is used to store the data generated by the content back-end server 110 and the security control device 120. For example, it can store the automatic processing volume of security policies, the automatic processing accuracy rate of security policies, the manual submission volume for security policies, the manual processing rate for security policies, the machine service cost of security policies, the manual service cost for each submitted content, and so on.

[0054] In some implementable ways, the database 130 can be a relational database, a non-relational database, a key-value database, etc., but is not limited thereto.

[0055] In some implementable ways, the security policy evaluation device 140 is used to evaluate security policies by reading the evaluation data for evaluating security policies in the database 130.

[0056] In some implementable manners, the security policy evaluation device 140 may be a terminal device or a security policy evaluation background server. The terminal device may be a smart phone, a tablet computer, a smart watch, VR, AR, etc., but is not limited thereto. The security policy evaluation background server may be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers, or may also be a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.

[0057] In some implementable manners, the content background server 110 and the security control device 120 may be directly or indirectly connected through wired or wireless communication means, and the present application does not limit this here.

[0058] In some implementable manners, the content background server 110, the security control device 120, and the security policy evaluation device 140 may be directly or indirectly connected to the database 130 through wired or wireless communication means, and the present application does not limit this here.

[0059] It should be noted that Figure 1 is only a schematic diagram of a system architecture provided by the embodiments of the present application, and the system architecture involved in the embodiments of the present application is not limited to Figure 1 the system architecture shown. For example, in some implementable manners, the content background server 110, the security control device 120, and the security policy evaluation device 140 may be the same device, or the security control device 120 and the security policy evaluation device 140 may be the same device, or the content background server 110 and the security control device 120 may be two devices sharing some hardware resources, etc.

[0060] Before introducing the embodiments of the present application, it should be noted that the evaluation data and other data of the target security policy involved in the embodiments of the present application are all authorized by relevant objects or fully authorized by all parties, and the collection, use, and processing of relevant information all comply with the relevant laws, regulations, and standards of relevant countries and regions.

[0061] The embodiments of the present application will be elaborated in detail below:

[0062] Figure 2 is a flowchart of a data processing method provided by an embodiment of the present application. This method may be executed by a security policy evaluation device, and the security policy evaluation device may be Figure 1 the security policy evaluation device 140 in Figure 2 but is not limited thereto. As

[0063] S210: After a preset duration since the target security policy goes online, read the evaluation data for evaluating the target security policy;

[0064] It should be understood that the target security policy can be any security policy, which can be used to detect whether unimodal or multimodal content such as images, texts, audios, and videos carries prohibited content, but is not limited thereto.

[0065] In some implementable manners, the value of the preset duration can be one day, one week, one month, etc., but is not limited thereto.

[0066] In some implementable manners, the evaluation data generated by the content background server and the security control device can be stored in a database. Based on this, the security policy evaluation device can read the evaluation data from the database.

[0067] In the embodiments of the present application, the evaluation data can be the following three cases, but is not limited thereto:

[0068] Case 1: The evaluation data includes, for each security policy among all the currently online security policies: the automatic processing volume of this security policy, the automatic processing accuracy rate of this security policy, the manual submission volume for this security policy, and the manual processing rate for this security policy.

[0069] Case 2: The evaluation data includes, for each security policy among all the currently online security policies: the machine service cost of this security policy, the manual submission volume for this security policy, and the manual service cost for each submitted content.

[0070] Case 3: The evaluation data includes, for each security policy among all the currently online security policies: the automatic processing volume of this security policy, the automatic processing accuracy rate of this security policy, the manual submission volume for this security policy, the manual processing rate for this security policy, the machine service cost of this security policy, and the manual service cost for each submitted content.

[0071] It should be understood that, for each security policy among all the currently online security policies, the automatic processing volume of this security policy is the difference between the automatic processing volume of all security policies after this security policy goes online and the automatic processing volume of all security policies before this security policy goes online for the same sample set.

[0072] For example, for a sample set composed of 1000 samples, the processing volume of security policies 1 and 2 for these 1000 samples is 100. After security policy 3 goes online, the processing volume of security policies 1, 2, and 3 for these 1000 samples is 150. Then the automatic processing volume of security policy 3 is 150 - 100 = 50.

[0073] S220: Determine at least one of the benefit ratio of the target security policy to all the currently implemented security policies and the cost ratio of the target security policy to all the currently implemented security policies based on the evaluation data;

[0074] S230: Evaluate the target security policy based on at least one of the benefit ratio and the cost ratio.

[0075] The following elaborates on S220 and S230:

[0076] In some implementable ways, after the security policy evaluation device reads the above evaluation data, it can perform at least one of preprocessing, cleaning, feature selection, feature transformation, and feature combination on the evaluation data, but not limited to this.

[0077] It should be understood that the security policy evaluation device can also directly use the read evaluation data to determine at least one of the benefit ratio of the target security policy to all the currently implemented security policies and the cost ratio of the target security policy to all the currently implemented security policies.

[0078] In some implementable ways, when the evaluation data includes: for each security policy among all the currently implemented security policies, the automatic processing volume of the security policy, the automatic processing accuracy rate of the security policy, the manual submission volume for the security policy, and the manual processing rate for the security policy, the security policy evaluation device can determine the benefit ratio of the target security policy to all the currently implemented security policies based on the automatic processing volume, automatic processing accuracy rate, manual submission volume, and manual processing rate of each security policy among all the currently implemented security policies.

[0079] In some implementable ways, the security policy evaluation device can calculate the benefit of the target security policy based on the automatic processing volume, automatic processing accuracy rate, manual submission volume, and manual processing rate of the target security policy; calculate the total benefit of all the currently implemented security policies based on the automatic processing volume, automatic processing accuracy rate, manual submission volume, and manual processing rate of each security policy among all the currently implemented security policies; calculate the ratio of the benefit of the target security policy to the total benefit of all the currently implemented security policies to obtain the benefit ratio of the target security policy to all the currently implemented security policies.

