Data security processing method and system

Through the collaborative work of the data monitoring end and the proxy client, the data interaction of the user device is monitored and processed, which solves the deviation when the user independently executes the data security operation specifications, improves data security, and ensures the confidentiality, integrity and availability of the data.

CN120415925BActive Publication Date: 2025-09-16BEIJING ANHUA JINHE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510919552.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-04
Publication Date
2025-09-16
Estimated Expiration
2045-07-04

AI Technical Summary

Technical Problem

Deviations occur when users independently execute data security operation specifications, leading to data security issues.

Method used

Through the collaborative work of the data monitoring terminal and the proxy client, the data interaction between the user device and the devices outside the LAN is monitored, the data packets are analyzed, and it is determined whether the data behavior complies with security regulations. If not, the data is intercepted, encrypted or desensitized, and a warning is displayed on the user device.

Benefits of technology

Improves data security, ensures confidentiality, integrity and availability during data transmission and storage, and reduces the risk of unauthorized access and modification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120415925B_ABST
    Figure CN120415925B_ABST
Patent Text Reader

Abstract

The present application discloses a data security processing method and system, which includes: a data monitoring end captures data packets generated when a user device interacts with other devices outside a local area network; the data monitoring end analyzes the data packets to obtain the protocol used by the data packets; the data monitoring end finds the proxy client in the user device that sends the data packet based on the network address in the data packet; the proxy client obtains the predetermined software in the user device that sends the data packet; the proxy client determines whether the data sent by the predetermined software and the behavior of sending the data comply with data security regulations based on the recorded previous behavior of the predetermined software that sends the data packet. If not, the proxy client sends an alarm message to the data monitoring end. This application solves the data security problem caused by deviations when users independently execute data security operation specifications, thereby improving data security to a certain extent.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data security, and more specifically, to a data security processing method and system. Background Art

[0002] Data security refers to the implementation of a series of management and technical measures to ensure the confidentiality, integrity, and availability of data during storage, processing, and transmission. Its core goal is to protect data from unauthorized access, use, disclosure, destruction, modification, or loss.

[0003] Data security covers a wide range, including but not limited to the following aspects: Confidentiality: Ensure that data is accessed only by authorized users and prevent sensitive information from being obtained by unauthorized persons. This is usually achieved through encryption, access control lists (ACLs), authentication and authorization mechanisms. Integrity: Ensure that data is not modified without authorization during transmission and storage, and maintain the authenticity and accuracy of the data. This can be achieved through hash functions, digital signatures and security protocols (such as HTTPS). Availability: Ensure that authorized users can access data in a timely manner when needed. This involves disaster recovery plans, redundant systems, backup and recovery strategies to prevent data from becoming unavailable due to hardware failures, natural disasters or malicious attacks. Compliance: Comply with relevant laws, regulations and industry standards to ensure that data processing activities comply with legal requirements.

[0004] In related technologies, data usage specifications are required. For example, when sending data via email, if the data involves sensitive information, a predetermined level of encryption algorithm must be used. These data usage specifications must be implemented by the user, and deviations may occur during user implementation, which can lead to data security issues. Summary of the Invention

[0005] The embodiments of the present application provide a data security processing method and system to at least solve the data security problem caused by deviations when users independently execute data security operation specifications.

[0006] According to one aspect of the present application, a data security processing method is provided, comprising: a data monitoring end captures a data packet generated when a user device interacts with other devices outside a local area network, wherein the user device and the data monitoring end are both located in the local area network; the data monitoring end analyzes the data packet to obtain the protocol used by the data packet; the data monitoring end determines whether the amount of data sent by the user device exceeds a pre-configured condition based on the number of data packets of the protocol captured within a predetermined time period and the size of the data packets; if the condition is exceeded, the data monitoring end finds the network address that sent the data packet based on the network address in the data packet. A proxy client in a user device; the proxy client obtains predetermined software in the user device that sends the data packet, wherein the proxy client is installed in the user device and monitors the operation of various software in the user device and records the behavior of the various software; the proxy client determines whether the data sent by the predetermined software and the behavior of sending the data comply with data security regulations based on the recorded previous behavior of the predetermined software that sent the data packet, and if not, the proxy client sends an alarm message to the data monitoring terminal, and the alarm message is used to instruct the data monitoring terminal to intercept the captured data packet from the predetermined software.

