Data leakage node positioning method and system, electronic equipment and program product
By staining the data and monitoring communication details and flow path information, the problem of data leakage positioning between data nodes is solved, and accurate data leakage node positioning and timely processing are achieved.
Patent Information
- Application Number
- CN202510586121.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-08-22
AI Technical Summary
When forwarding data between data nodes, how to efficiently and accurately locate nodes with data leakage to ensure data security.
By dyeing the original data to be forwarded, embedding the target test communication account, and monitoring the communication details and flow path information to determine the data leakage node.
It can efficiently and reliably locate data nodes with data leakage, handle data leakage problems in a timely manner, and ensure data security.
Smart Images

Figure CN120528634A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of data security technology, and in particular to a data leakage node positioning method, system, electronic device, and program product. Background Art
[0002] In some scenarios, data forwarding is required between different data nodes. It should be noted that data leakage may occur at some data nodes, which can easily affect data security. Locating data nodes with data leakage is a technical issue worthy of attention for those skilled in the art. Summary of the Invention
[0003] In order to solve the above technical problems, the present disclosure is proposed. The embodiments of the present disclosure provide a data leakage node location method, system, electronic device and program product.
[0004] According to one aspect of an embodiment of the present disclosure, a data leakage node location method is provided, which is applied to a gateway device, wherein the gateway device is used for forwarding data between multiple data nodes. The method includes:
[0005] Receive original data to be forwarded;
[0006] Performing coloring processing on the original data to be forwarded to obtain target data to be forwarded including the target test communication account;
[0007] Forwarding the target data to be forwarded;
[0008] Among them, the first target communication details information and the target flow path information are both used to determine the data node where data leakage occurs. The first target communication details information is the communication details information of the target test communication account, and the target flow path information is the flow path information of the target data to be forwarded between different data nodes.
[0009] According to another aspect of an embodiment of the present disclosure, a data leakage node location system is provided, including:
[0010] Multiple data nodes;
[0011] a gateway device for forwarding data between the plurality of data nodes, the gateway device being configured to receive original data to be forwarded, perform coloring processing on the original data to be forwarded, obtain target data to be forwarded including a target test communication account, and forward the target data to be forwarded;
[0012] a monitoring subsystem configured to monitor first target communication details information and target flow path information, wherein the first target communication details information is communication details information of the target test communication account, and the target flow path information is flow path information of the target to-be-forwarded data between different data nodes;
[0013] The first target communication details information and the target flow path information are both used to determine the data node where data leakage occurs.
[0014] According to another aspect of an embodiment of the present disclosure, a data leakage node location device is provided, which is applied to a gateway device, wherein the gateway device is used for forwarding data between multiple data nodes. The device includes:
[0015] A receiving module, used for receiving original data to be forwarded;
[0016] a coloring processing module, configured to perform coloring processing on the original data to be forwarded to obtain target data to be forwarded including a target test communication account;
[0017] A first forwarding module, configured to forward the target data to be forwarded;
[0018] Among them, the first target communication details information and the target flow path information are both used to determine the data node where data leakage occurs. The first target communication details information is the communication details information of the target test communication account, and the target flow path information is the flow path information of the target data to be forwarded between different data nodes.
[0019] According to another aspect of the embodiments of the present disclosure, there is provided an electronic device, including:
[0020] a memory for storing a computer program product;
[0021] The processor is configured to execute the computer program product stored in the memory, and when the computer program product is executed, the data leakage node location method is implemented.
[0022] According to another aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided, on which computer program instructions are stored, characterized in that when the computer program instructions are executed by a processor, the above-mentioned data leakage node locating method is implemented.
[0023] According to another aspect of an embodiment of the present disclosure, a computer program product is provided, including computer program instructions, which implement the above-mentioned data leakage node positioning method when executed by a processor.
[0024] In an embodiment of the present disclosure, after receiving the original data to be forwarded, the gateway device can perform coloring processing on the original data to be forwarded to obtain target data to be forwarded including the target test communication account, and then forward the target data to be forwarded. It should be noted that if the target data to be forwarded has not been leaked, the target test communication account is usually safe and will not be illegally obtained. Therefore, the target test communication account will not communicate with other communication accounts; if the target data to be forwarded has been leaked, the target test communication account is likely to be illegally obtained. Therefore, the target test communication account is likely to communicate with other communication accounts. Therefore, based on the communication details information of the target test communication account (i.e., the first target communication details information), it is possible to efficiently and reliably infer whether the target data to be forwarded has been leaked. If the target data to be forwarded has indeed been leaked, since the leakage of the target data to be forwarded usually occurs at certain data nodes on the flow path of the target data to be forwarded, based on the flow path information between different data nodes after the target data to be forwarded is forwarded (i.e., the target flow path information), the data nodes that may have data leakage can be preliminarily located. Subsequently, from the preliminarily located data nodes, the data nodes that have indeed data leakage can be further located. For example, the initially located data nodes can be manually checked one by one to further locate the data nodes that have indeed leaked data. For another example, a machine can run some positioning algorithms to further locate the data nodes that have indeed leaked data from the initially located data nodes. It can be seen that in the embodiments of the present disclosure, the first target communication details information and the target flow path information can provide an effective reference for locating the data leak node, thereby being able to more accurately locate the data node with data leak, so that the data leak problem can be dealt with in a timely manner, which is conducive to ensuring data security.
[0025] The technical solution of the present disclosure is further described in detail below through the accompanying drawings and examples. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] The above and other purposes, features, and advantages of the present disclosure will become more apparent through a more detailed description of the embodiments of the present disclosure in conjunction with the accompanying drawings. The accompanying drawings are intended to provide a further understanding of the embodiments of the present disclosure and constitute a part of the specification. Together with the embodiments of the present disclosure, they are used to explain the present disclosure and are not intended to limit the present disclosure. In the drawings, the same reference numerals generally represent the same components or steps.
[0027] Figure 1 It is a structural diagram of a data leakage node positioning system provided by an exemplary embodiment of the present disclosure.
[0028] Figure 2 It is a flowchart of a data leakage node location method provided by an exemplary embodiment of the present disclosure.
