Anti-divulging method and device for terminal geoscience literature data, storage medium and equipment

By using a dynamic risk assessment model to evaluate operational risks in real time and determine security mechanisms, the problem of insufficient flexibility in traditional methods for preventing geological literature data leakage is solved, and more efficient security protection and data protection are achieved.

CN120654246AActive Publication Date: 2025-09-16CHINA GEOLOGICAL LIBRARY (GEOLOGICAL LITERATURE CENT OF CHINA GEOLOGICAL SURVEY)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510553683.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-09-16
Estimated Expiration
2045-04-29

AI Technical Summary

Technical Problem

Traditional methods for preventing geological literature data from being leaked lack flexibility and are unable to cope with complex and changing operational scenarios and potential security threats. In particular, static strategies are difficult to effectively protect against unintentional leaks or malicious attacks by insiders.

Method used

A dynamic risk assessment model is used to comprehensively consider factors such as operation indicator parameters and terminal geoscience literature data itself to evaluate operation risks in real time, and determine the corresponding security mechanism based on the risk level, including logging, encryption processing, and alarm notification measures.

Benefits of technology

It improves the flexibility and accuracy of security protection, effectively preventing the leakage of terminal geological literature data without affecting the efficiency of normal business operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120654246A_ABST
    Figure CN120654246A_ABST
Patent Text Reader

Abstract

The invention discloses an anti-leakage method and device for terminal geoscience literature data, a storage medium and computer equipment, and the method comprises the steps: responding to an operation instruction for the terminal geoscience literature data, and calling a dynamic risk assessment model, the operation instruction being a reading instruction or a writing instruction; obtaining a target operation behavior associated with the operation instruction, determining an operation index parameter according to the target operation behavior, and calculating an operation risk level corresponding to the terminal geoscience literature data through a dynamic risk assessment model based on the operation index parameter and the terminal geoscience literature data; and based on the operation risk level, determining a security mechanism corresponding to the terminal geoscience literature data, and generating an operation result corresponding to the operation instruction according to the security mechanism. The operation risk can be evaluated in real time according to the actual operation condition, the flexibility and accuracy of safety protection are improved, the operation risk can be evaluated more comprehensively, and terminal geoscience literature data leakage is effectively prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to a method and device for preventing leakage of terminal geological literature data, a storage medium, and a computer device. Background Art

[0002] Earth science literature is a vital achievement of Earth science research, and its data constitutes a crucial component of national data resource development. The development and utilization of this data is of great significance for supporting the development of Earth science disciplines, geological surveys, and natural resource management. At the same time, as a core resource, the confidentiality and security of this data are paramount. With the rapid development of information technology, the management and transmission of this data are increasingly reliant on computer terminals and network systems. However, this digitization process also carries the risk of data leakage, particularly in terminal applications. Due to improper operation or malicious attacks, sensitive Earth literature data may be illegally obtained or tampered with, posing a serious threat to national security and the interests of the public.

[0003] Traditional methods for preventing data leaks in geoscience literature often rely on static security policies, such as file encryption and access control lists (ACLs). While these methods improve data security to a certain extent, they often lack flexibility and are unable to cope with complex and changing operational scenarios and potential security threats. Static policies are particularly inadequate when faced with unintentional leaks from insiders or malicious attacks. Summary of the Invention

[0004] In view of this, the present application provides a method and device, storage medium, and computer equipment for preventing the leakage of terminal geological literature data. It adopts a dynamic risk assessment model, which can evaluate operational risks in real time according to actual operating conditions, rather than adopting fixed security strategies, thereby improving the flexibility and accuracy of security protection; by comprehensively considering factors such as operational indicator parameters and the terminal geological literature data itself, it can more comprehensively evaluate operational risks and effectively prevent the leakage of terminal geological literature data; and determine the corresponding security mechanism according to different operational risk levels, which can not only ensure the security of terminal geological literature data, but also will not affect the normal business operation efficiency.

[0005] According to one aspect of the present application, a method for preventing leakage of terminal geoscience literature data is provided, comprising:

[0006] In response to an operation instruction of the terminal on the geoscience literature data, calling the dynamic risk assessment model, wherein the operation instruction is a read instruction or a write instruction;

[0007] Obtaining a target operation behavior associated with the operation instruction, determining an operation indicator parameter according to the target operation behavior, and calculating an operation risk level corresponding to the terminal geoscience document data based on the operation indicator parameter and the terminal geoscience document data using the dynamic risk assessment model;

[0008] Based on the operation risk level, a security mechanism corresponding to the terminal geoscience literature data is determined, and an operation result corresponding to the operation instruction is generated according to the security mechanism.

[0009] According to another aspect of the present application, a device for preventing leakage of terminal geoscience document data is provided, comprising:

[0010] A model calling module, configured to call a dynamic risk assessment model in response to an operation instruction on the terminal geoscience literature data, wherein the operation instruction is a read instruction or a write instruction;

[0011] a calculation module, configured to obtain a target operation behavior associated with the operation instruction, determine an operation index parameter according to the target operation behavior, and calculate an operation risk level corresponding to the terminal geoscience literature data based on the operation index parameter and the terminal geoscience literature data using the dynamic risk assessment model;

[0012] The security mechanism determination module is used to determine the security mechanism corresponding to the terminal geoscience literature data based on the operation risk level, and generate an operation result corresponding to the operation instruction according to the security mechanism.

[0013] According to another aspect of the present application, a storage medium is provided, on which a computer program is stored. When the program is executed by a processor, the above-mentioned method for preventing leakage of terminal geological literature data is implemented.

[0014] According to another aspect of the present application, a computer device is provided, comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor implements the above-mentioned method for preventing leakage of terminal geological literature data when executing the program.

[0015] By means of the above technical solution, the present application provides a method and device for preventing leakage of terminal geological literature data, a storage medium, and a computer device. When the terminal detects a read or write operation instruction for the terminal geological literature data, the dynamic risk assessment model can be automatically called. Then, the target operation behavior associated with the operation instruction can be obtained. According to the target operation behavior, a series of operation index parameters are determined. After the operation index parameters are determined, the determined operation index parameters and the terminal geological literature data can be further input into the dynamic risk assessment model. The model can comprehensively consider these factors and calculate the operation risk level corresponding to the terminal geological literature data. Afterwards, the corresponding security mechanism is determined based on the calculated operation risk level. Finally, the operation result corresponding to the operation instruction is generated based on the determined security mechanism. The embodiment of the present application adopts a dynamic risk assessment model, which can evaluate operational risks in real time according to actual operational conditions, rather than adopting fixed security strategies, thereby improving the flexibility and accuracy of security protection; by comprehensively considering factors such as operational indicator parameters and the terminal geoscience document data itself, it can more comprehensively evaluate operational risks and effectively prevent the leakage of terminal geoscience document data; according to different operational risk levels, the corresponding security mechanism is determined, which can not only ensure the security of terminal geoscience document data, but also will not affect the normal business operation efficiency.

