JSONPATH-based field transmission method and apparatus, and computer device
JSONPATH converts JSON data into a field pool, combined with field pool templates and regular expression verification, solves the problem of inaccurate field security detection in JSON data, and achieves the improvement of data transmission security and system performance.
Patent Information
- Application Number
- CN202510505343.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-22
- Publication Date
- 2025-08-26
AI Technical Summary
In the prior art, the field security detection in JSON data is not sensitive and accurate enough, and it is difficult to identify fields that exceed the expected range in a timely manner, resulting in the risk of data leakage and the system performance is poor when a large number of requests are requested.
JSONPATH is used to convert JSON data into a field pool. By matching with the preset field pool template, the target leaked fields are identified and the sensitivity check is performed. The sensitive fields are verified using regular expressions, and the hierarchical alarms and dynamic updates of the field pool template are performed.
Effectively identify and intercept the transmission of irregular data fields, avoid sensitive data leakage, improve system performance and timeliness of operation and maintenance processing, and reduce network delay.
Smart Images

Figure CN120540658A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this specification relate to the field of computer technology, and in particular to a field transmission method, apparatus, and computer device based on JSONPATH. Background Art
[0002] In the process of network application development and data interaction, the JSON format, as a concise and efficient form of data transmission, is widely used in various external request scenarios. However, with the increasing frequency and complexity of data interaction, ensuring the security and compliance of data transmission faces challenges. Existing technologies lack effective mechanisms to accurately detect and control the fields in external request JSON data: on the one hand, it is difficult to promptly identify and process fields that exceed the expected range, resulting in the risk of data leakage; on the other hand, there is a lack of flexible format verification methods for the values of specific key fields. In addition, when responding to a large number of requests, repeated reading of configuration information and processing of reported events leads to poor system performance.
[0003] In view of this, the embodiments of this specification aim to provide a field transmission method, apparatus, and computer device based on JSONPATH. Summary of the Invention
[0004] In response to the above-mentioned problems in the prior art, the purpose of the embodiments of this specification is to provide a field transmission method, apparatus and computer device based on JSONPATH to solve the problem of insufficient sensitivity and accuracy of field security detection in the prior art.
[0005] In order to solve the above technical problems, the specific technical solutions of the embodiments of this specification are as follows:
[0006] In a first aspect, an embodiment of this specification provides a field transmission method based on JSONPATH, including:
[0007] Get the JSON data of the external request;
[0008] Use JSONPATH to convert the JSON data of the external request into a field pool;
[0009] Determine whether all fields in the field pool are included in the preset field pool template;
[0010] If not, determining that the field not included in the field pool template is a target leakage field, and performing a sensitivity check on the target leakage field;
[0011] Determining whether the sensitivity check passes;
[0012] If the sensitivity check passes, the external request is allowed to be sent and a first alarm indicating a field leakage event is fed back;
[0013] If the sensitivity check fails, the external request is intercepted and a second alarm indicating a sensitive field leakage event is fed back.
[0014] Furthermore, a sensitivity check is performed on the target leakage field, including:
[0015] Matching the target leakage field according to a preset regular expression, wherein the preset regular expression includes at least a first regular expression for detecting identity card information, a second regular expression for detecting bank card information, and a third regular expression for detecting contact information;
[0016] Determining whether the target leakage field matches the regular expression;
[0017] If so, the target leakage field is determined to be a sensitive field, and the external request is intercepted.
[0018] Furthermore, when the target leakage field passes the sensitivity check, the method further includes:
[0019] The field pool template is updated using the target leakage field.
[0020] Specifically, the updating the field pool template using the target leaked field further includes:
[0021] Counting the occurrence frequency of the target leakage field within a preset observation period;
[0022] Determining whether the occurrence frequency is greater than or equal to a preset frequency threshold;
[0023] If so, the field pool template is updated using the target leaked field.
