Transmission behavior evaluation method and device and storage medium

By obtaining filing and data transmission information and utilizing a compliance assessment model based on graph structuring and semantic coding, we can identify and intercept non-compliant behaviors, addressing the risk of data leakage caused by inconsistent behaviors during cross-border data transmission and ensuring the security and compliance of data transmission.

CN120639657APending Publication Date: 2025-09-12CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511005894.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-21
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

During cross-border data transmission, the actual transmission behavior of enterprises may be inconsistent with the registered transmission behavior, resulting in an increased risk of data leakage and affecting industry development.

Method used

By obtaining registered transmission information and data transmission information, and using the trained compliance assessment model, based on graph structured processing and semantic coding, the differences between actual transmission behavior and registered transmission behavior are determined, compliance assessment results are obtained, and non-compliant behavior is identified and intercepted.

Benefits of technology

Effectively identify and intercept non-compliant data transmission behaviors, ensure the security of data transmission, prevent data leakage, and ensure that transmission behaviors meet compliance requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639657A_ABST
    Figure CN120639657A_ABST
Patent Text Reader

Abstract

The invention provides a transmission behavior evaluation method and device and a storage medium, relates to the technical field of communication, and is used for solving the problem that the behavior of an enterprise for transmitting data to a receiver may not be compliant. The method comprises the steps that filing transmission information and data transmission information are acquired, the filing transmission information is used for indicating a filing transmission behavior that a data sender sends data to be transmitted to a data receiver, and the data transmission information is used for indicating an actual transmission behavior that the data sender sends the data to be transmitted to the data receiver. And obtaining a compliance evaluation result based on the filing transmission information, the data transmission information and the trained compliance evaluation model, the trained compliance evaluation model being used for determining the difference between the actual transmission behavior and the filing transmission behavior, and the compliance evaluation result being used for indicating whether the actual transmission behavior is compliant or not.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a method, device, and storage medium for evaluating transmission behavior. Background Art

[0002] With the deepening of globalization, the demand for cross-border data flows is increasing. In this cross-border data scenario, if enterprises do not comply with regulations when transmitting data to the recipient, it may cause data leaks and harm industry development.

[0003] Therefore, how to determine whether the company's data transmission to the recipient is compliant has become an urgent problem that needs to be solved. Summary of the Invention

[0004] The present application provides a transmission behavior evaluation method, device, and storage medium for solving the problem that an enterprise may not comply with regulations when transmitting data to a recipient.

[0005] To achieve the above objectives, this application adopts the following technical solutions:

[0006] In a first aspect, the present application provides a method for evaluating transmission behavior. In this method, registered transmission information and data transmission information are obtained. The registered transmission information is used to indicate the registered transmission behavior of the data sender sending the data to be transmitted to the data recipient, and the data transmission information is used to indicate the actual transmission behavior of the data sender sending the data to be transmitted to the data recipient. Based on the registered transmission information, the data transmission information, and a trained compliance assessment model, a compliance assessment result is obtained. The trained compliance assessment model is used to determine the difference between the actual transmission behavior and the registered transmission behavior. The compliance assessment result is used to indicate whether the actual transmission behavior is compliant.

[0007] Based on the above technical solution, it is possible to obtain registered transmission information and data transmission information, and to obtain a compliance assessment result based on the registered transmission information, data transmission information, and the trained compliance assessment model. In this way, by determining whether the actual transmission behavior of the data sender to the data recipient is consistent with the registered transmission behavior recorded in the registered transmission information, it is possible to determine whether the data sender's behavior in sending the data to the data recipient is compliant. This allows for interception of non-compliant data transmission behavior, preventing data leakage and ensuring the security of data transmission.

[0008] In one possible design, the filing transmission information includes at least two of the following filing transmission types: filing data type, filing data quantity, filing data size, filing recipient information, filing sender information, filing data transmission protocol, filing data transmission method, filing data transmission time, filing transmission purpose, and filing data protection strategy.

[0009] In one possible design, a compliance assessment result is obtained based on the filing transmission information, data transmission information, and a trained compliance assessment model. This includes: performing graph-structuring processing on the filing transmission information to obtain a filing attribute graph of the filing transmission information, where the filing attribute graph is used to indicate operational information between multiple filing transmission types; performing semantic encoding on the data transmission information to obtain a semantic embedding vector of the data transmission information, where the semantic embedding vector is used to indicate the semantic information of the data transmission information; performing feature fusion based on the filing attribute graph and the semantic embedding vector to obtain a target fusion vector; and obtaining the compliance assessment result based on the target fusion vector and the trained compliance assessment model.

[0010] In one possible design, the filing attribute graph includes: node data and edge data. The node data includes: a node set of the filing transmission type and a node attribute set of the filing transmission type. The edge data includes: an edge set corresponding to the node set and an edge attribute set. The edge set is used to indicate the operational relationship between nodes in the node set. The edge attribute set includes: operation type data and weight data of the node set. The operation type data is used to indicate the operation type between multiple filing transmission types. Graph-structured processing of the filing transmission information is performed to obtain a filing attribute graph of the filing transmission information, including: graph-structured processing of the filing transmission information based on a preset weight strategy to obtain node data and edge data. The preset weight strategy is used to determine the degree of influence of the filing transmission type on the compliance of the transmission behavior.

[0011] In one possible design, the trained compliance assessment model includes: an aggregation layer, a fully connected layer, and an output layer. The aggregation layer is used to determine the difference between the actual transmission behavior and the registered transmission type, and the output layer is used to determine whether the actual transmission behavior is compliant. Based on the target fusion vector and the trained compliance assessment model, a compliance assessment result is obtained, including: pooling the target fusion vector through the aggregation layer to obtain global feature data, and the global feature data is used to indicate the difference between the actual transmission behavior and the registered transmission behavior. Linearly transforming the global feature data through the fully connected layer to obtain a risk feature result, and the risk feature result is used to indicate the risk level of the actual transmission behavior. Data mapping of the risk feature result is performed through the output layer to obtain a compliance probability result, and the compliance probability result is used to indicate the probability that the actual transmission behavior is compliant. Based on the compliance probability result, a compliance assessment result is obtained through the output layer.