[0080] Among them, the benefit of the target security policy and the total benefit of all the currently implemented security policies can be achieved through any of the following implementable ways, but not limited to this:

[0081] In the first implementable approach, the security policy evaluation device calculates the product of the automatic processing volume of the target security policy and the automatic processing accuracy rate of the target security policy to obtain a first product result; calculates the product of the manual submission volume of the target security policy and the manual processing rate of the target security policy to obtain a second product result; calculates the sum of the first product result and the second product result, and then multiplies it by the weight corresponding to the category to which the target security policy belongs to obtain the benefit of the target security policy. For each security policy among all the currently implemented security policies, the security policy evaluation device calculates the product of the automatic processing volume of the security policy and the automatic processing accuracy rate of the security policy to obtain a third product result; calculates the product of the manual submission volume of the security policy and the manual processing rate of the security policy to obtain a fourth product result; calculates the sum of the third product result and the fourth product result, and then multiplies it by the weight corresponding to the category to which the security policy belongs to obtain the benefit of the security policy; calculates the sum of the benefits of each security policy among all the currently implemented security policies to obtain the total benefit of all the currently implemented security policies.

[0082] Based on this, the benefit ratio of the target security policy to all the currently implemented security policies can be calculated through the following formula (1):

[0083]

[0084] Pr k,i represents the benefit ratio of the i-th policy (i.e., the target security policy) in the k-th category of policies to all the currently implemented security policies;

[0085] r k,i represents the automatic processing volume of the i-th policy in the k-th category of policies;

[0086] q k,i represents the automatic processing accuracy rate of the i-th policy in the k-th category of policies;

[0087] m k,i represents the manual submission volume for the i-th policy in the k-th category of policies;

[0088] u k,i represents the manual processing rate for the i-th policy in the k-th category of policies;

[0089] p k represents the weight corresponding to the k-th category of policies;

[0090] r l,j represents the automatic processing volume of the j-th policy in the l-th category of policies;

[0091] q l,j represents the automatic processing accuracy rate of the j-th policy in the l-th category of policies;

[0092] m l,jDenotes the manual submission volume for the j-th strategy in the l-th type of strategy;

[0093] u l,j Denotes the manual processing rate for the j-th strategy in the l-th type of strategy;

[0094] p l Denotes the weight corresponding to the l-th type of strategy;

[0095] r k,i *q k,i Denotes the first product result corresponding to the i-th strategy in the l-th type of strategy;

[0096] m k,i *u k,i Denotes the second product result corresponding to the i-th strategy in the l-th type of strategy;

[0097] (r k,i *q k,i +m k,i *u k,i )*p k Denotes the revenue of the i-th strategy in the k-th type of strategy;

[0098] r l,j *q l,j Denotes the third product result corresponding to the j-th strategy in the l-th type of strategy;

[0099] m l,j *u l,j Denotes the fourth product result corresponding to the j-th strategy in the l-th type of strategy;

[0100] (r l,j *q l,j +m l,j *u l,j )*p l Denotes the revenue of the j-th strategy in the k-th type of strategy;

[0101] Denotes the total revenue of all currently launched security strategies.

[0102] Implementation method 2: The security policy evaluation device calculates the product of the automatic processing volume of the target security policy and the automatic processing accuracy rate of the target security policy to obtain a first product result; calculates the product of the manual submission volume of the target security policy and the manual processing rate of the target security policy to obtain a second product result; calculates the sum of the first product result and the second product result to obtain the benefit of the target security policy. For each security policy among all the currently launched security policies, calculate the product of the automatic processing volume of the security policy and the automatic processing accuracy rate of the security policy to obtain a third product result; the security policy evaluation device calculates the product of the manual submission volume of the security policy and the manual processing rate of the security policy to obtain a fourth product result; calculates the sum of the third product result and the fourth product result to obtain the benefit of the security policy; calculates the sum of the benefits of each security policy among all the currently launched security policies to obtain the total benefit of all the currently launched security policies.

[0103] Based on this, the benefit ratio of the target security policy to all the currently launched security policies can be calculated through the following formula (2):

[0104]

[0105] It should be understood that the explanations of the various parameters in formula (2) can refer to the explanations of the various parameters in formula (1), and the embodiments of the present application will not elaborate on this.

[0106] Implementation method 3: The security policy evaluation device calculates the product of the automatic processing volume of the target security policy and the automatic processing accuracy rate of the target security policy to obtain a first product result; calculates the product of the manual submission volume of the target security policy and the manual processing rate of the target security policy to obtain a second product result; performs weighted summation on the first product result and the second product result, and then multiplies by the weight corresponding to the category to which the target security policy belongs to obtain the benefit of the target security policy. For each security policy among all the currently launched security policies, calculate the product of the automatic processing volume of the security policy and the automatic processing accuracy rate of the security policy to obtain a third product result; the security policy evaluation device calculates the product of the manual submission volume of the security policy and the manual processing rate of the security policy to obtain a fourth product result; performs weighted summation on the third product result and the fourth product result, and then multiplies by the weight corresponding to the category to which the security policy belongs to obtain the benefit of the security policy; calculates the sum of the benefits of each security policy among all the currently launched security policies to obtain the total benefit of all the currently launched security policies.

[0107] Based on this, the benefit ratio of the target security policy to all the currently launched security policies can be calculated through the following formula (3):

[0108]

[0109] Among them, ω1 represents the weight corresponding to the automated processing benefit, and ω2 represents the weight corresponding to the manual processing benefit. For the explanations of the remaining parameters in formula (3), reference can be made to the explanations of the respective parameters in formula (1), which will not be elaborated in this embodiment of the present application.

[0110] In a fourth implementable manner, the security policy evaluation device calculates the product of the automated processing volume of the target security policy and the automated processing accuracy rate of the target security policy to obtain a first product result; calculates the product of the manual submission volume of the target security policy and the manual processing rate of the target security policy to obtain a second product result; and performs a weighted sum of the first product result and the second product result to obtain the benefit of the target security policy. For each security policy among all the currently deployed security policies, the device calculates the product of the automated processing volume of the security policy and the automated processing accuracy rate of the security policy to obtain a third product result; calculates the product of the manual submission volume of the security policy and the manual processing rate of the security policy to obtain a fourth product result; performs a weighted sum of the third product result and the fourth product result to obtain the benefit of the security policy; and calculates the sum of the benefits of each security policy among all the currently deployed security policies to obtain the total benefit of all the currently deployed security policies.

[0111] Based on this, the benefit ratio of the target security policy to all the currently deployed security policies can be calculated through the following formula (4):

[0112]

[0113] Among them, for the explanations of the respective parameters in formula (4), reference can be made to the explanations of the respective parameters in formula (1) and formula (3), which will not be elaborated in this embodiment of the present application.