[0007] Furthermore, it also includes: after the proxy client sends the alarm information, the proxy client pops up a warning prompt box in the user device, wherein the warning prompt box displays the name of the predetermined software and the fact that the behavior of the predetermined software sending data exceeds the data security regulations; after the user uses the predetermined software to resend the data, the proxy client sends an indication message to the data monitoring end, and the indication message is used to instruct the data monitoring end to delete the previously intercepted data packet.

[0008] Furthermore, it also includes: the proxy client obtains the security level of the data and processes the data according to the security level of the data, wherein the processing includes at least one of the following: encryption, desensitization; and sending the processed data to the data monitoring end; the data monitoring end uses the processed data to replace the data of the data packet according to the protocol of the intercepted data packet; the data monitoring end uses the replaced data to construct a new data packet, and sends the constructed new data packet according to the destination address of the captured original data packet.

[0009] Furthermore, the method further includes: after intercepting the data packet, the data monitoring terminal sends the information of the data packet and the interception time to the service terminal for storage.

[0010] According to another aspect of the present application, a data security processing system is also provided, comprising: a data monitoring terminal and a proxy client, wherein the data monitoring terminal captures data packets generated when a user device interacts with other devices outside a local area network, wherein the user device and the data monitoring terminal are both located in the local area network; the data monitoring terminal analyzes the data packets to obtain the protocol used by the data packets; the data monitoring terminal determines whether the amount of data sent by the user device exceeds a pre-configured condition based on the number of data packets of the protocol captured within a predetermined time period and the size of the data packets; if the condition is exceeded, the data monitoring terminal searches for the network address in the data packet and checks whether the amount of data sent by the user device exceeds a pre-configured condition; to a proxy client in a user device that sends the data packet; the proxy client obtains the predetermined software in the user device that sends the data packet, wherein the proxy client is installed in the user device and monitors the operation of various software in the user device and records the behavior of the various software; the proxy client determines whether the data sent by the predetermined software and the behavior of sending the data comply with data security regulations based on the recorded previous behavior of the predetermined software that sends the data packet, and if not, the proxy client sends an alarm message to the data monitoring end, and the alarm message is used to instruct the data monitoring end to intercept the captured data packet from the predetermined software.

[0011] Furthermore, after the proxy client sends the alarm information, the proxy client pops up a warning prompt box in the user device, wherein the warning prompt box displays the name of the predetermined software and the fact that the behavior of the predetermined software sending data exceeds the data security regulations; after the user uses the predetermined software to resend the data, the proxy client sends an indication message to the data monitoring end, and the indication message is used to instruct the data monitoring end to delete the previously intercepted data packet.

[0012] Furthermore, the proxy client obtains the security level of the data and processes it according to the security level of the data, wherein the processing includes at least one of the following: encryption, desensitization; and sending the processed data to the data monitoring end; the data monitoring end uses the processed data to replace the data of the data packet according to the protocol of the intercepted data packet; the data monitoring end uses the replaced data to construct a new data packet, and sends the constructed new data packet according to the destination address of the captured original data packet.

[0013] Furthermore, it also includes: a server, wherein, after intercepting the data packet, the data monitoring terminal sends the information of the data packet and the interception time to the server for storage.

[0014] According to another aspect of the present application, an electronic device is also provided, comprising a memory and a processor; wherein the memory is used to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement the above-mentioned method steps.

[0015] According to another aspect of the present application, a readable storage medium is provided, on which computer instructions are stored, wherein the computer instructions implement the above method steps when executed by a processor.