[0012] In one possible design, a compliance assessment result is obtained based on the compliance probability result, including: if the compliance probability result is greater than or equal to a preset compliance probability threshold, determining the compliance assessment result as the actual transmission behavior is compliant; if the compliance probability result is less than the preset compliance probability threshold, determining the compliance assessment result as the actual transmission behavior is non-compliant.

[0013] In a second aspect, the present application provides a transmission behavior evaluation device, which includes an acquisition module and a processing module.

[0014] The acquisition module is used to obtain the registered transmission information and data transmission information. The registered transmission information is used to indicate the registered transmission behavior of the data sender to send the data to be transmitted to the data receiver, and the data transmission information is used to indicate the actual transmission behavior of the data sender to send the data to be transmitted to the data receiver.

[0015] The processing module is used to obtain the compliance assessment results based on the registered transmission information, data transmission information and the trained compliance assessment model. The trained compliance assessment model is used to determine the difference between the actual transmission behavior and the registered transmission behavior. The compliance assessment results are used to indicate whether the actual transmission behavior is compliant.

[0016] In one possible design, the filing transmission information includes at least two of the following filing transmission types: filing data type, filing data quantity, filing data size, filing recipient information, filing sender information, filing data transmission protocol, filing data transmission method, filing data transmission time, filing transmission purpose, and filing data protection strategy.

[0017] In one possible design, the processing module is configured to perform graph-structured processing on the filing transmission information to obtain a filing attribute graph of the filing transmission information. The filing attribute graph is used to indicate operational information between multiple filing transmission types. The processing module is also configured to perform semantic encoding based on the data transmission information to obtain a semantic embedding vector of the data transmission information. The semantic embedding vector is used to indicate the semantic information of the data transmission information. The processing module is also configured to perform feature fusion based on the filing attribute graph and the semantic embedding vector to obtain a target fusion vector. The processing module is also configured to obtain a compliance assessment result based on the target fusion vector and a trained compliance assessment model.

[0018] In one possible design, the filing attribute graph includes: node data and edge data. The node data includes: a node set of the filing transmission type and a node attribute set of the filing transmission type. The edge data includes: an edge set corresponding to the node set and an edge attribute set. The edge set is used to indicate the operational relationship between nodes in the node set. The edge attribute set includes: operation type data and weight data of the node set. The operation type data is used to indicate the operation type between multiple filing transmission types. The processing module is used to perform graph-structured processing on the filing transmission information based on a preset weight strategy to obtain node data and edge data. The preset weight strategy is used to determine the degree of influence of the filing transmission type on the compliance of the transmission behavior.

[0019] In one possible design, the trained compliance assessment model includes: an aggregation layer, a fully connected layer, and an output layer. The aggregation layer is used to determine the difference between the actual transmission behavior and the registered transmission type, and the output layer is used to determine whether the actual transmission behavior is compliant. The processing module is used to perform pooling processing on the target fusion vector through the aggregation layer to obtain global feature data. The global feature data is used to indicate the difference between the actual transmission behavior and the registered transmission behavior. The processing module is also used to perform linear transformation on the global feature data through the fully connected layer to obtain a risk feature result. The risk feature result is used to indicate the risk level of the actual transmission behavior. The processing module is also used to perform data mapping on the risk feature result through the output layer to obtain a compliance probability result. The compliance probability result is used to indicate the probability that the actual transmission behavior is compliant. The processing module is also used to obtain a compliance assessment result based on the compliance probability result through the output layer.

[0020] In one possible design, the processing module is configured to determine that the compliance assessment result indicates that the actual transmission behavior is compliant if the compliance probability result is greater than or equal to a preset compliance probability threshold. The processing module is further configured to determine that the compliance assessment result indicates that the actual transmission behavior is noncompliant if the compliance probability result is less than the preset compliance probability threshold.

[0021] In a third aspect, the present application provides a device for evaluating transmission behavior, the device comprising: a processor and a memory; the processor and the memory are coupled; the memory is used to store one or more programs, the one or more programs comprising computer-executable instructions, and when the device for evaluating transmission behavior is running, the processor executes the computer-executable instructions stored in the memory to implement the method described in the first aspect and any possible implementation of the first aspect.

[0022] In a fourth aspect, the present application provides a computer-readable storage medium, which stores instructions. When the instructions are executed on a computer, the computer executes the method described in the above-mentioned first aspect and any possible implementation of the first aspect.

[0023] In a fifth aspect, the present application provides a chip, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run a computer program or instructions to implement the method described in the first aspect and any possible implementation of the first aspect.

[0024] In a sixth aspect, the present application provides a computer program product comprising instructions, which, when executed by a computer, enables the computer to execute the method described in the above-mentioned first aspect and any possible implementation of the first aspect.

[0025] In the above scheme, the technical problems that can be solved and the technical effects achieved by the transmission behavior evaluation device, computer equipment, computer storage medium, chip or computer program product can be referred to the technical problems and technical effects solved by the above first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 A flow chart of a method for evaluating transmission behavior provided in an embodiment of the present application;

[0027] Figure 2 A flowchart of another transmission behavior evaluation method provided in an embodiment of the present application;

[0028] Figure 3 This is a schematic diagram of an example of a transmission behavior evaluation method provided in an embodiment of the present application;

[0029] Figure 4 A schematic diagram of the structure of a transmission behavior evaluation device provided in an embodiment of the present application;

[0030] Figure 5 A schematic structural diagram of another transmission behavior evaluation device provided in an embodiment of the present application;

[0031] Figure 6 A conceptual partial view of a computer program product provided in an embodiment of the present application. DETAILED DESCRIPTION

[0032] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0033] The terms “first” and “second” in the description and claims of the present application are used to distinguish different objects rather than to describe a specific order of the objects.