[0016] The above description is only an overview of the technical solution of this application. In order to more clearly understand the technical means of this application, it can be implemented in accordance with the contents of the specification. In order to make the purpose, features and advantages of this application more obvious and easy to understand, the specific implementation methods of this application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0018] Figure 1 A schematic diagram showing a flow chart of a method for preventing leakage of terminal geoscience document data provided by an embodiment of the present application is shown;

[0019] Figure 2 A schematic diagram of the structure of a terminal geoscience document data anti-leakage device provided in an embodiment of the present application is shown;

[0020] Figure 3 A schematic diagram of the device structure of a computer device provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0021] The present application will be described in detail below with reference to the accompanying drawings and in combination with embodiments. It should be noted that, unless there is a conflict, the embodiments and features in the embodiments of the present application can be combined with each other.

[0022] In this embodiment, a method for preventing leakage of terminal geoscience document data is provided, such as Figure 1 As shown, the method includes:

[0023] Step 101: In response to an operation instruction for terminal geoscience literature data, a dynamic risk assessment model is called, wherein the operation instruction is a read instruction or a write instruction.

[0024] Step 102: Obtain the target operation behavior associated with the operation instruction, determine the operation index parameter according to the target operation behavior, and calculate the operation risk level corresponding to the terminal geoscience literature data based on the operation index parameter and the terminal geoscience literature data through the dynamic risk assessment model.

[0025] Step 103: Based on the operation risk level, determine the security mechanism corresponding to the terminal geoscience literature data, and generate an operation result corresponding to the operation instruction according to the security mechanism.

[0026] A method for preventing leakage of terminal geological literature data provided in an embodiment of the present application can be applied to a terminal. When performing read or write operations on terminal geological literature data, a dynamic risk assessment model can be used to evaluate the operation risk level, and a corresponding security mechanism can be determined based on the risk level, and finally an operation result is generated to ensure the security of terminal geological literature data.

[0027] Specifically, the operator can issue various operation instructions to the terminal geological literature data through the terminal, such as read instructions or write instructions. The read instruction indicates that the operator wants to view the content of the terminal geological literature data, while the write instruction indicates that the operator wants to add or modify data to the terminal geological literature data. When the terminal geological literature data terminal detects a read or write operation instruction, the dynamic risk assessment model can be automatically called. The dynamic risk assessment model is a tool for assessing the operational risk of the terminal geological literature data, and can calculate the risk level of the operation based on the information provided subsequently. Then, the target operation behavior associated with the operation instruction can be obtained. Here, the target operation behavior can include storage operation behavior, historical operation behavior corresponding to the operation, version diffusion operation behavior, etc. Subsequently, a series of operation indicator parameters are determined based on the target operation behavior. These parameters are key factors for measuring operational risks.

[0028] After determining the operational indicator parameters, the determined operational indicator parameters and the terminal geoscience literature data can be input into a dynamic risk assessment model. This model comprehensively considers these factors and calculates the operational risk level corresponding to the terminal geoscience literature data. For example, operational risk levels can include low risk, medium risk, and high risk, representing the degree of threat the operation may pose to the security of the terminal geoscience literature data. Based on the calculated operational risk level, the corresponding security mechanism is then determined. A security mechanism is a series of measures implemented to ensure the security of terminal geoscience literature data. For example: Low risk: Only simple logging is performed, recording information such as the time, operator, and content of the operation for subsequent auditing. Medium risk: In addition to logging, encryption of the geoscience literature data on the terminal can also be performed. High risk: The operation can be directly rejected, triggering an alarm to notify security management personnel, and further investigation of the operator can be carried out.

[0029] Finally, based on the determined security mechanism, the corresponding operation result of the operation instruction is generated. For example, if the operation is allowed, the operation result may be the successful reading or writing of the terminal's geoscience literature data; if the operation is denied, the operation result may prompt the operator that the operation was unsuccessful and explain the reason.

[0030] By applying the technical solution of this embodiment, when a terminal detects an instruction to read or write terminal geoscience literature data, a dynamic risk assessment model can be automatically invoked. Next, the target operation behavior associated with the operation instruction can be obtained. Based on the target operation behavior, a series of operation indicator parameters can be determined. After the operation indicator parameters are determined, the determined operation indicator parameters and the terminal geoscience literature data can be input into the dynamic risk assessment model. The model can comprehensively consider these factors and calculate the operation risk level corresponding to the terminal geoscience literature data. Then, based on the calculated operation risk level, the corresponding security mechanism is determined. Finally, based on the determined security mechanism, the operation result corresponding to the operation instruction is generated. The embodiment of the present application adopts a dynamic risk assessment model, which can assess operation risk in real time based on actual operation conditions, rather than adopting a fixed security policy, thereby improving the flexibility and accuracy of security protection. By comprehensively considering factors such as the operation indicator parameters and the terminal geoscience literature data itself, the operation risk can be more comprehensively assessed, effectively preventing the leakage of terminal geoscience literature data. The corresponding security mechanism is determined according to different operation risk levels, which can ensure the security of terminal geoscience literature data without affecting the efficiency of normal business operations.

[0031] In an embodiment of the present application, optionally, the target operation behavior includes at least one of a storage operation behavior, a historical operation behavior corresponding to the operation instruction, and a version diffusion operation behavior; the "determining the operation indicator parameter according to the target operation behavior" in step 102 includes: determining the target storage location corresponding to the terminal geological literature data according to the storage operation behavior, wherein the operation indicator parameter includes the target storage location; and / or, generating a behavior baseline of the operation according to the historical operation behavior corresponding to the operation instruction, wherein the operation indicator parameter includes the behavior baseline of the operation; and / or, judging whether the terminal geological literature data corresponds to a newly added file copy according to the version diffusion operation behavior, and using the judgment result as the newly added copy judgment indicator parameter, wherein the operation indicator parameter includes the newly added copy judgment indicator parameter.

[0032] In this embodiment, the target operation behavior may include one or more of a storage operation behavior, a historical operation behavior corresponding to the operation instruction, and a version diffusion operation behavior.

[0033] Storage operations refer to the operator's response to storing geoscience literature data on the terminal. For example, this might involve saving geoscience literature data to a specific folder on the local disk, or to a USB flash drive (USB flash drive), a removable hard drive, or the like. This behavior, which involves the file's storage location, is crucial for assessing operational risk. Different storage locations can have different security levels. For example, sensitive areas on a local disk may be more vulnerable to physical attacks, while data stored on a USB flash drive may be more susceptible to leakage.

