Behavior marking and traceability tracking system and method for database sensitive data outgoing
By building a database sensitive data outflow behavior marking and traceability tracking system, and using the optimized bat algorithm and improved Markov chain model, we can accurately capture and quickly trace the outflow behavior of sensitive data in complex data environments, solve the identification and tracking problems in existing technologies, and improve the real-time and accuracy of data security protection.
Patent Information
- Application Number
- CN202510655994.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-21
- Publication Date
- 2025-09-05
- Estimated Expiration
- 2045-05-21
AI Technical Summary
Existing technologies are unable to accurately identify the complex and changeable outflow patterns of sensitive database data, and the traceability tracking system lacks systematicity and consistency, making it impossible to quickly and accurately locate the source of the data and track the flow of data, making it difficult to prevent the risk of data leakage.
By adopting data feature perception and collection unit, behavioral feature extraction unit for optimizing bat algorithm, improved Markov chain state transition analysis unit, data tag coding generation unit and traceability information storage and index construction unit, an efficient traceability tracking system is constructed through real-time data perception, feature extraction, state analysis and coding generation.
It achieves accurate capture and rapid tracing of sensitive data outflow in complex data environments, improves the real-time and accuracy of data security protection, and enables timely detection and handling of data leakage incidents.
Smart Images

Figure CN120597312A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of fire alarms, fire sensor hardware and algorithms, and in particular to a system and method for behavior marking and source tracing of outbound sensitive data from a database. Background Art
[0002] As digitalization accelerates, the exchange and outbound transmission of sensitive database data is becoming increasingly frequent. This data contains important information such as personal privacy and commercial secrets. Once illegally transmitted, it can lead to serious consequences such as data leakage, economic losses, and legal disputes. Therefore, building an effective system for marking and tracing the outbound transmission of sensitive database data is crucial to ensuring data security, but existing technologies have many shortcomings.
[0003] Traditional methods for extracting behavioral features related to sensitive data outbound transmission have significant limitations. Existing technologies often rely on fixed rules or simple statistical methods, making it difficult to accurately identify complex and changing patterns of outbound transmission. Faced with complex situations such as unusual fluctuations in data transmission volume, unique combinations of data field types, and periodic changes in data outbound transmission frequency, traditional methods are unable to comprehensively and accurately extract effective features. This results in a lack of reliable data support for subsequent analysis, making it difficult to promptly detect potential risks of sensitive data outbound transmission and effectively preventing data leaks.
[0004] The shortcomings of existing systems are also particularly prominent in the traceability and tracing process. Existing traceability and tracing technologies lack systematicity and consistency, data tagging and encoding are imprecise, and indexing is inefficient and often unreliable. This makes it impossible to quickly and accurately locate the source of sensitive data and track its flow when it is outsourced. This not only fails to meet the real-time and accuracy requirements of data security, but also hinders effective investigation and handling of data leaks, failing to provide a strong guarantee for data security. Summary of the Invention
[0005] In order to overcome the shortcomings and deficiencies of the prior art, the present invention provides a system and method for behavior marking and source tracing of outbound sensitive data from a database.
[0006] The technical solution adopted by the present invention is a behavior tagging and traceability tracking system for outgoing sensitive data from a database, which includes a data feature perception and collection unit, a behavior feature extraction unit with optimized bat algorithm, an improved Markov chain state transition analysis unit, a data tag coding generation unit, a traceability information storage and index construction unit, and a tracking instruction execution and feedback unit;
[0007] The data feature sensing and collection unit is used to sense in real time the data transmission flow, data field type, and data transmission frequency parameters during the outbound transmission of sensitive data from the database, and transmit the collected data to the behavioral feature extraction unit for optimizing the bat algorithm;
[0008] The behavior feature extraction unit of the optimized bat algorithm receives the data transmitted by the data feature sensing and collection unit, extracts features from the data using the optimized bat algorithm, and transmits the extracted behavior feature data to the improved Markov chain state transition analysis unit;
[0009] The improved Markov chain state transition analysis unit receives the behavior feature data, performs state transition analysis through the improved Markov chain model, and transmits the analysis result to the data mark code generation unit;
[0010] The data tag code generating unit generates a corresponding data tag code according to the received analysis result, and transmits the data tag code to the traceability information storage and index building unit;
[0011] The traceability information storage and index construction unit stores the data tag code and constructs an index. The tracking instruction execution and feedback unit executes the tracking instruction and feeds back the tracking result according to the index information of the traceability information storage and index construction unit. The orderly transmission and interaction of data between the units are achieved through the data transmission interface and communication protocol.
[0012] Furthermore, in the behavior feature extraction unit of the optimized bat algorithm, the optimized bat algorithm uses the following model formula to extract data features:
[0013] F new =F min +(F max -F min )×r1
[0014] Among them, F new represents the newly generated feature frequency, which is used to characterize the frequency of occurrence of the extracted sensitive data outflow behavior features; F min is the preset minimum characteristic frequency threshold, which is set based on the characteristic frequency statistics of historical sensitive data outflow behavior; F max is the preset maximum feature frequency threshold, which is also set based on historical data; r1 is a random number in the interval [0, 1], which is used to introduce randomness to optimize feature extraction.