[0114] In some implementable manners, when the evaluation data includes: for each security policy among all the currently deployed security policies, the machine service cost of the security policy, the manual submission volume of the security policy, and the manual service cost of each submission content; the security policy evaluation device can determine the cost ratio of the target security policy to all the currently deployed security policies based on the machine service cost, manual submission volume, and manual service cost of each submission content of each security policy among all the currently deployed security policies.

[0115] In some implementable ways, the security policy evaluation device may calculate the cost of the target security policy based on the machine service cost, the manual submission volume, and the manual service cost per submission content of the target security policy; calculate the total cost of all currently deployed security policies based on the machine service cost, the manual submission volume, and the manual service cost per submission content of each security policy in all currently deployed security policies; calculate the ratio of the cost of the target security policy to the total cost of all currently deployed security policies to obtain the cost ratio of the target security policy to all currently deployed security policies.

[0116] Among them, the cost of the target security policy and the total cost of all currently deployed security policies can be implemented through any of the following implementable ways, but are not limited to this:

[0117] Implementable way one: The security policy evaluation device may calculate the product of the manual submission volume of the target security policy and the manual service cost per submission content to obtain a fifth product result; calculate the sum of the fifth product result and the machine service cost of the target security policy to obtain the cost of the target security policy. For each security policy in all currently deployed security policies, the security policy evaluation device may calculate the product of the manual submission volume of this security policy and the manual service cost per submission content to obtain a sixth product result; calculate the sum of the sixth product result and the machine service cost of this security policy to obtain the cost of this security policy; calculate the sum of the costs of each security policy in all currently deployed security policies to obtain the total cost of all currently deployed security policies.

[0118] Based on this, the cost ratio of the target security policy to all currently deployed security policies can be calculated through the following formula (5):

[0119]

[0120] Cr k,i represents the cost ratio of the i-th policy (i.e., the target security policy) in the k-th type of policy to all currently deployed security policies;

[0121] c k,i represents the machine service cost of the i-th policy in the k-th type of policy;

[0122] m k,i represents the manual submission volume for the i-th policy in the k-th type of policy;

[0123] t represents the manual service cost per submission content;

[0124] c l,j represents the machine service cost of the j-th policy in the l-th type of policy;

[0125] m l,jDenotes the manual submission volume for the j-th policy in the l-th type of policy;

[0126] m k,i *t represents the fifth product result corresponding to the i-th policy in the k-th type of policy;

[0127] c k,i +m k,i *t represents the cost of the i-th policy in the k-th type of policy;

[0128] m l,j *t represents the sixth product result corresponding to the j-th policy in the k-th type of policy;

[0129] c l,j +m l,j *t represents the cost of the j-th policy in the k-th type of policy;

[0130] Denotes the total cost of all currently deployed security policies.

[0131] In the second implementation method, the security policy evaluation device can calculate the product of the manual submission volume for the target security policy and the manual service cost for each submission content to obtain the fifth product result; calculate the sum of the fifth product result and the machine service cost of the target security policy, and then multiply by the weight corresponding to the category to which the target security policy belongs to obtain the cost of the target security policy. For each security policy among all currently deployed security policies, the security policy evaluation device can calculate the product of the manual submission volume for the security policy and the manual service cost for each submission content to obtain the sixth product result; calculate the sum of the sixth product result and the machine service cost of the security policy, and then multiply by the weight corresponding to the category to which the security policy belongs to obtain the cost of the security policy; calculate the sum of the costs of each security policy among all currently deployed security policies to obtain the total cost of all currently deployed security policies.

[0132] Based on this, the cost ratio of the target security policy to all currently deployed security policies can be calculated through the following formula (6):

[0133]

[0134] where p k represents the weight corresponding to the k-th type of policy; p l represents the weight corresponding to the l-th type of policy; For the explanations of other parameters in formula (6), reference can be made to the explanations of each parameter in formula (5), which will not be elaborated in this embodiment of the present application.

[0135] In the third implementation method, the security policy evaluation device can calculate the product of the manual submission volume for the target security policy and the manual service cost of each submission content to obtain a fifth product result; perform a weighted sum of the fifth product result and the machine service cost of the target security policy to obtain the cost of the target security policy. For each security policy among all the currently launched security policies, the security policy evaluation device can calculate the product of the manual submission volume for the security policy and the manual service cost of each submission content to obtain a sixth product result; perform a weighted sum of the sixth product result and the machine service cost of the security policy to obtain the cost of the security policy; calculate the sum of the costs of each security policy among all the currently launched security policies to obtain the total cost of all the currently launched security policies.

[0136] Based on this, the cost ratio of the target security policy to all the currently launched security policies can be calculated through the following formula (7):

[0137]

[0138] Among them, ω3 represents the weight corresponding to the automatic processing cost, and ω4 represents the weight corresponding to the manual processing cost. The explanations of the other parameters in formula (7) can refer to the explanations of the respective parameters in formula (5), and the embodiments of the present application will not elaborate on this again.

[0139] In the fourth implementation method, the security policy evaluation device can calculate the product of the manual submission volume for the target security policy and the manual service cost of each submission content to obtain a fifth product result; perform a weighted sum of the fifth product result and the machine service cost of the target security policy, and then multiply by the weight corresponding to the category to which the target security policy belongs to obtain the cost of the target security policy. For each security policy among all the currently launched security policies, the security policy evaluation device can calculate the product of the manual submission volume for the security policy and the manual service cost of each submission content to obtain a sixth product result; perform a weighted sum of the sixth product result and the machine service cost of the security policy, and then multiply by the weight corresponding to the category to which the security policy belongs to obtain the cost of the security policy; calculate the sum of the costs of each security policy among all the currently launched security policies to obtain the total cost of all the currently launched security policies.

[0140] Based on this, the cost ratio of the target security policy to all the currently launched security policies can be calculated through the following formula (8):

[0141]

[0142] It should be understood that the explanations of the respective parameters in formula (8) can refer to the explanations of the respective parameters in formulas (5), (6), and (7), and the embodiments of the present application will not elaborate on this again.