[0034] The historical operation behavior corresponding to an operation instruction refers to the record of operations performed by the operator corresponding to that instruction on the terminal's geoscience literature data over a period of time. For example, the operator's average daily number of read operations and average daily number of write operations within a preset time period can be analyzed. By analyzing an operator's historical operation behavior, we can understand their operating habits and use them as a benchmark for subsequent evaluations. For example, if an operator's average daily number of read operations is 10, but suddenly increases to 30 on a certain day, this may indicate abnormal behavior and increase the risk of data leakage.

[0035] Version propagation primarily involves the version management and diffusion of geoscience literature data on terminals. During the use of geoscience literature data on terminals, multiple versions of files may be generated, and these files may be disseminated across different systems or devices. When a new version of geoscience literature data is created and distributed to multiple terminals, version propagation may occur. This behavior can lead to data inconsistencies and increased security risks, as more file copies mean more potential points of leakage.

[0036] When determining operational indicator parameters based on target operational behaviors, if the target operational behaviors include storage operations, the target storage location corresponding to the terminal's geoscience literature data can be determined based on the storage operations. The target storage location refers to the actual location where the files are stored, such as the "D:\GeologyData\ImportantFiles" folder on a local disk or the " / geology / sensitive_data" directory on a network storage server. This target storage location can be used as one of the operational indicator parameters. Because different storage locations have different security characteristics, incorporating the target storage location into the operational indicator parameters allows for a more accurate assessment of operational risks.

[0037] If the target operation behavior includes historical operation behaviors corresponding to the operation instructions, an operation behavior baseline can be generated based on the historical operation behaviors. The operation behavior baseline is a statistical description of the operator's normal operation behavior, which reflects the operator's operating patterns and habits over a period of time. For example, by analyzing the operator's operation records over the past month, the average daily number of read operations and the average daily number of write operations can be calculated. The average daily number of read operations and the average daily number of write operations can then be used as the operator's operation behavior baseline. This operation behavior baseline can be used as one of the operation indicator parameters. If the current operation behavior deviates significantly from the operation behavior baseline, it may indicate abnormal operation, and the risk level will increase accordingly.

[0038] When the target operation involves version proliferation, it is possible to determine whether there are any new file copies corresponding to the terminal's geoscience literature data. This determination can be made by examining file system metadata, version control system records, and other methods. The result can be used as a new copy determination indicator parameter. This new copy determination indicator parameter reflects the version proliferation of the terminal's geoscience literature data. If the number of new file copies is large or the spread is widespread, it may indicate an increased risk of data leakage, as more copies mean more potential leak paths. Incorporating the new copy determination indicator parameter into the operational indicator parameter system will facilitate a more comprehensive assessment of operational risks.

[0039] The embodiment of the present application determines the operation indicator parameters based on the storage operation behavior, historical operation behavior and version diffusion operation behavior, which can more comprehensively and accurately evaluate the operation risk level of the terminal geological literature data.

[0040] In an embodiment of the present application, optionally, the dynamic risk assessment model includes a data content sensitivity detection submodel and a behavioral risk detection submodel; the "based on the operation index parameters and the terminal geological literature data, calculating the operation risk level corresponding to the terminal geological literature data through the dynamic risk assessment model" in step 102 includes: calculating the sensitivity index of the terminal geological literature data based on a preset database through the data content sensitivity detection submodel, wherein the preset database includes at least one of a preset keyword library, a preset symbol library and a preset geological key coordinate library; calculating the behavioral risk index corresponding to the operation index parameter through the behavioral risk detection submodel; and determining the operation risk level corresponding to the terminal geological literature data based on the sensitivity index and the behavioral risk index.

[0041] In this embodiment, the dynamic risk assessment model is primarily composed of two sub-models: a data content sensitivity detection sub-model and a behavioral risk detection sub-model. These two sub-models assess the operational risk of terminal geoscience literature data from different perspectives, ultimately yielding a comprehensive operational risk level.

[0042] Among them, the data content sensitivity detection sub-model relies on the preset database to calculate the sensitivity index of the terminal geological literature data. The preset database contains various types of information related to the sensitivity of the terminal geological literature data, such as at least one of the preset keyword library, the preset symbol library and the preset geological key coordinate library. The preset keyword library contains a series of keywords related to the geological field and with sensitivity, such as "distribution of rare metal deposits". When these keywords appear in the terminal geological literature data, it may mean that the document involves important geological resource information, and its sensitivity will increase accordingly. The preset symbol library includes symbols for specific geological structures, mineral types, etc., and also includes stratigraphic division symbols (such as "Q4 2 al”), structural line types (such as reverse fault symbols), and other geological symbols. When these symbols appear in terminal geological literature data, it may imply that the file contains important information. For example, a symbol representing a large gold mine appearing in terminal geological literature data can increase the sensitivity of the terminal geological literature data. The preset geological key coordinate library includes key coordinates related to important geological locations, such as the coordinates of large oil fields and areas prone to geological disasters. If these key coordinates are included in terminal geological literature data, it means that the file may involve sensitive geographical location information, and its sensitivity will also be affected.

[0043] The behavioral risk detection sub-model primarily calculates a behavioral risk index based on the previously determined operational indicator parameters. These include target storage location, operational behavior baseline, and new copy determination indicators. These parameters reflect various aspects of operational behavior. The behavioral risk detection sub-model comprehensively considers these operational indicator parameters to calculate a quantitative behavioral risk index. This index reflects the potential risk posed by the operational behavior to the security of terminal geoscience literature data. Higher values ​​indicate greater risk.

[0044] Finally, a comprehensive assessment can be conducted using the sensitivity indicators calculated by the data content sensitivity detection sub-model and the behavioral risk indicators calculated by the behavioral risk detection sub-model to determine the operational risk level of the terminal geoscience literature data. For example, a weighted average approach can be used to assign different weights to the sensitivity indicators and behavioral risk indicators based on their importance. A comprehensive risk score can then be calculated. Based on this comprehensive risk score, the operational risk of the terminal geoscience literature data can be categorized into different levels, such as low risk, medium risk, and high risk. The specific categorization criteria can be set based on actual needs. For example, a comprehensive risk score within a certain range could be considered low risk, within another range could be considered medium risk, and above a certain threshold could be considered high risk.

[0045] This embodiment of the application utilizes a data content sensitivity detection sub-model and a behavioral risk detection sub-model to assess operational risk from two dimensions: data content and operational behavior. This allows for a more comprehensive and accurate reflection of the actual risk profile of terminal geoscience document data operations. Specifically, the pre-set database can be updated based on developments and changes in the geological field, and operational indicator parameters can dynamically change with actual operational conditions. This allows the dynamic risk assessment model to adapt to different terminal geoscience document data types and operational scenarios, improving the accuracy and effectiveness of risk assessment.