[0015] Furthermore, in the behavior feature extraction unit of the optimized bat algorithm, the optimized bat algorithm also uses the following formula to update the feature position:
[0016]
[0017] in, represents the updated feature position of the i-th bat individual at time t+1, corresponding to the position of the sensitive data outbound behavior feature in the data space; is the characteristic position of the i-th bat individual at time t; is the speed of the i-th bat individual at time t, reflecting the rate of feature position update; is the speed of the i-th bat individual at time t-1; represents the global optimal feature position at time t, which is determined by the outbound behavior features of all sensitive data currently extracted; F new is the newly generated characteristic frequency.
[0018] Furthermore, in the improved Markov chain state transition analysis unit, the improved Markov chain model adopts the following state transition probability formula:
[0019]
[0020] Among them, P ij (n, n+1) represents the probability of being in state i at time n and transitioning to state j at time n+1, which is used to analyze the possibility of sensitive data outflow behavior transitioning from one state to another; ω ij (n) is the weight of the transition from state i to state j at time n, which is calculated based on the data transmission flow and data outbound frequency parameters during the sensitive data outbound process; N is the total number of states set by the system, which is pre-divided and determined according to different modes of sensitive data outbound behavior.
[0021] Furthermore, in the improved Markov chain state transition analysis unit, the improved Markov chain model also adopts the following state update formula:
[0022]
[0023] Among them, S(n+1) represents the state of the system at time n+1, which is used to reflect the overall state of sensitive data outbound behavior at that time; P i (n) is the probability of being in state i at time n, which is obtained from the statistics of historical sensitive data outflow behavior.
[0024] Furthermore, the data tag code generation unit adopts the following code generation formula based on the analysis result of the improved Markov chain state transition analysis unit and various parameters of the sensitive data in the database:
[0025] C=H(D,F,S)
[0026] Among them, C represents the generated data tag code, which is used to uniquely identify the outbound behavior of sensitive data; D is the specific content of the sensitive data collected by the data feature perception and collection unit, including the data field type and data value; F is the behavioral feature data extracted by the behavioral feature extraction unit of the optimized bat algorithm; S is the state information analyzed by the improved Markov chain state transition analysis unit, and H is a hash function. By performing hash operations on the sensitive data content, behavioral feature data and state information, a unique and corresponding data tag code is generated.
[0027] Furthermore, the data mark code generation unit also uses the following verification formula when generating the data mark code:
[0028] V=G(C,D,F,S)
[0029] Among them, V represents the generated data tag code verification value, which is used to verify the accuracy of the data tag code; C is the data tag code defined in claim 6; D, F, and S are the corresponding data characteristics, behavioral characteristics, and status information in claim 6 respectively; G is a verification function, which generates a verification value by operating on the data tag code and related data characteristics, behavioral characteristics, and status information.
[0030] Furthermore, when constructing an index, the traceability information storage and index construction unit adopts the following index construction formula:
[0031] I = Index(C, T, L)
[0032] Among them, I represents the constructed traceability information index, which is used to quickly locate and query relevant information of sensitive data outflow behavior; C is the data tag code generated by the data tag code generation unit; T is the timestamp when the sensitive data outflow behavior occurs, which accurately records the time of the outflow behavior; L is the location information where the sensitive data outflow behavior occurs, including the network IP address; Index is the index construction function, which constructs a traceability information index with query performance by processing the data tag code, timestamp and location information.
[0033] Furthermore, the traceability information storage and index building unit adopts the following index update formula when updating the index:
[0034] I new =Update(I,ΔC,ΔT,ΔL)
[0035] Among them, I newRepresents the traceability information index after update; I is the traceability information index before update; ΔC is the change in the newly generated data tag code; ΔT is the change in the timestamp of the new sensitive data outbound behavior; ΔL is the change in the location information of the new sensitive data outbound behavior. Update is the index update function, which dynamically updates the original index according to the changes in the newly generated data tag code, timestamp and location information.
[0036] The method for marking and tracing the outgoing behavior of sensitive database data includes the following steps:
[0037] The first step is to use the data feature perception and collection unit to perceive in real time the data transmission flow, data field type, and data transmission frequency parameters of the database sensitive data during outbound transmission, and transmit the collected data to the behavioral feature extraction unit that optimizes the bat algorithm;
[0038] In the second step, after receiving the data, the behavior feature extraction unit of the optimized bat algorithm uses the optimized bat algorithm to extract features from the data and transmits the extracted behavior feature data to the improved Markov chain state transition analysis unit;
[0039] In the third step, the improved Markov chain state transition analysis unit receives the behavior feature data, performs state transition analysis through the improved Markov chain model, and transmits the analysis results to the data tag code generation unit;
[0040] In the fourth step, the data tag code generation unit generates a corresponding data tag code based on the received analysis results and various parameters of the sensitive data in the database, and transmits the data tag code to the traceability information storage and index construction unit;
[0041] In the fifth step, the traceability information storage and index construction unit stores the data tag code and constructs an index;
[0042] In the sixth step, the tracing instruction execution and feedback unit executes the tracing instruction and feeds back the tracing result according to the index information of the traceability information storage and index construction unit.