[0016] In an embodiment of the present application, a data monitoring terminal is used to capture data packets generated when a user device interacts with other devices outside a local area network, wherein the user device and the data monitoring terminal are both located in the local area network; the data monitoring terminal analyzes the data packets to obtain the protocol used by the data packets; the data monitoring terminal determines whether the amount of data sent by the user device exceeds a pre-configured condition based on the number and size of data packets of the protocol captured within a predetermined time period; if the condition is exceeded, the data monitoring terminal locates a proxy client in the user device that sent the data packet based on the network address in the data packet; the proxy client obtains a predetermined software in the user device that sends the data packet, wherein the proxy client is installed in the user device and monitors the operation of various software in the user device and records the behavior of the various software; the proxy client determines whether the data sent by the predetermined software and the behavior of sending the data comply with data security regulations based on the recorded previous behavior of the predetermined software that sent the data packet. If not, the proxy client sends an alarm message to the data monitoring terminal, wherein the alarm message is used to instruct the data monitoring terminal to intercept the captured data packet from the predetermined software. This application solves the data security problem caused by deviations when users independently execute data security operation specifications, thereby improving data security to a certain extent. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawings, which constitute part of this application, are intended to provide a further understanding of this application. The exemplary embodiments and descriptions of this application are intended to explain this application and do not constitute an improper limitation on this application. In the accompanying drawings:

[0018] Figure 1 is a schematic diagram of a data security processing system according to an embodiment of the present application;

[0019] Figure 2 It is a flowchart of a data security processing method according to an embodiment of the present application. DETAILED DESCRIPTION

[0020] It should be noted that, in the absence of conflict, the embodiments and features of the embodiments in this application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0021] It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and that, although a logical order is shown in the flowcharts, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0022] In the following embodiment, a software system is provided. The software system is divided into three parts: a server, a proxy client, and a data monitoring end. These three parts are used to monitor data within a network, for example, a local area network. Figure 1 is a schematic diagram of a data security processing system according to an embodiment of the present application. Figure 1 As shown, the above software system includes a data monitoring end and a server end, wherein the proxy client can be one or more, and the number of proxy clients is the same as the number of user devices that need to be monitored. A proxy client is installed in each user device 1 to user device n, that is, proxy client 1 to proxy client n. Figure 1 Only user device 1, proxy client 1, user device n, and proxy client n are shown. The user device may be a computer device used by a user, and various software may be installed on the computer device, such as software for sending emails, instant messaging software, data transmission software, etc. The data transmission software here may be a database client, FTP software, etc. Figure 1 The middle dotted line represents a local area network. The database, server, proxy client, and user device are all in the same local area network. The user device exchanges data with devices in other networks outside the local area network. Figure 1 The double-headed arrows in indicate data links.

[0023] In an optional embodiment, the server side connects to all proxy clients, obtains the software behavior recorded by the proxy clients, and determines a window period based on the recorded software behavior, wherein the window period is a period during which all proxy clients do not record any software behavior; the server side sends an upgrade software package to all proxy clients during the window period, and the upgrade software package is used to upgrade the proxy clients.

[0024] Figure 2 is a flow chart of a data security processing method according to an embodiment of the present application. Figure 2 As shown below, Figure 2 The steps involved in the method are described.

[0025] In step S202, the data monitoring terminal captures data packets generated when the user device interacts with other devices outside the local area network, wherein the user device and the data monitoring terminal are both located in the local area network.

[0026] Step S204: the data monitoring terminal analyzes the data packet to obtain the protocol used by the data packet.