[0046] In an embodiment of the present application, optionally, the sensitivity index of the terminal geoscience document data is calculated based on a preset keyword library through the data content sensitivity detection sub-model, including: identifying the target keywords contained in the terminal geoscience document data based on the preset keyword library through the data content sensitivity detection sub-model, and obtaining the scores and weights corresponding to the target keywords; calculating a first score corresponding to the target keywords based on the scores and weights corresponding to the target keywords, and calculating a corresponding second score based on the remaining part of the terminal geoscience document data except the target keywords; summing the first score and the second score to obtain a total score corresponding to the terminal geoscience document data, and calculating the ratio of the total score to the total number of words in the terminal geoscience document data, and using the ratio as a first sensitivity index, wherein the sensitivity index includes the first sensitivity index.

[0047] The sensitivity index of the terminal geological literature data is calculated based on a preset symbol library through the data content sensitivity detection submodel, including: extracting geological symbols contained in the terminal geological literature data through the data content sensitivity detection submodel, and determining target geological symbols contained in the symbol extraction results based on the preset symbol library; and calculating a second sensitivity index of the terminal geological literature data based on the frequency of occurrence of the target geological symbols, wherein the sensitivity index includes the second sensitivity index.

[0048] The sensitivity index of the terminal geoscience literature data is calculated based on a preset geological key coordinate library through the data content sensitivity detection sub-model, including: determining the coordinate format corresponding to the terminal geoscience literature data, and when the coordinate format is not a standard format, calling a coordinate conversion tool, and converting the coordinates corresponding to the terminal geoscience literature data into standard coordinates through the coordinate conversion tool to obtain a coordinate conversion result; based on the preset geological key coordinate library, determining the target geological key coordinates included in the coordinate conversion result, and calculating the third sensitivity index of the terminal geoscience literature data based on the target geological key coordinates, wherein the sensitivity index includes the third sensitivity index.

[0049] In this embodiment, first, a first sensitivity index is calculated based on a preset keyword library. Specifically, the data content sensitivity detection sub-model can scan and identify vocabulary in the terminal geological literature data based on the preset keyword library to identify target keywords contained in the terminal geological literature data. The preset keyword library contains a series of keywords related to geological sensitive information, such as "uranium mine" and "important geological disaster risk points." Each target keyword has a corresponding score and weight in the preset keyword library. The score reflects the sensitivity of the keyword, while the weight takes into account the importance of the keyword in the geological field. For example, a strategic resource term such as "uranium mine" can be assigned a higher score and a larger weight. Then, based on the score and weight corresponding to the target keyword, a specific algorithm (such as weighted summation) is used to calculate the first score corresponding to the target keyword. For example, if there are multiple target keywords, each with a score Si and a weight Wi, then the first score Score 1 = ∑(Si × Wi). In addition to the target keyword, there are remaining words in the terminal geological literature data. The data content sensitivity detection sub-model can evaluate these remaining words according to preset rules and calculate a second score Score 2 corresponding to the remaining words. The first and second scores are then summed to obtain the total score for the terminal geoscience literature data: TotalScore = Score1 + Score2. The ratio of the total score to the total number of words in the terminal geoscience literature data is then calculated and used as the first sensitivity index. The first sensitivity index reflects the combined sensitivity of the keywords and other words in the document.

[0050] Second, a second sensitivity index is calculated based on a preset symbol library. The data content sensitivity detection sub-model can extract geological symbols from terminal geological literature data. Geological symbols are graphics or symbols used in the geological field to represent specific geological phenomena, rock types, minerals, etc. Specifically, geological symbols can be extracted based on the ResNet-50 model. The extracted geological symbols are then compared with the preset symbol library to determine the target geological symbols included in the symbol extraction results. The preset symbol library contains a variety of sensitive geological symbols. For example, mineral symbols, special stratum marker symbols, exploration well identifiers, military sensitive area symbols, critical infrastructure markers, etc. The second sensitivity index of the terminal geological literature data can be calculated based on the frequency of occurrence of the target geological symbols. For example, if one "uranium mine symbol" is detected, the sensitivity score is increased by 5 points; if three "military restricted area symbols" appear in the same image, the sensitivity directly triggers the high-risk threshold.

[0051] Third, a third sensitivity index is calculated based on a preset geological key coordinate library. First, the coordinate format corresponding to the terminal geoscience literature data is determined. If the coordinate format is not standard, a coordinate conversion tool is used to convert it to standard coordinates, resulting in a coordinate conversion result. The coordinate conversion tool supports automatic recognition and conversion of multiple coordinate systems, such as WGS84 and CGCS2000. The standard coordinate format facilitates subsequent matching and calculation. Next, the target geological key coordinates included in the coordinate conversion result are determined based on the preset geological key coordinate library. This library contains coordinates of various important geological locations, such as large mineral deposits and areas prone to geological disasters. Based on the target geological key coordinates, the third sensitivity index of the terminal geoscience literature data is calculated. For example, the third sensitivity index can be calculated based on factors such as the number of target geological key coordinates and their correlation with important geological regions. If the terminal geoscience literature data contains multiple coordinates that match the target geological key coordinates, or if these coordinates are highly correlated with important geological regions, the third sensitivity index can be improved.

[0052] It should be noted that the calculation of the above sensitivity indicators does not distinguish between the order of calculation. If the preset database includes the preset keyword library, the preset symbol library and the preset geological key coordinate library, then the above three sensitivity indicators can be calculated at the same time.

[0053] In an embodiment of the present application, optionally, the behavioral risk index corresponding to the target storage location is calculated through the behavioral risk detection sub-model, including: inputting the target storage location into the storage location risk detection sub-model in the behavioral risk detection sub-model, and calculating the storage location risk coefficient, wherein the behavioral risk index includes the storage location risk coefficient; calculating the behavioral risk index corresponding to the behavioral baseline of the operation through the behavioral risk detection sub-model, including: obtaining the target operation record of the operator on the current date, inputting the target operation record and the behavioral baseline into the operation behavior abnormality detection sub-model in the behavioral risk detection sub-model, and calculating the behavioral deviation between the operation behavior indicated by the target operation record and the behavioral baseline, wherein the behavioral risk index includes the behavioral deviation; calculating the behavioral risk index corresponding to the newly added copy judgment index parameter through the behavioral risk detection sub-model, including: inputting the newly added copy judgment index parameter into the file version diffusion detection sub-model in the behavioral risk detection sub-model, and calculating the file version diffusion corresponding to the terminal geological document data, wherein the behavioral risk index includes the file version diffusion.

[0054] In this embodiment, first, the behavioral risk index corresponding to the target storage location is calculated. Specifically, the previously determined target storage location information can be input into the storage location risk detection sub-model within the behavioral risk detection sub-model. The target storage location is the actual location where the terminal's geoscience literature data is stored, such as a folder on a local disk or a specific directory on a network storage server. The storage location risk detection sub-model can calculate the storage location risk coefficient based on the target storage location.