[0043] Beneficial Effects: The present invention proposes a system and method for behavioral tagging and traceability of sensitive data outbound from a database. Regarding the extraction of behavioral features for sensitive data outbound, the present invention employs a data feature sensing and acquisition unit to acquire key parameters such as data transmission flow and field type in real time. The behavioral feature extraction unit, which optimizes the bat algorithm, conducts in-depth data mining. Compared to traditional fixed rules and simple statistical methods, this system and method can accurately capture the complex and changing behavioral patterns during data outbound transmission. Whether it is abnormal flow fluctuations or unique field combinations, it can comprehensively and accurately extract effective features, providing reliable data support for subsequent analysis. In the traceability and tracing process, an improved Markov chain state transition analysis unit performs state transition analysis on behavioral feature data. The data tag code generation unit combines the analysis results with data parameters to generate precise codes. The traceability information storage and index construction unit constructs an efficient index based on this information and dynamically updates it. Compared to existing traceability technologies that lack systematicity, suffer from inaccurate coding, and inefficient indexing, this system and method can quickly and accurately locate the source of sensitive data and track data flow when sensitive data outbound transmission occurs, enabling efficient investigation and handling of data leaks. This significantly improves the real-time and accuracy of data security protection, effectively ensuring the security and traceability of sensitive data outbound transmission from databases. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 It is a diagram of the system unit composition of the present invention;
[0045] Figure 2 The figure is a flow chart of the method steps of the present invention. DETAILED DESCRIPTION
[0046] It should be noted that, unless there is a conflict, the embodiments in this application and the features described in the embodiments can be combined with each other. The application is further described in detail below with reference to the accompanying drawings and specific embodiments.
[0047] like Figure 1 As shown, the behavior marking and traceability tracking system and method for outgoing sensitive data from a database includes a data feature perception and collection unit, a behavior feature extraction unit that optimizes the bat algorithm, an improved Markov chain state transition analysis unit, a data mark coding generation unit, a traceability information storage and index construction unit, and a tracking instruction execution and feedback unit;
[0048] The data feature sensing and collection unit is used to sense in real time various parameters such as data transmission flow, data field type, data transmission frequency, etc. during the outbound transmission of sensitive data from the database, and transmit the collected data to the behavioral feature extraction unit for optimizing the bat algorithm;
[0049] Specifically, the data feature perception and collection unit is deployed at the boundary of the database system, and the outbound data flow is monitored in real time through the protocol parsing engine. It supports mainstream database protocols such as MySQL and Oracle, and can identify more than 200 types of sensitive data (such as credit card numbers and medical records). Using deep packet inspection technology, it can capture and parse data packets within 100 microseconds, and the traffic monitoring accuracy reaches the byte level. For example, in the application of a certain financial institution, the unit successfully identified 5,000 abnormal data requests per second, and promptly blocked the risk of customer information leakage. In terms of technical parameters, the system supports millions of concurrent connections, the data collection throughput reaches 10GB / s, and the false alarm rate is less than 0.001%, ensuring full monitoring of the flow of sensitive data in complex network environments.
[0050] The behavior feature extraction unit of the optimized bat algorithm receives the data transmitted by the data feature sensing and collection unit, extracts features from the data using the optimized bat algorithm, and transmits the extracted behavior feature data to the improved Markov chain state transition analysis unit;
[0051] Specifically, the behavioral feature extraction unit of the optimized bat algorithm uses an improved bat algorithm to perform multi-dimensional feature extraction on the collected data. Through an adaptive search strategy, the feature space is divided into 512 dimensions, and each dimension corresponds to a different data behavior feature (such as access time distribution, operation sequence pattern). In the actual application of a certain e-commerce platform, the system successfully identified SQL injection attacks disguised as normal data exports by analyzing user behavior patterns, with an accuracy rate of 99.2%. The algorithm introduces a dynamic weighting mechanism to give higher weights to recent behaviors, which increases the system's response speed to new attack patterns by 30%. In terms of technical parameters, the feature extraction delay is controlled within 50 milliseconds, supporting the processing of 100,000 data records per second, effectively responding to real-time analysis needs in high-concurrency scenarios.
[0052] The improved Markov chain state transition analysis unit receives the behavior feature data, performs state transition analysis through the improved Markov chain model, and transmits the analysis result to the data mark code generation unit;
[0053] Specifically, the improved Markov chain state transition analysis unit constructs a Markov chain model containing 256 state nodes, each node corresponding to a data outbound state (such as normal query, batch export, abnormal transmission). By analyzing the state transition probability matrix, the system can predict the data flow trend within the next 3 steps. In a certain medical database, the system successfully intercepted an attempt to transfer patient genetic data to an overseas server by monitoring the state transition of the data access path. The model introduces a time window mechanism and assigns different weights to state transitions in different time periods, which increases the accuracy of abnormal behavior detection to 97.8%. In terms of technical parameters, the state update frequency is 100 times / second, and it supports dynamic expansion to 1024 state nodes to meet the behavior modeling needs in complex business scenarios.