[0143] It should be understood that if the security policy evaluation device determines the benefit ratio of the target security policy to all currently deployed security policies and the cost ratio of the target security policy to all currently deployed security policies based on the evaluation data, then the calculation methods for the benefit ratio and the cost ratio can refer to the above, and the embodiments of the present application will not elaborate on this again.

[0144] Based on this, the security policy evaluation device can evaluate the target security policy in any of the following implementable ways, but not limited to this:

[0145] Implementable way one: The security policy evaluation device evaluates the target security policy only based on the benefit ratio of the target security policy to all currently deployed security policies.

[0146] Among them, the larger the benefit ratio of the target security policy to all currently deployed security policies, the better the target security policy. On the contrary, the smaller the benefit ratio of the target security policy to all currently deployed security policies, the worse the target security policy.

[0147] In some implementable ways, when the benefit ratio of the target security policy to all currently deployed security policies is less than or equal to the first preset threshold, the security policy evaluation device determines that the target security policy is a security policy to be taken offline; when the benefit ratio of the target security policy to all currently deployed security policies is greater than the first preset threshold and less than or equal to the second preset threshold, the security policy evaluation device determines that the target security policy is a security policy to be adjusted; when the benefit ratio of the target security policy to all currently deployed security policies is greater than the second preset threshold and less than or equal to the third preset threshold, the security policy evaluation device determines that the target security policy is a security policy for normal operation; when the benefit ratio of the target security policy to all currently deployed security policies is greater than the third preset threshold, the security policy evaluation device determines that the target security policy is an SS-level security policy, that is, a key operation guarantee security policy.

[0148] Among them, the first preset threshold < the second preset threshold < the third preset threshold. The embodiments of the present application do not limit the values of the first preset threshold, the second preset threshold, and the third preset threshold.

[0149] It should be understood that the embodiments of the present application do not limit the evaluation method of evaluating the target security policy only based on the benefit ratio of the target security policy to all currently deployed security policies.

[0150] Implementable way two: The security policy evaluation device evaluates the target security policy only based on the cost ratio of the target security policy to all currently deployed security policies.

[0151] Among them, the smaller the cost ratio of the target security policy to all the currently implemented security policies, the better the target security policy. On the contrary, the larger the benefit ratio of the target security policy to all the currently implemented security policies, the worse the target security policy.

[0152] In some implementable ways, when the reciprocal of the cost ratio of the target security policy to all the currently implemented security policies is less than or equal to a fourth preset threshold, the security policy evaluation device determines that the target security policy is a security policy to be taken offline; when the reciprocal of the cost ratio of the target security policy to all the currently implemented security policies is greater than the fourth preset threshold and less than or equal to a fifth preset threshold, the security policy evaluation device determines that the target security policy is a security policy to be adjusted; when the reciprocal of the cost ratio of the target security policy to all the currently implemented security policies is greater than the fifth preset threshold and less than or equal to a sixth preset threshold, the security policy evaluation device determines that the target security policy is a security policy for normal operation; when the reciprocal of the cost ratio of the target security policy to all the currently implemented security policies is greater than the sixth preset threshold, the security policy evaluation device determines that the target security policy is an SS-level security policy, that is, a key operation guarantee security policy.

[0153] Among them, the fourth preset threshold < the fifth preset threshold < the sixth preset threshold. The embodiments of the present application do not limit the values of the fourth preset threshold, the fifth preset threshold, and the sixth preset threshold.

[0154] It should be understood that the embodiments of the present application do not limit the evaluation method for evaluating the target security policy only based on the cost ratio of the target security policy to all the currently implemented security policies.

[0155] Implementable way three: The security policy evaluation device evaluates the target security policy based on the first ratio of the benefit ratio to the cost ratio of the target security policy to all the currently implemented security policies.

[0156] Among them, the larger the first ratio, the better the target security policy. On the contrary, the smaller the first ratio, the worse the target security policy.

[0157] In some implementable ways, when the first ratio is less than or equal to a seventh preset threshold, the security policy evaluation device determines that the target security policy is a security policy to be taken offline; when the first ratio is greater than the seventh preset threshold and less than or equal to an eighth preset threshold, the security policy evaluation device determines that the target security policy is a security policy to be adjusted; when the first ratio is greater than the eighth preset threshold and less than or equal to a ninth preset threshold, the security policy evaluation device determines that the target security policy is a security policy for normal operation; when the first ratio is greater than the ninth preset threshold, the security policy evaluation device determines that the target security policy is an SS-level security policy, that is, a key operation guarantee security policy.

[0158] Among them, the seventh preset threshold < the eighth preset threshold < the ninth preset threshold. The embodiments of the present application do not limit the values of the seventh preset threshold, the eighth preset threshold, and the ninth preset threshold.

[0159] It should be understood that the embodiments of the present application do not limit the evaluation method for evaluating the target security policy based on the first ratio.

[0160] Implementable manner four: The security policy evaluation device can evaluate the target security policy based on the benefit ratio and stability index of the target security policy and all currently online security policies.

[0161] In some implementable manners, the security policy evaluation device can calculate the product of the benefit ratio and the stability index to obtain a seventh product result; and evaluate the target security policy based on the seventh product result.

[0162] For example, the security policy evaluation device can calculate the seventh product result through the following formula (9):

[0163] Pr k,i *PSI (9)

[0164] Among them, Pr k,i represents the benefit ratio of the target security policy and all currently online security policies, and PSI represents the stability index.

[0165] Among them, the larger the seventh product result, the better the target security policy. On the contrary, the smaller the seventh product result, the worse the target security policy.

[0166] In some implementable manners, when the seventh product result is less than or equal to the tenth preset threshold, the security policy evaluation device determines that the target security policy is a security policy to be taken offline; when the seventh product result is greater than the tenth preset threshold and less than or equal to the eleventh preset threshold, the security policy evaluation device determines that the target security policy is a security policy to be adjusted; when the seventh product result is greater than the eleventh preset threshold and less than or equal to the twelfth preset threshold, the security policy evaluation device determines that the target security policy is a normal operation security policy; when the seventh product result is greater than the twelfth preset threshold, the security policy evaluation device determines that the target security policy is an SS-level security policy, that is, a key operation guarantee security policy.

[0167] Among them, the tenth preset threshold < the eleventh preset threshold < the twelfth preset threshold. The embodiments of the present application do not limit the values of the tenth preset threshold, the eleventh preset threshold, and the twelfth preset threshold.

