Methods, devices, storage media, and equipment for preventing the leakage of terminal geoscientific literature data
By using a dynamic risk assessment model to evaluate operational risks in real time and determine security mechanisms, the problem of insufficient flexibility in traditional methods for preventing the leakage of geoscientific literature data is solved, and more efficient security protection is achieved.
Patent Information
- Application Number
- CN202510553683.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-29
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2045-04-29
AI Technical Summary
Traditional methods for preventing the leakage of geoscientific literature data lack flexibility and are difficult to cope with complex and ever-changing operational scenarios and potential security threats. In particular, static strategies are not effective in protecting data security when faced with unintentional leaks or malicious attacks by insiders.
A dynamic risk assessment model is adopted to assess operational risks in real time by comprehensively considering factors such as operational indicator parameters and the terminal geoscientific literature data itself, and to determine corresponding security mechanisms based on the risk level, including log recording, encryption processing and alarm notification measures.
It improves the flexibility and accuracy of security protection, effectively prevents the leakage of geoscientific literature data on the terminal, and does not affect the efficiency of normal business operations.
Smart Images

Figure CN120654246B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and in particular to a method and device, storage medium, and computer equipment for preventing the leakage of terminal geoscientific literature data. Background Technology
[0002] Geoscientific literature is a crucial output of Earth science research, and geoscientific data is an important component of national data resource construction. The development and utilization of geoscientific data are of great significance in supporting the development of Earth science disciplines, geological surveys, and natural resource management. At the same time, as a core resource, the confidentiality and security of geoscientific data are paramount. With the rapid development of information technology, the management and transmission of geoscientific data increasingly rely on computer terminals and network systems. However, this digitization process also brings the risk of data leakage, especially at the terminal application stage. Due to improper operation or malicious attacks, sensitive geoscientific data may be illegally obtained or tampered with, posing a serious threat to national security and the rights and interests of the public.
[0003] Traditional methods for preventing the leakage of geoscientific literature data mostly rely on static security policies, such as file encryption and access control lists (ACLs). While these methods improve data security to some extent, they often lack flexibility and are difficult to cope with complex and ever-changing operational scenarios and potential security threats. In particular, static policies are often inadequate when facing unintentional leaks or malicious attacks by internal personnel. Summary of the Invention
[0004] In view of this, this application provides a method, device, storage medium, and computer equipment for preventing the leakage of terminal geoscientific literature data. It employs a dynamic risk assessment model, which can assess operational risks in real time based on actual operating conditions, rather than using a fixed security strategy, thereby improving the flexibility and accuracy of security protection. By comprehensively considering operational indicator parameters and the terminal geoscientific literature data itself, it can more comprehensively assess operational risks and effectively prevent the leakage of terminal geoscientific literature data. Furthermore, it determines corresponding security mechanisms based on different operational risk levels, ensuring the security of terminal geoscientific literature data without affecting normal business operation efficiency.
[0005] According to one aspect of this application, a method for preventing the leakage of terminal geoscientific literature data is provided, comprising:
[0006] In response to the terminal's operation command on geoscientific literature data, a dynamic risk assessment model is invoked, wherein the operation command is a read command or a write command;
[0007] The target operation behavior associated with the operation instruction is obtained, the operation index parameters are determined according to the target operation behavior, and the operation risk level corresponding to the terminal geoscience literature data is calculated based on the operation index parameters and the terminal geoscience literature data through the dynamic risk assessment model.
[0008] Based on the operational risk level, the security mechanism corresponding to the terminal geoscientific literature data is determined, and the operation result corresponding to the operation instruction is generated according to the security mechanism.
[0009] According to another aspect of this application, a device for preventing the leakage of terminal geoscientific literature data is provided, comprising:
[0010] The model invocation module is used to invoke the dynamic risk assessment model in response to operation instructions on terminal geoscientific literature data, wherein the operation instructions are read instructions or write instructions;
[0011] The calculation module is used to obtain the target operation behavior associated with the operation instruction, determine the operation index parameters according to the target operation behavior, and calculate the operation risk level corresponding to the terminal geoscience literature data based on the operation index parameters and the terminal geoscience literature data through the dynamic risk assessment model.
[0012] The security mechanism determination module is used to determine the security mechanism corresponding to the terminal geoscientific literature data based on the operational risk level, and generate the operation result corresponding to the operation instruction according to the security mechanism.
[0013] According to another aspect of this application, a storage medium is provided that stores a computer program thereon, which, when executed by a processor, implements the above-described method for preventing the leakage of terminal geoscientific literature data.
[0014] According to another aspect of this application, a computer device is provided, including a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, wherein the processor executes the program to implement the above-mentioned method for preventing leakage of terminal geoscientific literature data.
[0015] By employing the above technical solution, this application provides a method, device, storage medium, and computer equipment for preventing the leakage of terminal geoscientific literature data. When the terminal detects a read or write operation command for the terminal geoscientific literature data, it can automatically invoke a dynamic risk assessment model. Next, the target operation behavior associated with the operation command can be obtained. Based on the target operation behavior, a series of operation indicator parameters are determined. After determining the operation indicator parameters, the determined operation indicator parameters and the terminal geoscientific literature data can be input into the dynamic risk assessment model. This model can comprehensively consider these factors and calculate the operation risk level corresponding to the terminal geoscientific literature data. Then, based on the calculated operation risk level, a corresponding security mechanism is determined. Finally, based on the determined security mechanism, the operation result corresponding to the operation command is generated. This application employs a dynamic risk assessment model, which can assess operational risks in real time based on actual operational conditions, rather than using a fixed security strategy, thereby improving the flexibility and accuracy of security protection. By comprehensively considering factors such as operational indicator parameters and the terminal geoscientific literature data itself, it can more comprehensively assess operational risks and effectively prevent the leakage of terminal geoscientific literature data. According to different operational risk levels, corresponding security mechanisms are determined, which can not only ensure the security of terminal geoscientific literature data, but also not affect the efficiency of normal business operations.
[0016] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the purpose, features and advantages of this application more obvious and easy to understand, the following are specific embodiments of this application. Attached Figure Description
[0017] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0018] Figure 1 A flowchart illustrating a method for preventing the leakage of terminal geoscientific literature data provided in an embodiment of this application is shown.
[0019] Figure 2 This illustration shows a schematic diagram of a device for preventing the leakage of terminal geoscientific literature data provided in an embodiment of this application;
[0020] Figure 3 A schematic diagram of the device structure of a computer device provided in an embodiment of this application is shown. Detailed Implementation
[0021] The present application will be described in detail below with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specified, the embodiments and features described in the embodiments of the present application can be combined with each other.
[0022] This embodiment provides a method for preventing the leakage of terminal geoscience literature data, such as... Figure 1 As shown, the method includes:
[0023] Step 101: In response to the operation command on the terminal geoscientific literature data, invoke the dynamic risk assessment model, wherein the operation command is a read command or a write command.