[0027] Analyzing data packets can also directly determine whether they are worm packets. For example, ① capture all data packets entering and leaving the network; ② analyze the captured data packets according to the corresponding protocol and extract the payload in the data packet, and then use the layers and standards of various protocols to decode, reassemble and parse the data packet payload; ③ filter the data packets containing the payload after step ②: a. If the data packet payload itself can match the signature code of a known malicious code, directly block and alarm it; b. Using the principle that the key code of a polymorphic worm data packet cannot contain null characters, use a pattern matching algorithm in the data packet payload to find the distance between two null characters. If the distance is less than a given threshold, the location cannot be the key code of the worm. Key code, so there is no need to continue to judge at this location, for each byte string in the data packet payload whose distance is greater than a given threshold, enter step ④ for processing; ④ determine whether the data packet processed in step ③ contains NopSled to determine whether the data packet is a worm data packet: corresponding to a byte string of length n, if the instruction string disassembled from each position is valid, it is considered to contain NopSled and the data packet is determined to be a worm data packet; ⑤ respond to the detected worm data packet: extract the source IP address, source port number, and destination IP address information in the data packet, and add rules in the firewall to filter data packets with the source IP address host and the source port number, and also filter data packets with the destination IP address host and the port number. According to the polymorphic worm self-detection method provided by the present invention, the valid instruction string in step ④ includes the following two situations: a. Each instruction in the instruction string has the correct opcode and operand. If the instruction has a memory address to access, the corresponding memory address can be accessed and the instruction does not contain any privileged instructions; b. Jump instructions such as jmp are encountered in the instruction string.

[0028] As an optional implementation, if the data monitoring end analyzes the data packet and concludes that the data packet is a worm data packet, the data monitoring end instructs the proxy client on the user device where the worm data packet is sourced to display a prompt message on the user device where the user device is located. After the prompt message is displayed, the user device is locked and the software on it cannot be used. The prompt message can only be closed by the administrator.

[0029] In step S206, the data monitoring end determines whether the amount of data sent by the user device exceeds a pre-configured condition based on the number of data packets of the protocol captured within a predetermined time period and the size of the data packets; if it exceeds the condition, the data monitoring end searches for the proxy client in the user device that sent the data packet based on the network address in the data packet.

[0030] In step S208, the proxy client obtains the predetermined software for sending the data packet in the user device, wherein the proxy client is installed in the user device and monitors the operation of various software in the user device and records the behavior of the various software.

[0031] In step S210, the proxy client determines whether the data sent by the predetermined software and the behavior of sending the data comply with data security regulations based on the recorded previous behavior of the predetermined software that sent the data packet. If not, the proxy client sends an alarm message to the data monitoring terminal, and the alarm message is used to instruct the data monitoring terminal to intercept the captured data packet from the predetermined software.

[0032] In one example, the data monitoring terminal records the received alarm information. When the number of alarm information from the same network address exceeds a preset number within a predetermined time length, the data monitoring terminal sends a command to the proxy client on the network address. In response to the command, the proxy client sends all the recorded software behaviors within a period of time closest to the current time to the data monitoring terminal; the data monitoring terminal judges the software behavior. If it is determined that the software behavior involves risky behavior, the data monitoring terminal instructs the proxy client to display a prompt message on the user device where it is located. After the prompt message is displayed, the user device is locked, and the software on it cannot be used. The prompt message can only be closed by the administrator.