[0024] Specifically, the method further includes:
[0025] Identifying key fields in the field pool;
[0026] Validating the value format of the key field according to pre-configured regular expression rules;
[0027] If the key field conforms to the regular expression rule, the outbound request is allowed to continue to be transmitted;
[0028] Otherwise, the external request is intercepted and a third alarm indicating a key field matching failure event is fed back.
[0029] Preferably, the method further comprises:
[0030] Cache the field pool template;
[0031] The field leakage event, the sensitive field leakage event, and the key field matching failure event are cached.
[0032] Specifically, it is determined whether all fields in the field pool are included in the preset field pool template, further comprising:
[0033] According to the interface source of the external request, it is determined whether each field in the field pool is included in the field pool template corresponding to the interface source of the external request.
[0034] In a second aspect, an embodiment of this specification provides a field transmission device based on JSONPATH, including:
[0035] The acquisition module is used to obtain JSON data requested externally;
[0036] A conversion module, configured to convert the JSON data of the external request into a field pool using JSONPATH;
[0037] A first judging module is used to judge whether each field in the field pool is included in a preset field pool template;
[0038] a sensitivity check module, configured to, if not, determine that the field not included in the field pool template is a target leakage field, and perform a sensitivity check on the target leakage field;
[0039] A second judgment module is used to judge whether the sensitivity check is passed;
[0040] A first alarm module, configured to allow sending the external request and feedback a first alarm indicating a field leakage event if the sensitivity check passes;
[0041] The second alarm module is configured to intercept the external request and feed back a second alarm indicating a sensitive field leakage event if the sensitivity check fails.
[0042] In a third aspect, an embodiment of this specification provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method provided by the above technical solution when executing the computer program.
[0043] In a fourth aspect, an embodiment of this specification provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method provided by the above technical solution is implemented.
[0044] In a fifth aspect, an embodiment of this specification provides a computer program product, comprising at least one instruction or at least one program segment, wherein the at least one instruction or the at least one program segment is loaded and executed by a processor to implement the method provided by the above technical solution.
[0045] By adopting the above technical solution, the embodiment of this specification provides a field transmission method, device and computer equipment based on JSONPATH, which can automatically convert the data requested from the outside into a field pool and match it with the field pool template, and perform sensitivity detection on the fields not included in the field pool template, effectively identifying and intercepting the transmission of non-standard data fields, and avoiding the leakage of sensitive data. Moreover, the method provided by the embodiment of this specification only needs to access the server to obtain the pre-configured field pool template and perform local verification, with less interaction with the server side, so as not to increase network delay. In addition, by performing graded alarms for different events, the events that have occurred can be determined only based on the alarm level, which makes it easier for operation and maintenance personnel to take corresponding response measures for different events and improves the timeliness of handling different events.
[0046] In order to make the above and other purposes, features and advantages of the embodiments of this specification more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the embodiments of this specification or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0048] Figure 1 A schematic diagram of the steps of a field transmission method based on JSONPATH provided in an embodiment of this specification is shown;
[0049] Figure 2 A schematic diagram of the steps for performing sensitivity check on the target leakage field is shown;
[0050] Figure 3 A schematic diagram of the steps for updating a field pool template is shown;
[0051] Figure 4 A schematic diagram showing the steps for validating the value format of key fields is shown;
[0052] Figure 5 A schematic diagram of the structure of a field transmission device based on JSONPATH provided in an embodiment of this specification is shown;
[0053] Figure 6 A schematic structural diagram of a computer device provided in an embodiment of this specification is shown.
[0054] Description of the accompanying symbols:
[0055] 51. Get module;
[0056] 52. Conversion module;
[0057] 53. First judgment module;
[0058] 54. Sensitivity check module;
[0059] 55. Second judgment module;
[0060] 56. First alarm module;
[0061] 57. Second alarm module;
[0062] 58. Reporting module;
[0063] 602. Computer equipment;
[0064] 604, processor;
[0065] 606, memory;
[0066] 608, driving mechanism;
[0067] 610, input / output module;
[0068] 612. Input devices;
[0069] 614. Output device;
[0070] 616. Presentation equipment;
[0071] 618. Graphical User Interface;
[0072] 620, network interface;
[0073] 622, communication link;
[0074] 624. Communication bus. DETAILED DESCRIPTION
[0075] The following will be combined with the drawings in the embodiments of this specification to clearly and completely describe the technical solutions in the embodiments of this specification. Obviously, the embodiments described are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this specification.