[0054] The data tag code generating unit generates a corresponding data tag code according to the received analysis result, and transmits the data tag code to the traceability information storage and index building unit;
[0055] Specifically, the data tag code generation unit generates a unique data tag code based on the results of the preamble analysis, and uses the SHA-256 hash algorithm combined with a timestamp and a random number to generate a 128-bit code. The coding structure contains five functional sections: data type identifier (16 bits), risk level (8 bits), timestamp (32 bits), source IP address mapping (32 bits), and checksum (40 bits). In a certain government system, the coding system successfully tracked an incident in which an internal employee illegally sent out sensitive files. It took only 3 minutes from discovering the anomaly to locating the person responsible. In terms of technical parameters, the code generation speed reaches 100,000 per second, and the collision probability is less than 10^-32, ensuring uniqueness and security in a large-scale data environment.
[0056] The traceability information storage and index construction unit stores the data tag code and constructs an index. The tracking instruction execution and feedback unit executes the tracking instruction and feeds back the tracking result according to the index information of the traceability information storage and index construction unit. The orderly transmission and interaction of data between the units are achieved through the data transmission interface and communication protocol.
[0057] Specifically, the traceability information storage and index construction unit uses a distributed graph database to store traceability information, supporting PB-level data storage and millisecond-level query response. The index structure is based on B+ tree optimization and adopts a three-level partitioning strategy (by time, risk level, and data type) to improve query efficiency by 40%. In an application of a multinational enterprise, the system successfully stored more than 5 billion data access records and located an abnormal data outbound event three years ago within 100 milliseconds. In terms of technical parameters, the system supports 1,000 concurrent query requests, and the data persistence rate reaches 99.999%, ensuring the integrity and availability of historical traceability information.
[0058] Specifically, the tracking instruction execution and feedback unit executes tracking instructions through a probe cluster deployed at the network boundary, supporting multi-path backtracking and traffic mirroring analysis. When suspicious data is detected being sent out, the system can initiate an emergency response process within 1 second, including blocking the connection, recording session information, and generating a security audit report. In a certain securities trading system, the unit successfully intercepted an APT attack targeting transaction data and analyzed the attack source IP and attack path through traffic backtracking. In terms of technical parameters, the instruction response delay is less than 500 milliseconds, supporting rapid retrieval of TB-level historical traffic data, ensuring that security incidents can be quickly located and handled in an emergency. Each unit implements data interaction through a standardized RESTful API interface to ensure the overall collaborative work efficiency of the system.
[0059] Preferably, in the behavior feature extraction unit of the optimized bat algorithm, the optimized bat algorithm uses the following model formula to extract data features:
[0060] F new =F min +(F max -F min )×r1
[0061] Among them, F new represents the newly generated feature frequency, which is used to characterize the frequency of occurrence of the extracted sensitive data outflow behavior features; F min is the preset minimum characteristic frequency threshold, which is set based on the characteristic frequency statistics of historical sensitive data outflow behavior; F max is the preset maximum feature frequency threshold, also set based on historical data; r1 is a random number in the interval [0, 1], used to introduce randomness to optimize feature extraction. This formula processes parameters such as the data field type and data outbound frequency during the outbound transmission of sensitive data to obtain more accurate behavioral feature data.
[0062] Specifically, the behavioral feature extraction unit of the optimized bat algorithm calculates a new characteristic frequency through a specific formula. This formula uses the preset minimum and maximum characteristic frequency thresholds as boundary constraints, combined with randomly generated values within a fixed interval, to process parameters such as the data field type and data outbound frequency in the process of sensitive data being sent out of the database. The core of this is to introduce uncertainty through random numbers and dynamically adjust the characteristic frequency within the preset threshold range, so that the algorithm can break through the conventional pattern during data processing and unearth potential and non-obvious features in data outbound behavior. This calculation method can enhance the algorithm's adaptability to complex data environments, avoid falling into local optimal solutions, and accurately extract more representative behavioral feature data from massive database parameters, providing more reliable input for subsequent analysis.
[0063] Preferably, in the behavior feature extraction unit of the optimized bat algorithm, the optimized bat algorithm also uses the following formula to update the feature position:
[0064]
[0065] in, represents the updated feature position of the i-th bat individual at time t+1, corresponding to the position of the sensitive data outbound behavior feature in the data space; is the characteristic position of the i-th bat individual at time t; is the speed of the i-th bat individual at time t, reflecting the rate of feature position update; is the speed of the i-th bat individual at time t-1; represents the global optimal feature position at time t, which is determined by the outbound behavior features of all sensitive data currently extracted; F new is the newly generated feature frequency. By combining these two formulas, the dynamic update and optimized extraction of the feature locations of sensitive data outbound behavior can be achieved.