[0055] For example, in a write operation, the target storage location is the location in the terminal's geoscience literature data. In this case, the storage location risk detection sub-model can calculate the storage location risk coefficient as follows:

[0056]

[0057] Among them, L represents the storage location risk coefficient, k can be taken as 0.5, and d represents the storage path depth of the terminal geoscience literature data, which is determined according to the target storage location.

[0058] During a read operation, the storage location risk detection sub-model can calculate the storage location risk coefficient as follows:

[0059] If stored on an external USB flash drive, the storage location risk factor is A; if stored on an encrypted hard drive, the storage location risk factor is B; if stored in the cloud, the storage location risk factor is C, and so on. A, B, and C can be determined based on actual needs. A is greater than B and C because USB flash drives are easily lost or taken away from the work environment. Once a USB flash drive is lost, the data can be directly leaked. Therefore, if terminal geoscience literature data is detected to be stored on a USB flash drive, the storage location risk factor can be increased.

[0060] Second, calculate the behavioral risk index corresponding to the operational behavior baseline. Specifically, obtain the operator's target operation record for the current day. The target operation record contains information about various operations performed by the operator on the terminal geoscience literature data on that day, such as the number of read operations and write operations to date. Subsequently, the target operation record and the pre-generated operational behavior baseline are input into the operational behavior abnormality detection sub-model in the behavioral risk detection sub-model. The operational behavior abnormality detection sub-model can compare the difference between the operational behavior indicated by the target operation record and the operational behavior baseline and calculate the behavioral deviation degree. The behavioral deviation degree reflects the degree of deviation of the current operational behavior from the normal operating mode. The larger the deviation degree, the more abnormal the operational behavior and the higher the potential risk. This deviation degree serves as one of the behavioral risk indicators.

[0061] Third, the behavioral risk indicator corresponding to the newly added copy judgment indicator parameter is calculated. Specifically, the newly added copy judgment indicator parameter obtained above is input into the file version diffusion detection sub-model within the behavioral risk detection sub-model. The newly added copy judgment indicator parameter reflects whether there are newly added file copies in the terminal geoscience document data. The file version diffusion detection sub-model can calculate the file version diffusion corresponding to the terminal geoscience document data based on the newly added copy judgment indicator parameter. The file version diffusion reflects the diffusion of the terminal geoscience document data version. The higher the diffusion, the more diffuse the file version.

[0062] For example, the file version diffusion detection sub-model can calculate the file version diffusion as follows:

[0063] V=1-e (-λ*n) ;

[0064] Wherein, V represents the file version diffusion, λ=0.1, and n represents the new copy judgment index parameter (ie, the number of file copies).

[0065] In an embodiment of the present application, optionally, when the operation instruction is a read instruction, the target operation behavior also includes a read operation behavior; determining the operation indicator parameters based on the target operation behavior includes: obtaining the original storage location corresponding to the terminal geological literature data based on the read operation behavior, and determining the path depth corresponding to the terminal geological literature data based on the original storage location, wherein the operation indicator parameters include the path depth; calculating the behavior risk indicator corresponding to the path depth through the behavior risk detection sub-model, including: inputting the path depth into the path depth risk detection sub-model in the behavior risk detection sub-model, and calculating the path risk coefficient, wherein the behavior risk indicator includes the path risk coefficient.

[0066] In this embodiment, when the operation instruction is a read instruction, the target operation behavior includes a read operation behavior in addition to the previous storage operation behavior, historical operation behavior, and version diffusion operation behavior. At this time, additional operation indicator parameters can be determined based on the read operation behavior, and the behavior risk indicator can be further calculated based on the parameter to more comprehensively evaluate the risk of the terminal geological literature data reading operation. Specifically, based on the read operation behavior, the original storage location corresponding to the terminal geological literature data is obtained. The original storage location refers to the starting location where the file is actually stored in the terminal geological literature data. Then, based on the original storage location, the path depth corresponding to the terminal geological literature data is determined. The path depth refers to the number of directory levels passed from the root directory of the storage system (or a predefined starting directory) to the directory where the file is located. The path depth reflects the degree of nesting of the file in the storage system. The greater the path depth, the more difficult it is to directly access and manage the file, and there may be certain security risks. When terminal geological literature data is hidden in multiple layers of subfolders (for example, "Geological Data / 2024 / Exploration Projects / Confidential / Uranium Data.docx"), it is more likely to be overlooked in permission settings or monitoring (some security systems only monitor the first three directories by default to save resources, and deep files may escape real-time scanning). Attackers may use complex paths to hide theft. Therefore, the deeper the path depth, the greater the risk. Subsequently, the path depth determined previously is input into the path depth risk detection submodel in the behavioral risk detection submodel. The path depth risk detection submodel can calculate the path risk coefficient based on the path depth.

[0067] Specifically, the path depth risk detection sub-model can calculate the path risk coefficient as follows:

[0068]

[0069] Among them, P represents the path risk coefficient, k can be taken as 0.5, and D represents the original path depth of the terminal geoscience literature data.

[0070] In an embodiment of the present application, optionally, when the operation instruction is a write instruction, after step 101, the method further includes: identifying whether the terminal geological literature data is a newly created file; when the terminal geological literature data is not a newly created file, performing an incremental scan on the terminal geological literature data based on a differential scanning algorithm to obtain an incremental scanning result; accordingly, after determining the operation indicator parameters according to the target operation behavior, the method further includes: calculating the operation risk level corresponding to the terminal geological literature data through the dynamic risk assessment model based on the operation indicator parameters and the incremental scanning result.

[0071] In this embodiment, when the operation instruction is a write instruction, it indicates that a write operation is to be performed on the terminal geological literature data. In order to avoid a full disk scan after the write operation, the embodiment of the present application introduces a differential scanning algorithm, which can greatly improve the efficiency of the scan. First, the status of the terminal geological literature data can be judged to distinguish between new files and non-new files. Specifically, it can be determined whether the file is a new file by checking the file's metadata (such as creation time, file identification, etc.) or the record of the file system. If the file has no historical record in the system, or the creation time is near the current operation time, it is determined to be a new file; otherwise, it is determined to be a non-new file.

[0072] When it is determined that the terminal geological literature data is not a newly created file, the current version and the previous version (or baseline version) of the file can be obtained, and then the two versions can be scanned using a differential scanning algorithm. During the scanning process, the algorithm can record the changed parts of the file, including new additions, deletions, and modifications, and ultimately obtain incremental scanning results. For example, if a paragraph in a file is modified, the algorithm can mark the specific location of the paragraph and the content before and after the modification. The differential scanning algorithm is a technology used to compare the differences between different versions of a file. It can quickly locate the changed parts of the file instead of comparing the entire file byte by byte, thereby improving scanning efficiency. Common differential scanning algorithms include hash value-based comparison and byte stream-based difference detection.