[0034] Furthermore, the terms "including," "having," and any variations thereof, as used in the description of this application are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or modules is not limited to the listed steps or modules, but may optionally include other steps or modules not listed, or may optionally include other steps or modules inherent to the process, method, product, or apparatus.

[0035] Additionally, in the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present concepts in a concrete manner.

[0036] With the deepening of globalization, the demand for cross-border data flows is increasing. Consequently, many regions have enacted cross-border data compliance rules, requiring companies to register data before transferring it to recipients to ensure compliance with regulations.

[0037] However, during data transmission, the actual transmission behavior of an enterprise may be inconsistent with the recorded transmission behavior. If an enterprise leaks important or sensitive data to the recipient, it may harm the development of the industry.

[0038] Therefore, in order to reduce the risk of data outflow and determine whether the company's transmission behavior is compliant during the data transmission process, it is necessary to evaluate the company's actual transmission behavior.

[0039] In order to solve the above technical problems, an embodiment of the present application provides a method for evaluating transmission behavior. In this method, the registered transmission information and data transmission information can be obtained, and the compliance assessment result can be obtained based on the registered transmission information, the data transmission information and the trained compliance assessment model. In this way, by determining whether the actual transmission behavior of the data sender sending the data to be transmitted to the data recipient is consistent with the registered transmission behavior recorded in the registered transmission information, it can be determined whether the behavior of the data sender sending the data to be transmitted to the data recipient is compliant. In this way, non-compliant data transmission behaviors can be intercepted to avoid data leakage and ensure the security of data transmission.

[0040] The embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0041] like Figure 1 As shown, a transmission behavior evaluation method provided by an embodiment of the present application includes:

[0042] S101. Obtain filing transmission information and data transmission information.

[0043] Among them, the registered transmission information is used to indicate the registered transmission behavior of the data sender sending the data to be transmitted to the data receiver, and the data transmission information is used to indicate the actual transmission behavior of the data sender sending the data to be transmitted to the data receiver.

[0044] Optionally, the filing transmission information includes at least two of the following filing transmission types: filing data type, filing data quantity, filing data size, filing recipient information, filing sender information, filing data transmission protocol, filing data transmission method, filing data transmission time, filing transmission purpose, and filing data protection strategy.

[0045] It can be understood that filed transmission information is data that needs to be filed in advance before the data sender sends the data to the data recipient. This filed transmission information can be used to determine the type, quantity, and size of the data sent to the data recipient; the transmission protocol, transmission method, and transmission time used by the data sender; and the purpose of the data transmission and the data protection strategy adopted by the data sender. This allows for the determination of the compliance of the data sent by the data sender to the data recipient.

[0046] It should be noted that the filing transmission information is structured data, and the data transmission information is unstructured data.

[0047] For example, the data transmission information may be log data during the process of the data sender sending the data to be transmitted to the data receiver. For example, the log data may be a data transmission log or a database operation log.

[0048] Optionally, the log data includes: actual data transmission time, actual data sender information, actual data receiver information, actual data transmission protocol, actual data transmission method, and actual data content.

[0049] Exemplarily, the actual data transmission time is a transmission timestamp, i.e., the data transmission date. The actual data sender information includes: the Internet Protocol (IP) address of the actual data sender, the host name of the actual data sender, and the port number of the actual data sender. The actual data receiver information includes: the IP address of the actual data receiver, the host name of the actual data receiver, and the port number of the actual data receiver. The actual data transmission protocol can be Hypertext Transfer Protocol (HTTP), File Transfer Protocol (FTP), Secure File Transfer Protocol (SFTP), or Simple Mail Transfer Protocol (SMTP). The actual data transmission method can be Application Programming Interface (API) call, file transfer, or database synchronization. The actual data content includes: actual data quantity, actual data type, and actual data payload.

[0050] S102. Obtain compliance assessment results based on the registered transmission information, data transmission information, and the trained compliance assessment model.

[0051] Among them, the trained compliance assessment model is used to determine the consistency between the actual transmission behavior and the registered transmission behavior, and the compliance assessment result is used to indicate whether the actual transmission behavior of the data sender is compliant.

[0052] Optionally, the trained compliance assessment model can be obtained in the following manner: the compliance assessment model, historical filing transmission information, and historical data transmission information can be obtained. Subsequently, the historical data transmission information can be extracted based on preset extraction rules to obtain first extracted data and second remaining data, where the first extracted data is data converted into structured fields, and the second remaining data is data not converted into structured fields. Subsequently, the second remaining data can be semantically encoded to obtain a historical embedding vector for the historical data transmission information. Subsequently, the first extracted data and the historical embedding vector can be concatenated to obtain a concatenated data transmission vector. Subsequently, the historical filing transmission information can be graph-constructed to obtain a historical graph structure for the historical filing transmission information. Subsequently, the historical graph structure and the concatenated data transmission vector can be feature-fused to obtain a historical fusion vector. Subsequently, the compliance assessment model can be trained based on the historical fusion vector to obtain a trained compliance assessment model.

[0053] It should be noted that in the process of training the compliance assessment model based on the historical fusion vector, the distribution difference between the actual transmission behavior and the registered transmission behavior can be measured by the binary cross-entropy loss function in the compliance assessment model, and the update step size of each parameter in the compliance assessment model can be dynamically adjusted based on the adaptive moment estimation (Adam) optimization algorithm to obtain the trained compliance assessment model.