[0076] It should be noted that the terms "first," "second," and the like in this specification, the claims, and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of this specification described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, apparatus, product, or device comprising a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such processes, methods, products, or devices.
[0077] In order to solve the above problems, the embodiments of this specification provide a field transmission method, apparatus and computer device based on JSONPATH, which can solve the problem of insufficient sensitivity and accuracy of field security detection in the prior art. Figure 1 This is a step diagram of a field transmission method based on JSONPATH provided in an embodiment of this specification. This specification provides method operation steps as described in the embodiment or flowchart, but may include more or fewer operation steps based on conventional or non-creative labor. The order of steps listed in the embodiment is only one way of executing the order of many steps and does not represent the only execution order. When the actual system or device product is executed, it can be executed in sequence or in parallel according to the method shown in the embodiment or the accompanying drawings. Specifically, Figure 1 As shown, the method may include:
[0078] S101: Obtain JSON data requested externally.
[0079] S102: Utilize JSONPATH to convert the JSON data of the external request into a field pool.
[0080] In the examples of this specification, JSONPATH is an expression language for locating and extracting data from JSON (JavaScript Object Notation) data structures. It provides concise syntax that allows developers to easily select specific fields or values from complex JSON object hierarchies, similar to using XPath in XML. For example, the expression $.store.products[*].name can extract the names of all products from JSON data representing a store's product list.
[0081] The field pool is a collection of all fields and their corresponding values parsed from the JSON data of the external request. In the embodiments of this specification, the field pool, a structured representation of the data content, is used to perform subsequent comparative analysis with the standards set by the administrator (i.e., the field pool template) to determine the compliance of the external request.
[0082] S103: Determine whether all fields in the field pool are included in a preset field pool template.
[0083] The field pool template is a collection of standard fields that is pre-configured by the administrator in the background according to business requirements and security policies. The field pool template can be stored in the server template configuration center.
[0084] S104: If not, the fields not included in the field pool template are determined to be target leakage fields, and a sensitivity check is performed on the target leakage fields.
[0085] S105: Determine whether the sensitivity check is passed.
[0086] S106: If the sensitivity check passes, the external request is allowed to be sent and a first alarm indicating a field leakage event is fed back.
[0087] If the sensitivity check passes, it is determined that the target leakage field is not a sensitive field, and the external request will be allowed to be reported. However, since the target leakage field is a field that is not included in the field pool template, an alarm will be issued while allowing it to be reported, that is, the first alarm corresponds to a field leakage event.
[0088] S107: If the sensitivity check fails, intercept the external request and feed back a second alarm indicating a sensitive field leakage event.
[0089] If the sensitivity check fails, the target leaked field is determined to be a sensitive field, such as ID card information, bank card information, contact information, etc., and the leakage of these fields may lead to serious consequences. Therefore, in the embodiments of this specification, fields that fail the sensitivity check are intercepted and the external request is not allowed to be reported. At the same time, a high-level alarm is also issued, that is, the level of the second alarm is higher than the level of the first alarm.
[0090] Furthermore, the method further comprises:
[0091] S108: If yes, then allow the external request to be reported.
[0092] That is, when all fields in the field pool are included in the preset field pool template, there is no leaked field in the external request and it can be reported directly.
