Sensitive data analysis method, device and system and flow probe equipment
By performing data sensitive identification on the front end of the traffic probe device, the problems of network bandwidth occupation and time delay during the traffic data identification process are solved, and efficient sensitive data identification is achieved.
Patent Information
- Application Number
- CN202510709275.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-29
- Publication Date
- 2025-08-08
AI Technical Summary
In the prior art, the identification process of traffic data occupies a large network bandwidth and leads to a large data identification delay.
Data sensitive identification is performed on the front end of the traffic probe device, identify the target traffic data and report the identification results to the central service server to avoid transmitting all the original data to the central service system.
It reduces the use of network bandwidth and data identification delay of traffic data identification, and improves sensitive identification efficiency.
Smart Images

Figure CN120455335A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security technology, and in particular to a sensitive data analysis method, device, system and flow probe equipment. Background Art
[0002] Traffic probes are generally deployed at the edge of the network. Through port mirroring, the traffic of the edge switch is mirrored to the traffic probe. The traffic collected in this way is generally the inbound and outbound traffic of the edge. After the traffic is collected, the Ethernet data frame is first parsed, and the network traffic is decomposed and understood according to different levels of network protocols. Subsequently, it will undergo content decoding to restore the encoded data to the original data format and store the original traffic data packets. At the same time, the files in the traffic data are restored and stored in the local file system.
[0003] Currently, only central business systems possess this recognition capability, requiring them to continuously transmit files written to disk to the central end via the network. This method of collecting and transmitting all traffic typically consumes significant network bandwidth, and the large amount of traffic data transmitted also causes significant data recognition latency. Therefore, reducing the bandwidth consumed by traffic data recognition and lowering data recognition latency are pressing issues. Summary of the Invention
[0004] The purpose of the present invention is to provide a sensitive data analysis method, device, system and flow probe equipment to reduce the network bandwidth occupied by flow data identification and reduce data identification delay.
[0005] To solve the above technical problems, the present invention provides a sensitive data analysis method applied to a flow probe device, comprising:
[0006] Obtain the original traffic data collected by the traffic probe;
[0007] Identifying target traffic data in the original traffic data; wherein the target traffic data includes cross-border data;
[0008] Perform sensitivity identification on the target traffic data to obtain a data sensitivity identification result of the target traffic data, and report the data sensitivity identification result to a central business server.
[0009] In another aspect, identifying target traffic data in the raw traffic data includes:
[0010] Identifying IP data to be monitored in the original traffic data;
[0011] The cross-border data in the IP data to be monitored is detected according to the source IP and the destination IP in the IP data to be monitored.
[0012] On the other hand, detecting cross-border data in the IP data to be monitored based on the source IP and the destination IP in the IP data to be monitored includes:
[0013] Using a preset IP library, detecting whether the source IP in the current IP data to be monitored is a preset domestic IP and the destination IP is a preset overseas IP; wherein the current IP data to be monitored is any of the IP data to be monitored;
[0014] If so, it is determined that the current IP data to be monitored is the cross-border data.
[0015] On the other hand, identifying the IP data to be monitored in the original traffic data includes:
[0016] Identifying the data to be monitored in the original traffic data; wherein the application layer protocol type of the data to be monitored is a preset protocol to be monitored;
[0017] Identify the IP data to be monitored in the data to be monitored.
[0018] On the other hand, performing sensitivity identification on the target traffic data to obtain a data sensitivity identification result of the target traffic data includes:
[0019] Parsing the target traffic data to obtain content to be identified;
[0020] Using a preset regular expression, the content to be identified is sensitively identified to obtain a data sensitivity identification result of the target traffic data.
[0021] On the other hand, parsing the target traffic data to obtain content to be identified includes:
[0022] Detecting whether current traffic data is file transfer data; wherein the current traffic data is any of the target traffic data;
[0023] If the data is not transmitted for the file, the current traffic data is content decoded to obtain the content to be identified of the current traffic data;
[0024] If it is the file transfer data, then perform file restoration on the current traffic data and determine whether the restored file is a picture;
[0025] If it is an image, the restored file is analyzed to obtain the content to be identified of the current traffic data;
[0026] If it is not a picture, the restored file is parsed to obtain the content to be identified of the current traffic data.