[0024] Step 102: Obtain the target operation behavior associated with the operation instruction, determine the operation index parameters based on the target operation behavior, and calculate the operation risk level corresponding to the terminal geoscientific literature data based on the operation index parameters and the terminal geoscientific literature data through the dynamic risk assessment model.
[0025] Step 103: Based on the operational risk level, determine the security mechanism corresponding to the terminal geoscientific literature data, and generate the operation result corresponding to the operation instruction according to the security mechanism.
[0026] This application provides a method for preventing the leakage of geoscientific literature data on a terminal. This method can be applied to a terminal. When reading or writing geoscientific literature data on a terminal, a dynamic risk assessment model can be used to assess the risk level of the operation, and a corresponding security mechanism can be determined based on the risk level to finally generate the operation result, thereby ensuring the security of the geoscientific literature data on the terminal.
[0027] Specifically, operators can issue various operation commands to the terminal geoscientific literature data through the terminal, such as read commands or write commands. A read command indicates that the operator wants to view the content of the terminal geoscientific literature data, while a write command indicates that the operator wants to add or modify data into the terminal geoscientific literature data. When the terminal geoscientific literature data terminal detects a read or write operation command, it can automatically invoke a dynamic risk assessment model. The dynamic risk assessment model is a tool used to assess the operational risks of the terminal geoscientific literature data, and it can calculate the risk level of the operation based on subsequently provided information. Next, the target operational behavior associated with the operation command can be obtained. Here, the target operational behavior can include storage operations, corresponding historical operations, version diffusion operations, etc. Subsequently, based on the target operational behavior, a series of operational indicator parameters are determined. These parameters are key factors used to measure operational risk.
[0028] After determining the operational parameters, the next step is to input these parameters and the terminal geoscientific literature data into a dynamic risk assessment model. This model can comprehensively consider these factors and calculate the operational risk level corresponding to the terminal geoscientific literature data. For example, operational risk levels can include low risk, medium risk, and high risk, with different levels representing the degree of threat the operation may pose to the security of the terminal geoscientific literature data. Then, based on the calculated operational risk level, corresponding security mechanisms are determined. Security mechanisms are a series of measures taken to ensure the security of the terminal geoscientific literature data, such as: Low risk: only simple log recording, recording the operation time, operator, and operation content for subsequent auditing. Medium risk: in addition to log recording, encryption processing can be applied to the terminal geoscientific literature data. High risk: operation can be directly rejected, triggering an alarm to notify security management personnel, and further investigation of the operator can be conducted.
[0029] Finally, based on the established security mechanisms, the corresponding operation results are generated. For example, if the operation is allowed, the result could be successful reading or writing of geoscientific literature data to the terminal; if the operation is rejected, the result could indicate to the operator that the operation was unsuccessful and explain the reason.
[0030] By applying the technical solution of this embodiment, when the terminal detects a read or write operation command for terminal geoscientific literature data, a dynamic risk assessment model can be automatically invoked. Next, the target operation behavior associated with the operation command can be obtained. Based on the target operation behavior, a series of operation indicator parameters are determined. After determining the operation indicator parameters, the determined operation indicator parameters and the terminal geoscientific literature data can be input into the dynamic risk assessment model. This model can comprehensively consider these factors and calculate the operation risk level corresponding to the terminal geoscientific literature data. Then, based on the calculated operation risk level, a corresponding security mechanism is determined. Finally, based on the determined security mechanism, the operation result corresponding to the operation command is generated. This embodiment of the application adopts a dynamic risk assessment model, which can assess operation risk in real time according to the actual operation situation, rather than using a fixed security strategy, thereby improving the flexibility and accuracy of security protection; by comprehensively considering factors such as operation indicator parameters and the terminal geoscientific literature data itself, it can more comprehensively assess operation risk and effectively prevent the leakage of terminal geoscientific literature data; by determining the corresponding security mechanism according to different operation risk levels, it can both ensure the security of terminal geoscientific literature data and not affect the efficiency of normal business operations.
[0031] In this embodiment of the application, optionally, the target operation behavior includes at least one of storage operation behavior, historical operation behavior corresponding to the operation instruction, and version diffusion operation behavior; the step 102 of "determining operation index parameters according to the target operation behavior" includes: determining the target storage location corresponding to the terminal geoscientific literature data according to the storage operation behavior, wherein the operation index parameters include the target storage location; and / or, generating the operation behavior baseline according to the historical operation behavior corresponding to the operation instruction, wherein the operation index parameters include the operation behavior baseline; and / or, determining whether the terminal geoscientific literature data corresponds to a new file copy according to the version diffusion operation behavior, and using the determination result as the new copy judgment index parameter, wherein the operation index parameter includes the new copy judgment index parameter.
[0032] In this embodiment, the target operation behavior may include one or more of the following: storage operation behavior, historical operation behavior corresponding to the operation instruction, and version diffusion operation behavior.
[0033] Storage operation behavior refers to the actions taken by operators when storing terminal geoscientific literature data. For example, saving the data to a specific folder on a local hard drive, or to a USB flash drive, external hard drive, etc. This behavior involves the storage location of the files and is crucial for assessing operational risks. Different storage locations can have different security levels; for example, certain sensitive areas on a local hard drive may be more vulnerable to physical attacks, while data saved to a USB flash drive is more likely to be leaked.
[0034] Historical operational behavior corresponding to an operation instruction refers to the operation records of the operator on the terminal geoscientific literature data over a past period, such as the average number of read operations and the average number of write operations per day within a preset time period. Analyzing the operator's historical operational behavior can reveal their operational habits, which can serve as a benchmark for subsequent evaluation. For example, if an operator's average daily read operations are 10, but suddenly increase to 30 on a certain day, this may indicate abnormal behavior and increase the risk of data leakage.
[0035] Version diffusion operations primarily involve the version management and dissemination of terminal geoscientific literature data. During the use of terminal geoscientific literature data, multiple versions of the files may be generated, and these files may be distributed between different systems or devices. Version diffusion operations may occur when a new version of terminal geoscientific literature data is created and distributed to multiple terminals. This behavior can lead to increased data inconsistency and security risks, as more file copies mean more potential points of leakage.
[0036] When determining operational indicator parameters based on target operational behaviors, if the target operational behavior includes storage operations, the target storage location corresponding to the terminal geoscience literature data can be determined based on the storage operations. The target storage location refers to the actual location where the files are stored, such as the "D:\GeologyData\ImportantFiles" folder on a local disk, or the " / geology / sensitive_data" directory on a network storage server. This target storage location can be used as one of the operational indicator parameters. Because different storage locations have different security characteristics, incorporating the target storage location into the operational indicator parameters allows for a more accurate assessment of operational risks.