[0029] Figure 3 It is a flowchart of a method for obtaining target data to be forwarded including a target test communication account provided by an exemplary embodiment of the present disclosure.
[0030] Figure 4 It is a flowchart of a method for processing original data to be forwarded provided by an exemplary embodiment of the present disclosure.
[0031] Figure 5 It is a flowchart of a data leakage node locating method provided by another exemplary embodiment of the present disclosure.
[0032] Figure 6 It is a flowchart of a method for processing original data to be forwarded provided by another exemplary embodiment of the present disclosure.
[0033] Figure 7 It is a structural diagram of a data leakage node locating device provided by an exemplary embodiment of the present disclosure.
[0034] Figure 8 It is a structural schematic diagram of a dyeing processing module in an exemplary embodiment of the present disclosure.
[0035] Figure 9 It is a structural diagram of a data leakage node locating device provided by another exemplary embodiment of the present disclosure.
[0036] Figure 10 4 is a schematic diagram of a module for assisting in updating preset dyeing configuration information in an exemplary embodiment of the present disclosure.
[0037] Figure 11 It is a structural diagram of a data leakage node locating device provided by another exemplary embodiment of the present disclosure.
[0038] Figure 12 is a structural diagram of an electronic device provided by some exemplary embodiments of the present disclosure. DETAILED DESCRIPTION
[0039] Below, the exemplary embodiments according to the present disclosure will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present disclosure, rather than all the embodiments of the present disclosure, and it should be understood that the present disclosure is not limited to the exemplary embodiments described herein.
[0040] It should be noted that the relative arrangement of components and steps, the numerical expressions and numerical values set forth in these embodiments do not limit the scope of the present disclosure unless specifically stated otherwise.
[0041] Those skilled in the art will understand that the terms "first" and "second" in the embodiments of the present disclosure are only used to distinguish different steps, devices or modules, and do not represent any specific technical meanings, nor do they indicate a necessary logical order between them.
[0042] It should also be understood that in the embodiments of the present disclosure, “a plurality of” may refer to two or more than two, and “at least one” may refer to one, two, or more than two.
[0043] It should also be understood that any component, data or structure mentioned in the embodiments of the present disclosure can generally be understood as one or more, unless explicitly limited or otherwise indicated in the context.
[0044] In addition, the term "and / or" in this disclosure is merely a description of the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this disclosure generally indicates that the related objects are in an "or" relationship.
[0045] It should also be understood that the description of the various embodiments in this disclosure focuses on the differences between the various embodiments, and the same or similar aspects thereof can be referenced with each other. For the sake of brevity, they will not be described one by one.
[0046] At the same time, it should be understood that for the convenience of description, the sizes of the various parts shown in the drawings are not drawn according to the actual proportional relationship.
[0047] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way intended to limit the present disclosure, its application, or uses.
[0048] Technologies, methods, and equipment known to ordinary technicians in the relevant art may not be discussed in detail, but where appropriate, the technologies, methods, and equipment should be considered part of the specification.
[0049] It should be noted that like reference numerals and letters refer to like items in the following figures, and therefore, once an item is defined in one figure, it need not be further discussed in subsequent figures.
[0050] The embodiments of the present disclosure can be applied to electronic devices such as terminal devices, computer systems, and servers, and can operate in conjunction with numerous other general-purpose or special-purpose computing system environments or configurations. Examples of well-known terminal devices, computing systems, environments, and / or configurations suitable for use with electronic devices such as terminal devices, computer systems, and servers include, but are not limited to, personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, microprocessor-based systems, set-top boxes, programmable consumer electronics, network personal computers, minicomputer systems, mainframe computer systems, and distributed cloud computing technology environments including any of the above systems, among others.
[0051] Electronic devices such as terminal devices, computer systems, and servers can be described in the general context of computer system-executable instructions (such as program modules) executed by a computer system. Generally, program modules can include routines, programs, object programs, components, logic, data structures, etc., which perform specific tasks or implement specific abstract data types. Computer systems / servers can be implemented in a distributed cloud computing environment, where tasks are performed by remote processing devices linked via a communication network. In a distributed cloud computing environment, program modules can be located on local or remote computing system storage media, including storage devices.
[0052] Exemplary Overview
[0053] Figure 1 1 is a system architecture diagram applicable to some exemplary embodiments of the present disclosure, including a data node 110 , a gateway device 120 and a monitoring subsystem 130 .
[0054] Optionally, the data node 110 may be a node in the network architecture capable of storing and processing data, such as a server. The number of data nodes 110 may be multiple, such as N, where N may be an integer greater than or equal to 2.
[0055] Optionally, the gateway device 120 can be a node in the network architecture that can centrally manage and control data inflow and outflow, such as a router or switch. The gateway device 120 provides a unified interface, protocol conversion, traffic management, and security policy, and can act as a bridge between different data nodes 110.
[0056] Optionally, the monitoring subsystem 130 may be a subsystem with an information monitoring function. The information monitored by the monitoring subsystem 130 may be used to determine the data node 110 where data leakage occurs.
[0057] Exemplary Methods
[0058] Figure 2It is a flowchart of a data leakage node location method provided by some exemplary embodiments of the present disclosure. Figure 2 The method shown can be applied to a gateway device. Since the gateway device can act as a bridge between different data nodes, the gateway device can be used to forward data between multiple data nodes. For ease of understanding, the following description uses the case where the multiple data nodes are N data nodes as an example. Figure 2 The illustrated method may include step 210 , step 220 , and step 230 .
[0059] Step 210: Receive original data to be forwarded.
[0060] Optionally, the gateway device can receive data from any data node among the N data nodes, and the data to be forwarded to another data node among the N data nodes can be used as the original data to be forwarded. The N data nodes and the gateway device can all belong to a real estate company. Accordingly, the original data to be forwarded can be housing data, which can include but is not limited to the housing address, housing floor, housing type, housing orientation, contact information of the homeowner (or contact person), etc. Of course, the N data nodes and the gateway device can also belong to companies other than the real estate company, such as an insurance company. In this case, the original data to be forwarded can be insurance policy data. For ease of understanding, the following description will be based on the case where the N data nodes and the gateway device all belong to the real estate company.