[0027] On the other hand, before performing sensitivity identification on the content to be identified using a preset regular expression and obtaining the data sensitivity identification result of the target traffic data, the method further includes:
[0028] Sending an identification rule issuance request to the central business server;
[0029] Receive the preset regular expression returned by the central service server.
[0030] The present invention also provides a sensitive data analysis device, which is applied to a flow probe device, comprising:
[0031] The probe acquisition module is used to obtain the original flow data collected by the flow probe;
[0032] a target identification module, configured to identify target traffic data in the original traffic data; wherein the target traffic data includes cross-border data;
[0033] The sensitive identification module is used to perform sensitive identification on the target traffic data, obtain a data sensitive identification result of the target traffic data, and report the data sensitive identification result to the central business server.
[0034] The present invention also provides a flow probe device, comprising:
[0035] memory for storing computer programs;
[0036] A processor is used to implement the steps of the sensitive data analysis method as described above when executing the computer program.
[0037] In addition, the present invention also provides a sensitive data analysis system, including: a central business server and the traffic probe device as described above.
[0038] A sensitive data analysis method provided by the present invention is applied to a traffic probe device, including: obtaining the original traffic data collected by the traffic probe; identifying target traffic data in the original traffic data; wherein the target traffic data includes cross-border data; performing sensitive identification on the target traffic data to obtain a data sensitive identification result of the target traffic data, and reporting the data sensitive identification result to a central business server.
[0039] It can be seen that the present invention uses the flow probe device to complete the data sensitivity identification at the collection front end, and only needs to upload the identification results to the central business system, avoiding the process of transmitting all the original data to the central business system for identification, greatly reducing the transmission load, reducing the network bandwidth occupied by the identification of flow data and the data identification delay; and by identifying the target flow data in the original flow data, it can accurately filter out the flow data in the cross-border scenario that needs to be identified, thereby improving the efficiency of sensitive identification. In addition, the present invention also provides a sensitive data analysis device, system and flow probe device, which also have the above-mentioned beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0041] Figure 1 A flowchart of a sensitive data analysis method provided by an embodiment of the present invention;
[0042] Figure 2 A schematic diagram of the architecture of another sensitive data analysis method provided by an embodiment of the present invention;
[0043] Figure 3 A schematic diagram of a traffic filtering process of another sensitive data analysis method provided by an embodiment of the present invention;
[0044] Figure 4 A schematic diagram of a sensitive data identification process of another sensitive data analysis method provided by an embodiment of the present invention;
[0045] Figure 5 A schematic diagram of a process for issuing a regular expression provided by an embodiment of the present invention;
[0046] Figure 6 A structural block diagram of a sensitive data analysis device provided by an embodiment of the present invention;
[0047] Figure 7 This is a structural schematic diagram of a flow probe device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0048] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0049] Please refer to Figure 1 , Figure 1 This is a flow chart of a sensitive data analysis method provided by an embodiment of the present invention. The method is applied to a flow probe device and may include:
[0050] Step 101: Obtain the original traffic data collected by the traffic probe.
[0051] It can be understood that the flow probe device in this embodiment can be a device that collects original flow data through flow probe technology, that is, a device where the flow probe used to collect original flow data in the related art is located.
[0052] Correspondingly, the specific method for obtaining the original traffic data collected by the traffic probe in this step and the specific process of using the traffic probe to collect the original traffic data can be set by the designer according to the usage scenario and user needs. For example, it can be implemented in a manner that is the same as or similar to the method for collecting traffic data by traffic probes in related technologies. For example, the traffic probe can be used to collect all traffic on the edge switch through port mirroring to obtain the original traffic data. This embodiment does not impose any restrictions on this.
[0053] Step 102: Identify target traffic data in the original traffic data; wherein the target traffic data includes cross-border data.
[0054] It is understood that the target traffic data in this embodiment can be the data in the raw traffic data that requires data sensitivity identification. In other words, in this step, by identifying the target traffic data in the raw traffic data, the raw traffic data can be filtered to reduce the total amount of raw traffic data that needs to be identified, thereby reducing the overall data identification delay and improving the efficiency of sensitive identification.