[0168] It should be understood that the embodiments of the present application do not limit the evaluation method for evaluating the target security policy based on the seventh product result.

[0169] In some implementable manners, the security policy evaluation device may respectively determine the benefit ratio of the target security policy to all the currently online security policies for N content sets (i.e., N sample sets), and obtain N benefit ratios; where N is an integer greater than 1; based on the expected values corresponding to the N benefit ratios and the N benefit ratios, a stability index is determined.

[0170] For example, the security policy evaluation device may calculate the stability index through the following formula (10), but not limited thereto:

[0171]

[0172] where y i represents the i-th benefit ratio, represents the expected value corresponding to the i-th benefit ratio.

[0173] Implementable manner five: The security policy evaluation device may evaluate the target security policy based on the cost ratio of the target security policy to all the currently online security policies and the stability index.

[0174] In some implementable manners, the security policy evaluation device may calculate the product of the reciprocal of the cost ratio and the stability index to obtain an eighth product result; and evaluate the target security policy based on the eighth product result.

[0175] For example, the security policy evaluation device may calculate the eighth product result through the following formula (10):

[0176]

[0177] where Cr k,i represents the cost ratio of the target security policy to all the currently online security policies, and PSI represents the stability index.

[0178] Among them, the larger the eighth product result, the better the target security policy; on the contrary, the smaller the eighth product result, the worse the target security policy.

[0179] In some implementable manners, when the eighth product result is less than or equal to the thirteenth preset threshold, the security policy evaluation device determines that the target security policy is a security policy to be taken offline; when the eighth product result is greater than the thirteenth preset threshold and less than or equal to the fourteenth preset threshold, the security policy evaluation device determines that the target security policy is a security policy to be adjusted; when the eighth product result is greater than the fourteenth preset threshold and less than or equal to the fifteenth preset threshold, the security policy evaluation device determines that the target security policy is a normal operation security policy; when the eighth product result is greater than the fifteenth preset threshold, the security policy evaluation device determines that the target security policy is an SS-level security policy, that is, a key operation guarantee security policy.

[0180] Among them, the thirteenth preset threshold < the fourteenth preset threshold < the fifteenth preset threshold. The embodiments of the present application do not limit the values of the thirteenth preset threshold, the fourteenth preset threshold, and the fifteenth preset threshold.

[0181] It should be understood that the embodiments of the present application do not limit the evaluation method for evaluating the target security policy based on the eighth product result.

[0182] In some implementable ways, the security policy evaluation device can respectively determine the cost ratio of the target security policy to all the currently launched security policies for N content sets (i.e., N sample sets), and obtain N cost ratios; where N is an integer greater than 1; based on the expected values corresponding to the N cost ratios and the N cost ratios, determine the stability index.

[0183] For example, the security policy evaluation device can calculate the stability index through the following formula (11), but is not limited thereto:

[0184]

[0185] where, z i represents the i-th cost ratio, represents the expected value corresponding to the i-th cost ratio.

[0186] Implementable way six, the security policy evaluation device can evaluate the target security policy based on the cost ratio, benefit ratio, and stability index of the target security policy to all the currently launched security policies.

[0187] In some implementable ways, the security policy evaluation device can calculate the ratio of the benefit ratio to the cost ratio, and then multiply it by the stability index to obtain the ninth product result; and evaluate the target security policy based on the ninth product result.

[0188] For example, the security policy evaluation device can calculate the ninth product result through the following formula (12):

[0189]

[0190] where, Pr k,i represents the benefit ratio of the target security policy to all the currently launched security policies, Cr k,i represents the cost ratio of the target security policy to all the currently launched security policies, and PSI represents the stability index.

[0191] Among them, the larger the ninth product result, the better the target security policy; on the contrary, the smaller the ninth product result, the worse the target security policy.

[0192] In some implementable manners, when the ninth product result is less than or equal to the sixteenth preset threshold, the security policy evaluation device determines that the target security policy is a security policy to be taken offline; when the ninth product result is greater than the sixteenth preset threshold and less than or equal to the seventeenth preset threshold, the security policy evaluation device determines that the target security policy is a security policy to be adjusted; when the ninth product result is greater than the seventeenth preset threshold and less than or equal to the eighteenth preset threshold, the security policy evaluation device determines that the target security policy is a normal operation security policy; when the ninth product result is greater than the eighteenth preset threshold, the security policy evaluation device determines that the target security policy is an SS-level security policy, that is, a key operation guarantee security policy.

[0193] Among them, the sixteenth preset threshold < the seventeenth preset threshold < the eighteenth preset threshold, and the embodiments of the present application do not limit the values of the sixteenth preset threshold, the seventeenth preset threshold, and the eighteenth preset threshold.

[0194] It should be understood that the embodiments of the present application do not limit the evaluation method for evaluating the target security policy based on the ninth product result.

[0195] In some implementable manners, the security policy evaluation device may calculate the ratio of the benefit ratio to the cost ratio for N content sets respectively to obtain N target ratios; where N is an integer greater than 1; based on the expected values corresponding to the N target ratios and the N target ratios, a stability index is determined.

[0196] For example, the security policy evaluation device may calculate the stability index through the following formula (13), but not limited thereto:

[0197]

[0198] where s i represents the i-th target ratio, represents the expected value corresponding to the i-th target ratio.

[0199] In some implementable manners, if the target security policy is evaluated as a security policy to be taken offline, the security policy evaluation device may take offline the target security policy.

[0200] In some implementable manners, the security policy evaluation device also performs at least one of the following: if the target security policy is evaluated as a security policy to be taken offline, take offline the service related to the target security policy; if the target security policy is evaluated as a security policy to be taken offline, release the hardware resources of the target security policy.

[0201] In some implementable manners, if the target security policy is evaluated as a security policy to be adjusted, the security policy evaluation device pushes an alarm message to prompt the object to adjust the target security policy.

[0202] Figure 3 is a flowchart of the data processing method provided by the embodiment of the present application. As Figure 3 shown, the method includes:

[0203] S310: If the target security policy is evaluated as a security policy to be adjusted, the security policy evaluation device pushes an alarm message to prompt the object to adjust the target security policy.