[0066] Specifically, the feature position update formula of the optimized bat algorithm iteratively calculates the position and speed of individual bats to dynamically locate the behavioral features of sensitive data outflow in the data space. The speed update of the individual bat in the formula depends on the speed at the previous moment, the difference between the current position and the global optimal position, and the newly generated characteristic frequency. This update mechanism enables the algorithm to dynamically adjust the search direction and step size based on the distribution of the behavioral features of the current data outflow. The global optimal position guides the algorithm to search in the direction of a more optimal solution, while the characteristic frequency affects the search step size, improving search efficiency while ensuring search accuracy. Through continuous iterative updates, the algorithm can more accurately capture the position of behavioral features in the data space, thereby achieving precise extraction and positioning of the behavioral features of sensitive data outflow.
[0067] Preferably, in the improved Markov chain state transition analysis unit, the improved Markov chain model adopts the following state transition probability formula:
[0068]
[0069] Among them, P ij (n, n+1) represents the probability of being in state i at time n and transitioning to state j at time n+1, which is used to analyze the possibility of sensitive data outflow behavior transitioning from one state to another; ω ij(n) is the weight of transitioning from state i to state j at time n. This weight is calculated based on parameters such as the data transmission volume and frequency of sensitive data outbound transmission. N is the total number of states set by the system, which is pre-determined based on different modes of sensitive data outbound transmission. This formula allows for quantitative analysis of state transitions in sensitive data outbound transmission, providing a basis for subsequent processing.
[0070] Specifically, the improved Markov chain state transition analysis unit calculates the state transition probability using a specific formula. This formula is based on the weight of transitions from one state to another, combined with the total number of states set by the system, and the state transition probability is obtained through normalization. The weights in the formula are determined by a combination of parameters such as the data transmission volume and data outbound frequency during the sensitive data outbound process. This calculation method can quantify the probability of sensitive data outbound behavior transitioning between different states, converting complex data outbound behavior patterns into measurable probability values. These probability values provide a quantitative basis for the system to judge the development trend of data outbound behavior, allowing the system to more scientifically assess the risk level of data outbound behavior and promptly detect abnormal state transitions.
[0071] Preferably, in the improved Markov chain state transition analysis unit, the improved Markov chain model further adopts the following state update formula:
[0072]
[0073] Among them, S(n+1) represents the state of the system at time n+1, which is used to reflect the overall state of sensitive data outbound behavior at that time; P i (n) is the probability of being in state i at time n, derived from historical statistics of sensitive data outflow behavior. This formula combines the state transition probability with the probability of each state at the current moment to dynamically update and analyze the state of sensitive data outflow behavior.
[0074] Specifically, the improved state update formula of the Markov chain state transition analysis unit combines the probabilities of each state at the current moment with the state transition probabilities to calculate the system state at the next moment. This formula comprehensively considers historical state probabilities and current state transition trends, enabling the system to dynamically reflect the overall state of sensitive data outflow behavior at different moments. This calculation method avoids the limitations of relying solely on current data and fully utilizes historical data information to provide more comprehensive and accurate updates and predictions of data outflow behavior. By continuously updating the state, the system can promptly capture changing trends in data outflow behavior, providing more accurate status information for subsequent data labeling and traceability.
[0075] Preferably, the data tag code generation unit adopts the following code generation formula based on the analysis result of the improved Markov chain state transition analysis unit and various parameters of the sensitive data in the database:
[0076] C=H(D,F,S)
[0077] Here, C represents the generated data tag code, used to uniquely identify the outbound sensitive data; D represents the specific content of the sensitive data collected by the data feature perception and collection unit, including data field type and data value; F represents the behavioral feature data extracted by the behavioral feature extraction unit of the optimized bat algorithm; and S represents the state information analyzed by the improved Markov chain state transition analysis unit. H represents the hash function, which generates a unique and corresponding data tag code by performing a hash operation on the sensitive data content, behavioral feature data, and state information.
[0078] Specifically, the code generation formula of the data tag code generation unit integrates the specific content of sensitive data, behavioral feature data, and state information through a hash function to generate a unique data tag code. The formula takes the data content obtained by the data feature perception and acquisition unit, the behavioral feature data extracted by the behavioral feature extraction unit of the optimized bat algorithm, and the state information obtained by the improved Markov chain state transition analysis unit as input. Through the operation of the hash function, the multi-dimensional information is compressed and mapped into a fixed-length code. This encoding method ensures that each sensitive data outflow behavior has a unique corresponding code. The code contains key information related to the behavior, which facilitates the rapid positioning and association of the code to the specific sensitive data outflow behavior in the subsequent traceability process, thereby realizing the effective marking and management of data outflow behavior.
[0079] Preferably, the data mark code generation unit also uses the following verification formula when generating the data mark code:
[0080] V=G(C,D,F,S)
[0081] Among them, V represents the generated data tag code verification value, which is used to verify the accuracy of the data tag code; C is the data tag code defined in claim 6; D, F, and S are the corresponding data characteristics, behavioral characteristics, and status information in claim 6 respectively; G is a verification function that generates a verification value by operating on the data tag code and related data characteristics, behavioral characteristics, and status information to ensure the consistency of the data tag code with the actual sensitive data outbound behavior.