[0061] Step 220 : performing coloring processing on the original data to be forwarded to obtain target data to be forwarded including the target test communication account.
[0062] Data coloring is a technique used in the fields of data security and privacy protection. It embeds specific identifiers or metadata into data, enabling effective tracking and monitoring of data as it flows between different systems, applications, or network nodes. The specific identifiers or metadata are analogous to the color of the data, hence the term "data coloring."
[0063] Optionally, the target test communication account can be a communication account introduced to assist in identifying data nodes with data leaks. The communication account can be understood as an account for logging into an instant messaging platform. The test communication account may include, but is not limited to, a test phone number, a test email address, a test social application account, etc. The target test communication account can be used as a specific identifier or metadata. Using data coloring technology, the original data to be forwarded can be colorized, so that the original data to be forwarded after coloring can be embedded with the specific identifier or metadata. The original data to be forwarded after coloring can be used as the target data to be forwarded including the target test communication account.
[0064] Step 230, forward the target data to be forwarded; wherein, the first target communication details information and the target flow path information are both used to determine the data node where the data leakage occurs, the first target communication details information is the communication details information of the target test communication account, and the target flow path information is the flow path information of the target data to be forwarded between different data nodes.
[0065] As described above, the original data to be forwarded can originate from any of the N data nodes and be forwarded to another of the N data nodes. This other data node can then serve as the intended recipient of the original data to be forwarded. After performing the coloring process to obtain the target data to be forwarded, the gateway device can forward the target data to the intended recipient of the original data to be forwarded.
[0066] After forwarding the target data to be forwarded, the communication details of the target test communication account can be monitored to obtain the first target communication details information. For example, Figure 1 The monitoring subsystem 130 shown may include a monitoring platform, through which detailed communication information of the first target may be monitored and obtained.
[0067] Optionally, the target test communication account may include: a virtual communication account; the first target communication detail information may include: the target communication account that communicated with the virtual communication account, and the communication content between the virtual communication account and the target communication account.
[0068] Taking the case where the virtual communication account is a virtual phone number as an example, the target communication account that has communicated with the virtual communication account may include, but is not limited to, the phone number that sent a short message to the virtual phone number, the phone number that made a call to the virtual phone number, etc. The content of the communication between the virtual communication account and the target communication account may include, but is not limited to, the content of the aforementioned short messages, the recording of the aforementioned call, etc. Based on the first target communication details, it is possible to effectively determine whether the virtual communication account has been harassed (for example, by manually checking whether it has been harassed), thereby facilitating the location of the data leakage node.
[0069] It should be noted that the first target communication details are associated with whether the target data to be forwarded has been leaked. For example, if the first target communication details determine that the virtual communication account has been harassed, it can be inferred that the virtual communication account has been illegally accessed, indicating that the target data to be forwarded has been leaked. For another example, if the first target communication details determine that the virtual communication account has not been harassed, it can be inferred that the virtual communication account has not been illegally accessed, indicating that the target data to be forwarded has not been leaked.
[0070] After the target data to be forwarded is forwarded, the target data to be forwarded can flow between different data nodes. Then, the flow path of the target data to be forwarded can be monitored to obtain the flow path information of the target data to be forwarded between different data nodes, that is, to obtain the target flow path information. For example, Figure 1 The monitoring subsystem shown may include a monitoring server, through which Kafka monitoring technology may be used (since there are specific identifiers or metadata in the target data to be forwarded, the monitoring may be relatively easy to implement) to monitor and obtain target flow path information.
[0071] It should be noted that the leakage of the target data to be forwarded usually occurs at the data node through which it flows. For example, due to the leakage of the target data to be forwarded at a certain data node through which it flows, the virtual communication account may be illegally obtained (in this case, based on the first target communication details information, it can be determined that the virtual communication account is harassed). Then, when locating the data node where the leak has occurred, it is necessary to determine which data nodes the target data to be forwarded flows through, so as to determine the data node where the data leak has occurred from these data nodes. Therefore, in the embodiments of the present disclosure, the target flow path information can be monitored to assist in locating the data leakage node.
[0072] Assume that N data nodes are six data nodes, namely data node A, data node B, data node C, data node D, data node E, and data node F. The gateway device receives the original data to be forwarded from data node A and forwards the target data to be forwarded after coloring the original data. Data node D first receives the target data to be forwarded. Then, data node D sends the target data to be forwarded to data node F through the gateway device. Data node F sends the target data to be forwarded to data node E through the gateway device. Data node E sends the target data to be forwarded to data node B through the gateway device. The target flow path information can be expressed as follows: data node D → data node F → data node E → data node B.
[0073] In an embodiment of the present disclosure, after receiving the original data to be forwarded, the gateway device can perform coloring processing on the original data to be forwarded to obtain the target data to be forwarded including the target test communication account, and forward the target data to be forwarded. It should be noted that if the target data to be forwarded has not been leaked, the target test communication account is usually safe and will not be illegally obtained. In this case, the target test communication account will not communicate with other communication accounts; if the target data to be forwarded has been leaked, the target test communication account is likely to be illegally obtained. In this case, the target test communication account is likely to communicate with other communication accounts. Therefore, based on the communication details information of the target test communication account (i.e., the first target communication details information), it is possible to efficiently and reliably infer whether the target data to be forwarded has been leaked. If the target data to be forwarded has indeed been leaked, since the leakage of the target data to be forwarded usually occurs at certain data nodes on the flow path of the target data to be forwarded, based on the flow path information between different data nodes after the target data to be forwarded is forwarded (i.e., the target flow path information), the data nodes that may have data leaks (e.g., data node D, data node F, data node E, data node B in the above paragraph) can be preliminarily located. Afterwards, the data nodes where data leakage actually occurs can be further located from the data nodes initially located. For example, the data nodes initially located can be manually checked one by one to further locate the data nodes where data leakage actually occurs. For another example, some positioning algorithms can be run by a machine to further locate the data nodes where data leakage actually occurs from the data nodes initially located. It can be seen that in the embodiment of the present disclosure, the first target communication detail information and the target flow path information can provide an effective reference for the location of the data leakage node, thereby being able to more accurately locate the data node where data leakage occurs, so that the data leakage problem can be dealt with in a timely manner, which is conducive to ensuring data security.