[0204] S320: After the object pairs with the target security policy, the security policy evaluation device continues to evaluate the adjusted target security policy by using the data processing method provided by the embodiment of the present application. If the adjusted target security policy is evaluated as an SS-level security policy or a normal operation security policy, then execute S330; when the adjusted target security policy is evaluated as a security policy to be taken offline, then execute S340;

[0205] S330: The security policy evaluation device matches the remaining content with the adjusted target security policy to detect the security of the remaining content;

[0206] It should be understood that the remaining content refers to the content whose detection result is secure after the target security policy goes online.

[0207] S340: The security policy evaluation device takes the adjusted target security policy offline.

[0208] The embodiment of the present application provides a data processing method, including: after a preset duration since the target security policy goes online, reading evaluation data for evaluating the target security policy; based on the evaluation data, determining at least one of the benefit ratio of the target security policy to all currently online security policies and the cost ratio of the target security policy to all currently online security policies; evaluating the target security policy based on at least one of the benefit ratio and the cost ratio. On the one hand, since the technical solution provided by the embodiment of the present application does not involve indicators that restrict each other and increase or decrease in a reciprocal manner; on the other hand, the technical solution provided by the present application evaluates a single security policy from the overall perspective of all currently online security policies. Based on this, the evaluation accuracy can be improved through the technical solution provided by the present application.

[0209] The preferred embodiments of the present application have been described in detail above in conjunction with the accompanying drawings. However, the present application is not limited to the specific details in the above embodiments. Within the scope of the technical concept of the present application, various simple modifications can be made to the technical solutions of the present application, and these simple modifications all fall within the protection scope of the present application. For example, in the various specific technical features described in the above specific embodiments, they can be combined in any appropriate manner without contradiction. To avoid unnecessary repetition, the present application will not separately describe various possible combination methods. Again, for example, any combination can be made between various different embodiments of the present application, as long as it does not violate the idea of the present application, it should also be regarded as the content disclosed by the present application.

[0210] It should also be understood that in various method embodiments of the present application, the magnitudes of the serial numbers of the above processes do not mean the order of execution is prior or posterior. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0211] The method provided by the embodiments of the present application has been described above. Next, the data processing device provided by the embodiments of the present application will be described.

[0212] Figure 4 It is a schematic diagram of a data processing device 400 provided by an embodiment of the present application. As Figure 4 shown, the device 400 includes: a reading module 410, a determining module 420, and an evaluating module 430. Among them, the reading module 410 is configured to read evaluation data for evaluating the target security policy after a preset duration when the target security policy goes online; the determining module 420 is configured to determine at least one of the benefit ratio of the target security policy to all currently online security policies and the cost ratio of the target security policy to all currently online security policies based on the evaluation data; the evaluating module 430 is configured to evaluate the target security policy based on at least one of the benefit ratio and the cost ratio.

[0213] In some implementable manners, the determining module 420 is specifically configured to perform at least one of the following:

[0214] The evaluation data includes: for each security policy among all currently online security policies, the automatic processing volume of the security policy, the automatic processing accuracy rate of the security policy, the manual submission volume for the security policy, and the manual processing rate for the security policy; determine the benefit ratio based on the automatic processing volume, automatic processing accuracy rate, manual submission volume, and manual processing rate of each security policy among all currently online security policies;

[0215] The evaluation data includes: for each security policy among all the currently online security policies, the machine service cost of the security policy, the manual submission volume for the security policy, and the manual service cost for each submission content; based on the machine service cost, manual submission volume, and manual service cost for each submission content of each security policy among all the currently online security policies, determine the cost ratio.

[0216] In some implementable ways, the determining module 420 is specifically configured to: calculate the benefit of the target security policy based on the automatic processing volume, automatic processing accuracy rate, manual submission volume, and manual processing rate of the target security policy; calculate the total benefit of all the currently online security policies based on the automatic processing volume, automatic processing accuracy rate, manual submission volume, and manual processing rate of each security policy among all the currently online security policies; calculate the ratio of the benefit of the target security policy to the total benefit of all the currently online security policies to obtain the benefit ratio.

[0217] In some implementable ways, the determining module 420 is specifically configured to: calculate the product of the automatic processing volume of the target security policy and the automatic processing accuracy rate of the target security policy to obtain a first product result; calculate the product of the manual submission volume of the target security policy and the manual processing rate of the target security policy to obtain a second product result; calculate the sum of the first product result and the second product result, and then multiply by the weight corresponding to the category to which the target security policy belongs to obtain the benefit of the target security policy.

[0218] In some implementable ways, the determining module 420 is specifically configured to: for each security policy among all the currently online security policies, calculate the product of the automatic processing volume of the security policy and the automatic processing accuracy rate of the security policy to obtain a third product result; calculate the product of the manual submission volume of the security policy and the manual processing rate of the security policy to obtain a fourth product result; calculate the sum of the third product result and the fourth product result, and then multiply by the weight corresponding to the category to which the security policy belongs to obtain the benefit of the security policy; calculate the sum of the benefits of each security policy among all the currently online security policies to obtain the total benefit of all the currently online security policies.

[0219] In some implementable ways, the determining module 420 is specifically configured to: calculate the cost of the target security policy based on the machine service cost, manual submission volume, and manual service cost for each submission content of the target security policy; calculate the total cost of all the currently online security policies based on the machine service cost, manual submission volume, and manual service cost for each submission content of each security policy among all the currently online security policies; calculate the ratio of the cost of the target security policy to the total cost of all the currently online security policies to obtain the cost ratio.

[0220] In some implementable ways, the determining module 420 is specifically configured to: calculate the product of the manual submission quantity for the target security policy and the manual service cost for each submission content to obtain a fifth product result; calculate the sum of the fifth product result and the machine service cost of the target security policy to obtain the cost of the target security policy.

[0221] In some implementable ways, the determining module 420 is specifically configured to: for each security policy among all the currently launched security policies, calculate the product of the manual submission quantity for the security policy and the manual service cost for each submission content to obtain a sixth product result; calculate the sum of the sixth product result and the machine service cost of the security policy to obtain the cost of the security policy; calculate the sum of the costs of each security policy among all the currently launched security policies to obtain the total cost of all the currently launched security policies.

[0222] In some implementable ways, the determining module 420 is further configured to determine the stability index of the target security policy; correspondingly, the determining module 420 is specifically configured to: evaluate the target security policy based on at least one of the benefit ratio and the cost ratio, and the stability index.