[0033] The data monitoring terminal can also perform the following steps: S1. Confirmation of abnormal terminal device (i.e., user device) IP addresses: Collect the IP addresses of each terminal device historically connected to the target company's wireless LAN, build a terminal device IP database for the target company, monitor the terminal device IP addresses connected to the target company's wireless LAN during the current monitoring period, and confirm each abnormal terminal device IP address during the current monitoring period. S2. Feedback on seriously abnormal terminal device IP addresses: Extract the online duration, traffic consumption, and traffic transmission speed corresponding to each abnormal terminal device IP address during the current monitoring period, analyze the traffic anomaly warning coefficient for each abnormal terminal device IP address, confirm each seriously abnormal terminal device IP address during the current monitoring period, and feedback each seriously abnormal terminal device IP address to the network administrator. S3. Confirmation of abnormal terminal devices: Extract the traffic consumption corresponding to each terminal device of the target company during each monitoring time period on each historical monitoring day, and collect the traffic consumption corresponding to each terminal device during each monitoring time period on the current monitoring day, and confirm each abnormal terminal device of the target company during each monitoring time period on the current monitoring day. S4. Feedback on traffic anomaly types: Extract the historical usage records of each terminal device of the target company to obtain the historical usage information of each terminal device, and extract the IP addresses of each abnormal terminal device, the names of each app running in the background, and the URLs of each web page visited corresponding to each monitoring time period of the target company on the current monitoring day, confirm the traffic anomaly type of each abnormal terminal device corresponding to each monitoring time period of the current monitoring day, and feedback the traffic anomaly type of each abnormal terminal device to the network administrator. The method for confirming the IP addresses of each abnormal terminal device in the current monitoring period is as follows: match and compare the IP addresses of the terminal devices connected to the target company's wireless LAN during the current monitoring period with the IP addresses of the terminal devices in the target company's terminal device IP library. If the IP address of a terminal device connected during the current monitoring period is not in the terminal device IP library, then the IP address of the terminal device is recorded as an abnormal terminal device IP, thereby obtaining the IP addresses of each abnormal terminal device in the current monitoring period.

[0034] The above steps solve the data security problem caused by deviations when users independently execute data security operation specifications, thereby improving data security to a certain extent.

[0035] If it does not comply, there are two ways to handle it. In the first way, after sending the alarm information, the proxy client pops up a warning prompt box in the user device, wherein the warning prompt box displays the name of the predetermined software and the fact that the behavior of the predetermined software sending data exceeds the data security regulations; after the user uses the predetermined software to resend the data, the proxy client sends an indication message to the data monitoring end, and the indication message is used to instruct the data monitoring end to delete the previously intercepted data packet.

[0036] Method 2: The proxy client obtains the security level of the data and processes it according to the security level of the data, wherein the processing includes at least one of the following: encryption, desensitization; and sends the processed data to the data monitoring end; the data monitoring end replaces the data of the data packet with the processed data according to the protocol of the intercepted data packet, and the data monitoring end uses the replaced data to construct a new data packet, and sends the constructed new data packet according to the destination address of the captured original data packet.

[0037] There are many ways to encrypt, which are explained below with a few examples.

[0038] Example 1

[0039] Data is encrypted to obtain an initial intermediate result; the initial intermediate result is input into a basic operator layer to obtain target encrypted data output by the basic operator layer; wherein the basic operator layer includes a linear calculation layer, a data type conversion layer, and a nonlinear element-by-element calculation layer. Inputting the initial intermediate result into the basic operator layer to obtain the target encrypted data output by the basic operator layer includes: if the data type of the initial intermediate result is inconsistent with the target data type, inputting the initial intermediate result into the data type conversion layer to obtain first data of the target data type output by the data type conversion layer; inputting the first data into the linear calculation layer to obtain first encrypted data output by the linear calculation layer; inputting the first encrypted data into the nonlinear element-by-element calculation layer to obtain target encrypted data output by the nonlinear element-by-element calculation layer. Inputting the first data into the linear calculation layer to obtain the first encrypted data output by the linear calculation layer includes: splitting the first data to obtain at least two subsequences; and determining the first encrypted data based on the at least two subsequences. Determining the first encrypted data based on the at least two subsequences includes: obtaining a target multiplication triplet; and determining the first encrypted data based on the target multiplication triplet and the at least two subsequences. Inputting first encrypted data into a nonlinear element-by-element computation layer to obtain target encrypted data output by the nonlinear element-by-element computation layer includes: obtaining a first shared value and a second shared value corresponding to the first encrypted data; processing the first shared value and the second shared value using a target random permutation to obtain a third shared value and a fourth shared value; determining an element-by-element function result based on the third shared value and the fourth shared value; splitting the element-by-element function result to obtain a fifth shared value and a sixth shared value; and performing inverse permutations on the fifth shared value and the sixth shared value to determine the target encrypted data. Processing the first shared value and the second shared value using a target random permutation to obtain a third shared value and a fourth shared value includes: obtaining a target random flip vector; processing the first shared value and the second shared value based on the target random permutation and the target random flip vector to obtain the third shared value and the fourth shared value. The basic operator layer includes at least one basic operator selected from the group consisting of addition, subtraction, multiplication, shape transformation, and shape broadcasting.