[0055] Correspondingly, the specific data content of the target traffic data in this embodiment can be set by the designer according to the practical scenario and user needs. For example, the target traffic data can include cross-border data, such as data transmitted from within the country to abroad, and can also include monitoring and identification of other required types of data. This embodiment does not impose any restrictions on this.
[0056] Accordingly, the specific method of identifying the target traffic data in the original traffic data in this step can be set by the designer according to the practical scenario and user needs. For example, when the target traffic data may include cross-border data, the traffic probe device can identify the IP data to be monitored in the original traffic data; according to the source IP and destination IP in the IP data to be monitored, the cross-border data in the IP data to be monitored is detected. Among them, the IP data to be detected can be the IP data that needs to be monitored, such as all IP data, or the IP data that needs to be monitored for business purposes, such as Figure 3 The IP addresses that need to be monitored are the IP addresses that need to be monitored. This embodiment does not impose any restrictions on this.
[0057] Correspondingly, the specific method for identifying the IP data to be monitored in the original traffic data can be set by the designer, such as the traffic probe device can identify the data to be monitored in the original traffic data; identify the IP data to be monitored in the data to be monitored; wherein the application layer protocol type of the data to be monitored is the preset protocol to be monitored; for example, the traffic probe device can identify the application protocol of the original traffic data, and during the identification process, the application layer protocol type (i.e., the upper layer protocol type) used can be determined based on the Ethernet type field in the Ethernet frame. The upper layer protocol type, such as HTTP (Hypertext Transfer Protocol), FTP (File Transfer Protocol) and SMTP (Simple Mail Transfer Protocol), will thereby discard data of protocol types that do not need to be monitored to achieve protocol type filtering and avoid further data processing.
[0058] Accordingly, the above process of identifying the IP data to be monitored in the data to be monitored can identify all the IP data in the data to be monitored, and can also identify the IP data that needs to be monitored in the data to be monitored, such as Figure 3 The data corresponding to the key monitored IP in the system is discarded to discard the IP data that does not need to be monitored in the business.
[0059] The specific process of detecting cross-border data in the IP data to be monitored based on the source IP and destination IP in the IP data to be monitored can be set by the designer. For example, when the cross-border data to be monitored is data transmitted from domestic to overseas, the flow probe device can use the preset IP library to detect whether the source IP in the current IP data to be monitored is the preset domestic IP and the destination IP is the preset overseas IP; if so, it is determined that the current IP data to be monitored is cross-border data; if not, it is determined that the current IP data to be monitored is not cross-border data. The current IP data to be monitored is any IP data to be monitored.
[0060] Step 103: Perform sensitivity identification on the target traffic data to obtain a data sensitivity identification result of the target traffic data, and report the data sensitivity identification result to the central business server.
[0061] It should be noted that compared with the related technology in which the original traffic data needs to be transmitted to the central business system for data-sensitive identification, this embodiment enables the traffic probe device to have data-sensitive identification capabilities, reducing the transmission of original traffic data.
[0062] Among them, since the original types of data identification include various structured and unstructured files, the identification methods of different files are different, such as using algorithm matching for precise matching, using regular expressions for fuzzy matching, and using AI (Artificial Intelligence) technology for identification. In this embodiment, in order to unify the identification technology of different data into an identification technology based on content fuzzy matching, regular expression matching technology can be used. For example, the traffic analysis engine used by the traffic probe device uses Hyperscan (a high-performance regular expression matching library). This eliminates the need to introduce AI technology and hardware, reducing the complexity of operation and maintenance and overall costs. In other words, in this step, the traffic probe device can parse the target traffic data to obtain the content to be identified; use the preset regular expression to perform sensitive identification on the content to be identified, and obtain the data sensitive identification result of the target traffic data.