[0223] In some implementable ways, the determining module 420 is specifically configured to perform at least one of the following:

[0224] Calculate the product of the benefit ratio and the stability index to obtain a seventh product result; and evaluate the target security policy based on the seventh product result;

[0225] Calculate the product of the reciprocal of the cost ratio and the stability index to obtain an eighth product result; and evaluate the target security policy based on the eighth product result;

[0226] Calculate the ratio of the benefit ratio to the cost ratio, and then calculate the product of the ratio and the stability index to obtain a ninth product result; and evaluate the target security policy based on the ninth product result.

[0227] In some implementable ways, when evaluating the target security policy based on the benefit ratio and the cost ratio, the determining module 420 is specifically configured to: calculate the ratio of the benefit ratio to the cost ratio for N content sets respectively to obtain N target ratios; where N is an integer greater than 1; determine the stability index based on the expected values corresponding to the N target ratios and the N target ratios.

[0228] In some implementable ways, the apparatus 400 further includes: a pushing module 440, configured to, after the evaluating module 430 evaluates the target security policy based on at least one of the benefit ratio and the cost ratio, if the target security policy is evaluated as a security policy to be adjusted, push an alarm message to prompt the object to adjust the target security policy.

[0229] In some implementable manners, the apparatus 400 further includes: a decommissioning module 450, configured to: if a target security policy is evaluated as a security policy to be decommissioned, decommission the target security policy.

[0230] In some implementable manners, the apparatus 400 further includes: a release module 460. If a target security policy is evaluated as a security policy to be decommissioned, the decommissioning module 450 is further configured to decommission services related to the target security policy; and / or, if a target security policy is evaluated as a security policy to be decommissioned, the release module 460 releases the hardware resources of the target security policy.

[0231] It should be understood that the apparatus embodiments and the method embodiments can correspond to each other, and similar descriptions can refer to the method embodiments. To avoid repetition, details are not described herein again. Specifically, Figure 4 the illustrated apparatus 400 can execute Figure 2 the corresponding method embodiments, and the foregoing and other operations and / or functions of each module in the apparatus 400 are respectively for implementing Figure 2 the corresponding processes in each method in, for the sake of brevity, details are not described herein again.

[0232] The apparatus 400 of the embodiments of the present application has been described above from the perspective of functional modules with reference to the accompanying drawings. It should be understood that the functional modules can be implemented in the form of hardware, or in the form of instructions in software, or in a combination of hardware and software modules. Specifically, the steps of the method embodiments in the present application can be completed by the integrated logic circuit in the hardware in the processor and / or instructions in software. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by a combination of the hardware and software modules in the decoding processor. Optionally, the software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps in the foregoing method embodiments.

[0233] Figure 5 is a schematic block diagram of an electronic device provided by an embodiment of the present application.

[0234] As Figure 5 shown, the electronic device may include:

[0235] a memory 510 and a processor 520. The memory 510 is used to store a computer program and transmit the program code to the processor 520. In other words, the processor 520 can call and run the computer program from the memory 510 to implement the methods in the embodiments of the present application.

[0236] For example, the processor 520 can be used to execute the above method embodiments according to the instructions in the computer program.

[0237] In some embodiments of the present application, the processor 520 may include, but is not limited to:

[0238] a general-purpose processor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and so on.

[0239] In some embodiments of the present application, the memory 510 includes, but is not limited to:

[0240] a volatile memory and / or a non-volatile memory. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synch link dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).

[0241] In some embodiments of the present application, the computer program may be divided into one or more modules. The one or more modules are stored in the memory 510 and executed by the processor 520 to complete the method provided by the present application. The one or more modules may be a series of computer program instruction segments capable of performing specific functions, and the instruction segments are used to describe the execution process of the computer program in the electronic device.

[0242] As Figure 5 shown, the electronic device may further include:

[0243] a transceiver 530, which may be connected to the processor 520 or the memory 510.

[0244] Among them, the processor 520 may control the transceiver 530 to communicate with other devices. Specifically, it may send information or data to other devices, or receive information or data sent by other devices. The transceiver 530 may include a transmitter and a receiver. The transceiver 530 may further include an antenna, and the number of antennas may be one or more.

[0245] It should be understood that each component in the electronic device is connected through a bus system. Among them, the bus system includes not only a data bus, but also a power bus, a control bus, and a status signal bus.

[0246] The present application also provides a computer storage medium, on which a computer program is stored. When the computer program is executed by the computer, the computer can execute the method of the above method embodiments. Or rather, the embodiments of the present application also provide a computer program product including instructions. When the instructions are executed by the computer, the computer executes the method of the above method embodiments.

[0247] When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of this application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a digital video disc (DVD)), or a semiconductor medium (such as a solid state disk (SSD)), etc.

[0248] Those of ordinary skill in the art can realize that the modules and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0249] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division. In actual implementation, there can be other division methods. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of devices or modules can be in electrical, mechanical, or other forms.

[0250] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed across multiple network elements. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. For example, in each embodiment of the present application, the functional modules can be integrated in one processing module, or each module can exist physically alone, or two or more modules can be integrated in one module.

[0251] The above content is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A data processing method, characterized in that, Including: After a preset duration since the target security policy goes online, reading evaluation data for evaluating the target security policy; Based on the evaluation data, determining at least one of a benefit ratio of the target security policy to all currently online security policies and a cost ratio of the target security policy to all currently online security policies; Evaluating the target security policy based on at least one of the benefit ratio and the cost ratio.

2. The method according to claim 1, wherein The determining at least one of the benefit ratio of the target security policy to all currently online security policies and the cost ratio of the target security policy to all currently online security policies based on the evaluation data includes at least one of the following: The evaluation data includes: for each security policy among all currently online security policies, the automatic processing volume of the security policy, the automatic processing accuracy rate of the security policy, the manual submission volume for the security policy, and the manual processing rate for the security policy; determining the benefit ratio based on the automatic processing volume, automatic processing accuracy rate, manual submission volume, and manual processing rate of each security policy among all currently online security policies; The evaluation data includes: for each security policy among all currently online security policies, the machine service cost of the security policy, the manual submission volume for the security policy, and the manual service cost of each submission content; determining the cost ratio based on the machine service cost, manual submission volume, and manual service cost of each submission content of each security policy among all currently online security policies.