[0074] In some optional examples, such as Figure 3 As shown, step 220 may include step 310 , step 320 and step 330 .
[0075] Step 310: Determine the target original communication account in the original data to be forwarded.
[0076] Optionally, the type of the target test communication account and the type of the target original communication account in the original data to be forwarded can be similar. For example, the target original communication account in the original data to be forwarded can include but is not limited to the original phone number, original email address, original social application account, etc.
[0077] Step 320 : Based on the preset binding relationship between the original communication account and the test communication account, determine a target test communication account bound to the target original communication account.
[0078] Optionally, mapping relationships between multiple original communication accounts and multiple test communication accounts can be pre-set; wherein, the multiple original communication accounts and the multiple test communication accounts can be mapped one-to-one. The mapping of any original communication account to any test communication account means that communication information for the test communication account will be forwarded to the original communication account. In this way, the test communication account mapped to any original communication account can serve as the test communication account bound to the original communication account, and the pre-set mapping relationship can serve as the binding relationship in step 320. The binding relationship can be stored in a database, which can also be called a communication account mapping repository.
[0079] After determining the target original communication account, the target original communication account can be used as index information to search for the corresponding test communication account in the communication account mapping warehouse. The found test communication account can be used as the target test communication account bound to the target original communication account. Taking the case where the target original communication account is the original phone number and the target test communication account is the test phone number as an example, the binding of the target test communication account and the target original communication account can be understood as: incoming calls, short messages, etc. to the test phone number will be forwarded to the original phone number. Taking the case where the target original communication account is the original email address and the target test communication account is the test email address as an example, the binding of the target test communication account and the target original communication account can be understood as: emails to the test email address will be forwarded to the original email address.
[0080] Optionally, the monitoring platform mentioned above may store a binding relationship between the original communication account and the test communication account. Based on the binding relationship, the monitoring platform may determine each test communication account (including the target test communication account) whose communication details need to be monitored.
[0081] Step 330 : Replace the target original communication account in the original data to be forwarded with the target test communication account to obtain the target data to be forwarded including the target test communication account.
[0082] Assuming that the position occupied by the target original communication account in the original data to be forwarded is called the target position, the target original communication account at the target position can be deleted, and the target test communication account can be written to the target position to obtain the target data to be forwarded including the target test communication account.
[0083] Generally speaking, the target original communication account in the original data to be forwarded is a communication account that can contact a specific object (such as the homeowner, contact, etc. mentioned above). If the target original communication account in the original data to be forwarded is illegally obtained, the illegal elements will communicate with the target original communication account through the communication account. In view of this, in the embodiment of the present disclosure, the target test communication account bound to the target original communication account can be determined, and the target original communication account in the original data to be forwarded can be replaced with the target test communication account to obtain the target data to be forwarded including the target test communication account. In this way, if the target data to be forwarded is illegally obtained, the illegal elements will mistake the target test communication account for the target original communication account, and the illegal elements will communicate with the target test communication account through the target communication account. Therefore, based on the communication details information of the target test communication account (i.e., the first communication details information), it is possible to efficiently and reliably infer whether the target data to be forwarded has been leaked, so as to provide an effective reference for locating the data leakage node.
[0084] In some optional examples, the second target communication details information, the first target communication details information and the target flow path information are all used to determine the data node where data leakage occurs, and the second target communication details information is the communication details information of the target original communication account.
[0085] Optionally, while the above description describes monitoring the communication details of the target test communication account to obtain first target communication details, in a specific implementation, the communication details of the target original communication account can also be monitored to obtain second target communication details. The composition of the second target communication details can be referred to the relevant description of the composition of the first target communication details, and will not be repeated here.
[0086] Referring to the example above, the N data nodes are data node A, data node B, data node C, data node D, data node E, and data node F. The gateway device receives the original data to be forwarded from data node A and forwards the target data to be forwarded obtained by coloring the original data to be forwarded. The target flow path information is represented as follows: data node D → data node F → data node E → data node B. Based on the second target communication details, it is possible to effectively determine whether the target original communication account has been harassed. If the target original communication account has been harassed, it can be determined that the original data to be forwarded of the target original communication account has been leaked. Since the original data to be forwarded originated from data node A, data node A can be considered a data node with a data leak. If the target original communication account has not been harassed, it can be determined that the original data to be forwarded of the target original communication account has not been leaked, and data node A is not a data node with a data leak. In addition, if it is determined based on the first target communication details that the target data to be forwarded has been leaked, since data node D, data node F, data node E, and data node B are all located on the flow path of the target data to be forwarded, the data node where the data leak actually occurs can be further located from data node D, data node F, data node E, and data node B.
[0087] In the embodiment of the present disclosure, the second target communication detail information, the target flow path information and the first target communication detail information can provide an effective reference for locating the data leakage node, which is conducive to completely and accurately locating each data node where data leakage occurs.
[0088] In some optional examples, such as Figure 4 As shown, the method provided by the embodiment of the present disclosure may further include step 410 , step 420 , step 430 and step 440 .
[0089] Step 410: Obtain preset dyeing configuration information.
[0090] Step 420: Determine the source data node and the destination data node indicated by the preset coloring configuration information.
[0091] Optionally, the preset coloring configuration information may be pre-configured in the gateway device and used to indicate conditions that must be met by data to be processed. For example, the preset coloring configuration information may be used to indicate the data node from which the data to be processed must originate. This data node may also be referred to as the source data node indicated by the preset coloring configuration information. For another example, the preset coloring configuration information may be used to indicate the data node to which the data to be processed must be forwarded. This data node may also be referred to as the destination data node indicated by the preset coloring configuration information.
[0092] Step 430, in response to the source data node being the data node from which the original data to be forwarded comes, and the destination data node being the data node to which the original data to be forwarded is to be forwarded, performs a step of coloring the original data to be forwarded to obtain target data to be forwarded including a target test communication account, and a step of forwarding the target data to be forwarded.