[0082] Specifically, the verification formula of the data marker code generation unit operates on the generated data marker code and related data features, behavioral features, and status information through a specific function to generate a verification value. The purpose of this formula is to verify the consistency of the code and the original data information. By using the code and the original data information as input for the operation, the obtained verification value can be compared with the pre-set rules or standards. If the verification value meets expectations, it means that the code accurately reflects the actual outbound behavior of sensitive data; if it does not meet the requirements, it means that the code may be erroneous or tampered with. This verification mechanism provides a guarantee for the accuracy of the data marker code, ensuring that the query and analysis results based on the code are reliable during the traceability process, thereby enhancing the security and credibility of the entire system.
[0083] Preferably, the traceability information storage and index construction unit uses the following index construction formula when constructing the index:
[0084] I = Index(C, T, L)
[0085] Here, I represents the traceability information index, which is used to quickly locate and query information related to sensitive data outflows; C is the data tag code generated by the data tag code generation unit; T is the timestamp of the sensitive data outflow, which accurately records the time of the outflow; and L is the location information of the sensitive data outflow, including the network IP address. Index is an index construction function that processes data tag codes, timestamps, and location information to construct a traceability information index with efficient query performance.
[0086] Specifically, the index construction formula of the traceability information storage and index construction unit processes the data tag code, timestamp and location information through a specific index construction function to construct a traceability information index. The formula uses the data tag code as the unique identifier of the behavior, the timestamp records the time sequence of the data outflow behavior, and the location information determines the network location of the behavior. These key information are integrated and organized through the index construction function. This index construction method enables the system to quickly locate the corresponding traceability information record according to different query requirements, such as query by time, query by location, or precise query by code. By building an efficient index structure, the query efficiency of massive traceability information is greatly improved, providing strong support for quickly tracking the outflow of sensitive data.
[0087] Preferably, the traceability information storage and index building unit adopts the following index update formula when updating the index:
[0088] I new =Update(I,ΔC,ΔT,ΔL)
[0089] Among them, Inew The index represents the updated traceability information index; I represents the traceability information index before the update; ΔC represents the change in the newly generated data tag code; ΔT represents the change in the timestamp of the newly generated sensitive data outbound behavior; and ΔL represents the change in the location information of the newly generated sensitive data outbound behavior. Update is an index update function that dynamically updates the original index based on changes in the newly generated data tag code, timestamp, and location information to ensure the index's timeliness and accuracy.
[0090] Specifically, the index update formula of the traceability information storage and index construction unit dynamically updates the original index based on the newly generated data tag code change, timestamp change, and location information change through the index update function. The formula can perceive changes in data outflow behavior in real time. When new data outflow behavior occurs or existing behavior information changes, it calculates the change and passes it as input to the index update function. The index update function adjusts and optimizes the original index structure based on these changes to ensure that the index is always consistent with the actual sensitive data outflow behavior information. This dynamic update mechanism ensures the timeliness and accuracy of the index, and can always maintain efficient query performance even in a database environment where data changes frequently, ensuring the continuous and effective operation of the traceability tracking function.
[0091] like Figure 2 As shown in FIG, the behavior marking and traceability tracking method for outgoing sensitive data from a database includes the following steps:
[0092] The first step is to use the data feature perception and collection unit to perceive in real time various parameters such as data transmission flow, data field type, and data transmission frequency during the outbound transmission of sensitive data from the database, and transmit the collected data to the behavioral feature extraction unit that optimizes the bat algorithm;
[0093] In the second step, after receiving the data, the behavior feature extraction unit of the optimized bat algorithm uses the optimized bat algorithm to extract features from the data and transmits the extracted behavior feature data to the improved Markov chain state transition analysis unit;
[0094] In the third step, the improved Markov chain state transition analysis unit receives the behavior feature data, performs state transition analysis through the improved Markov chain model, and transmits the analysis results to the data tag code generation unit;
[0095] In the fourth step, the data tag code generation unit generates a corresponding data tag code based on the received analysis results and various parameters of the sensitive data in the database, and transmits the data tag code to the traceability information storage and index construction unit;
[0096] In the fifth step, the traceability information storage and index construction unit stores the data tag code and constructs an index;
[0097] In the sixth step, the tracking instruction execution and feedback unit executes the tracking instruction and feeds back the tracking result according to the index information of the traceability information storage and index construction unit. Through the data transmission and processing between each step, the outbound behavior of sensitive data in the database is marked and traced.
[0098] This system and method have achieved a breakthrough in the extraction of behavioral features of sensitive data outbound transmission. Existing technologies rely on fixed rules and simple statistics, making it difficult to identify complex behavioral patterns. However, this system uses a data feature perception and acquisition unit to obtain multi-dimensional parameters such as data transmission flow and field type in real time. On this basis, the behavioral feature extraction unit of the optimized bat algorithm simulates the principle of bat echolocation and conducts in-depth data mining, which can accurately capture the complex and changeable behavioral patterns in the process of data outbound transmission. Whether it is abnormal fluctuations in data flow or special combinations of field types, effective features can be fully and accurately extracted to avoid missing potential risk behaviors and provide reliable data support for subsequent analysis, which completely changes the situation of inaccurate feature extraction of traditional methods.