[0037] If the target operational behavior includes historical operational behaviors corresponding to the operational instructions, an operational behavior baseline can be generated based on these historical behaviors. The operational behavior baseline is a statistical description of an operator's normal operational behavior, reflecting their operational patterns and habits over a period of time. For example, by analyzing an operator's operational records over the past month, calculating their average daily read operations and average daily write operations, these average daily read operations and average daily write operations can be used as the operator's operational behavior baseline. This baseline can be used as one of the operational indicator parameters. If the current operational behavior deviates significantly from the operational behavior baseline, it may indicate abnormal operation, and the risk level will increase accordingly.
[0038] When the target operation involves version diffusion, it's possible to determine whether new file copies have been added to the terminal geoscientific literature data. This can be done by checking file system metadata, version control system records, etc. The results can be used as a parameter for determining new copies. This parameter reflects the version diffusion status of the terminal geoscientific literature data. A large number of new file copies or a wide diffusion range may indicate an increased risk of data leakage, as more copies mean more potential leakage pathways. Incorporating the new copy determination parameter into the operational parameter system helps to more comprehensively assess operational risks.
[0039] The embodiments of this application determine the operation index parameters based on storage operation behavior, historical operation behavior, and version diffusion operation behavior, which can more comprehensively and accurately assess the operation risk level of terminal geoscientific literature data.
[0040] Optionally, in this embodiment, the dynamic risk assessment model includes a data content sensitivity detection sub-model and a behavioral risk detection sub-model; step 102, "calculating the operational risk level corresponding to the terminal geoscientific literature data based on the operational indicator parameters and the terminal geoscientific literature data using the dynamic risk assessment model," includes: calculating the sensitivity index of the terminal geoscientific literature data based on a preset database using the data content sensitivity detection sub-model, wherein the preset database includes at least one of a preset keyword library, a preset symbol library, and a preset geological key coordinate library; calculating the behavioral risk index corresponding to the operational indicator parameters using the behavioral risk detection sub-model; and determining the operational risk level corresponding to the terminal geoscientific literature data based on the sensitivity index and the behavioral risk index.
[0041] In this embodiment, the dynamic risk assessment model mainly consists of two sub-models: a data content sensitivity detection sub-model and a behavioral risk detection sub-model. These two sub-models assess the operational risks of terminal geoscientific literature data from different perspectives, and ultimately derive the operational risk level by combining the results.
[0042] The data content sensitivity detection sub-model relies on a pre-set database to calculate the sensitivity index of terminal geoscientific literature data. The pre-set database contains various types of information related to the sensitivity of terminal geoscientific literature data, such as at least one of a pre-set keyword library, a pre-set symbol library, and a pre-set geological key coordinate library. The pre-set keyword library contains a series of sensitive keywords related to the geological field, such as "distribution of rare metal deposits." When these keywords appear in the terminal geoscientific literature data, it may mean that the document involves important geological resource information, and its sensitivity will increase accordingly. The pre-set symbol library includes symbols for specific geological structures and mineral types, and also includes stratigraphic division symbols (such as "Q4"). 2 Various geological symbols, such as "al" and structural lines (e.g., reverse fault symbols), are used in the final geological literature data. The appearance of these symbols in the final geological literature data may indicate that the document contains important information. For example, the presence of a symbol representing a large gold deposit in the final geological literature data can increase the sensitivity of the data. The pre-set geological key coordinate database includes key coordinates related to important geological locations, such as the coordinates of large oil fields or areas prone to geological hazards. If the final geological literature data contains these key coordinates, it indicates that the document may involve sensitive geographical location information, and its sensitivity will be affected.
[0043] The behavioral risk detection sub-model primarily calculates the behavioral risk index based on the previously determined operational indicator parameters. These parameters include the target storage location, operational behavior baseline, and new copy judgment indicators, reflecting various aspects of the operational behavior. The behavioral risk detection sub-model can comprehensively consider these operational indicator parameters to calculate a quantitative behavioral risk index. This index reflects the potential risk that the operational behavior itself poses to the security of the terminal geoscientific literature data; the higher the index value, the greater the risk of the operational behavior.
[0044] Finally, the sensitivity index calculated by the data content sensitivity detection sub-model and the behavioral risk index calculated by the behavioral risk detection sub-model can be comprehensively evaluated to determine the operational risk level of the terminal geoscientific literature data. For example, a weighted average method can be used, assigning different weights to the sensitivity index and behavioral risk index according to their importance, and then calculating a comprehensive risk score. Based on the comprehensive risk score, the operational risk of the terminal geoscientific literature data can be divided into different levels, such as low risk, medium risk, and high risk. The specific classification criteria can be set according to actual needs. For example, a comprehensive risk score within a certain range might be considered low risk, another range medium risk, and exceeding a certain threshold high risk.
[0045] This application's embodiments assess operational risks from two dimensions: data content and operational behavior, through a data content sensitivity detection sub-model and a behavioral risk detection sub-model. This provides a more comprehensive and accurate reflection of the actual risks associated with operating terminal geoscientific literature data. The preset database can be updated according to developments and changes in the geological field, and the operational indicator parameters can also dynamically change with actual operational situations. This allows the dynamic risk assessment model to adapt to different types of terminal geoscientific literature data and operational scenarios, improving the accuracy and effectiveness of risk assessment.
[0046] In this embodiment of the application, optionally, the sensitivity index of the terminal geoscientific literature data is calculated based on a preset keyword library using the data content sensitivity detection sub-model, including: using the data content sensitivity detection sub-model, based on the preset keyword library, identifying target keywords contained in the terminal geoscientific literature data, and obtaining the score and weight corresponding to the target keywords; calculating a first score corresponding to the target keywords based on the score and weight corresponding to the target keywords, and calculating a corresponding second score based on the remaining part of the terminal geoscientific literature data excluding the target keywords; summing the first score and the second score to obtain the total score corresponding to the terminal geoscientific literature data, and calculating the ratio of the total score to the total number of words in the terminal geoscientific literature data, using the ratio as a first sensitivity index, wherein the sensitivity index includes the first sensitivity index.
[0047] The sensitivity index of the terminal geoscientific literature data is calculated based on a preset symbol library using the data content sensitivity detection sub-model. This includes: extracting geological symbols contained in the terminal geoscientific literature data using the data content sensitivity detection sub-model, and determining target geological symbols contained in the symbol extraction results based on the preset symbol library; and calculating a second sensitivity index of the terminal geoscientific literature data based on the frequency of occurrence of the target geological symbols, wherein the sensitivity index includes the second sensitivity index.