[0093] The embodiment of this specification provides a field transmission method based on JSONPATH, which can automatically convert the data requested from the outside into a field pool and match it with the field pool template, and perform sensitivity detection on the fields not included in the field pool template, effectively identifying and intercepting the transmission of non-standard data fields, and avoiding the leakage of sensitive data. Moreover, the method provided by the embodiment of this specification only needs to access the server to obtain the pre-configured field pool template for local verification, and has less interaction with the server side, so as not to increase network delay. In addition, the method provided by the embodiment of this specification provides graded alarms for different events, and the operation and maintenance personnel can determine the events that have occurred according to the alarm level, which is convenient for the operation and maintenance personnel to take corresponding response measures for different events and improve the timeliness of handling different events.
[0094] Furthermore, in the embodiments of this specification, Figure 2 As shown, in step S104, performing a sensitivity check on the target leakage field may further include:
[0095] S201: Match the target leakage field according to a preset regular expression, where the preset regular expression includes at least a first regular expression for detecting identity card information, a second regular expression for detecting bank card information, and a third regular expression for detecting contact information.
[0096] Specifically, the first regular expression can verify whether the target leakage field is 18 characters, whether the first 17 characters are all numbers, and whether the last character is a number or a capital letter X. To further improve the stringency of the verification, it can also be verified whether the 7th and 8th characters of the target leakage field are 1 and 9, or 2 and 0, respectively.
[0097] The second regular expression can check whether the target leakage field is a mobile phone number or a landline phone number, for example, check whether the target leakage field is an 11-digit number and the first digit is 1.
[0098] The third regular expression can verify whether the target leakage field is a 19-digit number.
[0099] S202: Determine whether the target leakage field matches the regular expression.
[0100] S203: If yes, determine that the target leakage field is a sensitive field, and intercept the external request.
[0101] In addition to the above-mentioned checks on the three types of sensitive information, namely ID card information, bank card information and contact information, in the embodiments of this specification, the position of the name field in the external request is relatively fixed. Therefore, sensitive information such as name information can also be detected through invasive modification.
[0102] Specifically, in the embodiment of this specification, after the target leakage field passes the sensitivity check, the method may further include:
[0103] The field pool template is updated using the target leakage field.
[0104] As data continues to change and new data emerges, more and more fields may not be included in the preset field pool module and are not sensitive information. In this case, if the first alert is sent to the operation and maintenance personnel every time such fields are detected, it will greatly affect the normal work of the operation and maintenance personnel. Therefore, the field pool template can be updated with target leakage fields that are not sensitive information to improve the system's adaptability and recognition accuracy, thereby enhancing the system's scalability.
[0105] Specifically, if Figure 3 As shown, the field pool template can be updated using the following method and steps:
[0106] S301: Counting the occurrence frequency of the target leakage field within a preset observation period;
[0107] S302: Determine whether the occurrence frequency is greater than or equal to a preset frequency threshold;
[0108] S303: If yes, update the field pool template using the target leaked field.
[0109] Considering that some fields that are not included in the field pool template and do not represent sensitive information may appear sporadically, in this embodiment of the specification, the frequency of occurrence of such fields within a certain observation period can be counted. When the frequency is high, the field is added to the field pool template; when the frequency is low, the field is ignored. This ensures the accuracy of the newly added fields while ensuring dynamic updates, and reduces the waste of field pool template storage space.
[0110] In some other feasible embodiments, updating the field pool template using the target leaked field may include the following steps:
[0111] Collecting fields that are not included in the field pool template and pass the sensitivity check;
[0112] Input the above fields into a pre-built feature learning model, which can obtain feature representations of the above fields and generate new fields based on the feature representations of the above fields;
[0113] The field pool template is updated using the above fields and the above new fields.
[0114] That is, in this embodiment, when updating the field pool template using a field (such as field A) that has been determined not to be included in the existing field pool template and is not a sensitive field, a feature learning module can also be constructed to generate field B, field C, etc. that have relevant features with field A (that is, field B and field C can be obtained by the feature learning model based on a statistical feature selection method or a machine learning feature selection method), thereby improving the updating efficiency of the field pool template and realizing the early deployment and expansion of fields that may be carried in some future external requests.