[0054] In this way, the trained model can be used to detect new logs and identify abnormal behaviors that are inconsistent with the recorded information.

[0055] It should be noted that this application does not limit the preset extraction rules. For example, the preset extraction rules can be regular expressions.

[0056] For example, the historical data transmission information is historical transmission log data. Afterwards, the historical transmission log data can be extracted based on a regular expression to obtain the data receiver, data name, and data sender.

[0057] It should be noted that this application does not limit the compliance assessment model. For example, the compliance assessment model can be a convolutional neural network model or a graph neural network model (GNN).

[0058] It should be understood that the GNN model is a deep neural network model that can handle machine learning tasks for graph-structured data. Traditional deep neural network models are mainly used to process regularly structured data, such as vector data or sequence data. However, the GNN model can process graph-structured data based on preset message passing rules and preset aggregation rules. This allows each node in the graph structure data to be updated based on its own information and that of its neighboring nodes, capturing the complex structural information in the graph structure data. This allows for multiple functions such as vertex classification, graph classification, and connection estimation.

[0059] For example, the GNN model can propagate information through a layered approach. At each level of the GNN model, a node can obtain information about its immediate neighbors and their neighbors' neighbors. The node can then perform weighted aggregation based on this information to update its own information.

[0060] In other words, after inputting graph structure data into the GNN model, the graph structure data can be processed by the GNN layer to obtain a graph with updated node attributes. After that, the graph with updated node attributes is processed by the fully connected layer to obtain the output results for classification or prediction.

[0061] The following introduces this application using the GNN model as an example of a compliance assessment model.

[0062] It should be noted that there are no restrictions on GNN models. For example, GNN models can be Graph Convolutional Network (GCN), Graph Attention Network (GAT), Graph Autoencoder (GAE), or Graph Generative Adversarial Network (GAN). You can choose the appropriate GNN model based on deployment conditions or actual needs.

[0063] In one possible implementation, data preprocessing can be performed on the filing transmission information and the data transmission information to obtain preprocessed model input data. The model input data can then be input into the trained GNN model to obtain the compliance assessment results.

[0064] In this way, by comparing and analyzing the consistency between the log data of the data to be transmitted from the data sender to the data receiver and the registered transmission information through the trained compliance assessment model, it is possible to determine whether each enterprise data outbound transfer is compliant, and detect whether there are any behaviors that do not meet the compliance rules, helping to identify potential enterprise data outbound transfer violations, and thus effectively preventing the occurrence of events that endanger the development of the industry.

[0065] Based on the above technical solution, it is possible to obtain registered transmission information and data transmission information, and to obtain a compliance assessment result based on the registered transmission information, data transmission information, and the trained compliance assessment model. In this way, by determining whether the actual transmission behavior of the data sender to the data recipient is consistent with the registered transmission behavior recorded in the registered transmission information, it is possible to determine whether the data sender's behavior in sending the data to the data recipient is compliant. This allows for interception of non-compliant data transmission behavior, preventing data leakage and ensuring the security of data transmission.

[0066] like Figure 2 As shown in FIG, a transmission behavior evaluation method provided by an embodiment of the present application is provided. Figure 1 , S102 includes:

[0067] S201. Perform graph-structuring processing on the filing transmission information to obtain a filing attribute graph of the filing transmission information.

[0068] Among them, the filing attribute diagram is used to indicate the operational relationship between multiple filing transmission types.

[0069] Optionally, the filing attribute graph includes: node data and edge data, the node data includes: a node set of the filing transmission type and a node attribute set of the filing transmission type, the edge data includes: an edge set and an edge attribute set corresponding to the node set, the edge set is used to indicate the operation relationship between the nodes in the node set, the edge attribute set includes: operation type data and weight data of the node set, the operation type data is used to indicate the operation type between multiple filing transmission types.

[0070] In one possible implementation, the registered transmission information can be processed into a graph structure based on a preset weight strategy to obtain node data and edge data. The preset weight strategy is used to determine the degree of influence of the registered transmission type on the compliance of the transmission behavior.

[0071] Exemplarily, the registered attribute graph satisfies Formula 1.

[0072] G=(V,E,A V ,A E )Formula 1.

[0073] Among them, G is used to represent the record attribute graph, V is used to represent the node set of the record transmission type, E is used to represent the edge set corresponding to the node set, and A V A node attribute set used to represent the record transfer type. E Used to represent a set of edge attributes.

[0074] It should be understood that the edge attribute set is a matrix representation of additional information used to describe the edges (i.e., edges) in the graph in the graph structured data, and is used to convert the unstructured attributes of the edges into structured data for easy computer processing and analysis.

[0075] For example, the edge corresponding to the node set is Edge(u,v,t), where u is a node in the node attribute set of the registered transmission type, v is the node adjacent to u, and t is the time when the transmission occurred. The edge attribute set includes: If the edge is Edge(Data Sender 1, Data Receiver 1, 10:00), the operation type is Transfer Data, and the weight data is 0.3, then it means that Data Sender 1 transmitted data to Data Receiver 1 at 10:00, and the weight data is 0.3.

[0076] It should be noted that this application does not limit the calculation method of weight data. For example, the risk weight can be obtained by the frequency of transmission operations and the compliance of transmission behavior, and the compliance of transmission behavior can be determined based on preset compliance rules.

[0077] In this way, the weight of the registered transmission type on the compliance of the transmission behavior can be determined through a preset weight strategy, so as to more accurately determine whether the actual transmission behavior of the data sender to the data receiver to send the data to be transmitted is compliant.

[0078] S202: Perform semantic encoding based on the data transmission information to obtain a semantic embedding vector of the data transmission information.