[0040] Example 2

[0041] A common key is generated between a first user and a second user (here the first user is a user using a first user device, and the second user is a user using a second user device), and the first user also generates his own first secret key, and the second user also generates his own second secret key. At the same time, the first user performs an XOR calculation on the common key and the first secret key, and the second user performs an XOR calculation on the common key and the second secret key; the first user and the second user respectively use encrypted transmission to send the results of the XOR calculation of the common key and the first secret key, as well as the results of the XOR calculation of the common key and the second secret key to the analysis server; the analysis server continues to perform an XOR calculation on the results of the XOR calculation of the common key and the first secret key by the first user and the results of the XOR calculation of the common key and the second secret key by the second user to obtain an analysis key; the first user performs an XOR calculation on his own first confidential data and the first secret key, and sends the result of the XOR calculation to the analysis server using encrypted transmission, and the second user performs an XOR calculation on his own second confidential data and the second secret key, and also sends the result of the XOR calculation to the analysis server using encrypted transmission. The analysis server performs a joint analysis and processing based on the result of the XOR calculation of the first confidential data and the first secret key, and the result of the XOR calculation of the second confidential data and the second secret key, and sends the result of the analysis and processing back to the first user and the second user; the first user and the second user respectively receive the result of the analysis and processing from the analysis server, and perform decryption processing on the result of the analysis and processing; the analysis server performs a joint analysis and processing based on the result of the XOR calculation of the first confidential data and the first secret key, and the result of the XOR calculation of the second confidential data and the second secret key, including the following steps: performing an XOR calculation on the result of the XOR calculation of the first confidential data and the first secret key and the analysis key to obtain the result of the XOR calculation of the first confidential data and the second secret key; performing a pre-set joint analysis and processing step based on the result of the XOR calculation of the first confidential data and the second secret key, and the result of the XOR calculation of the second confidential data and the second secret key, and obtaining an intermediate result of the analysis and processing; performing an XOR calculation on the intermediate result of the analysis and processing and the result of the XOR calculation of the common key and the second secret key to obtain the result of the analysis and processing.

[0042] The first user and the second user respectively receive the results of the analysis and processing from the analysis server, and decrypt the results of the analysis and processing, including the following steps: the first user performs an XOR calculation on the result of the analysis and processing and the shared key, and obtains the result of the XOR calculation at the same time; the second user performs an XOR calculation on the result of the analysis and processing and the shared key, and obtains the result of the XOR calculation at the same time.

[0043] Generating a shared key between a first user and a second user includes the following steps: setting a data length of the shared key and generating random data, using the random data as seed data, wherein the data length of the seed data is less than the set data length of the shared key; dividing the seed data into a predetermined number of seed data blocks, and calculating the results of the exclusive-or calculation of two different seed data blocks for each pair of different seed data blocks, and connecting the results of the exclusive-or calculations to form an initial shared key; determining whether the data length of the initial shared key meets the set data length of the shared key; if so, using the initial shared key as the shared key; if not, using the initial shared key as new seed data, and repeating the steps of generating the initial shared key.

