Sensitive information leakage monitoring method and device, equipment, medium and program product
Through dynamically updated sensitive information search terms and associated user analysis, the accuracy problem of sensitive information leakage monitoring in the existing technology is solved, real-time and accurate monitoring of sensitive information is achieved, and false alarms and missed alarms are reduced.
Patent Information
- Application Number
- CN202510625600.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-09-19
AI Technical Summary
In existing sensitive information leakage monitoring methods, static search term matching cannot adapt to changes in sensitive information, resulting in low monitoring accuracy and a high rate of missed reports and false positives.
By determining the target search terms based on dynamically updated sensitive information search terms and initial search terms, and combining the association relationship of user IDs, dynamic updates and precise searches are performed to screen out risky users and their associated users, and monitor sensitive information.
It achieves real-time and accurate monitoring of sensitive information, reduces the number of retrieval objects, improves the accuracy and efficiency of monitoring, and reduces the false alarm and missed alarm rates.
Smart Images

Figure CN120671171A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a sensitive information leakage monitoring method, device, equipment, medium and program product. Background Art
[0002] With the development of the Internet, open source code has become a mainstream, but open source code may contain sensitive internal information of the enterprise, such as: core technology code, server-related information, database account and password, interface private key-related information, etc. The leakage of this sensitive information may cause great harm to the enterprise.
[0003] In existing sensitive information leakage monitoring methods, open source code is searched using predetermined search terms. If the same search terms are found, it is considered that sensitive information has been leaked in the open source code.
[0004] However, static search term matching cannot adapt to changes in sensitive information and has great limitations. It will have a high rate of missed reports, which reduces monitoring accuracy. If fuzzy search is used, there will be a lot of false positives in the case of a large amount of code, which also reduces monitoring accuracy. Summary of the Invention
[0005] The present invention provides a sensitive information leakage monitoring method, device, equipment, medium and program product, which are used to solve the problem of low accuracy of sensitive information leakage monitoring in the prior art.
[0006] In a first aspect, the present invention provides a sensitive information leakage monitoring method, comprising: Determining target search terms based on the sensitive information search terms updated in the current monitoring process and the initial search terms; the initial search terms are determined based on the target sample code set containing sensitive information; the sensitive information search terms updated in the current monitoring process are determined based on the target search terms and supplementary search terms from the previous round of monitoring process; Based on the target search term, searching the set of code files to be monitored to obtain the initial code files containing sensitive information; Based on the target search term, all code files uploaded by the monitoring object set are searched to obtain target code files containing sensitive information; the monitoring object set includes the risk user ID that uploaded the initial code file and the associated user ID of the risk user ID.
[0007] In one embodiment, the target sample code is implemented in the following manner: Sort multiple user IDs to be monitored according to the time sequence of the last code file uploaded by the user ID to obtain a user sequence to be monitored; Select the first N user IDs from the sequence of users to be monitored as candidate user IDs; Select the K most recently uploaded code files from the code files uploaded by each candidate user ID as the initial sample code; Based on the sensitive information search terms updated in the current monitoring process, multiple initial sample codes are searched to obtain a target sample code set containing sensitive information.
[0008] In one embodiment, the initial search term is implemented in the following manner: Performing word segmentation processing on each target sample code in the target sample code set containing sensitive information to obtain multiple word segments of each target sample code; Calculating the probability of each segmentation in the target sample code set according to the number of target sample codes containing segmentations, the number of times the segmentation appears in the target sample codes containing segmentations, the total number of target sample codes, and the total number of segmentations; Select the top M segmentations with the highest probability from multiple segmentations of each target sample code as candidate segmentations; Integrate each candidate participle of each target sample code with the remaining candidate participles to obtain an integrated search term for each candidate participle of each target sample code; the remaining candidate participles are the remaining candidate participles in the multiple candidate participles of the target sample code except the candidate participle; The integrated search terms of each candidate segmentation of each target sample code are merged into an initial search term.
[0009] In one embodiment, when integrating each candidate segmentation of each target sample code with the remaining candidate segmentations to obtain an integrated search term for each candidate segmentation of each target sample code, the following steps are performed for each candidate segmentation of each target sample code: Determine the leftmost character of the candidate word segmentation as the starting comparison character; Determine the position of the starting comparison character in each of the remaining candidate segmentations as the starting comparison position; Starting from the starting comparison position, determine the longest character string with the same characters at each consecutive position between the remaining candidate participles and the candidate participle; The shortest character string among the plurality of longest character strings is determined as an integrated search term of the candidate word segmentations.