[0079] The semantic embedding vector is used to indicate the semantic information of the data transmission information.

[0080] It should be noted that this application does not limit the semantic encoding method. For example, the semantic encoding method can be to process the data transmission information through deep context embedding. For another example, the semantic encoding method can be to process the data transmission information through Bidirectional Encoder Representations from Transformers (BERT) based on Transformer.

[0081] It should be understood that BERT's core architecture is based on a stack of multi-layer Transformer encoders. Each Transformer encoder consists of four modules: a multi-head self-attention mechanism, a residual connection module, a layer normalization module, and a feedforward neural network module. Unlike the original Transformer, BERT retains only the encoder module and generates context-aware word embeddings through pre-training tasks using a masked language model and a next sentence prediction model.

[0082] In one possible implementation, data transmission information can be input into a BERT model to obtain an initial embedding vector for the data transmission information. The initial embedding vector can then be linearly transformed using the fully connected layer of the BERT model to obtain a semantic embedding vector.

[0083] Exemplarily, the initial embedding vector satisfies Formula 2.

[0084] h [CLS] =BERT (Tokenized Log) formula 2.

[0085] Among them, h ([CLS]) It is used to represent the initial embedding vector, BERT() is used to represent the function of calling the BERT model, and Tokenized Log is used to indicate the word segmentation of data transmission information.

[0086] It should be noted that the initial embedding vector is specifically used for the semantic representation of the entire sentence / text. And, the initial embedding vector ∈ R d , R d A real number vector representing d dimensions. This application does not impose any restrictions on d. For example, d can be 768 or 1024.

[0087] Exemplarily, the semantic embedding vector satisfies Formula 3.

[0088] hlog =W c h [CLS] +b c Formula 3.

[0089] Among them, h log Used to represent the initial eigenvector, W c is the weight matrix of the initial embedding vector, b c is the bias term.

[0090] It should be noted that the initial feature vector ∈R d1 , R d1 A real number vector representing d dimensions. This application does not limit d1. For example, d can be 128 or 256.

[0091] In this way, energy consumption during the computing process can be reduced.

[0092] S203: Perform feature fusion based on the registered attribute graph and the semantic embedding vector to obtain a target fusion vector.

[0093] In one possible implementation, data transmission information can be extracted based on preset extraction rules to obtain second extracted data. Subsequently, the semantic embedding vector can be concatenated with the second extracted data to obtain an initial concatenated vector for the data transmission information. Subsequently, the node attribute set and the initial concatenated vector can be concatenated to obtain a target fused vector.

[0094] Exemplarily, the initial concatenation vector satisfies Formula 4.

[0095] h final =Concat(h log , e entity )Formula 4.

[0096] Among them, h final Used to represent the initial splicing vector, e entity It is used to represent the second extracted data, and Concat() is used to represent the vector concatenation operation.

[0097] In this way, by combining BERT's semantic understanding ability with GNN's relational reasoning ability, we can break through the limitations of traditional solutions that only rely on structured rules or a single modality.

[0098] Optionally, a calculation may be performed based on the node attribute set and the initial concatenation vector to obtain an attention weight. Subsequently, a weighted summation of the node attribute set and the initial concatenation vector may be performed based on the attention weight to obtain a target fusion vector.

[0099] For example, the attention weight satisfies Formula 5.

[0100] α=σ(Wa [h final ;h attr ]+b a )Formula 5.

[0101] Among them, α is used to represent the attention weight, σ is used to represent the activation function, and W a The weight matrix used to represent the attention weight, h attr Used to represent a node attribute set, b a A bias term used to represent the attention weights.

[0102] Exemplarily, the composite vector satisfies Formula 6.

[0103] h fused =αh final +(1-α)h attr Formula 6.

[0104] Among them, h fused Used to represent the target fusion vector.

[0105] It can be understood that the attention mechanism can adaptively fuse the structured node feature matrix and the unstructured semantic embedding vector, and splice the filing transmission information with the data transmission information through the attention mechanism. The weight matrix of the attention weight and the bias item of the attention weight can be used to autonomously adjust the importance of the node feature matrix and the semantic embedding vector according to the data characteristics, thereby improving the flexibility of feature representation.

[0106] S204. Obtain a compliance assessment result based on the target fusion vector and the trained compliance assessment model.

[0107] It should be noted that non-compliant transmission behaviors include: the actual data type is inconsistent with the registered data type, the actual data quantity is inconsistent with the registered data quantity, the actual data recipient information is inconsistent with the registered recipient information, and the actual data transmission protocol is inconsistent with the registered data transmission protocol.

[0108] It should be understood that if the actual data type is inconsistent with the registered data type, or the actual data quantity is inconsistent with the registered data quantity (that is, the actual data transmission volume is inconsistent with the registered data transmission volume), or the actual data recipient information is inconsistent with the registered recipient information, or the actual data transmission agreement is inconsistent with the registered data transmission agreement, it means that the company may have engaged in non-compliant behaviors such as concealing data and sending it abroad without declaring data.

[0109] In an embodiment of the present application, the trained compliance assessment model includes: an aggregation layer, a fully connected layer, and an output layer. The aggregation layer is used to determine the difference between the actual transmission behavior and the registered transmission type, and the output layer is used to determine whether the actual transmission behavior is compliant.

[0110] In one possible implementation, the target fusion vector can be pooled using an aggregation layer to generate global feature data. This global feature data indicates the difference between actual transmission behavior and the recorded transmission behavior. Subsequently, a fully connected layer can be used to perform a linear transformation on this global feature data to generate a risk feature result. This risk feature result indicates the risk level of the actual transmission behavior. The output layer can then perform data mapping on this risk feature result to generate a compliance probability result. This compliance probability result indicates the probability that the actual transmission behavior is compliant. The output layer can then generate a compliance assessment result based on the compliance probability result.