[0073] Subsequently, the operation indicator parameters and incremental scanning results are input into the dynamic risk assessment model, and only the risks of the newly added parts are evaluated through the dynamic risk assessment model.

[0074] By introducing an incremental scanning process for non-newly created files, the embodiment of the present application can more accurately and quickly assess the risks of write operations, while greatly reducing the system's resource usage and improving assessment efficiency.

[0075] In an embodiment of the present application, optionally, the step 103 of "determining the security mechanism corresponding to the terminal geoscience document data based on the operational risk level" includes: determining the target file category corresponding to the terminal geoscience document data, calling the risk threshold list corresponding to the target file category, and determining the security mechanism corresponding to the terminal geoscience document data based on the risk threshold list and the operational risk level, wherein the security mechanism is at least one of a release mechanism, an encryption mechanism, a blocking operation mechanism, and an alarm mechanism.

[0076] In this embodiment, different terminal geological literature data may have different importance and sensitivity, and classifying them helps to formulate security strategies more accurately. For example, some files may contain core geological exploration data and belong to the highly confidential category; while other files may be ordinary geological reports with relatively low sensitivity. Therefore, when determining the security mechanism of terminal geological literature data based on the operational risk level, first, the target file category of the terminal geological literature data can be determined. Here, the target file category can be in the form of a two-level category. Among them, the first level is divided into three-level frameworks: regional geology, mineral geology and engineering geology; the second level is divided into nine sub-fields: basic geology, energy minerals, metal minerals, etc. For different file categories, different risk threshold lists can be pre-set (such as the risk coefficient of mineral geological literature data is higher than that of regional geology). The risk threshold list contains security mechanism recommendations corresponding to different operational risk levels. For the same operational risk level, different security mechanisms can be determined for different target file categories.

[0077] After determining the target file category, the corresponding risk threshold list can be retrieved from a pre-stored list library. The previously calculated operational risk level is then matched against the risk threshold list. Based on the matching results, a corresponding security mechanism recommendation is retrieved from the risk threshold list. The security mechanism can be at least one of a release mechanism, an encryption mechanism, a blocking mechanism, and an alert mechanism. Regarding the release mechanism: If the operational risk level is low, the release mechanism can be selected, allowing normal write operations to the terminal's geoscience literature data without additional security restrictions. Regarding the encryption mechanism: When the operational risk level is in the medium range, an encryption mechanism can be employed to ensure the security of the file data. After the write operation is completed, the file is encrypted, and only authorized operators can decrypt and access it. Regarding the blocking mechanism: If the operational risk level is high, the blocking mechanism can be activated to directly block the current write operation and prevent potential security threats. Regarding the alert mechanism: Regardless of the operational risk level, the alert mechanism can be enabled simultaneously. When the operational risk level exceeds a certain level, an alert message can be sent to security management personnel to alert them to the potential security risks of the operation.

[0078] This embodiment of the application combines the target file category and the risk threshold list to determine the security mechanism, enabling personalized security protection. Different file categories have different security requirements. Using a targeted risk threshold list can more accurately assess risk and select the appropriate security mechanism, improving the flexibility and effectiveness of security protection.

[0079] In addition, in an embodiment of the present application, when the operator operates on multiple files at the same time, it is also possible to determine whether the operated file is a geological professional file based on the extension of the file (such as .gdb / .sgy). If it is a geological professional file, it is automatically marked as a high priority and inserted into the head of the processing queue for priority processing.

[0080] When the terminal geoscience literature data being processed is in the SEG-Y seismic data format, the following method can be used to analyze the data to determine its sensitivity index. Specifically, the data header information (such as the number and coordinates) is quickly read from each data segment, and the coordinate format is automatically identified and converted. The data is then divided into small blocks and processed simultaneously using multiple threads. Each thread calls the data content sensitivity detection submodel, thereby improving the computational efficiency of the sensitivity index for the terminal geoscience literature data.

[0081] When operators work with terminal geoscience literature data in MapGIS files, topological analysis within these files is directly related to data leakage. These files also detail the spatial location and logical relationships of geological elements (such as mineral deposits, fault lines, and engineering zones). Therefore, in addition to detecting sensitivity indicators using the data content sensitivity detection sub-model, further detection can be performed based on the following methods. For example, a polygon file may accurately mark the distribution range of a strategic mineral, while a line file may reveal the orientation of geological structures. Leakage of this information could expose national resource allocation or key geological strategic points. When operators work with such terminal geoscience literature data, they can analyze the topological relationships between points, lines, and polygons within the files (e.g., region inclusion and line segment connectivity) to identify sensitive spatial associations hidden within the map (e.g., the overlap between a mining area and a military restricted zone). Furthermore, combined with the sensitive area matching algorithm in the spatial rule library, higher-level confidentiality measures (e.g., export prohibition or encrypted storage) can be automatically triggered to prevent attackers from circumventing traditional content detection by tampering with map elements (e.g., moving coordinate points) or splitting sensitive areas, thereby plugging security vulnerabilities caused by spatial data leakage. Specifically, the system can first read the coordinate data of points, lines, and surfaces in the MapGIS file (such as the location of each turning point of a line and the closed line segments that make up a surface). Then, it can intelligently analyze the connection relationships between these graphics. For example, it can automatically identify which line ends should be connected and which surface areas are adjacent or contain each other. Then, it can use the sensitive area matching algorithm to perform sensitive area matching on the analyzed regional relationships to determine whether the coordinate point falls into the preset sensitive area. The fourth sensitivity index is obtained based on the sensitive area matching algorithm.

[0082] Further, as Figure 1 The specific implementation of the method, the embodiment of the present application provides a terminal geological literature data anti-leakage device, such as Figure 2 As shown, the device includes:

[0083] A model calling module, configured to call a dynamic risk assessment model in response to an operation instruction on the terminal geoscience literature data, wherein the operation instruction is a read instruction or a write instruction;

[0084] a calculation module, configured to obtain a target operation behavior associated with the operation instruction, determine an operation index parameter according to the target operation behavior, and calculate an operation risk level corresponding to the terminal geoscience literature data based on the operation index parameter and the terminal geoscience literature data using the dynamic risk assessment model;

[0085] The security mechanism determination module is used to determine the security mechanism corresponding to the terminal geoscience literature data based on the operation risk level, and generate an operation result corresponding to the operation instruction according to the security mechanism.

[0086] Optionally, the target operation behavior includes at least one of a storage operation behavior, a historical operation behavior corresponding to the operation instruction, and a version diffusion operation behavior; and the calculation module is configured to:

[0087] Determining a target storage location corresponding to the terminal geoscience literature data according to the storage operation behavior, wherein the operation indicator parameter includes the target storage location; and / or,

[0088] generating a behavior baseline of the operation according to the historical operation behavior corresponding to the operation instruction, wherein the operation indicator parameter includes the behavior baseline of the operation; and / or,

[0089] According to the version diffusion operation behavior, it is determined whether the terminal geological literature data corresponds to a newly added file copy, and the determination result is used as a newly added copy determination indicator parameter, wherein the operation indicator parameter includes the newly added copy determination indicator parameter.