[0115] After adding a new field to the field pool template, you can also continuously monitor the hit rate of external requests for the new field and the performance of the updated field pool template, and further adjust and optimize the field pool as needed. After the field pool template in the server-side template configuration center is dynamically updated, the field pool template in the local cache must also be dynamically updated synchronously.
[0116] Furthermore, in some feasible embodiments, the hit rate of each field in the existing field pool template against the field pool obtained by converting each external request JSON data can be monitored during a preset observation period to determine whether the hit rate of each field in the field pool template is less than or equal to a preset hit rate threshold; if so, the field in the field pool template is deleted. In other words, in the embodiments of this specification, by adding fields with high frequency of occurrence and deleting fields in the field pool template that have not been hit for a long time, the field pool template is kept dynamically updated to meet the verification requirements of field transmission.
[0117] like Figure 4 As shown, the field transmission method provided in the embodiment of this specification also includes:
[0118] S401: Identify key fields in the field pool.
[0119] In the embodiments of this specification, the key fields are fields that play a key role in business logic, and the accuracy and format of their values are crucial to the normal operation of the business process. Key fields include at least order number, transaction ID, etc.
[0120] S402: Validate the value format of the key field according to pre-configured regular expression rules.
[0121] The regular expression rule is pre-configured by the administrator in the background to verify whether the format of the key field value is correct. The regular expression rule defines the matching pattern through a specific character combination to ensure that the value of the key field meets the format specifications required by the business. For example, the regular expression rule can check whether the order number is 12 digits. If not, the value format of the order number field does not meet the requirements.
[0122] S403: Determine whether the key field complies with the regular expression rule.
[0123] S404: If yes, allow the external request to continue transmitting.
[0124] S405: If not, intercept the external request and feed back a third alarm indicating a key field matching failure event.
[0125] When performing regular value format validation on key fields, if the field value does not meet the format requirements defined by the regular expression rules configured in the backend, a field match failure event is generated, indicating that there may be a problem with the outbound request and that corresponding processing is required.
[0126] Therefore, the field transmission method provided in the embodiments of this specification can, on the one hand, promptly identify and handle the occurrence of fields outside the expected range, avoiding the risk of data leakage and ensuring the security of data transmission. On the other hand, it can also perform flexible format verification on the values of specific key fields to avoid business process anomalies caused by data format errors. Furthermore, different events are reported in a hierarchical manner, facilitating more efficient handling of different events by administrators, operation and maintenance personnel, etc.
[0127] Furthermore, in the embodiments of this specification, the following is also included:
[0128] Cache the field pool template;
[0129] The field leakage event, the sensitive field leakage event, and the key field matching failure event are cached.
[0130] The field transmission method provided in the embodiments of this specification improves comparison efficiency by caching field pool templates. It also caches different events, reducing system pressure. By caching frequently used data such as field pool templates and various events, the number of accesses to slow storage devices such as backend databases can be reduced, thereby speeding up data acquisition and processing, improving system performance and responsiveness.
[0131] In some preferred embodiments, S103: determining whether all fields in the field pool are included in a preset field pool template is further performed as follows:
[0132] According to the interface source of the external request, it is determined whether each field in the field pool is included in the field pool template corresponding to the interface source of the external request.
[0133] That is, in the embodiments of this specification, a specific field pool template can also be configured for each interface, which defines the range of fields allowed to be included in normal requests of the interface as a basis for determining whether the fields are compliant.
[0134] In summary, the JSONPATH-based field transmission method provided in the embodiments of this specification can improve the efficiency and compatibility of the system while ensuring data transmission security, providing a new data protection solution for enterprises.
[0135] Based on the above-mentioned field transmission method based on JSONPATH, the embodiment of this specification also provides a field transmission device based on JSONPATH. The device may include a system (including a distributed system), software (application), module, component, server, client, etc. using the method described in the embodiment of this specification and combined with the necessary implementation hardware. Based on the same innovative concept, the device in one or more embodiments provided in the embodiment of this specification is as described in the following embodiments. Since the implementation scheme and method for solving the problem of the device are similar, the implementation of the specific device in the embodiment of this specification can refer to the implementation of the aforementioned method, and the repetitions will not be repeated. As used below, the term "unit" or "module" can implement a combination of software and / or hardware for a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceived.