[0099] In terms of traceability and tracking, this system also shows significant advantages. Existing traceability and tracking technologies have problems such as insufficient systematization, inaccurate coding, and low index construction efficiency, which makes it difficult to quickly locate the source of the data and track the flow. This system improves the Markov chain state transition analysis unit to conduct in-depth analysis of behavioral feature data to determine the state transition of data outbound behavior; the data tag code generation unit combines the analysis results with the data parameters to generate accurate and unique data tag codes; the traceability information storage and index construction unit constructs an efficient index structure and implements dynamic updates to ensure fast and accurate data queries. The tracking instruction execution and feedback unit interacts with network equipment and security protection systems based on index information to achieve accurate tracking of data flows and provide timely feedback. This interlocking design enables the system to quickly locate the source of the data and clearly track the flow of data when sensitive data outbound events occur, greatly improving the efficiency and accuracy of traceability and tracking, and effectively making up for the shortcomings of existing technologies.
[0100] Furthermore, the various units of this system and method work together to form a complete closed-loop data security protection loop. From data feature collection to behavioral feature extraction, to state analysis, tag encoding, index construction, and tracking feedback, each link is closely connected and coordinated. Compared to existing technologies, where each link is relatively independent and lacks effective coordination, this system can more efficiently handle sensitive data outbound events, promptly identify risks and implement countermeasures, comprehensively improve the security and reliability of database sensitive data outbound management, and provide strong protection for the security of database sensitive data.
[0101] In the description of the present invention, it should be noted that, unless otherwise expressly specified or limited, the terms "disposed," "installed," "connected," "connected," and "fixed" should be understood in a broad sense. For example, they may refer to fixed connections, detachable connections, or integral connections; they may refer to mechanical connections or electrical connections; they may refer to direct connections or indirect connections through an intermediate medium; and they may refer to internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.
[0102] While embodiments of the present invention have been shown and described, it will be understood by those skilled in the art that various equivalent changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A behavioral tagging and traceability system for outgoing sensitive database data, characterized by: It includes a data feature perception and collection unit, a behavioral feature extraction unit for optimizing the bat algorithm, an improved Markov chain state transition analysis unit, a data tag encoding generation unit, a traceability information storage and index construction unit, and a tracking instruction execution and feedback unit; The data feature sensing and collection unit is used to sense in real time the data transmission flow, data field type, and data transmission frequency parameters during the outbound transmission of sensitive data from the database, and transmit the collected data to the behavioral feature extraction unit for optimizing the bat algorithm; The behavior feature extraction unit of the optimized bat algorithm receives the data transmitted by the data feature sensing and collection unit, extracts features from the data using the optimized bat algorithm, and transmits the extracted behavior feature data to the improved Markov chain state transition analysis unit; The improved Markov chain state transition analysis unit receives the behavior feature data, performs state transition analysis through the improved Markov chain model, and transmits the analysis result to the data mark code generation unit; The data tag code generating unit generates a corresponding data tag code according to the received analysis result, and transmits the data tag code to the traceability information storage and index building unit; The traceability information storage and index construction unit stores the data tag code and constructs an index. The tracking instruction execution and feedback unit executes the tracking instruction and feeds back the tracking result according to the index information of the traceability information storage and index construction unit. The orderly transmission and interaction of data between the units are achieved through the data transmission interface and communication protocol.
2. The database sensitive data outbound behavior marking and traceability tracking system according to claim 1 is characterized in that: In the behavior feature extraction unit of the optimized bat algorithm, the optimized bat algorithm uses the following model formula to extract data features: F new =F min +(F max -F min )×r1 Among them, F new represents the newly generated feature frequency, which is used to characterize the frequency of occurrence of the extracted sensitive data outflow behavior features; F min is the preset minimum characteristic frequency threshold, which is set based on the characteristic frequency statistics of historical sensitive data outflow behavior; F max is the preset maximum feature frequency threshold, which is also set based on historical data; r1 is a random number in the interval [0, 1], which is used to introduce randomness to optimize feature extraction.
3. The behavior marking and traceability tracking system for outgoing sensitive database data according to claim 1 is characterized in that: In the behavior feature extraction unit of the optimized bat algorithm, the optimized bat algorithm also uses the following formula to update the feature position: in, represents the updated feature position of the i-th bat individual at time t+1, corresponding to the position of the sensitive data outbound behavior feature in the data space; is the characteristic position of the i-th bat individual at time t; is the speed of the i-th bat individual at time t, reflecting the rate of feature position update; is the speed of the i-th bat individual at time t-1; represents the global optimal feature position at time t, which is determined by the outbound behavior features of all sensitive data currently extracted; F new is the newly generated characteristic frequency.