[0090] Optionally, the dynamic risk assessment model includes a data content sensitivity detection sub-model and a behavior risk detection sub-model; and the calculation module is further configured to:

[0091] Calculating the sensitivity index of the terminal geological literature data based on a preset database using the data content sensitivity detection sub-model, wherein the preset database includes at least one of a preset keyword library, a preset symbol library, and a preset geological key coordinate library;

[0092] Calculating the behavioral risk index corresponding to the operation index parameter through the behavioral risk detection sub-model;

[0093] An operational risk level corresponding to the terminal geoscience literature data is determined according to the sensitivity index and the behavioral risk index.

[0094] Optionally, the calculation module is further configured to:

[0095] Using the data content sensitivity detection sub-model, based on the preset keyword library, target keywords included in the terminal geoscience literature data are identified, and scores and weights corresponding to the target keywords are obtained;

[0096] Calculating a first score corresponding to the target keyword based on the score and weight corresponding to the target keyword, and calculating a corresponding second score based on the remaining portion of the terminal geoscience literature data except the target keyword;

[0097] Summing the first score and the second score to obtain a total score corresponding to the terminal geoscience document data, and calculating a ratio of the total score to a total number of words in the terminal geoscience document data, and using the ratio as a first sensitivity index, wherein the sensitivity index includes the first sensitivity index;

[0098] The computing module is further configured to:

[0099] Extracting geological symbols contained in the terminal geological literature data through the data content sensitivity detection sub-model, and determining target geological symbols contained in the symbol extraction results based on the preset symbol library;

[0100] Calculating a second sensitivity index of the terminal geological literature data based on the frequency of occurrence of the target geological symbol, wherein the sensitivity index includes the second sensitivity index;

[0101] The computing module is further configured to:

[0102] determining a coordinate format corresponding to the terminal geoscience document data; and if the coordinate format is not a standard format, calling a coordinate conversion tool to convert the coordinates corresponding to the terminal geoscience document data into standard coordinates through the coordinate conversion tool to obtain a coordinate conversion result;

[0103] Based on the preset geological key coordinate library, the target geological key coordinates included in the coordinate conversion result are determined, and based on the target geological key coordinates, the third sensitivity index of the terminal geological literature data is calculated, wherein the sensitivity index includes the third sensitivity index.

[0104] Optionally, the calculation module is further configured to:

[0105] Inputting the target storage location into the storage location risk detection sub-model in the behavior risk detection sub-model to calculate a storage location risk coefficient, wherein the behavior risk indicator includes the storage location risk coefficient;

[0106] The computing module is further configured to:

[0107] Obtaining a target operation record of the operator on the current date, inputting the target operation record and the behavior baseline into an operation behavior abnormality detection sub-model in the behavior risk detection sub-model, and calculating a behavior deviation between the operation behavior indicated by the target operation record and the behavior baseline, wherein the behavior risk indicator includes the behavior deviation;

[0108] The computing module is further configured to:

[0109] The newly added copy judgment index parameter is input into the file version diffusion detection sub-model in the behavior risk detection sub-model to calculate the file version diffusion corresponding to the terminal geoscience document data, wherein the behavior risk index includes the file version diffusion.

[0110] Optionally, when the operation instruction is a read instruction, the target operation behavior further includes a read operation behavior;

[0111] The computing module is further configured to:

[0112] Obtaining, according to the read operation behavior, an original storage location corresponding to the terminal geoscience document data, and determining, based on the original storage location, a path depth corresponding to the terminal geoscience document data, wherein the operation indicator parameter includes the path depth;

[0113] The computing module is further configured to:

[0114] The path depth is input into the path depth risk detection sub-model in the behavior risk detection sub-model to calculate the path risk coefficient, wherein the behavior risk indicator includes the path risk coefficient.

[0115] Optionally, when the operation instruction is a write instruction, the device further includes an incremental scanning module; the incremental scanning module is configured to:

[0116] In response to an operation instruction on the terminal geoscience document data, after calling the dynamic risk assessment model, identifying whether the terminal geoscience document data is a new file, and when the terminal geoscience document data is not a new file, performing an incremental scan on the terminal geoscience document data based on a difference scanning algorithm to obtain an incremental scanning result;

[0117] Accordingly, the calculation module is further configured to:

[0118] After determining the operation index parameters according to the target operation behavior, the operation risk level corresponding to the terminal geoscience literature data is calculated based on the operation index parameters and the incremental scanning results through the dynamic risk assessment model.

[0119] Optionally, the security mechanism determination module is configured to:

[0120] Determine the target file category corresponding to the terminal geoscience document data, call the risk threshold list corresponding to the target file category, and determine the security mechanism corresponding to the terminal geoscience document data based on the risk threshold list and the operation risk level, wherein the security mechanism is at least one of a release mechanism, an encryption mechanism, a blocking operation mechanism, and an alarm mechanism.

[0121] It should be noted that for other corresponding descriptions of the functional units involved in the terminal geological literature data anti-leakage device provided in the embodiment of the present application, please refer to Figure 1 The corresponding description in the method will not be repeated here.

[0122] The present application also provides a computer device, which can be a personal computer, a server, a network device, etc. Figure 3 As shown, the computer device includes a bus, a processor, a memory, and a communication interface, and may also include an input / output interface and a display device. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store location information. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, the steps of each method embodiment are implemented.

[0123] Those skilled in the art will understand that Figure 3 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0124] In one embodiment, a computer-readable storage medium is provided. The computer-readable storage medium may be non-volatile or volatile, and stores a computer program thereon. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0125] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0126] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0127] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.

[0128] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0129] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A method for preventing leakage of terminal geoscience literature data, characterized in that: include: In response to an operation instruction on the terminal geoscience literature data, calling a dynamic risk assessment model, wherein the operation instruction is a read instruction or a write instruction; Obtaining a target operation behavior associated with the operation instruction, determining an operation indicator parameter according to the target operation behavior, and calculating an operation risk level corresponding to the terminal geoscience document data based on the operation indicator parameter and the terminal geoscience document data using the dynamic risk assessment model; Based on the operation risk level, a security mechanism corresponding to the terminal geoscience literature data is determined, and an operation result corresponding to the operation instruction is generated according to the security mechanism.