[0010] In one embodiment, the associated user ID includes a first type of associated user ID, and the first type of associated user ID is determined in the following manner: The user ID that has updated the code file uploaded by the risky user ID is determined as the first type of associated user ID of the risky user ID.
[0011] In one embodiment, the associated user ID includes an associated user ID of a second type, and the associated user ID of the second type is determined in the following manner: The user ID to which the code file modified by the risky user ID belongs is determined as the second type of associated user ID of the risky user ID.
[0012] In one embodiment, the associated user ID includes an associated user ID of a third type, and the associated user ID of the third type is determined in the following manner: Determine a user ID that has appeared in any network address identical to the risk user ID as a candidate associated user ID; Calculate the similarity between each candidate associated user ID and the risk user ID based on the total size of the code files uploaded by the user ID, the frequency of the uploaded code files, and the IP address to which the code files were uploaded; The candidate associated user IDs whose similarity is greater than a preset threshold are determined as associated user IDs of the third type of the risky user ID.
[0013] In a second aspect, the present invention further provides a sensitive information leakage monitoring device, comprising: A search term generation module is configured to determine a target search term based on the sensitive information search term updated during the current monitoring process and the initial search term; the initial search term is determined based on a target sample code set containing sensitive information; the sensitive information search term updated during the current monitoring process is determined based on the target search term and the supplementary search term from the previous round of monitoring process; A first retrieval module is configured to search the set of code files to be monitored based on the target search term to obtain an initial code file containing sensitive information; The second retrieval module is used to search all code files uploaded by the monitoring object set based on the target search term to obtain target code files containing sensitive information; the monitoring object set includes the risk user ID that uploaded the initial code file and the associated user ID of the risk user ID.
[0014] In a third aspect, the present invention provides an electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of any of the above-described sensitive information leakage monitoring methods are implemented.
[0015] In a fourth aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of any of the above-mentioned sensitive information leakage monitoring methods are implemented.
[0016] In a fifth aspect, the present invention also provides a computer program product, which includes a computer program, which can be stored on a non-transitory computer-readable storage medium, and when the computer program is executed by the processor, implements the steps of any of the above-mentioned sensitive information leakage monitoring methods.
[0017] The sensitive information leakage monitoring method, device, equipment, medium and program product provided by the present invention determine the target search term based on dynamically updated sensitive information search terms and the initial search term determined by the target sample code containing sensitive information, realize continuous updating of the search term, so that it has semantic expansion capability while maintaining semantic accuracy, conducts precise search based on the target search term, obtains the initial code file containing sensitive information, and determines the risk user who leaks sensitive information on this basis. The risk user and its associated users are used as monitoring objects, which can ensure the accuracy of the search object and greatly reduce the number of search objects. Therefore, all code files uploaded by the monitoring object are searched based on the target search term to obtain the target code file containing sensitive information, thereby ensuring the efficiency and effect of the re-search, thereby realizing real-time and precise monitoring of sensitive information. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0019] Figure 1 It is a flow chart of module power consumption control during the startup phase provided by the present invention.
[0020] Figure 2 It is a structural diagram of the sensitive information leakage monitoring device provided by the present invention.
[0021] Figure 3 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION
[0022] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0023] The terms "first," "second," and the like in the present invention are used to distinguish similar objects and are not used to describe a particular order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the present invention can be implemented in orders other than those illustrated or described herein.
[0024] The following combination Figure 1-Figure 3 The sensitive information leakage monitoring method, apparatus, device, medium and program product provided by the present invention are described.
[0025] It should be noted that the sensitive information leakage monitoring method provided in the embodiment of the present invention is implemented based on the sensitive information leakage monitoring device.