4. The database sensitive data outbound behavior marking and traceability tracking system according to claim 1 is characterized in that: In the improved Markov chain state transition analysis unit, the improved Markov chain model adopts the following state transition probability formula: Among them, P ij (n, n+1) represents the probability of being in state i at time n and transitioning to state j at time n+1, which is used to analyze the possibility of sensitive data outflow behavior transitioning from one state to another; ω ij (n) is the weight of the transition from state i to state j at time n, which is calculated based on the data transmission flow and data outbound frequency parameters during the sensitive data outbound process; N is the total number of states set by the system, which is pre-divided and determined according to different modes of sensitive data outbound behavior.
5. The behavior marking and traceability tracking system for outgoing sensitive database data according to claim 4 is characterized in that: In the improved Markov chain state transition analysis unit, the improved Markov chain model also adopts the following state update formula: Among them, S(n+1) represents the state of the system at time n+1, which is used to reflect the overall state of sensitive data outbound behavior at that time; P i (n) is the probability of being in state i at time n, which is obtained from the statistics of historical sensitive data outflow behavior.
6. The database sensitive data outbound behavior marking and traceability tracking system according to claim 1 is characterized in that: The data tag code generation unit adopts the following code generation formula based on the analysis results of the improved Markov chain state transition analysis unit and various parameters of the sensitive data in the database: C=H(D,F,S) Among them, C represents the generated data tag code, which is used to uniquely identify the outbound behavior of sensitive data; D is the specific content of the sensitive data collected by the data feature perception and collection unit, including the data field type and data value; F is the behavioral feature data extracted by the behavioral feature extraction unit of the optimized bat algorithm; S is the state information analyzed by the improved Markov chain state transition analysis unit, and H is a hash function. By performing hash operations on the sensitive data content, behavioral feature data and state information, a unique and corresponding data tag code is generated.
7. The database sensitive data outbound behavior marking and traceability tracking system according to claim 6 is characterized in that: When generating the data mark code, the data mark code generation unit also uses the following verification formula: V=G(C,D,F,S) Among them, V represents the generated data tag code verification value, which is used to verify the accuracy of the data tag code; C is the data tag code defined in claim 6; D, F, and S are the corresponding data characteristics, behavioral characteristics, and status information in claim 6 respectively; G is a verification function, which generates a verification value by operating on the data tag code and related data characteristics, behavioral characteristics, and status information.
8. The database sensitive data outbound behavior marking and traceability tracking system according to claim 1 is characterized in that: When the traceability information storage and index construction unit constructs an index, the following index construction formula is used: I = Index(C, T, L) Among them, I represents the constructed traceability information index, which is used to quickly locate and query relevant information of sensitive data outflow behavior; C is the data tag code generated by the data tag code generation unit; T is the timestamp when the sensitive data outflow behavior occurs, which accurately records the time of the outflow behavior; L is the location information where the sensitive data outflow behavior occurs, including the network IP address; Index is the index construction function, which constructs a traceability information index with query performance by processing the data tag code, timestamp and location information.
9. The database sensitive data outbound behavior marking and traceability tracking system according to claim 8 is characterized in that: When updating the index, the traceability information storage and index construction unit adopts the following index update formula: I new =Update(I,ΔC,ΔT,ΔL) Among them, I new Represents the traceability information index after update; I is the traceability information index before update; ΔC is the change in the newly generated data tag code; ΔT is the change in the timestamp of the new sensitive data outbound behavior; ΔL is the change in the location information of the new sensitive data outbound behavior. Update is the index update function, which dynamically updates the original index according to the changes in the newly generated data tag code, timestamp and location information.
10. A method for marking and tracing the outgoing behavior of sensitive database data, characterized in that: The following steps are involved: The first step is to use the data feature perception and collection unit to perceive in real time the data transmission flow, data field type, and data transmission frequency parameters of the database sensitive data during outbound transmission, and transmit the collected data to the behavioral feature extraction unit that optimizes the bat algorithm; In the second step, after receiving the data, the behavior feature extraction unit of the optimized bat algorithm uses the optimized bat algorithm to extract features from the data and transmits the extracted behavior feature data to the improved Markov chain state transition analysis unit; In the third step, the improved Markov chain state transition analysis unit receives the behavior feature data, performs state transition analysis through the improved Markov chain model, and transmits the analysis results to the data tag code generation unit; In the fourth step, the data tag code generation unit generates a corresponding data tag code based on the received analysis results and various parameters of the sensitive data in the database, and transmits the data tag code to the traceability information storage and index construction unit; In the fifth step, the traceability information storage and index construction unit stores the data tag code and constructs an index; In the sixth step, the tracing instruction execution and feedback unit executes the tracing instruction and feeds back the tracing result according to the index information of the traceability information storage and index construction unit.
Citation Information
Patent Citations
Methods and systems for data collection, learning, and streaming of machine signals for analytics and maintenance using the industrial internet of things
CN112703457A
Chemical industrial park illegal behavior intervention and tracing system based on edge calculation
CN119339334A
Systems and methodologies for auto labeling vulnerabilities
US20250021657A1