3. The method according to claim 2, wherein The determining the benefit ratio based on the automatic processing volume, automatic processing accuracy rate, manual submission volume, and manual processing rate of each security policy among all currently online security policies includes: Calculating the benefit of the target security policy based on the automatic processing volume, automatic processing accuracy rate, manual submission volume, and manual processing rate of the target security policy; Calculating the total benefit of all currently online security policies based on the automatic processing volume, automatic processing accuracy rate, manual submission volume, and manual processing rate of each security policy among all currently online security policies; Calculating the ratio of the benefit of the target security policy to the total benefit of all currently online security policies to obtain the benefit ratio.

4. The method according to claim 3, characterized in that The calculating the benefit of the target security policy based on the automatic processing volume, automatic processing accuracy rate, manual submission volume, and manual processing rate of the target security policy includes: Calculating the product of the automatic processing volume of the target security policy and the automatic processing accuracy rate of the target security policy to obtain a first product result; Calculating the product of the manual submission volume of the target security policy and the manual processing rate of the target security policy to obtain a second product result; Calculating the product of the sum of the first product result and the second product result and the weight corresponding to the category to which the target security policy belongs to obtain the benefit of the target security policy.

5. The method according to claim 3, characterized in that, Calculating the total revenue of all the currently launched security policies based on the automated processing volume, automated processing accuracy rate, manual review volume, and manual processing rate of each security policy among all the currently launched security policies, includes: For each security policy among all the currently launched security policies, calculate the product of the automated processing volume of the security policy and the automated processing accuracy rate of the security policy to obtain a third product result; Calculate the product of the manual review volume of the security policy and the manual processing rate of the security policy to obtain a fourth product result; Calculate the sum of the third product result and the fourth product result, and then multiply by the weight corresponding to the category to which the security policy belongs to obtain the revenue of the security policy; Calculate the sum of the revenues of each security policy among all the currently launched security policies to obtain the total revenue of all the currently launched security policies.

6. The method according to claim 2, wherein Determining the cost ratio based on the machine service cost, manual review volume, and manual service cost per reviewed content of each security policy among all the currently launched security policies, includes: Based on the machine service cost, manual review volume, and manual service cost per reviewed content of the target security policy, calculate the cost of the target security policy; Based on the machine service cost, manual review volume, and manual service cost per reviewed content of each security policy among all the currently launched security policies, calculate the total cost of all the currently launched security policies; Calculate the ratio of the cost of the target security policy to the total cost of all the currently launched security policies to obtain the cost ratio.

7. The method according to claim 6, wherein Calculating the cost of the target security policy based on the machine service cost, manual review volume, and manual service cost per reviewed content of the target security policy, includes: Calculate the product of the manual review volume for the target security policy and the manual service cost per reviewed content to obtain a fifth product result; Calculate the sum of the fifth product result and the machine service cost of the target security policy to obtain the cost of the target security policy.

8. The method according to claim 6, characterized in that Calculating the total cost of all the currently launched security policies based on the machine service cost, manual review volume, and manual service cost per reviewed content of each security policy among all the currently launched security policies, includes: For each security policy among all the currently launched security policies, calculate the product of the manual review volume for the security policy and the manual service cost per reviewed content to obtain a sixth product result; Calculate the sum of the sixth product result and the machine service cost of the security policy to obtain the cost of the security policy; Calculate the sum of the costs of each security policy among all the currently launched security policies to obtain the total cost of all the currently launched security policies.

9. The method according to any one of claims 1-8, characterized in that, Before evaluating the target security policy based on at least one of the revenue ratio and the cost ratio, further includes: Determine the stability index of the target security policy; Evaluating the target security policy based on at least one of the revenue ratio and the cost ratio, includes: Evaluate the target security policy based on at least one of the benefit ratio and the cost ratio, and the stability index.

10. The method according to claim 9, wherein The evaluating the target security policy based on at least one of the benefit ratio and the cost ratio, and the stability index includes at least one of the following: Calculate the product of the benefit ratio and the stability index to obtain a seventh product result; and evaluate the target security policy based on the seventh product result; Calculate the product of the reciprocal of the cost ratio and the stability index to obtain an eighth product result; And evaluate the target security policy based on the eighth product result; Calculate the ratio of the benefit ratio to the cost ratio, and then multiply it by the stability index to obtain a ninth product result; And evaluate the target security policy based on the ninth product result.

11. The method according to claim 9, wherein When evaluating the target security policy based on the benefit ratio and the cost ratio, determining the stability index of the target security policy includes: Calculate the ratio of the benefit ratio to the cost ratio for N content sets respectively to obtain N target ratios; where N is an integer greater than 1; Determine the stability index based on the expected values corresponding to the N target ratios and the N target ratios.

12. The method according to any one of claims 1-8, characterized in that After evaluating the target security policy based on at least one of the benefit ratio and the cost ratio, it further includes: If the target security policy is evaluated as a security policy to be adjusted, push an alarm message to prompt the object to adjust the target security policy.

13. The method according to any one of claims 1-8, characterized in that, After evaluating the target security policy based on at least one of the benefit ratio and the cost ratio, it further includes: If the target security policy is evaluated as a security policy to be taken offline, take the target security policy offline.

14. The method according to claim 13, wherein It further includes at least one of the following: If the target security policy is evaluated as a security policy to be taken offline, take offline the services related to the target security policy; If the target security policy is evaluated as a security policy to be taken offline, release the hardware resources of the target security policy.

15. A data processing device, characterized in that, It includes: A reading module, configured to read evaluation data for evaluating the target security policy after a preset duration since the target security policy goes online; A determining module, configured to determine at least one of the benefit ratio of the target security policy to all currently online security policies and the cost ratio of the target security policy to all currently online security policies based on the evaluation data; An evaluating module, configured to evaluate the target security policy based on at least one of the benefit ratio and the cost ratio.

16. An electronic device, characterized in that, It includes: A processor and a memory, the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory to execute the method according to any one of claims 1 to 14.

17. A computer-readable storage medium, characterized in that, For storing a computer program, the computer program causes a computer to execute the method according to any one of claims 1 to 14.

18. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, the method according to any one of claims 1 to 14 is implemented.