[0026] The sensitive information leakage monitoring method provided by the embodiment of the present invention can realize the sensitive information leakage monitoring in the massive managed code uploaded by the hosting platform, such as the GitHub platform. The GitHub platform is a hosting platform for open source and private software projects. Of course, this method is not limited to the sensitive information leakage monitoring of the massive code of the hosting platform. The present invention is implemented through two major parts. In the first part, sample code is determined from all monitored code files in two directions: from the code file uploading user and whether the code file is an updated file. The target search term is determined based on the sample code. The risk user of sensitive information leakage is determined by the target search term and used as seed information. In the second part, the associated user is expanded based on the seed information to obtain the monitoring object of the second part, and the code files uploaded by the monitoring object are monitored. Finally, the code file with sensitive information leakage is determined, and then an early warning is issued based on the code file with sensitive information leakage. The first part serves as the basis of the second part, ensuring the monitoring efficiency and effect of the second part, thereby realizing real-time and accurate monitoring of sensitive information.
[0027] The embodiment of the present invention takes a sensitive information leakage monitoring device as an execution subject to describe a sensitive information leakage monitoring method.
[0028] Combine Figure 1 , Figure 1 It is a flow chart of the sensitive information leakage monitoring method provided by the present invention.
[0029] like Figure 1 As shown, the sensitive information leakage monitoring method includes the following steps: Step 101: Determine a target search term based on the sensitive information search term updated in the current monitoring process and the initial search term; Step 102: Based on the target search term, search the set of code files to be monitored to obtain the initial code files containing sensitive information; Step 103: Based on the target search term, all code files uploaded by the monitoring object set are searched to obtain target code files containing sensitive information.
[0030] Specifically, the first part is executed first. The first part is the full monitoring process. This process does not require search efficiency or recall, but only ensures that the searched managed code is accurately monitored. The first part is a basic process and does not produce the final monitoring results of the monitoring method provided by this invention. It only provides seed information for the subsequent second part.
[0031] Taking GitHub as an example, we need to monitor code files uploaded to GitHub. Because users always attach a user identifier (ID), such as their username, when uploading code files to GitHub, all user IDs that upload code files to GitHub form a set, the user set, which contains all the users to be monitored.
[0032] From the code files uploaded by the users to be monitored, multiple recently uploaded code files are selected as initial sample codes. Then, based on the sensitive information search terms updated in the current monitoring process, the initial sample codes are searched to obtain the code files containing sensitive information as the target sample codes. Then, through the analysis and processing of the target sample codes, accurate initial search terms can be obtained, and the initial search terms are merged with the sensitive information search terms updated in the current monitoring process to form the target search terms. The target search terms can accurately search out all code files containing sensitive information in the code files to be monitored.
[0033] It should be noted that if this is the first time the monitoring method provided by this embodiment is being executed, the sensitive information search term for the current monitoring process is entered by the user. This implementation method is the existing method and will not be described in detail. Since the first part is a basic process, the user will use more general terms such as "password" and "email" when setting the search term, rather than more specific terms. This ensures that the search term will appear in more code files.
[0034] If this is not the first time the monitoring method provided by this embodiment is being executed, the sensitive information search terms for this non-first round of monitoring are derived by combining the search terms from the previous monitoring round with the supplementary search terms. More specifically, the sensitive information search terms for this non-first round of monitoring are derived by combining the updated sensitive information search terms from the previous monitoring round, the initial search terms, and the supplementary search terms. Supplementary search terms are sensitive terms entered by the user before each monitoring round. Alternatively, sensitive terms can be periodically crawled and added to the sensitive information search terms as supplementary search terms.
[0035] Therefore, the sensitive information search term is a dynamic update process. Similarly, the target search term composed of the sensitive information search term and the initial search term is also a dynamic update process. The result of each round of update is the search term result.
[0036] Furthermore, based on the target search terms, all code files uploaded to GitHub, that is, the monitored code file set, can be searched. Existing mature precise search technology can be used to obtain the initial code files containing sensitive information.
[0037] The above completes the retrieval process of the first part. Record and submit the user ID to which the initial code file containing sensitive information belongs, that is, the user ID at risk of sensitive information leakage, and use it as seed information for the retrieval process of the second part. In other words, once an initial code file containing sensitive information is retrieved, then the file must have leaked sensitive information, but the file is not recorded after the first part is completed. Instead, only the user ID who uploaded the initial code file containing sensitive information is recorded and used as seed information for rapid and accurate monitoring of the subsequent second part. Because there may be multiple initial code files containing sensitive information provided by the same user ID, only one user ID needs to be recorded, which can greatly reduce the amount of data in the final result of the first part.