[0044] The encrypted transmission method includes the following steps: the first user and the second user divide the results of the XOR calculation into a preset number of sending data blocks; for the first sending data block, generate a random data as seed data, divide the seed data into a preset number of seed data blocks, and at the same time, for two different seed data blocks, respectively calculate the results of the XOR calculation of two different seed data blocks, and also connect the results of each XOR calculation to form an initial sending key, repeat the method of generating the initial sending key until the data length of the initial sending key meets the preset requirements, and select data of the preset data length starting from a preset position from the initial sending key as the sending key. Key, encrypt the first sending data block by sending the key, and send the encryption result to the analysis server; for the second sending data block, use the sending key of the first sending data block as seed data, and generate the sending key by adopting the same method as the first sending data block, encrypt the second sending data block by sending the key, and send the encryption result to the analysis server; for other sending data blocks, use the sending key of the previous sending data block as the seed data of the next sending data block in turn to generate the sending key of the next sending data block, and encrypt the next sending data block by sending the key, and send the encryption result to the analysis server.

[0045] The system setting server can manage the proxy client and the data monitoring terminal. After intercepting the data packet, the data monitoring terminal sends the information of the data packet and the interception time to the server for storage.

[0046] In the above method, the data sent out by the user device is mainly monitored. In an optional embodiment, data requests from the external network can also be monitored. For example, the data monitoring end captures an access request to the database and determines whether the network address of the source of the access request is from outside the local area network. If so, the access request is intercepted; if not, the user device where the network address is located is obtained, and a notification message is sent to the proxy client on the user device where the network address is located. The proxy client that receives the notification message checks the recorded behavior of the software on the user device and determines whether a message from the external network is received within a predetermined time period before the user device sends the data request. If the judgment result is yes, the data request is intercepted; and a prompt message is sent to the user device, wherein the prompt message is used to instruct the user using the user device to send a data request to the database again after a predetermined time interval; wherein, the data security specification stipulates that data in the local area network can only be accessed by intranet software.

[0047] In one example, automatic security level adjustment can be achieved: users in the system define security level rules based on data usage specifications. When operations from the external network do not comply with the usage specifications, these behaviors are assigned a security level and an alert is generated. However, in practice, inaccurate rule definition can still lead to incorrect security level judgments, necessitating manual verification. For example, a normal business operation may contain SQL injection vulnerability characteristics in a query statement. However, because this operation is trustworthy in the user's business, the warning level can be manually adjusted to a risk-free level. The next time the proxy client executes the configured policy, it will automatically determine similar operations as risk-free, while maintaining the SQL injection attack protection rule attributes. No adjustments are required to the manually created rules.

[0048] In this embodiment, an electronic device is provided, including a memory and a processor. The memory stores a computer program, and the processor is configured to run the computer program to execute the method in the above embodiment.

[0049] The above program can be executed in a processor or stored in a memory (or computer-readable medium). Computer-readable media includes both permanent and non-permanent, removable and non-removable media, and can be implemented using any method or technology for information storage. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.

[0050] These computer programs can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps of the functions specified in one or more blocks can be implemented by different modules corresponding to different steps.

[0051] The system or device is used to implement the functions of the method in the above-mentioned embodiment. Each module in the system or device corresponds to each step in the method, which has been explained in the method and will not be repeated here.

[0052] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.

Claims

1. A data security processing method, characterized in that: include: The data monitoring terminal captures data packets generated when a user device interacts with other devices outside the local area network, wherein the user device and the data monitoring terminal are both located in the local area network; The data monitoring terminal analyzes the data packet to obtain the protocol used by the data packet; The data monitoring terminal determines whether the amount of data sent by the user device exceeds a pre-configured condition based on the number and size of data packets of the protocol captured within a predetermined time period; if the amount exceeds the condition, the data monitoring terminal searches for a proxy client in the user device that sent the data packet based on the network address in the data packet; The proxy client obtains predetermined software in the user device for sending the data packet, wherein the proxy client is installed in the user device and monitors the operation of various software in the user device and records the behavior of the various software; The proxy client determines whether the data sent by the predetermined software and the behavior of sending the data comply with data security regulations based on the recorded previous behavior of the predetermined software that sent the data packet. If not, the proxy client sends an alarm message to the data monitoring terminal, and the alarm message is used to instruct the data monitoring terminal to intercept the captured data packet from the predetermined software.