2. The method according to claim 1, characterized in that The target operation behavior includes at least one of a storage operation behavior, a historical operation behavior corresponding to the operation instruction, and a version diffusion operation behavior; and determining the operation indicator parameter according to the target operation behavior includes: Determining a target storage location corresponding to the terminal geoscience literature data according to the storage operation behavior, wherein the operation indicator parameter includes the target storage location; and / or, generating a behavior baseline of the operation according to the historical operation behavior corresponding to the operation instruction, wherein the operation indicator parameter includes the behavior baseline of the operation; and / or, According to the version diffusion operation behavior, it is determined whether the terminal geological literature data corresponds to a newly added file copy, and the determination result is used as a newly added copy determination indicator parameter, wherein the operation indicator parameter includes the newly added copy determination indicator parameter.

3. The method according to claim 2, characterized in that The dynamic risk assessment model includes a data content sensitivity detection sub-model and a behavior risk detection sub-model; the operation risk level corresponding to the terminal geoscience document data is calculated by the dynamic risk assessment model based on the operation indicator parameters and the terminal geoscience document data, including: Calculating the sensitivity index of the terminal geological literature data based on a preset database using the data content sensitivity detection sub-model, wherein the preset database includes at least one of a preset keyword library, a preset symbol library, and a preset geological key coordinate library; Calculating the behavioral risk index corresponding to the operation index parameter through the behavioral risk detection sub-model; An operational risk level corresponding to the terminal geoscience literature data is determined according to the sensitivity index and the behavioral risk index.

4. The method according to claim 3, characterized in that The sensitivity index of the terminal geoscience literature data is calculated based on a preset keyword library by using the data content sensitivity detection sub-model, including: Using the data content sensitivity detection sub-model, based on the preset keyword library, target keywords included in the terminal geoscience literature data are identified, and scores and weights corresponding to the target keywords are obtained; Calculating a first score corresponding to the target keyword based on the score and weight corresponding to the target keyword, and calculating a corresponding second score based on the remaining portion of the terminal geoscience literature data except the target keyword; Summing the first score and the second score to obtain a total score corresponding to the terminal geoscience document data, and calculating a ratio of the total score to a total number of words in the terminal geoscience document data, and using the ratio as a first sensitivity index, wherein the sensitivity index includes the first sensitivity index; The sensitivity index of the terminal geoscience document data is calculated based on a preset symbol library by using the data content sensitivity detection sub-model, including: Extracting geological symbols contained in the terminal geological literature data through the data content sensitivity detection sub-model, and determining target geological symbols contained in the symbol extraction results based on the preset symbol library; Calculating a second sensitivity index of the terminal geological literature data based on the frequency of occurrence of the target geological symbol, wherein the sensitivity index includes the second sensitivity index; The sensitivity index of the terminal geological literature data is calculated based on a preset geological key coordinate library through the data content sensitivity detection sub-model, including: determining a coordinate format corresponding to the terminal geoscience document data; and if the coordinate format is not a standard format, calling a coordinate conversion tool to convert the coordinates corresponding to the terminal geoscience document data into standard coordinates through the coordinate conversion tool to obtain a coordinate conversion result; Based on the preset geological key coordinate library, the target geological key coordinates included in the coordinate conversion result are determined, and based on the target geological key coordinates, the third sensitivity index of the terminal geological literature data is calculated, wherein the sensitivity index includes the third sensitivity index.

5. The method according to claim 3, characterized in that Calculating the behavior risk index corresponding to the target storage location using the behavior risk detection sub-model includes: Inputting the target storage location into the storage location risk detection sub-model in the behavior risk detection sub-model to calculate a storage location risk coefficient, wherein the behavior risk indicator includes the storage location risk coefficient; Calculating the behavioral risk index corresponding to the behavioral baseline of the operation through the behavioral risk detection sub-model includes: Obtaining a target operation record of the operator on the current date, inputting the target operation record and the behavior baseline into an operation behavior abnormality detection sub-model in the behavior risk detection sub-model, and calculating a behavior deviation between the operation behavior indicated by the target operation record and the behavior baseline, wherein the behavior risk indicator includes the behavior deviation; Calculating the behavior risk index corresponding to the newly added copy judgment index parameter through the behavior risk detection sub-model includes: The newly added copy judgment index parameter is input into the file version diffusion detection sub-model in the behavior risk detection sub-model to calculate the file version diffusion corresponding to the terminal geoscience document data, wherein the behavior risk index includes the file version diffusion.

6. The method according to any one of claims 3 to 6, characterized in that In the case where the operation instruction is a read instruction, the target operation behavior also includes a read operation behavior; Determining the operation indicator parameters according to the target operation behavior includes: Obtaining, according to the read operation behavior, an original storage location corresponding to the terminal geoscience document data, and determining, based on the original storage location, a path depth corresponding to the terminal geoscience document data, wherein the operation indicator parameter includes the path depth; Calculating the behavioral risk index corresponding to the path depth using the behavioral risk detection sub-model includes: The path depth is input into the path depth risk detection sub-model in the behavior risk detection sub-model to calculate the path risk coefficient, wherein the behavior risk indicator includes the path risk coefficient.

7. The method according to claim 1, characterized in that In the case where the operation instruction is a write instruction, after calling the dynamic risk assessment model in response to the operation instruction on the terminal geoscience literature data, the method further includes: Identifying whether the terminal geoscience document data is a newly created file; and when the terminal geoscience document data is not a newly created file, performing an incremental scan on the terminal geoscience document data based on a difference scanning algorithm to obtain an incremental scanning result; Accordingly, after determining the operation indicator parameters according to the target operation behavior, the method further includes: Based on the operation indicator parameters and the incremental scanning results, the operation risk level corresponding to the terminal geoscience literature data is calculated by the dynamic risk assessment model; Determining a security mechanism corresponding to the terminal geoscience literature data based on the operational risk level includes: Determine the target file category corresponding to the terminal geoscience document data, call the risk threshold list corresponding to the target file category, and determine the security mechanism corresponding to the terminal geoscience document data based on the risk threshold list and the operation risk level, wherein the security mechanism is at least one of a release mechanism, an encryption mechanism, a blocking operation mechanism, and an alarm mechanism.

8. A device for preventing leakage of terminal geoscience document data, characterized in that: include: A model calling module, configured to call a dynamic risk assessment model in response to an operation instruction on the terminal geoscience literature data, wherein the operation instruction is a read instruction or a write instruction; a calculation module, configured to obtain a target operation behavior associated with the operation instruction, determine an operation index parameter according to the target operation behavior, and calculate an operation risk level corresponding to the terminal geoscience literature data based on the operation index parameter and the terminal geoscience literature data using the dynamic risk assessment model; The security mechanism determination module is used to determine the security mechanism corresponding to the terminal geoscience literature data based on the operation risk level, and generate an operation result corresponding to the operation instruction according to the security mechanism.

9. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

10. A computer device comprising a storage medium, a processor, and a computer program stored in the storage medium and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Electronic archive data security system and method

    CN119249483A

  • Systems and methods for detecting security blind spots

    US10091231B1