[0136] like Figure 5 As shown, the embodiment of this specification provides a field transmission device based on JSONPATH, including:
[0137] The acquisition module 51 is used to obtain the JSON data requested externally;
[0138] A conversion module 52, configured to convert the JSON data of the external request into a field pool using JSONPATH;
[0139] A first judging module 53 is configured to judge whether all fields in the field pool are included in a preset field pool template;
[0140] a sensitivity check module 54 for determining, if not, that a field not included in the field pool template is a target leakage field, and performing a sensitivity check on the target leakage field;
[0141] A second judgment module 55 is used to judge whether the sensitivity check is passed;
[0142] A first alarm module 56 is configured to allow the external request to be sent and to feed back a first alarm indicating a field leakage event if the sensitivity check passes;
[0143] The second alarm module 57 is configured to intercept the external request and feed back a second alarm indicating a sensitive field leakage event if the sensitivity check fails.
[0144] Furthermore, the field transmission device based on JSONPATH further includes:
[0145] The reporting module 58 is configured to allow the external request to be reported when all fields in the field pool are included in a preset field pool template.
[0146] The beneficial effects achieved by the device provided in the embodiments of this specification are consistent with the beneficial effects achieved by the above-mentioned method and will not be repeated here.
[0147] like Figure 6 As shown, a computer device provided in an embodiment of this specification is provided. A field transmission device based on JSONPATH provided in an embodiment of this specification can be a computer device in this embodiment, executing the above-mentioned method of this specification. The computer device 602 may include one or more processors 604, such as one or more central processing units (CPUs), each of which can implement one or more hardware threads. The computer device 602 may also include any memory 606, which is used to store any type of information such as code, settings, data, etc. Without limitation, for example, the memory 606 may include any one or more combinations of the following: any type of RAM, any type of ROM, flash memory device, hard disk, optical disk, etc. More generally, any memory can use any technology to store information. Furthermore, any memory can provide volatile or non-volatile retention of information. Furthermore, any memory can represent a fixed or removable component of the computer device 602. In one case, when the processor 604 executes the associated instructions stored in any memory or combination of memories, the computer device 602 can perform any operation of the associated instructions. The computer device 602 also includes one or more drive mechanisms 608 for interacting with any storage, such as a hard disk drive mechanism, an optical disk drive mechanism, and the like.
[0148] The computer device 602 may also include an input / output module 610 (I / O) for receiving various inputs (via input devices 612) and for providing various outputs (via output devices 614). A specific output mechanism may include a presentation device 616 and an associated graphical user interface (GUI) 618. In other embodiments, the input / output module 610 (I / O), input devices 612, and output devices 614 may not be included, and the computer device 602 may simply be a computer device in a network. The computer device 602 may also include one or more network interfaces 620 for exchanging data with other devices via one or more communication links 622. One or more communication buses 624 couple the components described above together.
[0149] The communication link 622 may be implemented in any manner, for example, via a local area network, a wide area network (e.g., the Internet), a point-to-point connection, etc., or any combination thereof. The communication link 622 may include any combination of hardwired links, wireless links, routers, gateway functions, name servers, etc., governed by any protocol or combination of protocols.
[0150] Corresponding to Figures 1 to 4 In addition to the method shown, an embodiment of this specification also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the above method are executed.
[0151] The embodiment of this specification also provides a computer-readable instruction, wherein when the processor executes the instruction, the program therein causes the processor to execute the following Figures 1 to 4 The method shown.
[0152] The embodiment of this specification also provides a computer program product, including at least one instruction or at least one program, which is loaded and executed by a processor to implement the following Figures 1 to 4 The method shown.
[0153] It should be understood that in the various embodiments of this specification, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this specification.