[0093] Step 440 : forwarding the original data to be forwarded in response to the source data node being different from the data node from which the original data to be forwarded comes, and / or the destination data node being different from the data node to which the original data to be forwarded is to be forwarded.
[0094] Optionally, the original data to be forwarded can be carried in a data message and sent to the gateway device. In addition to the original data to be forwarded, the data message can also include a source address and a destination address. The data node with the source address is the data node from which the original data to be forwarded comes, and the data node with the destination address is the data node to which the original data to be forwarded is to be forwarded.
[0095] In the embodiment of the present disclosure, it can be determined whether the source data node is the data node from which the original data to be forwarded comes, and whether the destination data node is the data node to which the original data to be forwarded is to be forwarded.
[0096] If the source data node is the data node from which the original data to be forwarded comes, and the destination data node is the data node to which the original data to be forwarded is to be forwarded, this indicates that the original data to be forwarded meets the conditions indicated by the preset coloring configuration information. Then, steps 220 and 230 of the present disclosure can be executed, that is, the original data to be forwarded is color-processed, and the target data to be forwarded obtained after the coloring process is forwarded.
[0097] If the source data node is not the data node from which the original data to be forwarded comes, and / or the destination data node is not the data node to which the original data to be forwarded is to be forwarded, this indicates that the original data to be forwarded does not meet the conditions indicated by the preset coloring configuration information. In this case, the original data to be forwarded may not be colored, but may be forwarded directly.
[0098] Referring to the example above, the N data nodes may be data node A, data node B, data node C, data node D, data node E, and data node F. The source data node and destination data node indicated by the preset coloring configuration information may be data node A and data node B, respectively. If the gateway device receives original data to be forwarded from data node A and to be forwarded to data node B, the gateway device may perform coloring processing on the original data to be forwarded and forward the target data to be forwarded obtained after the coloring processing to data node B. If the gateway device receives original data to be forwarded from data node A and to be forwarded to data node C, the gateway device may not perform coloring processing on the original data to be forwarded, but may directly forward the original data to be forwarded to data node C.
[0099] It should be noted that when the value of N is large, when data flows between different data nodes, the flow path may be very complicated. If the gateway device performs coloring processing on the data from all data nodes, the solution complexity is high, which easily increases the difficulty of locating the data leakage node. In view of this, in the embodiment of the present disclosure, the gateway device can only perform coloring processing on the original data to be forwarded that meets the conditions indicated by the preset coloring configuration information, without having to perform coloring processing on all original data to be forwarded. In this way, the data nodes that may have data leakage can be preliminarily located based on the flow path information of the target data to be forwarded between different data nodes, and then the data nodes that do have data leakage can be further located from the preliminarily located data nodes. The solution complexity is relatively low, and the location of the data leakage node can be achieved more quickly and effectively.
[0100] In some optional examples, such as Figure 5 As shown, the method provided by the embodiment of the present disclosure may further include step 510.
[0101] Step 510, in response to the first target communication detail information satisfying the preset data leakage condition, the preset coloring configuration information is updated so that two data nodes in the candidate leakage node set serve as the source data node and the destination data node indicated by the preset coloring configuration information, so as to facilitate determining the data node where the data leakage occurs from the candidate leakage node set; wherein the candidate leakage node set includes: each data node on the flow path represented by the target flow path information.
[0102] Optionally, the operation of determining whether the first target communication details information satisfies the preset data leakage condition can be performed by a machine, for example, by a server different from the gateway device. Of course, the operation of determining whether the first target communication details information satisfies the preset data leakage condition can also be performed manually.
[0103] Taking the case where the target test communication account includes a virtual communication account, and the virtual communication account is a virtual phone number as an example, the first target communication details information may include at least one of the following: the phone number that sent a short message to the virtual phone number, the phone number that made a call to the virtual phone number, the message content of the above short message, and the call recording of the above call. If the number of phone numbers that sent short messages to the virtual phone number is greater than a first preset number, and the attributes of these phone numbers are all sales attributes, it can be determined that the first target communication details information meets the preset data leakage condition. Alternatively, if the number of phone numbers that made calls to the virtual phone number is greater than a second preset number, and the attributes of these phone numbers are all sales attributes, it can be determined that the first target communication details information meets the preset data leakage condition. Alternatively, if the message content of the short message is some sales content of a competitor of the real estate company, it can be determined that the first target communication details information meets the preset data leakage condition.
[0104] If the first target communication details information satisfies the preset data leakage condition, it can be determined that the target data to be forwarded has been leaked, and each data node on the flow path represented by the target flow path information may be a data node where data leakage has occurred. The data nodes on the flow path represented by the target flow path information can constitute a candidate leakage node set. The gateway device can update the preset coloring configuration information so that two data nodes in the candidate leakage node set serve as the source data node and destination data node indicated by the preset coloring configuration information. For example, two data nodes can be randomly selected from the candidate leakage node set. By updating the preset coloring configuration information, one of the two selected data nodes can be used as a new source data node, and the other of the two selected data nodes can be used as a new destination data node.
[0105] After completing the update of the preset coloring configuration information, the gateway device can continue to execute steps 210 to 230 of the present disclosure. During this process, the gateway device only performs coloring processing on the original data to be forwarded that meets the conditions indicated by the current preset coloring configuration information, obtains the corresponding target data to be forwarded and forwards it, so as to determine the data node with data leakage from the candidate leakage node set.
[0106] Referring to the example above, the N data nodes may be data node A, data node B, data node C, data node D, data node E, and data node F. The source data node and destination data node indicated by the preset coloring configuration information may be data node A and data node B, respectively. If, based on the second target communication details information, it is determined that the target original communication account has not been harassed, and based on the first target communication details information, it is determined that the target test communication account has been harassed, and the flow path of the target to-be-forwarded data includes data nodes B, data node C, data node D, data node E, and data node F, then it can be determined that data node A is not a data node with a data leak, and data nodes B, data node C, data node D, data node E, and data node F may all be data nodes with a data leak. Therefore, the candidate leak node set may include data nodes B, data node C, data node D, data node E, and data node F.