[0048] The sensitivity index of the terminal geoscientific literature data is calculated based on a preset geological key coordinate library using the data content sensitivity detection sub-model. This includes: determining the coordinate format corresponding to the terminal geoscientific literature data; if the coordinate format is not a standard format, calling a coordinate transformation tool to convert the coordinates corresponding to the terminal geoscientific literature data into standard coordinates, obtaining a coordinate transformation result; determining the target geological key coordinates contained in the coordinate transformation result based on the preset geological key coordinate library; and calculating a third sensitivity index of the terminal geoscientific literature data based on the target geological key coordinates, wherein the sensitivity index includes the third sensitivity index.
[0049] In this embodiment, firstly, a first sensitivity index is calculated based on a preset keyword library. Specifically, the data content sensitivity detection sub-model can scan and identify words in the terminal geoscientific literature data based on the preset keyword library to find target keywords contained in the terminal geoscientific literature data. The preset keyword library contains a series of keywords related to geologically sensitive information, such as "uranium mine" and "important geological hazard hazard point". Each target keyword has a corresponding score and weight in the preset keyword library. The score reflects the sensitivity of the keyword, while the weight considers the importance of the keyword in the geological field. For example, a strategic resource term such as "uranium mine" can be given a higher score and a larger weight. Next, based on the score and weight corresponding to the target keyword, the first score corresponding to the target keyword is calculated using a specific algorithm (such as weighted summation). For example, if there are multiple target keywords, each keyword has a score of Si and a weight of Wi, then the first score Score 1 = ∑(Si × Wi). In addition to the target keywords, there are remaining words in the terminal geoscientific literature data. The data content sensitivity detection sub-model can evaluate these remaining words according to preset rules and calculate the second score Score 2 corresponding to the remaining words. Next, the first and second scores are summed to obtain the total score (TotalScore = Score1 + Score2) for the terminal geoscientific literature data. Then, the ratio of the total score to the total number of words in the terminal geoscientific literature data is calculated, and this ratio is used as the first sensitivity index. The first sensitivity index reflects the sensitivity of the keywords and other words in the document combined.
[0050] Second, a second sensitivity index is calculated based on a pre-set symbol library. The data content sensitivity detection sub-model can extract geological symbols from the terminal geoscientific literature data. Geological symbols are graphics or symbols used in the geological field to represent specific geological phenomena, rock types, minerals, etc. Specifically, geological symbols can be extracted based on the ResNet-50 model. Subsequently, the extracted geological symbols are compared with the pre-set symbol library to determine the target geological symbols contained in the symbol extraction results. The pre-set symbol library contains various sensitive geological symbols, such as mineral symbols, special stratigraphic markers, exploration well markers, military sensitive area symbols, and critical infrastructure markers. Based on the frequency of occurrence of the target geological symbols, a second sensitivity index of the terminal geoscientific literature data can be calculated. For example, if one "uranium ore symbol" is detected, the sensitivity increases by 5 points; if three "military restricted area symbols" appear in the same image, the sensitivity directly triggers the high-risk threshold.
[0051] Third, the third sensitivity index is calculated based on a pre-set geological key coordinate library. First, the coordinate format corresponding to the terminal geoscientific literature data is determined. If the coordinate format is not a standard format, a coordinate transformation tool is used to convert it to standard coordinates, obtaining the transformation result. The coordinate transformation tool supports automatic recognition and conversion of multiple coordinate systems such as WGS84 and CGCS2000, and the standard coordinate format facilitates subsequent matching and calculation. Next, based on the pre-set geological key coordinate library, the target geological key coordinates contained in the coordinate transformation result are determined. The pre-set geological key coordinate library contains coordinates of various important geological locations, such as coordinates of large mineral deposits and geologically hazardous areas. The third sensitivity index of the terminal geoscientific literature data is calculated based on the target geological key coordinates. For example, it can be calculated based on factors such as the number of target geological key coordinates and their correlation with important geological regions. If the terminal geoscientific literature data contains multiple coordinates matching the target geological key coordinates, or if these coordinates are highly correlated with important geological regions, the third sensitivity index can be improved.
[0052] It should be noted that the calculation of the above sensitivity indicators does not distinguish the order. If the preset database includes a preset keyword library, a preset symbol library, and a preset geological key coordinate library, then the above three sensitivity indicators can be calculated simultaneously.
[0053] Optionally, in this embodiment, calculating the behavioral risk index corresponding to the target storage location using the behavioral risk detection sub-model includes: inputting the target storage location into the storage location risk detection sub-model within the behavioral risk detection sub-model, and calculating the storage location risk coefficient, wherein the behavioral risk index includes the storage location risk coefficient; calculating the behavioral risk index corresponding to the behavioral baseline of the operation using the behavioral risk detection sub-model includes: obtaining the target operation record of the operator for the current date, inputting the target operation record and the behavioral baseline into the operation behavior anomaly detection sub-model within the behavioral risk detection sub-model, and calculating the behavioral deviation between the operation behavior indicated by the target operation record and the behavioral baseline, wherein the behavioral risk index includes the behavioral deviation; and calculating the behavioral risk index corresponding to the new copy judgment index parameter using the behavioral risk detection sub-model includes: inputting the new copy judgment index parameter into the file version diffusion detection sub-model within the behavioral risk detection sub-model, and calculating the file version diffusion degree corresponding to the terminal geoscientific literature data, wherein the behavioral risk index includes the file version diffusion degree.
[0054] In this embodiment, firstly, the behavioral risk index corresponding to the target storage location is calculated. Specifically, the previously determined target storage location information can be input into the storage location risk detection sub-model within the behavioral risk detection sub-model. The target storage location is the actual location where the terminal geoscientific literature data is stored, such as a folder on a local disk or a specific directory on a network storage server. The storage location risk detection sub-model can calculate the storage location risk coefficient based on the target storage location.
[0055] For example, in a write operation, the target storage location is a location within the terminal geoscientific literature data. In this case, the storage location risk detection sub-model can calculate the storage location risk coefficient as follows:
[0056]
[0057] Where L represents the storage location risk coefficient, k can be 0.5, and d represents the storage path depth of the terminal geoscientific literature data, which is determined according to the target storage location.
[0058] During read operations, the storage location risk detection sub-model can calculate the storage location risk coefficient in the following way:
[0059] Storing data on an external USB flash drive carries a risk factor of A; storing it on an encrypted hard drive carries a risk factor of B; storing it in the cloud carries a risk factor of C, and so on. A, B, and C can be determined based on actual needs, with A being higher than B and C. This is because USB flash drives are easily lost or taken away from the work environment, and if the flash drive is lost, the data could be directly leaked. Therefore, when it is detected that geoscientific literature data is stored on a USB flash drive, the risk factor for the storage location can be increased.