[0111] Optionally, the output layer includes: an activation function and a preset compliance probability threshold. The target fusion vector includes: a plurality of fusion nodes.

[0112] This application does not restrict the activation function in the compliance assessment model. For example, the activation function can be a Sigmoid function or a Softmax function.

[0113] For example, a Sigmoid function may be used to map the anomaly score vector to a probability value between 0 and 1, thereby obtaining a compliance probability result.

[0114] Optionally, the aggregation layer can be used to pool the node set of the registered transmission type, multiple fusion nodes, the edge set corresponding to the set, and the edge attribute set to obtain an updated node fusion feature matrix, and the updated node fusion feature matrix is ​​the global feature data. Afterwards, the global feature data can be linearly transformed through the fully connected layer to obtain an anomaly score vector, which is used to indicate the degree of deviation between the characteristics of the registered transmission information and the characteristics of the data transmission information in the fusion node. Afterwards, the fully connected layer can be used to obtain the risk feature result based on the anomaly score vector. Afterwards, the intermediate feature vector can be data mapped through the activation function of the output layer to obtain the compliance probability result. Afterwards, the output layer can be used to obtain the compliance assessment result based on the preset compliance probability threshold and the compliance probability result.

[0115] It should be noted that the features of each fused node in the updated fused node include both its own features and the features of the adjacent fused nodes.

[0116] In this way, the difference between the registered transmission information and the data transmission information can be determined through the aggregation layer, fully connected layer and output layer of the trained compliance assessment model, so as to determine whether the actual transmission behavior of the data sender to the data receiver to send the data to be transmitted is compliant.

[0117] It should be noted that the compliance probability result can be converted into a binary classification result by presetting the compliance probability threshold to determine whether the actual transmission behavior is compliant.

[0118] Specifically, if the compliance probability result is greater than or equal to a preset compliance probability threshold, the compliance assessment result may be determined to indicate that the actual transmission behavior is compliant. Subsequently, if the compliance probability result is less than the preset compliance probability threshold, the compliance assessment result may be determined to indicate that the actual transmission behavior is non-compliant.

[0119] In this way, if the probability of the actual transmission behavior being compliant is low, it can be determined that the actual transmission behavior of the data sender sending the data to be transmitted to the data receiver is not compliant. If the probability of the actual transmission behavior being compliant is high, it can be determined that the actual transmission behavior of the data sender sending the data to be transmitted to the data receiver is compliant.

[0120] Based on the above technical solution, by graph-structuring the registered transmission information, a graph structure of the registered transmission information, namely the registered attribute graph, can be obtained. Because graph structures can capture explicit relationships between entities, the registered attribute graph can capture the topological relationships and hierarchical dependencies between multiple registered transmission types in the registered transmission information, thereby more accurately modeling the rule logic of the registered attribute graph. Subsequently, by performing semantic encoding based on the data transmission information, a semantic embedding vector of the data transmission information can be obtained, capturing the implicit semantics in the data transmission information, thereby enabling the model to more accurately identify the data sender's intent to send data. Feature fusion can then be performed based on the registered attribute graph and the semantic embedding vector to obtain a target fusion vector. The compliance assessment results are then obtained based on the target fusion vector and the trained compliance assessment model. This allows the registered transmission behavior and actual transmission behavior to be aggregated to determine the degree of semantic match between the registered transmission behavior and the actual transmission behavior. If the actual transmission behavior contains implicit intent, the trained compliance assessment model can quickly locate anomalies and determine whether the actual transmission behavior is compliant.

[0121] In some embodiments, updated filing transmission information may be obtained. Subsequently, data processing may be performed on the updated filing transmission information and the trained compliance assessment model based on an incremental learning method to obtain a retrained compliance assessment model.

[0122] It should be noted that the incremental learning method is: whenever new data is added, it is not necessary to rebuild the entire knowledge base. Instead, based on the original knowledge base, only the changes caused by the new data are updated.

[0123] It should be understood that after the filing transmission information is updated, the updated filing information can be used as new training data through incremental learning methods to dynamically adjust the parameters of the filing attribute graph and the compliance assessment model, and update the node feature matrix and adjacency matrix to retrain the compliance assessment model to adapt to the new compliance requirements.

[0124] In some embodiments, updated data transmission information may be obtained, and then the target fusion vector may be updated based on the updated data transmission information to obtain an updated target fusion vector.

[0125] It should be noted that after the data transmission information is updated, the existing graph structure will be updated and the feature timeliness will be refreshed.

[0126] Exemplarily, if the entity node of the registered attribute graph includes the entity node in the updated data transmission information, the target fusion vector is updated. If the entity node of the registered attribute graph does not include the entity node in the updated data transmission information, a new entity node is created.

[0127] For example, based on the operation type (e.g., "access"), edges can be created between the data receiver and the data sender, and between the data sender and the data transmission protocol. The weights of the edges between the data receiver and the data sender can then be adjusted using a time decay factor to obtain updated edge weights. A temporal supernode can then be introduced and edges established with all entity nodes.

[0128] Exemplarily, the updated edge weight satisfies Formula 7.

[0129] w t =w t0 ×e -λ(t-t0) Formula 7.

[0130] Among them, w t Used to represent the updated edge weight, w t0 It is used to represent the weight of the edge between the data receiver and the data sender, and λ is used to represent the time decay factor.

[0131] In this way, the impact of historical edges can be reduced, alleviating the problem of traditional GNN ignoring temporal dynamics.

[0132] In some embodiments, Gaussian noise may be added to the target fusion vector to obtain a noisy target fusion vector. The noisy target fusion vector may then be input into a trained compliance assessment model to obtain a compliance assessment result.

[0133] Exemplarily, the target fusion vector after noise satisfies Formula 8.