[0063] Correspondingly, the specific method of parsing the target traffic data and obtaining the content to be identified can be set by the designer, such as Figure 4 Therefore, the traffic probe device can detect whether the current traffic data is file transfer data; wherein, the current traffic data is any target traffic data; if it is not file transfer data, the current traffic data is decoded to obtain the content to be identified of the current traffic data; if it is file transfer data, the current traffic data is restored, and it is determined whether the restored file is a picture; if it is a picture, the restored file is parsed to obtain the content to be identified of the current traffic data; if it is not a picture, the restored file is parsed to obtain the content to be identified of the current traffic data. In other words, as the data-sensitive identification capability is moved down to the traffic analysis engine of the traffic probe device, some basic capabilities that data identification depends on will also be moved down accordingly, such as the above-mentioned reading and format parsing of the restored file, content extraction of the picture file, etc.; all these dependent processes need to be migrated to the traffic analysis engine, so that the traffic analysis engine can directly report the identification results to the central business system.
[0064] Accordingly, the specific content and acquisition method of the above-mentioned preset regular expression can be set by the designer. For example, the preset regular expression can be a regular expression requested by the traffic probe device from the central business system of the central business server, such as Figure 2 As shown, the central business system can manage and send a preset regular expression to the traffic analysis engine of the traffic probe device, enabling it to perform data sensitivity identification. In other words, the method provided in this embodiment can also include: sending an identification rule issuance request to the central business server; and receiving the preset regular expression returned by the central business server.
[0065] It should be noted that the traffic analysis engine of the traffic probe device in this embodiment can utilize the regular expression matching library Hyperscan. Regular expressions (i.e., pre-set regular expressions) can be maintained by the business system and distributed to the traffic analysis engine. The same set of regular expressions can support regular expression engines in both C++ (a programming language) and Java (a programming language), providing greater compatibility. While regular expressions are highly versatile, the syntax of regular expressions with the same semantics can vary across different programming languages or rule engines. Therefore, this embodiment addresses these differences in syntax by implementing regular expression syntax escape conversion to adapt to different environments using different syntaxes. For example, in Chinese, \x{4e00} can be automatically converted to \u4e00. In other words, the pre-set regular expressions sent to the traffic probe device by the central business server can be regular expressions that have undergone syntax conversion.
[0066] Moreover, in terms of flexibility, the related art stores the pre-compiled form of regular expressions in the code, which can reduce the compilation time during execution. However, the scalability and flexibility of this method are almost zero. In this embodiment, a built-in + custom + dynamically configured regular expression setting can be adopted, that is, the central business system can build regular expressions into the system, and the built-in regular expressions can be used after installation; it also supports users to add new data types and corresponding regular expressions in the management interface.
[0067] like Figure 5 As shown, after the central business server receives the identification rule issuance request sent by the traffic probe device, it can obtain all built-in and configured regular expressions; summarize and group the regular expressions; find the regular expression corresponding to the identification rule issuance request from the grouped regular expressions; determine whether the regular expression requires syntax conversion; if so, perform syntax conversion on the regular expression, perform parameter encapsulation on the regular expression after syntax conversion and return it to the traffic probe device; if not, directly perform parameter encapsulation on the regular expression and return it to the traffic probe device.
[0068] In this embodiment, the embodiment of the present invention uses a traffic probe device to complete data sensitivity identification at the collection front end, and only needs to upload the identification results to the central business system, avoiding the process of transmitting all the original data to the central business system for identification, greatly reducing the transmission load, and reducing the network bandwidth occupied by traffic data identification and data identification delay; and by identifying the target traffic data in the original traffic data, it can accurately filter out the traffic data in the cross-border scenario that needs to be identified, thereby improving the efficiency of sensitive identification.
[0069] Corresponding to the above method embodiment, an embodiment of the present invention further provides a sensitive data analysis device. The sensitive data analysis device described below and the sensitive data analysis method described above can refer to each other.
[0070] Please refer to Figure 6 , Figure 6 This is a block diagram of a sensitive data analysis device provided by an embodiment of the present invention. The device is applied to a flow probe device and may include:
[0071] The probe acquisition module 10 is used to obtain the original flow data collected by the flow probe;
[0072] A target identification module 20 is configured to identify target traffic data in the original traffic data; wherein the target traffic data includes cross-border data;
[0073] The sensitive identification module 30 is used to perform sensitive identification on the target traffic data, obtain a data sensitive identification result of the target traffic data, and report the data sensitive identification result to the central business server.