[0060] Second, calculate the behavioral risk indicators corresponding to the operational behavior baseline. Specifically, obtain the target operation record for the current date. The target operation record contains various operational information of the operator on the terminal geoscientific literature data on that day, such as the number of read operations and write operations to date. Subsequently, the target operation record and the pre-generated operational behavior baseline are input into the operational behavior anomaly detection sub-model within the behavioral risk detection sub-model. The operational behavior anomaly detection sub-model can compare the operational behavior indicated by the target operation record with the operational behavior baseline to calculate the behavioral deviation degree. The behavioral deviation degree reflects the degree of deviation of the current operational behavior from the normal operational mode. The greater the deviation degree, the more abnormal the operational behavior, and the higher the potential risk. This deviation degree serves as one of the behavioral risk indicators.
[0061] Third, calculate the behavioral risk indicators corresponding to the new copy judgment index parameters. Specifically, input the new copy judgment index parameters obtained above into the document version diffusion detection sub-model within the behavioral risk detection sub-model. The new copy judgment index parameters reflect whether there are new document copies in the terminal geoscientific literature data. The document version diffusion detection sub-model can calculate the document version diffusion degree corresponding to the terminal geoscientific literature data based on the new copy judgment index parameters. The document version diffusion degree reflects the version diffusion of the terminal geoscientific literature data; the higher the diffusion degree, the greater the diffusion degree.
[0062] For example, the file version diffusion detection sub-model can calculate the file version diffusion as follows:
[0063] V = 1 - e (-λ*n) ;
[0064] Where V represents the file version diffusion degree, λ = 0.1, and n represents the indicator parameter for judging new copies (i.e., the number of file copies).
[0065] Optionally, in this embodiment of the application, when the operation instruction is a read instruction, the target operation behavior further includes a read operation behavior; determining the operation index parameter based on the target operation behavior includes: obtaining the original storage location corresponding to the terminal geoscientific literature data based on the read operation behavior, and determining the path depth corresponding to the terminal geoscientific literature data based on the original storage location, wherein the operation index parameter includes the path depth; calculating the behavior risk index corresponding to the path depth through the behavior risk detection sub-model includes: inputting the path depth into the path depth risk detection sub-model in the behavior risk detection sub-model, and calculating the path risk coefficient, wherein the behavior risk index includes the path risk coefficient.
[0066] In this embodiment, when the operation instruction is a read instruction, the target operation behavior includes a read operation behavior in addition to the previously mentioned storage operation behavior, historical operation behavior, and version diffusion operation behavior. At this time, additional operation indicator parameters can be determined based on the read operation behavior, and a behavior risk indicator can be further calculated based on these parameters to more comprehensively assess the risk of reading terminal geoscientific literature data. Specifically, based on the read operation behavior, the original storage location corresponding to the terminal geoscientific literature data is obtained. The original storage location refers to the actual starting location where the file is stored in the terminal geoscientific literature data. Next, based on the original storage location, the path depth corresponding to the terminal geoscientific literature data is determined. Path depth refers to the number of directory levels traversed from the root directory of the storage system (or a predefined starting directory) to the directory where the file is located. Path depth reflects the degree of nesting of the file in the storage system; the greater the path depth, the more difficult it is for the file to be directly accessed and managed, potentially posing a certain security risk. When geoscientific literature data is hidden in multiple subfolders (e.g., "Geological Data / 2024 / Exploration Projects / Confidential / Uranium Data.docx"), it is more likely to be overlooked in terms of access control settings or monitoring (some security systems, to save resources, only monitor the first three levels of directories by default, and deeper files may escape real-time scanning). Attackers may exploit complex paths to conceal their theft activities. Therefore, the deeper the path, the greater the risk. Subsequently, the previously determined path depth is input into the path depth risk detection sub-model within the behavioral risk detection sub-model. The path depth risk detection sub-model can calculate the path risk coefficient based on the path depth.
[0067] Specifically, the path depth risk detection sub-model can calculate the path risk coefficient in the following way:
[0068]
[0069] Where P represents the path risk coefficient, k can be 0.5, and D represents the original path depth of the terminal geoscientific literature data.
[0070] Optionally, in the case that the operation instruction is a write instruction, after step 101, the method further includes: identifying whether the terminal geoscientific literature data is a newly created file; when the terminal geoscientific literature data is not a newly created file, performing an incremental scan on the terminal geoscientific literature data based on a differential scanning algorithm to obtain an incremental scan result; correspondingly, after determining the operation index parameters according to the target operation behavior, the method further includes: calculating the operation risk level corresponding to the terminal geoscientific literature data based on the operation index parameters and the incremental scan result through the dynamic risk assessment model.
[0071] In this embodiment, when the operation instruction is a write instruction, it indicates that a write operation is to be performed on the terminal geoscientific literature data. To avoid performing a full scan after the write operation, this embodiment introduces a differential scanning algorithm, which can greatly improve scanning efficiency. First, the status of the terminal geoscientific literature data can be determined to distinguish between newly created and non-new files. Specifically, this can be determined by checking the file's metadata (such as creation time, file identifier, etc.) or the file system records. If the file has no historical records in the system, or its creation time is close to the current operation time, it is determined to be a newly created file; otherwise, it is determined to be a non-new file.
[0072] When it's determined that the terminal geoscientific literature data is not a newly created file, the current version and the previous version (or baseline version) of the file can be obtained, and then a differential scanning algorithm can be used to scan these two versions. During the scanning process, the algorithm can record the parts of the file that have changed, including additions, deletions, and modifications, ultimately obtaining incremental scan results. For example, if a paragraph in the file is modified, the algorithm can mark the specific location of the paragraph and the content before and after the modification. A differential scanning algorithm is a technique used to compare differences between different versions of a file. It can quickly locate the parts of the file that have changed, rather than comparing the entire file byte by byte, thus improving scanning efficiency. Common differential scanning algorithms include hash-based comparison and byte-stream-based difference detection.
[0073] Subsequently, the operational indicator parameters and incremental scan results are input into the dynamic risk assessment model, which assesses the risk of only the newly added part.
[0074] This application embodiment introduces an incremental scanning step for non-new files, which can more accurately and quickly assess the risk of write operations, while greatly reducing system resource consumption and improving assessment efficiency.
[0075] Optionally, in this embodiment of the application, step 103, "determining the security mechanism corresponding to the terminal geoscientific literature data based on the operational risk level," includes: determining the target file category corresponding to the terminal geoscientific literature data; calling the risk threshold list corresponding to the target file category; and determining the security mechanism corresponding to the terminal geoscientific literature data based on the risk threshold list and the operational risk level. The security mechanism is at least one of a release mechanism, an encryption mechanism, an operation blocking mechanism, and an alarm mechanism.