[0134] h noisy =h fused +N(0,σ 2 I) Formula 8.

[0135] Among them, h noisy Used to represent the target fusion vector after noise, N(0,σ 2 I) is used to represent a random noise matrix that follows a normal distribution.

[0136] In this way, data privacy protection can be achieved.

[0137] The following describes the embodiments of the present application with reference to specific examples. Figure 3 As shown, data transmission information can be input into the BERT model to obtain a semantic embedding vector. Simultaneously, the record transmission information can be structured into a graph to obtain a record attribute graph. Feature fusion can then be performed based on the semantic embedding vector and the record attribute graph to obtain a target fusion vector. This target fusion vector can then be input into the trained compliance assessment model to obtain the compliance assessment result.

[0138] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the method. It can be understood that in order to realize the above functions, the evaluation device of the transmission behavior includes a hardware structure and / or software module corresponding to the execution of each function. Those skilled in the art should easily realize that, in combination with the steps of the evaluation method of the transmission behavior of each example described in the embodiment disclosed in this application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0139] The present application also provides a transmission behavior evaluation device, which can be a server, a CPU in the server, a module for evaluating data in the mobile terminal, or a client in the server.

[0140] In the embodiment of the present application, the transmission behavior evaluation device can be divided into functional modules or functional units according to the above method example. For example, each functional module or functional unit can be divided according to each function, or two or more functions can be integrated into one processing module. The above-mentioned integrated module can be implemented in the form of hardware or in the form of software functional modules or functional units. Among them, the division of modules or units in the embodiment of the present application is schematic and is only a logical functional division. There may be other division methods in actual implementation.

[0141] The embodiment of the present application provides a transmission behavior evaluation device. Figure 4 As shown, the transmission behavior evaluation device may include: an acquisition module 401 and a processing module 402.

[0142] The acquisition module 401 is used to obtain the registered transmission information and the data transmission information. The registered transmission information is used to indicate the registered transmission behavior of the data sender to send the data to be transmitted to the data receiver, and the data transmission information is used to indicate the actual transmission behavior of the data sender to send the data to be transmitted to the data receiver.

[0143] Processing module 402 is used to obtain a compliance assessment result based on the registered transmission information, data transmission information and the trained compliance assessment model. The trained compliance assessment model is used to determine the difference between the actual transmission behavior and the registered transmission behavior. The compliance assessment result is used to indicate whether the actual transmission behavior is compliant.

[0144] Figure 5 1 is a schematic diagram of another transmission behavior evaluation device according to an exemplary embodiment. The transmission behavior evaluation device may include a processor 502, which is configured to execute application code to implement the transmission behavior evaluation method of the present application.

[0145] The processor 502 may be a central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.

[0146] like Figure 5 As shown, the transmission behavior evaluation device may further include a memory 503. The memory 503 is used to store application code for executing the solution of the present application, and the execution is controlled by the processor 502.

[0147] The memory 503 may be a read-only memory (ROM) or other static storage device capable of storing static information and instructions, a random access memory (RAM) or other dynamic storage device capable of storing information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and capable of being accessed by a computer, but is not limited thereto. The memory 503 may be independent and connected to the processor 502 via a bus 504. The memory 503 may also be integrated with the processor 502.

[0148] like Figure 5 As shown, the transmission behavior evaluation apparatus may further include a communication interface 501, wherein the communication interface 501, the processor 502, and the memory 503 may be coupled to each other, for example, via a bus 504. The communication interface 501 is used to exchange information with other devices, for example, to support information exchange between the transmission behavior evaluation apparatus and other devices.

[0149] It should be pointed out that Figure 5 The device structure shown in the figure does not constitute a limitation on the evaluation device of the transmission behavior, except Figure 5 In addition to the components shown, the device for evaluating the transmission behavior may include more or fewer components than shown, or a combination of certain components or a different arrangement of the components.

[0150] In actual implementation, the functions implemented by the processing module 402 can be Figure 5 The processor 502 shown calls the program code in the memory 503 to implement it.

[0151] The present application also provides a computer-readable storage medium having instructions stored thereon. When the instructions in the computer-readable storage medium are executed by a processor of a computer device, the computer is enabled to perform the transmission behavior evaluation method provided in the above-described embodiment. For example, the computer-readable storage medium may be a memory 503 including instructions, and the instructions may be executed by the processor 502 of the computer device to perform the above-described method. Alternatively, the computer-readable storage medium may be a non-transitory computer-readable storage medium, for example, a ROM, RAM, CD-ROM, magnetic tape, floppy disk, or optical data storage device.

[0152] Figure 6 A conceptual partial view of a computer program product provided by an embodiment of the present application is schematically shown. The computer program product includes a computer program for executing a computer process on a computing device.

[0153] In one embodiment, the computer program product is provided using a signal bearing medium 600. The signal bearing medium 600 may include one or more program instructions that, when executed by one or more processors, may provide the above-described Figure 1 、 Figure 2 Thus, for example, reference to Figure 1 In the embodiment shown in , one or more features of S101 to S102 may be undertaken by one or more instructions associated with the signal bearing medium 600. In addition, Figure 6 The program instructions in also describe example instructions.

[0154] In some examples, the signal-bearing medium 600 may include a computer-readable medium 601, such as, but not limited to, a hard drive, a compact disk (CD), a digital video disk (DVD), a digital tape, a memory, a read-only memory (ROM), or a random access memory (RAM), and the like.

[0155] In some implementations, signal bearing medium 600 may include computer recordable medium 602 such as, but not limited to, memory, read / write (R / W) CD, R / W DVD, or the like.

[0156] In some embodiments, signal bearing medium 600 may include communication medium 603 such as, but not limited to, digital and / or analog communication media (eg, fiber optic cables, waveguides, wired communication links, wireless communication links, etc.).