2. The method according to claim 1, characterized in that Also includes: After the proxy client sends the warning information, the proxy client pops up a warning prompt box on the user device, wherein the warning prompt box displays the name of the predetermined software and the fact that the behavior of the predetermined software sending data exceeds the data security regulations; After the user uses the predetermined software to resend the data, the proxy client sends instruction information to the data monitoring terminal, where the instruction information is used to instruct the data monitoring terminal to delete the previously intercepted data packet.

3. The method according to claim 1, characterized in that Also includes: The proxy client obtains the security level of the data and processes the data according to the security level of the data, wherein the processing includes at least one of the following: encryption and desensitization; And send the processed data to the data monitoring end; The data monitoring terminal replaces the data of the data packet with the processed data according to the protocol of the intercepted data packet; The data monitoring terminal constructs a new data packet using the replaced data, and sends the constructed new data packet according to the destination address of the captured original data packet.

4. The method according to claim 1, wherein Also includes: After intercepting the data packet, the data monitoring terminal sends the information of the data packet and the interception time to the service terminal for storage.

5. A data security processing system, characterized in that: include: Data monitoring terminal and proxy client, among which, The data monitoring terminal captures data packets generated when a user device interacts with other devices outside the local area network, wherein the user device and the data monitoring terminal are both located in the local area network; The data monitoring terminal analyzes the data packet to obtain the protocol used by the data packet; The data monitoring terminal determines whether the amount of data sent by the user device exceeds a pre-configured condition based on the number and size of data packets of the protocol captured within a predetermined time period; if the amount exceeds the condition, the data monitoring terminal searches for a proxy client in the user device that sent the data packet based on the network address in the data packet; The proxy client obtains predetermined software in the user device for sending the data packet, wherein the proxy client is installed in the user device and monitors the operation of various software in the user device and records the behavior of the various software; The proxy client determines whether the data sent by the predetermined software and the behavior of sending the data comply with data security regulations based on the recorded previous behavior of the predetermined software that sent the data packet. If not, the proxy client sends an alarm message to the data monitoring terminal, and the alarm message is used to instruct the data monitoring terminal to intercept the captured data packet from the predetermined software.

6. The system according to claim 5, characterized in that After the proxy client sends the warning information, the proxy client pops up a warning prompt box on the user device, wherein the warning prompt box displays the name of the predetermined software and the fact that the behavior of the predetermined software sending data exceeds the data security regulations; After the user uses the predetermined software to resend the data, the proxy client sends instruction information to the data monitoring terminal, where the instruction information is used to instruct the data monitoring terminal to delete the previously intercepted data packet.

7. The system according to claim 5, characterized in that The proxy client obtains the security level of the data and processes the data according to the security level of the data, wherein the processing includes at least one of the following: encryption and desensitization; and sends the processed data to the data monitoring terminal; The data monitoring terminal replaces the data of the data packet with the processed data according to the protocol of the intercepted data packet; The data monitoring terminal constructs a new data packet using the replaced data, and sends the constructed new data packet according to the destination address of the captured original data packet.

8. The system according to claim 5, wherein: Also includes: Server, where After intercepting the data packet, the data monitoring terminal sends the information of the data packet and the interception time to the service terminal for storage.

9. An electronic device comprising a memory and a processor; wherein: The memory is configured to store one or more computer instructions, wherein the one or more computer instructions are executed by the processor to implement the method steps according to any one of claims 1 to 4.

10. A readable storage medium having computer instructions stored thereon, wherein: When the computer instructions are executed by a processor, the method steps according to any one of claims 1 to 4 are implemented.

Citation Information

Patent Citations

  • Network security monitoring method based on bypass monitoring and software packet capturing technology

    CN104601570A

  • Network security monitoring method and defense system based on same

    CN115883215A