[0076] In this embodiment, different terminal geoscientific literature data may have different levels of importance and sensitivity, and classifying them helps to formulate more precise security strategies. For example, some documents may contain core geological exploration data and belong to the highly confidential category; while other documents may be ordinary geological reports with relatively low sensitivity. Therefore, when determining the security mechanism for terminal geoscientific literature data based on operational risk levels, the target document category of the terminal geoscientific literature data can be determined first. Here, the target document category can be in the form of a two-level category. The first level is divided into a three-level framework of regional geology, mineral geology, and engineering geology; the second level is divided into nine sub-fields such as basic geology, energy minerals, and metallic minerals. Different risk threshold lists can be pre-set for different document categories (e.g., the risk coefficient of mineral geoscientific literature data is higher than that of regional geology). The risk threshold list contains security mechanism recommendations corresponding to different operational risk levels. For the same operational risk level, different security mechanisms can be determined for different target document categories.
[0077] After determining the target file category, the corresponding risk threshold list can be retrieved from a pre-stored list library. The previously calculated operation risk level is matched against the risk threshold list. Based on the matching result, a corresponding security mechanism suggestion is obtained from the risk threshold list. The security mechanism can be at least one of the following: a permission mechanism, an encryption mechanism, an operation blocking mechanism, and an alarm mechanism. Specifically: Permission mechanism: If the operation risk level is low, a permission mechanism can be selected, allowing normal write operations on the terminal geoscientific literature data without additional security restrictions. Encryption mechanism: When the operation risk level is in the medium range, an encryption mechanism can be used to ensure the security of the file data. After the write operation is completed, the file is encrypted, and only authorized personnel can decrypt and access it. Operation blocking mechanism: If the operation risk level is high, reaching the high-risk level, an operation blocking mechanism can be activated to directly block the current write operation and prevent potential security threats. Alarm mechanism: Regardless of the operation risk level, an alarm mechanism can be enabled simultaneously. When the operation risk level exceeds a certain level, an alarm message can be sent to the security management personnel to remind them of the potential security risks of the operation.
[0078] This application's embodiments determine security mechanisms by combining target file categories and risk threshold lists, enabling personalized security protection. Different file categories have different security requirements; using targeted risk threshold lists allows for more accurate risk assessment and selection of appropriate security mechanisms, improving the flexibility and effectiveness of security protection.
[0079] Furthermore, in this embodiment, when an operator operates on multiple files simultaneously, it can also determine whether the file is a geological file based on its extension (e.g., .gdb / .sgy). If it is a geological file, it is automatically marked as high priority and inserted at the head of the processing queue for priority processing.
[0080] When the terminal geoscientific literature data being processed by operators is in SEG-Y seismic data format, the data can be analyzed to determine its sensitivity indicators. Specifically, the header information (such as number and coordinates) of each data segment is quickly read, the coordinate format is automatically identified and converted, and then the terminal geoscientific literature data is divided into smaller blocks and processed simultaneously using multiple threads. Each thread calls the data content sensitivity detection sub-model, thereby improving the calculation efficiency of the sensitivity indicators for the terminal geoscientific literature data.
[0081] When operators manipulate geoscientific literature data on the terminal, which consists of MapGIS files, the topological relationships within these files are directly related to data leakage. These files meticulously record the spatial locations and logical relationships of geological elements (such as mineral areas, fault lines, and engineering zones). Therefore, in addition to detecting sensitivity indicators through the data content sensitivity detection sub-model, further detection can be conducted using the following methods. For example, a polygon file might precisely mark the distribution range of a strategic mineral, while a line file might reveal the direction of geological structures. If this information is leaked, it could expose national resource allocation or key geological strategic points. When operators manipulate this type of geoscientific literature data, they can analyze the topological relationships between points, lines, and polygons in the file (such as regional inclusion and line segment connections) to identify hidden sensitive spatial relationships in the map (such as the overlap between a mining area and a military restricted area). Then, combined with the sensitive area matching algorithm in the spatial rule base, higher-level security measures (such as prohibiting export or encrypted storage) can be automatically triggered to prevent attackers from bypassing traditional content detection by tampering with map elements (such as moving coordinate points) or splitting sensitive areas, thereby plugging security vulnerabilities caused by spatial data leakage. Specifically, the system first reads the coordinate data of points, lines, and polygons from the MapGIS file (such as the location of each turning point of a line and which closed line segments make up a polygon). Then, it intelligently analyzes the connection relationships between these graphics. For example, it automatically identifies which line ends should be connected and which polygon areas are adjacent or contain each other. Then, through a sensitive area matching algorithm, it performs sensitive area matching on the analyzed regional relationships to determine whether the coordinate points fall into the preset sensitive areas. The fourth sensitivity index is obtained based on the sensitive area matching algorithm.
[0082] Furthermore, as Figure 1 In terms of specific implementation, this application provides a device for preventing the leakage of terminal geoscientific literature data, such as... Figure 2 As shown, the device includes:
[0083] The model invocation module is used to invoke the dynamic risk assessment model in response to operation instructions on terminal geoscientific literature data, wherein the operation instructions are read instructions or write instructions;
[0084] The calculation module is used to obtain the target operation behavior associated with the operation instruction, determine the operation index parameters according to the target operation behavior, and calculate the operation risk level corresponding to the terminal geoscience literature data based on the operation index parameters and the terminal geoscience literature data through the dynamic risk assessment model.
[0085] The security mechanism determination module is used to determine the security mechanism corresponding to the terminal geoscientific literature data based on the operational risk level, and generate the operation result corresponding to the operation instruction according to the security mechanism.
[0086] Optionally, the target operation behavior includes at least one of storage operation behavior, historical operation behavior corresponding to the operation instruction, and version diffusion operation behavior; the calculation module is used for:
[0087] Based on the storage operation behavior, the target storage location corresponding to the terminal geoscientific literature data is determined, wherein the operation index parameters include the target storage location; and / or,
[0088] Based on the historical operation behaviors corresponding to the operation instructions, a behavioral baseline for the operation is generated, wherein the operation indicator parameters include the behavioral baseline for the operation; and / or,
[0089] Based on the version diffusion operation behavior, it is determined whether the terminal geoscientific literature data corresponds to a newly added file copy, and the determination result is used as the new copy judgment index parameter, wherein the operation index parameter includes the new copy judgment index parameter.
[0090] Optionally, the dynamic risk assessment model includes a data content sensitivity detection sub-model and a behavioral risk detection sub-model; the calculation module is further used for:
[0091] The sensitivity index of the terminal geoscientific literature data is calculated based on a preset database using the data content sensitivity detection sub-model. The preset database includes at least one of a preset keyword database, a preset symbol database, and a preset geological key coordinate database.
[0092] The behavioral risk detection sub-model is used to calculate the behavioral risk index corresponding to the operational indicator parameter.
[0093] Based on the sensitivity index and the behavioral risk index, the operational risk level corresponding to the terminal geoscientific literature data is determined.