[0157] The signal bearing medium 600 may be conveyed by a wireless form of communication medium 603. The one or more program instructions may be, for example, computer executable instructions or logic implemented instructions.

[0158] In some examples, the transmission behavior evaluation device can be configured to provide various operations, functions, or actions in response to one or more program instructions in the computer-readable medium 601 , the computer-recordable medium 602 , and / or the communication medium 603 .

[0159] Through the description of the above implementation methods, technical personnel in the relevant field can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete the full classification or partial functions described above.

[0160] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0161] The units described as separate components may or may not be physically separate, and the components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple different places. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.

[0162] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0163] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or the full classification part or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions to enable a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to execute the full classification part or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk or an optical disk.

[0164] The above are only specific embodiments of the present application, but the scope of protection of the present application is not limited thereto. Any changes or replacements within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A method for evaluating transmission behavior, characterized in that: The method comprises: Obtaining record transmission information and data transmission information, wherein the record transmission information is used to indicate the record transmission behavior of the data sender sending the data to be transmitted to the data receiver, and the data transmission information is used to indicate the actual transmission behavior of the data sender sending the data to be transmitted to the data receiver; Based on the registered transmission information, the data transmission information and the trained compliance assessment model, a compliance assessment result is obtained. The trained compliance assessment model is used to determine the difference between the actual transmission behavior and the registered transmission behavior. The compliance assessment result is used to indicate whether the actual transmission behavior is compliant.

2. The method according to claim 1, characterized in that The filing transmission information includes at least two of the following filing transmission types: filing data type, filing data quantity, filing data size, filing recipient information, filing sender information, filing data transmission protocol, filing data transmission method, filing data transmission time, filing transmission purpose, and filing data protection strategy.

3. The method according to claim 2, characterized in that Obtaining a compliance assessment result based on the filing transmission information, the data transmission information, and the trained compliance assessment model includes: Performing graph-structuring processing on the filing transmission information to obtain a filing attribute graph of the filing transmission information, wherein the filing attribute graph is used to indicate operation information between multiple filing transmission types; Performing semantic encoding based on the data transmission information to obtain a semantic embedding vector of the data transmission information, wherein the semantic embedding vector is used to indicate semantic information of the data transmission information; Perform feature fusion based on the registered attribute graph and the semantic embedding vector to obtain a target fusion vector; The compliance assessment result is obtained based on the target fusion vector and the trained compliance assessment model.

4. The method according to claim 3, characterized in that The filing attribute graph includes: node data and edge data, the node data includes: a node set of the filing transmission type and a node attribute set of the filing transmission type, the edge data includes: an edge set and an edge attribute set corresponding to the node set, the edge set is used to indicate the operation relationship between the nodes in the node set, the edge attribute set includes: operation type data and weight data of the node set, the operation type data is used to indicate the operation type between multiple filing transmission types; The graph-structuring processing of the filing transmission information to obtain a filing attribute graph of the filing transmission information includes: The registered transmission information is graph-structured based on a preset weight strategy to obtain the node data and the edge data. The preset weight strategy is used to determine the degree of influence of the registered transmission type on the compliance of the transmission behavior.

5. The method according to claim 3 or 4, characterized in that The trained compliance assessment model includes: an aggregation layer, a fully connected layer, and an output layer. The aggregation layer is used to determine the difference between the actual transmission behavior and the registered transmission type, and the output layer is used to determine whether the actual transmission behavior is compliant. The compliance assessment result obtained based on the target fusion vector and the trained compliance assessment model includes: performing pooling processing on the target fusion vector by the aggregation layer to obtain global feature data, wherein the global feature data is used to indicate the difference between the actual transmission behavior and the recorded transmission behavior; Performing a linear transformation on the global feature data through the fully connected layer to obtain a risk feature result, wherein the risk feature result is used to indicate the risk level of the actual transmission behavior; Performing data mapping on the risk feature result through the output layer to obtain a compliance probability result, wherein the compliance probability result is used to indicate the probability that the actual transmission behavior is compliant; The compliance assessment result is obtained through the output layer based on the compliance probability result.

6. The method according to claim 5, characterized in that Obtaining the compliance assessment result based on the compliance probability result includes: When the compliance probability result is greater than or equal to a preset compliance probability threshold, determining that the compliance assessment result is that the actual transmission behavior is compliant; When the compliance probability result is less than the preset compliance probability threshold, it is determined that the compliance assessment result is that the actual transmission behavior is non-compliant.

7. A transmission behavior evaluation device, characterized in that The device includes an acquisition module and a processing module: The acquisition module is used to acquire record transmission information and data transmission information, wherein the record transmission information is used to indicate the record transmission behavior of the data sender sending the data to be transmitted to the data receiver, and the data transmission information is used to indicate the actual transmission behavior of the data sender sending the data to be transmitted to the data receiver; The processing module is used to obtain a compliance assessment result based on the registered transmission information, the data transmission information and the trained compliance assessment model. The trained compliance assessment model is used to determine the difference between the actual transmission behavior and the registered transmission behavior. The compliance assessment result is used to indicate whether the actual transmission behavior is compliant.

8. A transmission behavior evaluation device, characterized in that include: processor and memory; The processor is coupled to the memory; The memory is used to store one or more programs, and one or more of the programs include computer-executable instructions. When the transmission behavior evaluation device is running, the processor executes the computer-executable instructions stored in the memory to enable the transmission behavior evaluation device to perform the method as described in any one of claims 1 to 6.

9. A computer-readable storage medium storing instructions, characterized in that: When a computer executes the instruction, the computer performs the method according to any one of claims 1 to 6.

10. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device, the computing device is caused to perform the method according to any one of claims 1 to 6.