[0107] Next, the preset coloring configuration information can be updated. For example, the source data node indicated by the preset coloring configuration information can be updated from data node A to data node C in the candidate leakage node set, and the destination data node indicated by the preset coloring configuration information can be updated from data node B to data node D in the candidate leakage node set. The gateway device can then perform coloring processing only on the original data to be forwarded from data node C and to be forwarded to data node D. On this basis, the second target communication details information and the first target communication details information can be obtained again through monitoring, as well as the target flow path information can be obtained again through monitoring. If it is determined that the target original communication account has not been harassed based on the second target communication details information obtained again, it can be determined that data node C is not a data node with data leakage; otherwise, it can be determined that data node C is a data node with data leakage. If, based on the re-obtained first target communication details, it is determined that the target test communication account is being harassed, and the re-obtained target flow path information indicates a flow path that includes data node B, data node D, data node F, and data node A, since data node A has already been determined in the previous section to not be a data node with a data leak, it can be determined that data node B, data node D, and data node F are all likely data nodes with a data leak, and a candidate leakage node set is determined again, which may include data node B, data node D, and data node F. Subsequent operations are analogous until the data node with a data leak is located from data node B, data node D, and data node F.
[0108] In an embodiment of the present disclosure, when the first target communication detail information meets the preset data leakage conditions, by updating the preset coloring configuration information, it is helpful to determine the data node where the data leakage exists from the candidate leakage node set. This is equivalent to narrowing the range used for locating the data leakage node. By narrowing the range one by one, the data node where the data leakage actually exists can be finally located, which is helpful to ensure the accuracy of locating the data leakage node and to reduce the workload of manual investigation.
[0109] In some optional examples, such as Figure 6 As shown, the method provided by the embodiment of the present disclosure may further include step 610 , step 620 , step 630 and step 640 .
[0110] Step 610: Obtain a preset communication account set.
[0111] Optionally, the preset communication account set may be a set of multiple communication accounts pre-configured in the gateway device and used to assist in identifying data leakage nodes. Each communication account in the preset communication account set may be a communication account that does not affect the normal business of the real estate company. For example, the predetermined recipients corresponding to each communication account in the preset communication account set may not be homeowners or contacts, but rather staff members of the real estate company involved in the data leakage node location project.
[0112] Step 620: Determine the target original communication account in the original data to be forwarded.
[0113] Optionally, the target original communication account in the original data to be forwarded may include but is not limited to an original phone number, an original email address, an original social application account, and the like.
[0114] Step 630 , in response to the target original communication account being in the preset communication account set, performs coloring processing on the original data to be forwarded to obtain target data to be forwarded including the target test communication account, and forwards the target data to be forwarded.
[0115] Step 640 : In response to the target original communication account being outside the preset communication account set, forwarding the original data to be forwarded.
[0116] In an embodiment of the present disclosure, after determining the target original communication account in the original data to be forwarded, the target original communication account can be compared with a preset communication account set to determine whether the target original communication account is within the preset communication account set. If the target original communication account is within the preset communication account set, this indicates that the target original communication account is a communication account used to assist in locating the data leakage node, and coloring the original data to be forwarded where the target original communication account is located will not affect the normal business of the real estate company. Then, steps 220 and 230 of the present disclosure can be performed, that is, coloring the original data to be forwarded and forwarding the target data to be forwarded obtained after coloring. If the target original communication account is outside the preset communication account set, this indicates that the target original communication account is not a communication account used to assist in identifying the data leakage node, but a communication account related to the normal business of the real estate company (such as the homeowner's communication account). Then, the original data to be forwarded can be forwarded directly without coloring. Therefore, using the embodiment of the present disclosure, it is possible to locate the data leakage node while minimizing the impact on the normal business of the real estate company.
[0117] In summary, in the embodiments of the present disclosure, based on the data dyeing technology, it is possible to first preliminarily locate the data nodes that may have data leaks from N data nodes, and then gradually narrow the range for locating the data leak nodes until the data nodes that do have data leaks are accurately located. This is applicable to complex multi-environment systems, and is conducive to ensuring the efficiency and accuracy of locating data leak nodes, thereby enabling timely processing of data leakage issues and ensuring data security. Optionally, the data dyeing operation can be performed in the gateway device, which can ensure that each data node is unaware of the operation and minimize interference with the business logic. In addition, the embodiments of the present disclosure can be used in various environments and are highly versatile.
[0118] It is important to emphasize that the collection, storage, use, processing, transmission, provision, and disclosure of user personal information involved in the technical solutions disclosed herein comply with relevant laws and regulations and do not violate public order and good morals. Furthermore, the collection and use of user personal information involved in the technical solutions disclosed herein are conducted with the user's knowledge and authorization, and do not involve any illegal collection or use of user personal information.
[0119] Exemplary Systems
[0120] Figure 1 It is a structural diagram of a data leakage node positioning system provided by some exemplary embodiments of the present disclosure. Figure 1 The system shown may include:
[0121] multiple data nodes 110;
[0122] A gateway device 120 for forwarding data between the plurality of data nodes 110, the gateway device 120 being configured to receive original data to be forwarded, perform coloring processing on the original data to be forwarded, obtain target data to be forwarded including a target test communication account, and forward the target data to be forwarded;
[0123] Monitoring subsystem 130, monitoring subsystem 130 is configured to monitor first target communication details information and target flow path information, the first target communication details information is the communication details information of the target test communication account, and the target flow path information is the flow path information of the target to-be-forwarded data between different data nodes 110;
[0124] The first target communication details information and the target flow path information are both used to determine the data node 110 where data leakage occurs.
[0125] In the system disclosed in the present invention, the various optional embodiments, optional implementation methods and optional examples disclosed above can be flexibly selected and combined as needed to achieve corresponding functions and effects, and the present invention does not list them one by one.
[0126] Exemplary devices
[0127] Figure 7 It is a structural diagram of a data leakage node locating device provided by an exemplary embodiment of the present disclosure. Figure 7 The device shown is applied to a gateway device, which is used for forwarding data between multiple data nodes. Figure 7 The apparatus shown may include:
[0128] Receiving module 710, configured to receive original data to be forwarded;
[0129] The coloring processing module 720 is used to perform coloring processing on the original data to be forwarded to obtain target data to be forwarded including the target test communication account;
[0130] A first forwarding module 730, configured to forward target data to be forwarded;
[0131] Among them, the first target communication details information and the target flow path information are both used to determine the data node where data leakage occurs. The first target communication details information is the communication details information of the target test communication account, and the target flow path information is the flow path information of the target to-be-forwarded data between different data nodes.