[0094] Optionally, the computing module is further configured to:
[0095] Using the data content sensitivity detection sub-model, based on the preset keyword library, the target keywords contained in the terminal geoscience literature data are identified, and the scores and weights corresponding to the target keywords are obtained.
[0096] Based on the scores and weights corresponding to the target keywords, a first score corresponding to the target keywords is calculated, and a second score is calculated based on the remaining parts of the terminal geoscience literature data excluding the target keywords.
[0097] The first score and the second score are summed to obtain the total score corresponding to the terminal geoscientific literature data, and the ratio of the total score to the total number of words in the terminal geoscientific literature data is calculated. The ratio is used as the first sensitivity index, wherein the sensitivity index includes the first sensitivity index.
[0098] The computing module is also used for:
[0099] The data content sensitivity detection sub-model is used to extract geological symbols contained in the terminal geoscience literature data, and the target geological symbols contained in the symbol extraction results are determined based on the preset symbol library.
[0100] Based on the frequency of occurrence of the target geological symbols, a second sensitivity index is calculated for the terminal geoscientific literature data, wherein the sensitivity index includes the second sensitivity index;
[0101] The computing module is also used for:
[0102] Determine the coordinate format corresponding to the terminal geoscientific literature data. If the coordinate format is not a standard format, call the coordinate transformation tool to convert the coordinates corresponding to the terminal geoscientific literature data into standard coordinates to obtain the coordinate transformation result.
[0103] Based on the preset geological key coordinate library, the target geological key coordinates contained in the coordinate transformation result are determined, and based on the target geological key coordinates, the third sensitivity index of the terminal geoscientific literature data is calculated, wherein the sensitivity index includes the third sensitivity index.
[0104] Optionally, the computing module is further configured to:
[0105] The target storage location is input into the storage location risk detection sub-model in the behavior risk detection sub-model to calculate the storage location risk coefficient, wherein the behavior risk index includes the storage location risk coefficient;
[0106] The computing module is also used for:
[0107] Obtain the target operation record of the operator for the current date, input the target operation record and the behavior baseline into the operation behavior anomaly detection sub-model in the behavior risk detection sub-model, and calculate the behavior deviation degree between the operation behavior indicated by the target operation record and the behavior baseline, wherein the behavior risk index includes the behavior deviation degree;
[0108] The computing module is also used for:
[0109] The parameters of the newly added copy judgment index are input into the file version diffusion detection sub-model in the behavior risk detection sub-model to calculate the file version diffusion degree corresponding to the terminal geoscientific literature data, wherein the behavior risk index includes the file version diffusion degree.
[0110] Optionally, if the operation instruction is a read instruction, the target operation behavior also includes a read operation behavior;
[0111] The computing module is also used for:
[0112] Based on the read operation behavior, the original storage location corresponding to the terminal geoscientific literature data is obtained, and the path depth corresponding to the terminal geoscientific literature data is determined based on the original storage location, wherein the operation index parameter includes the path depth;
[0113] The computing module is also used for:
[0114] The path depth is input into the path depth risk detection sub-model in the behavior risk detection sub-model to calculate the path risk coefficient, wherein the behavior risk index includes the path risk coefficient.
[0115] Optionally, when the operation instruction is a write instruction, the device further includes an incremental scanning module; the incremental scanning module is used to:
[0116] In response to the operation command on the terminal geoscience literature data, after calling the dynamic risk assessment model, it identifies whether the terminal geoscience literature data is a newly created file. When the terminal geoscience literature data is not a newly created file, it performs an incremental scan on the terminal geoscience literature data based on the differential scanning algorithm to obtain the incremental scan result.
[0117] Accordingly, the computing module is also used for:
[0118] After determining the operational indicator parameters based on the target operational behavior, the operational risk level corresponding to the terminal geoscientific literature data is calculated based on the operational indicator parameters and the incremental scanning results through the dynamic risk assessment model.
[0119] Optionally, the security mechanism determination module is used to:
[0120] The target file category corresponding to the terminal geoscientific literature data is determined, and the risk threshold list corresponding to the target file category is invoked. Based on the risk threshold list and the operation risk level, the security mechanism corresponding to the terminal geoscientific literature data is determined, wherein the security mechanism is at least one of the following: a release mechanism, an encryption mechanism, an operation blocking mechanism, and an alarm mechanism.
[0121] It should be noted that other corresponding descriptions of the functional units involved in the terminal geoscientific literature data leakage prevention device provided in this application embodiment can be found in the following references. Figure 1 The corresponding descriptions in the method will not be repeated here.
[0122] This application also provides a computer device, which may specifically be a personal computer, a server, a network device, etc. Figure 3 As shown, the computer device includes a bus, a processor, memory, and a communication interface, and may also include an input / output interface and a display device. The processor provides computing and control capabilities. The memory includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database stores location information. The network interface allows communication with external terminals via a network connection. When the computer program is executed by the processor, it implements the steps in the various method embodiments.
[0123] Those skilled in the art will understand that Figure 3 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0124] In one embodiment, a computer-readable storage medium is provided, which may be non-volatile or volatile, having stored thereon a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0125] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0126] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0127] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0128] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0129] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A method for preventing the leakage of terminal geoscientific literature data, characterized in that, include: In response to an operation command on the terminal geoscientific literature data, a dynamic risk assessment model is invoked, wherein the operation command is a read command or a write command; The target operation behavior associated with the operation instruction is obtained, the operation index parameters are determined according to the target operation behavior, and the operation risk level corresponding to the terminal geoscience literature data is calculated based on the operation index parameters and the terminal geoscience literature data through the dynamic risk assessment model. Based on the operational risk level, the security mechanism corresponding to the terminal geoscientific literature data is determined, and the operation result corresponding to the operation instruction is generated according to the security mechanism. The dynamic risk assessment model includes a data content sensitivity detection sub-model and a behavioral risk detection sub-model; the calculation of the operational risk level corresponding to the terminal geoscientific literature data based on the operational indicator parameters and the terminal geoscientific literature data through the dynamic risk assessment model includes: The sensitivity index of the terminal geoscientific literature data is calculated based on a preset database using the data content sensitivity detection sub-model. The preset database includes at least one of a preset keyword database, a preset symbol database, and a preset geological key coordinate database. The behavioral risk detection sub-model is used to calculate the behavioral risk index corresponding to the operational indicator parameter. Based on the sensitivity index and the behavioral risk index, the operational risk level corresponding to the terminal geoscientific literature data is determined.
2. The method according to claim 1, characterized in that, The target operation behavior includes at least one of storage operation behavior, historical operation behavior corresponding to the operation instruction, and version diffusion operation behavior; the step of determining operation indicator parameters based on the target operation behavior includes: Based on the storage operation behavior, the target storage location corresponding to the terminal geoscientific literature data is determined, wherein the operation index parameters include the target storage location; and / or, Based on the historical operation behaviors corresponding to the operation instructions, a behavioral baseline for the operation is generated, wherein the operation indicator parameters include the behavioral baseline for the operation; and / or, Based on the version diffusion operation behavior, it is determined whether the terminal geoscientific literature data corresponds to a newly added file copy, and the determination result is used as the new copy judgment index parameter, wherein the operation index parameter includes the new copy judgment index parameter.