[0074] In another aspect, the target identification module 20 may include:
[0075] The monitoring and identification submodule is used to identify the IP data to be monitored in the original traffic data;
[0076] The IP detection submodule is used to detect cross-border data in the IP data to be monitored based on the source IP and destination IP in the IP data to be monitored.
[0077] On the other hand, the IP detection submodule can be specifically used to use the preset IP library to detect whether the source IP in the current IP data to be monitored is a preset domestic IP and the destination IP is a preset overseas IP; if so, it is determined that the current IP data to be monitored is cross-border data; wherein, the current IP data to be monitored is any IP data to be monitored.
[0078] In another aspect, the monitoring and identification submodule may include:
[0079] A protocol identification unit, configured to identify data to be monitored in the original traffic data; wherein the application layer protocol type of the data to be monitored is a preset protocol to be monitored;
[0080] The IP identification unit is used to identify the IP data to be monitored in the data to be monitored.
[0081] In another aspect, the sensitive identification module 30 may include:
[0082] The data parsing submodule is used to parse the target traffic data and obtain the content to be identified;
[0083] The regular expression recognition submodule is used to perform sensitive recognition on the content to be recognized using a preset regular expression to obtain the data sensitivity recognition result of the target traffic data.
[0084] In another aspect, the data parsing submodule may include:
[0085] A file determination unit, configured to detect whether current flow data is file transfer data; wherein the current flow data is any target flow data;
[0086] A content decoding unit, configured to perform content decoding on the current traffic data to obtain the content to be identified of the current traffic data if the data is not file transmission data;
[0087] A file restoration unit, configured to restore the current traffic data if the data is file transmission data, and determine whether the restored file is a picture;
[0088] An image parsing unit, configured to parse the restored file if it is an image, and obtain the content to be identified of the current traffic data;
[0089] The file parsing unit is used to parse the restored file if it is not a picture, and obtain the content to be identified of the current traffic data.
[0090] In another aspect, the apparatus may further comprise:
[0091] Regular request module, used to send identification rule issuance request to the central business server;
[0092] The regular expression receiving module is used to receive the preset regular expression returned by the central business server.
[0093] In this embodiment, the embodiment of the present invention uses a traffic probe device to complete data sensitivity identification at the collection front end, and only needs to upload the identification results to the central business system, avoiding the process of transmitting all the original data to the central business system for identification, greatly reducing the transmission load, and reducing the network bandwidth occupied by traffic data identification and data identification delay; and by identifying the target traffic data in the original traffic data, it can accurately filter out the traffic data in the cross-border scenario that needs to be identified, thereby improving the efficiency of sensitive identification.
[0094] Corresponding to the above method embodiment, an embodiment of the present invention further provides a flow probe device. The flow probe device described below and the sensitive data analysis method described above can refer to each other.
[0095] Please refer to Figure 7 , Figure 7 This is a schematic diagram of the structure of a flow probe device provided by an embodiment of the present invention. The flow probe device may include:
[0096] Memory D1, for storing computer programs;
[0097] Processor D2 is used to implement the steps of the sensitive data analysis method provided by the above method embodiment when executing a computer program.
[0098] Corresponding to the above method embodiment, an embodiment of the present invention further provides a sensitive data analysis system. The sensitive data analysis system described below and the sensitive data analysis method described above can refer to each other.
[0099] A sensitive data analysis system includes: a central business server and a flow probe device as provided in the above-mentioned device embodiment.
[0100] Accordingly, the central service server in this embodiment may issue a request according to the identification rule sent by the traffic probe device to obtain a corresponding preset regular expression; and send the preset regular expression to the traffic probe device.
[0101] Corresponding to the above method embodiment, an embodiment of the present invention further provides a computer program product. The computer program product described below and the sensitive data analysis method described above can refer to each other.
[0102] A computer program product includes a computer program / instruction, which, when executed by a processor, implements the steps of the sensitive data analysis method provided by the above method embodiment.
[0103] Corresponding to the above method embodiment, an embodiment of the present invention further provides a computer-readable storage medium. The computer-readable storage medium described below and the sensitive data analysis method described above can refer to each other.