[0154] It should also be understood that in the embodiments of this specification, the term "and / or" is merely a description of the relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. Furthermore, the character " / " in this specification generally indicates that the associated objects are in an "or" relationship.
[0155] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed in this specification can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the composition and steps of each example according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this specification.
[0156] Those skilled in the art will clearly understand that, for the sake of convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0157] In the several embodiments provided in this specification, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, or can be an electrical, mechanical or other form of connection.
[0158] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the embodiments of this specification.
[0159] In addition, the functional units in the various embodiments of this specification may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0160] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this specification is essentially or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of this specification. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0161] Specific embodiments are used in this specification to illustrate the principles and implementation methods of this specification. The description of the above embodiments is only used to help understand the methods and core ideas of this specification. At the same time, for those skilled in the art, based on the ideas of this specification, there will be changes in the specific implementation methods and application scope. In summary, the contents of this specification should not be understood as limiting this specification.
Claims
1. A field transmission method based on JSONPATH, characterized in that: include: Get the JSON data of the external request; Use JSONPATH to convert the JSON data of the external request into a field pool; Determine whether all fields in the field pool are included in the preset field pool template; If not, determining that the field not included in the field pool template is a target leakage field, and performing a sensitivity check on the target leakage field; Determining whether the sensitivity check passes; If the sensitivity check passes, the external request is allowed to be sent and a first alarm indicating a field leakage event is fed back; If the sensitivity check fails, the external request is intercepted and a second alarm indicating a sensitive field leakage event is fed back.
2. The method according to claim 1, characterized in that Performing a sensitivity check on the target leakage field further includes: Matching the target leakage field according to a preset regular expression, wherein the preset regular expression includes at least a first regular expression for detecting identity card information, a second regular expression for detecting bank card information, and a third regular expression for detecting contact information; Determining whether the target leakage field matches the regular expression; If so, the target leakage field is determined to be a sensitive field, and the external request is intercepted.
3. The method according to claim 2, characterized in that When the target leakage field passes the sensitivity check, the method further includes: The field pool template is updated using the target leakage field.
4. The method according to claim 3, characterized in that The updating of the field pool template using the target leaked field further includes: Counting the occurrence frequency of the target leakage field within a preset observation period; Determining whether the occurrence frequency is greater than or equal to a preset frequency threshold; If so, the field pool template is updated using the target leaked field.
5. The method according to claim 1, wherein The method further comprises: Identifying key fields in the field pool; Validating the value format of the key field according to pre-configured regular expression rules; If the key field conforms to the regular expression rule, the outbound request is allowed to continue to be transmitted; Otherwise, the external request is intercepted and a third alarm indicating a key field matching failure event is fed back.
6. The method according to claim 5, characterized in that The method further comprises: Cache the field pool template; The field leakage event, the sensitive field leakage event, and the key field matching failure event are cached.
7. The method according to claim 1, characterized in that Determining whether all fields in the field pool are included in the preset field pool template is further as follows: According to the interface source of the external request, it is determined whether each field in the field pool is included in the field pool template corresponding to the interface source of the external request.
8. A field transmission device based on JSONPATH, characterized in that: include: The acquisition module is used to obtain JSON data requested externally; A conversion module, configured to convert the JSON data of the external request into a field pool using JSONPATH; A first judging module is used to judge whether each field in the field pool is included in a preset field pool template; a sensitivity check module, configured to, if not, determine that the field not included in the field pool template is a target leakage field, and perform a sensitivity check on the target leakage field; A second judgment module is used to judge whether the sensitivity check is passed; A first alarm module, configured to allow sending the external request and feedback a first alarm indicating a field leakage event if the sensitivity check passes; The second alarm module is configured to intercept the external request and feed back a second alarm indicating a sensitive field leakage event if the sensitivity check fails.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
11. A computer program product, characterized in that The method comprises at least one instruction or at least one program, wherein the at least one instruction or the at least one program is loaded and executed by a processor to implement the method according to any one of claims 1 to 7.