3. The method according to claim 2, characterized in that, The sensitivity index of the terminal geoscientific literature data is calculated based on a preset keyword database using the data content sensitivity detection sub-model, including: Using the data content sensitivity detection sub-model, based on the preset keyword library, the target keywords contained in the terminal geoscience literature data are identified, and the scores and weights corresponding to the target keywords are obtained. Based on the scores and weights corresponding to the target keywords, a first score corresponding to the target keywords is calculated, and a second score is calculated based on the remaining parts of the terminal geoscience literature data excluding the target keywords. The first score and the second score are summed to obtain the total score corresponding to the terminal geoscientific literature data, and the ratio of the total score to the total number of words in the terminal geoscientific literature data is calculated. The ratio is used as the first sensitivity index, wherein the sensitivity index includes the first sensitivity index. The sensitivity index of the terminal geoscientific literature data is calculated based on a preset symbol library using the data content sensitivity detection sub-model, including: The data content sensitivity detection sub-model is used to extract geological symbols contained in the terminal geoscience literature data, and the target geological symbols contained in the symbol extraction results are determined based on the preset symbol library. Based on the frequency of occurrence of the target geological symbols, a second sensitivity index is calculated for the terminal geoscientific literature data, wherein the sensitivity index includes the second sensitivity index; The sensitivity index of the terminal geoscientific literature data is calculated based on a preset geological key coordinate database using the data content sensitivity detection sub-model, including: Determine the coordinate format corresponding to the terminal geoscientific literature data. If the coordinate format is not a standard format, call the coordinate transformation tool to convert the coordinates corresponding to the terminal geoscientific literature data into standard coordinates to obtain the coordinate transformation result. Based on the preset geological key coordinate library, the target geological key coordinates contained in the coordinate transformation result are determined, and based on the target geological key coordinates, the third sensitivity index of the terminal geoscientific literature data is calculated, wherein the sensitivity index includes the third sensitivity index.
4. The method according to claim 2, characterized in that, The behavioral risk detection sub-model calculates the behavioral risk index corresponding to the target storage location, including: The target storage location is input into the storage location risk detection sub-model in the behavior risk detection sub-model to calculate the storage location risk coefficient, wherein the behavior risk index includes the storage location risk coefficient; The behavioral risk detection sub-model calculates the behavioral risk index corresponding to the behavioral baseline of the operation, including: Obtain the target operation record of the operator for the current date, input the target operation record and the behavior baseline into the operation behavior anomaly detection sub-model in the behavior risk detection sub-model, and calculate the behavior deviation degree between the operation behavior indicated by the target operation record and the behavior baseline, wherein the behavior risk index includes the behavior deviation degree; The behavioral risk detection sub-model calculates the behavioral risk indicators corresponding to the new copy judgment indicator parameters, including: The parameters of the newly added copy judgment index are input into the file version diffusion detection sub-model in the behavior risk detection sub-model to calculate the file version diffusion degree corresponding to the terminal geoscientific literature data, wherein the behavior risk index includes the file version diffusion degree.
5. The method according to any one of claims 2 to 4, characterized in that, When the operation instruction is a read instruction, the target operation behavior also includes a read operation behavior; The step of determining the operation index parameters based on the target operation behavior includes: Based on the read operation behavior, the original storage location corresponding to the terminal geoscientific literature data is obtained, and the path depth corresponding to the terminal geoscientific literature data is determined based on the original storage location, wherein the operation index parameter includes the path depth; The behavioral risk detection sub-model calculates the behavioral risk index corresponding to the path depth, including: The path depth is input into the path depth risk detection sub-model in the behavior risk detection sub-model to calculate the path risk coefficient, wherein the behavior risk index includes the path risk coefficient.
6. The method according to claim 1, characterized in that, When the operation instruction is a write instruction, after invoking the dynamic risk assessment model in response to the operation instruction on the terminal geoscientific literature data, the method further includes: The system identifies whether the terminal geoscientific literature data is a newly created file. When the terminal geoscientific literature data is not a newly created file, it performs an incremental scan on the terminal geoscientific literature data based on a differential scanning algorithm to obtain the incremental scan result. Accordingly, after determining the operation index parameters based on the target operation behavior, the method further includes: Based on the operational indicator parameters and the incremental scanning results, the operational risk level corresponding to the terminal geoscience literature data is calculated using the dynamic risk assessment model. The security mechanism for determining the terminal geoscientific literature data based on the operational risk level includes: The target file category corresponding to the terminal geoscientific literature data is determined, and the risk threshold list corresponding to the target file category is invoked. Based on the risk threshold list and the operation risk level, the security mechanism corresponding to the terminal geoscientific literature data is determined, wherein the security mechanism is at least one of the following: a release mechanism, an encryption mechanism, an operation blocking mechanism, and an alarm mechanism.
7. A device for preventing the leakage of terminal geoscientific literature data, characterized in that, include: The model invocation module is used to invoke the dynamic risk assessment model in response to operation instructions on terminal geoscientific literature data, wherein the operation instructions are read instructions or write instructions; The calculation module is used to obtain the target operation behavior associated with the operation instruction, determine the operation index parameters according to the target operation behavior, and calculate the operation risk level corresponding to the terminal geoscience literature data based on the operation index parameters and the terminal geoscience literature data through the dynamic risk assessment model. The security mechanism determination module is used to determine the security mechanism corresponding to the terminal geoscientific literature data based on the operation risk level, and generate the operation result corresponding to the operation instruction according to the security mechanism; The dynamic risk assessment model includes a data content sensitivity detection sub-model and a behavioral risk detection sub-model; the calculation module is also used for: The sensitivity index of the terminal geoscientific literature data is calculated based on a preset database using the data content sensitivity detection sub-model. The preset database includes at least one of a preset keyword database, a preset symbol database, and a preset geological key coordinate database. The behavioral risk detection sub-model is used to calculate the behavioral risk index corresponding to the operational indicator parameter. Based on the sensitivity index and the behavioral risk index, the operational risk level corresponding to the terminal geoscientific literature data is determined.
8. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the method of any one of claims 1 to 6.
9. A computer device, comprising a storage medium, a processor, and a computer program stored on the storage medium and executable on the processor, characterized in that, When the processor executes the computer program, it implements the method of any one of claims 1 to 6.
Citation Information
Patent Citations
Electronic archive data security system and method
CN119249483A
Systems and methods for detecting security blind spots
US10091231B1