[0132] In some optional examples, such as Figure 8 As shown, the dyeing processing module 730 includes:
[0133] The first determining submodule 810 is used to determine the target original communication account in the original data to be forwarded;
[0134] The second determining submodule 820 is configured to determine a target test communication account bound to the target original communication account based on a preset binding relationship between the original communication account and the test communication account;
[0135] The coloring processing submodule 830 is configured to replace the target original communication account in the original data to be forwarded with the target test communication account, thereby obtaining the target data to be forwarded including the target test communication account.
[0136] In some optional examples, such as Figure 9 As shown, the apparatus provided by the embodiment of the present disclosure further includes:
[0137] A first acquisition module 910 is used to acquire preset dyeing configuration information;
[0138] A first determining module 920 is configured to determine a source data node and a destination data node indicated by the preset coloring configuration information;
[0139] The first triggering module 930 is configured to trigger the coloring processing module 720 and the first forwarding module 730 in response to the source data node being the data node from which the original data to be forwarded comes and the destination data node being the data node to which the original data to be forwarded is to be forwarded;
[0140] The second forwarding module 940 is configured to forward the original data to be forwarded in response to the source data node being different from the data node from which the original data to be forwarded comes and / or the destination data node being different from the data node to which the original data to be forwarded is to be forwarded.
[0141] In some optional examples, such as Figure 10 As shown, the apparatus provided by the embodiment of the present disclosure further includes:
[0142] An updating module 1010 is configured to update the preset coloring configuration information in response to the first target communication detail information satisfying a preset data leakage condition, so that two data nodes in the candidate leakage node set serve as the source data node and the destination data node indicated by the preset coloring configuration information, so as to facilitate determining the data node with data leakage from the candidate leakage node set;
[0143] The candidate leakage node set includes: each data node on the flow path represented by the target flow path information.
[0144] In some optional examples, such as Figure 11 As shown, the apparatus provided by the embodiment of the present disclosure further includes:
[0145] The second acquisition module 1110 is used to obtain a preset communication account set;
[0146] The second determining module 1120 is used to determine the target original communication account in the original data to be forwarded;
[0147] The second triggering module 1130 is configured to trigger the coloring processing module 720 and the first forwarding module 730 in response to the target original communication account being within the preset communication account set;
[0148] The third forwarding module 1140 is configured to forward the original data to be forwarded in response to the target original communication account being outside the preset communication account set.
[0149] In some optional examples, the second target communication details information, the target flow path information and the first target communication details information are all used to determine the data node where data leakage occurs, and the second target communication details information is the communication details information of the target original communication account.
[0150] In some optional examples, the target test communication account includes: a virtual communication account; the first target communication detail information includes: the target communication account that communicated with the virtual communication account, and the communication content between the virtual communication account and the target communication account.
[0151] In the device of the present disclosure, the various optional embodiments, optional implementation methods and optional examples disclosed above can be flexibly selected and combined as needed to achieve corresponding functions and effects, and the present disclosure does not list them one by one.
[0152] Exemplary electronic devices
[0153] Below, reference Figure 12 The electronic device according to the embodiment of the present disclosure is described. The electronic device may be either or both of the first device and the second device, or a standalone device independent of them, and the standalone device may communicate with the first device and the second device to receive collected input signals from them.
[0154] Figure 12 A block diagram of an electronic device 1200 according to an embodiment of the present disclosure is illustrated.
[0155] like Figure 12 As shown, electronic device 1200 includes one or more processors 1210 and memory 1220 .
[0156] The processor 1210 may be a central processing unit (CPU) or other forms of processing units having data processing capabilities and / or instruction execution capabilities, and may control other components in the electronic device 1200 to perform desired functions.
[0157] The memory 1220 may store one or more computer program products, and the memory 1220 may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory. The non-volatile memory may include, for example, read-only memory (ROM), a hard disk, a flash memory, etc. One or more computer program products may be stored on the computer-readable storage medium, and the processor 1210 may execute the computer program products to implement the contract-based data processing method of each embodiment of the present disclosure described above and / or other desired functions. Various contents such as input signals, signal components, noise components, etc. may also be stored in the computer-readable storage medium.
[0158] In one example, the electronic device 1200 may further include an input device 1230 and an output device 1240 , and these components are interconnected via a bus system and / or other forms of connection mechanisms (not shown).
[0159] For example, when the electronic device 1200 is a first device or a second device, the input device 1230 may be a microphone or a microphone array. When the electronic device 1200 is a standalone device, the input device 1230 may be a communication network connector for receiving collected input signals from the first device and the second device.
[0160] In addition, the input device 1230 may also include, for example, a keyboard, a mouse, and the like.
[0161] The output device 1240 can output various information to the outside, and can include, for example, a display, a speaker, a printer, a communication network and a remote output device connected thereto.
[0162] Of course, to simplify, Figure 12 Only some of the components related to the present disclosure in the electronic device 1200 are shown, and components such as buses, input / output interfaces, etc. are omitted. In addition, according to specific application scenarios, the electronic device 1200 may further include any other appropriate components.
[0163] Exemplary computer program products and computer-readable storage media
[0164] In addition to the above-mentioned methods and devices, an embodiment of the present disclosure may also be a computer program product, which includes computer program instructions, which, when executed by a processor, enable the processor to perform the steps of the method according to various embodiments of the present disclosure described in the above-mentioned "Exemplary Method" section of this specification.
[0165] The computer program product may be written in any combination of one or more programming languages to implement the operations of the disclosed embodiments, including object-oriented programming languages such as Java, C++, and conventional procedural programming languages such as C or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0166] In addition, an embodiment of the present disclosure may also be a computer-readable storage medium having computer program instructions stored thereon, which, when executed by a processor, enable the processor to execute the steps of the method according to various embodiments of the present disclosure described in the above “Exemplary Method” section of this specification.