[0104] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the sensitive data analysis method of the above-mentioned method embodiment.
[0105] The computer-readable storage medium may be a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, which may store program codes.
[0106] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference will be made to the descriptions of the devices, flow probe equipment, systems, computer program products, and computer-readable storage media disclosed in the embodiments for similarities and differences. Since these devices, flow probe devices, systems, computer program products, and computer-readable storage media, correspond to the methods disclosed in the embodiments, their descriptions are relatively brief. For relevant details, refer to the descriptions of the methods.
[0107] The above is a detailed introduction to a sensitive data analysis method, device, system and flow probe equipment provided by the present invention. This article uses specific examples to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of the present invention, the present invention can also be improved and modified, and these improvements and modifications also fall within the scope of protection of the present invention.
Claims
1. A sensitive data analysis method, characterized in that: Applicable to flow probe equipment, including: Obtain the original traffic data collected by the traffic probe; Identifying target traffic data in the original traffic data; wherein the target traffic data includes cross-border data; Perform sensitivity identification on the target traffic data to obtain a data sensitivity identification result of the target traffic data, and report the data sensitivity identification result to a central business server.
2. The sensitive data analysis method according to claim 1, characterized in that: Identifying target traffic data in the original traffic data includes: Identifying IP data to be monitored in the original traffic data; The cross-border data in the IP data to be monitored is detected according to the source IP and the destination IP in the IP data to be monitored.
3. The sensitive data analysis method according to claim 2, characterized in that: Detecting cross-border data in the IP data to be monitored based on the source IP and destination IP in the IP data to be monitored, including: Using a preset IP library, detecting whether the source IP in the current IP data to be monitored is a preset domestic IP and the destination IP is a preset overseas IP; wherein the current IP data to be monitored is any of the IP data to be monitored; If so, it is determined that the current IP data to be monitored is the cross-border data.
4. The sensitive data analysis method according to claim 2, characterized in that: Identifying the IP data to be monitored in the original traffic data includes: Identifying the data to be monitored in the original traffic data; wherein the application layer protocol type of the data to be monitored is a preset protocol to be monitored; Identify the IP data to be monitored in the data to be monitored.
5. The sensitive data analysis method according to any one of claims 1 to 4, characterized in that: Performing sensitivity identification on the target traffic data to obtain a data sensitivity identification result of the target traffic data includes: Parsing the target traffic data to obtain content to be identified; Using a preset regular expression, the content to be identified is sensitively identified to obtain a data sensitivity identification result of the target traffic data.
6. The sensitive data analysis method according to claim 5, characterized in that: Parsing the target traffic data to obtain the content to be identified includes: Detecting whether current traffic data is file transfer data; wherein the current traffic data is any of the target traffic data; If the data is not transmitted for the file, the current traffic data is content decoded to obtain the content to be identified of the current traffic data; If it is the file transfer data, then perform file restoration on the current traffic data and determine whether the restored file is a picture; If it is an image, the restored file is analyzed to obtain the content to be identified of the current traffic data; If it is not a picture, the restored file is parsed to obtain the content to be identified of the current traffic data.
7. The sensitive data analysis method according to claim 5, characterized in that: Before performing sensitivity identification on the content to be identified by using a preset regular expression and obtaining the data sensitivity identification result of the target traffic data, the method further includes: Sending an identification rule issuance request to the central business server; Receive the preset regular expression returned by the central service server.
8. A sensitive data analysis device, characterized in that: Applicable to flow probe equipment, including: The probe acquisition module is used to obtain the original flow data collected by the flow probe; a target identification module, configured to identify target traffic data in the original traffic data; wherein the target traffic data includes cross-border data; The sensitive identification module is used to perform sensitive identification on the target traffic data, obtain a data sensitive identification result of the target traffic data, and report the data sensitive identification result to the central business server.
9. A flow probe device, characterized in that: include: memory for storing computer programs; A processor, configured to implement the steps of the sensitive data analysis method according to any one of claims 1 to 7 when executing the computer program.
10. A sensitive data analysis system, characterized in that: include: A central business server and a flow probe device as claimed in claim 9.