[0167] The computer-readable storage medium can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can, for example, include but is not limited to a system, device or component of electricity, magnetism, light, electromagnetic, infrared, or semiconductor, or any combination thereof. More specific examples (non-exhaustive list) of readable storage media include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.
[0168] The basic principles of the present disclosure have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, strengths, and effects mentioned in this disclosure are merely illustrative and not restrictive, and should not be construed as necessarily possessed by each embodiment of the present disclosure. Furthermore, the specific details disclosed above are provided for illustrative purposes and to facilitate understanding, rather than as limitations. These details do not limit the present disclosure to necessarily being implemented using these specific details.
[0169] Each embodiment in this specification is described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. References to the same or similar parts between the various embodiments are sufficient. For system embodiments, since they largely correspond to method embodiments, their description is relatively simple. For relevant parts, references to the description of the method embodiments are sufficient.
[0170] The block diagrams of the devices, devices, equipment, and systems involved in this disclosure are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As will be appreciated by those skilled in the art, these devices, devices, equipment, and systems can be connected, arranged, or configured in any manner. Words such as "include," "comprise," "have," and the like are open-ended words, meaning "including but not limited to," and can be used interchangeably therewith. The words "or" and "and" used herein refer to the words "and / or" and can be used interchangeably therewith, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to," and can be used interchangeably therewith.
[0171] The methods and apparatus of the present disclosure may be implemented in many ways. For example, the methods and apparatus of the present disclosure may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above order of steps for the method is for illustration only, and the steps of the method of the present disclosure are not limited to the order specifically described above unless otherwise specified. In addition, in some embodiments, the present disclosure may also be implemented as programs recorded in a recording medium, which include machine-readable instructions for implementing the methods according to the present disclosure. Thus, the present disclosure also covers recording media that store programs for executing the methods according to the present disclosure.
[0172] It should also be noted that in the apparatus, device, and method of the present disclosure, each component or each step can be decomposed and / or recombined. Such decomposition and / or recombination should be regarded as equivalent solutions of the present disclosure.
[0173] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present disclosure. Therefore, the present disclosure is not intended to be limited to the aspects shown herein, but rather to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0174] The above description has been provided for the purpose of illustration and description. In addition, this description is not intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although a number of example aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations thereof.
Claims
1. A data leakage node location method, characterized in that: Applied to a gateway device, the gateway device is used for data forwarding between multiple data nodes, and the method includes: Receive original data to be forwarded; Performing coloring processing on the original data to be forwarded to obtain target data to be forwarded including the target test communication account; Forwarding the target data to be forwarded; Among them, the first target communication details information and the target flow path information are both used to determine the data node where data leakage occurs. The first target communication details information is the communication details information of the target test communication account, and the target flow path information is the flow path information of the target data to be forwarded between different data nodes.
2. The method according to claim 1, characterized in that The coloring process is performed on the original data to be forwarded to obtain target data to be forwarded including the target test communication account, including: Determining a target original communication account in the original data to be forwarded; Determining a target test communication account bound to the target original communication account based on a pre-set binding relationship between the original communication account and the test communication account; The target original communication account in the original data to be forwarded is replaced with the target test communication account to obtain target data to be forwarded including the target test communication account.
3. The method according to claim 1, characterized in that The method further comprises: Get preset dyeing configuration information; Determining a source data node and a destination data node indicated by the preset coloring configuration information; In response to the source data node being the data node from which the original data to be forwarded comes, and the destination data node being the data node to which the original data to be forwarded is to be forwarded, performing the steps of coloring the original data to be forwarded to obtain target data to be forwarded including a target test communication account, and forwarding the target data to be forwarded; In response to the source data node being different from the data node from which the original data to be forwarded comes, and / or the destination data node being different from the data node to which the original data to be forwarded is to be forwarded, the original data to be forwarded is forwarded.
4. The method according to claim 3, characterized in that The method further comprises: In response to the first target communication detail information satisfying a preset data leakage condition, updating the preset coloring configuration information so that two of the data nodes in the candidate leakage node set serve as the source data node and the destination data node indicated by the preset coloring configuration information, so as to facilitate determining the data node with data leakage from the candidate leakage node set; The candidate leakage node set includes: each of the data nodes on the flow path represented by the target flow path information.
5. The method according to claim 1, wherein The method further comprises: Get the preset communication account set; Determining a target original communication account in the original data to be forwarded; In response to the target original communication account in the original data to be forwarded being within the preset communication account set, performing the step of coloring the original data to be forwarded to obtain target data to be forwarded including the target test communication account, and the step of forwarding the target data to be forwarded; In response to the target original communication account in the original data to be forwarded being outside the preset communication account set, the original data to be forwarded is forwarded.
6. The method according to any one of claims 2 and 5, characterized in that The second target communication details information, the first target communication details information and the target flow path information are all used to determine the data node where data leakage occurs. The second target communication details information is the communication details information of the target original communication account.
7. The method according to any one of claims 1 to 5, characterized in that The target test communication account includes: a virtual communication account; The first target communication detail information includes: a target communication account that has communicated with the virtual communication account, and communication content between the virtual communication account and the target communication account.
8. A data leakage node positioning system, characterized in that: include: Multiple data nodes; a gateway device for forwarding data between the plurality of data nodes, the gateway device being configured to receive original data to be forwarded, perform coloring processing on the original data to be forwarded, obtain target data to be forwarded including a target test communication account, and forward the target data to be forwarded; a monitoring subsystem configured to monitor first target communication details information and target flow path information, wherein the first target communication details information is communication details information of the target test communication account, and the target flow path information is flow path information of the target to-be-forwarded data between different data nodes; The first target communication details information and the target flow path information are both used to determine the data node where data leakage occurs.
9. An electronic device, characterized in that: include: a memory for storing a computer program product; A processor is configured to execute a computer program product stored in the memory, and when the computer program product is executed, the data leakage node locating method according to any one of claims 1 to 7 is implemented.
10. A computer program product comprising computer program instructions, characterized in that When the computer program instructions are executed by a processor, the data leakage node locating method described in any one of 1 to 7 above is implemented.