[0038] The second part is the key monitoring process. Based on the seed information obtained in the first part, the precise monitoring object is determined, and the monitored object is efficiently monitored for sensitive information leakage. This part is the output part of the monitoring results of this example.
[0039] Because the seed is a user who has actually leaked sensitive information, the possibility of this user leaking sensitive information again is extremely high. By searching for the seed information in the second part, the accuracy of the search objects in the second part can be guaranteed, and the number of search objects in the second part can be reduced, thereby achieving efficient and accurate monitoring of sensitive information leakage.
[0040] The expansion based on the risk user ID determined in the first part is an expansion process based on the association relationship between users. The associated user ID of the risk user ID can be obtained, and the risk user ID and its associated user ID are both used as monitoring objects.
[0041] Furthermore, all code files uploaded by the monitored target are obtained as search files. Based on the target search terms, these search files are searched. Existing, mature precision search techniques can be used to obtain target code files containing sensitive information. If any of the search terms are present, the code file must be identified as a target code file with sensitive information leakage. Furthermore, fuzzy search can be used based on the data volume of the search files, further improving the comprehensiveness of sensitive information leakage monitoring.
[0042] This completes the second part of the retrieval process and outputs the actual output results of the current monitoring process, allowing for alerts based on target code files containing sensitive information. Furthermore, each target code file for which an alert is issued can be recorded. The next time an alert is issued, previously issued target code files will no longer be issued, with only newly released target code files containing sensitive information leaked being issued. This can further reduce the number of alerts.
[0043] As can be seen from the above, the monitoring method of this embodiment is implemented in two major parts. Taking GitHub as an example, the first part is the process of searching all code files hosted on GitHub. Due to the large amount of data, the search is slow. Therefore, an off-peak search method is used. For example, this part of the search is performed between 11 PM and 5 AM each day. If all code files cannot be retrieved in one day, the search can be continued the next day until all files are retrieved. After the search is completed, the search can be repeated, or a new round of searches can be performed after a period of time (such as one month, depending on actual needs). The purpose of the first part is to provide seed information for the actual monitoring process. Therefore, its execution efficiency and the real-time nature of the search results are not required. The second part is to determine the currently monitored code object based on the seed information and conduct a rapid search of the code object. The code objects monitored in this process are obtained based on the seed information, not the entire amount of hosted code. At the same time, the seed information is very accurate and includes sensitive information. Therefore, the number of code objects can be significantly reduced while ensuring the accuracy of the monitored objects. This allows the second part of the search to be completed in a short time and with high monitoring accuracy, thus achieving real-time and accurate monitoring of sensitive information. The second part can be executed daily, or bi-monthly, or whenever monitoring is needed.
[0044] Through the linkage of the two parts, the amount of code for final monitoring is reduced, the retrieval efficiency is improved, and the accuracy of the monitored objects and the monitoring effect are guaranteed.
[0045] The sensitive information leakage monitoring method provided by the present invention determines the target search term based on dynamically updated sensitive information search terms and the initial search term determined by the target sample code containing sensitive information, realizes continuous updating of the search term, and makes it have semantic expansion capability while maintaining semantic accuracy. It performs precise search based on the target search term to obtain the initial code file containing sensitive information, and determines the risk user who leaks sensitive information on this basis. The risk user and its associated users are used as monitoring objects, which can ensure the accuracy of the search object and greatly reduce the number of search objects. Therefore, all code files uploaded by the monitoring object are searched based on the target search term to obtain the target code file containing sensitive information, thereby ensuring the efficiency and effect of the re-search, thereby realizing real-time and precise monitoring of sensitive information.
[0046] In some embodiments, before obtaining the initial search term, it is necessary to filter out target sample codes from the code file uploaded by the user ID to be monitored. The target sample codes are obtained by: Sort multiple user IDs to be monitored according to the time sequence of the last code file uploaded by the user ID to obtain a user sequence to be monitored; Select the first N user IDs from the sequence of users to be monitored as candidate user IDs; Select the K most recently uploaded code files from the code files uploaded by each candidate user ID as the initial sample code; Based on the sensitive information search terms updated in the current monitoring process, multiple initial sample codes are searched to obtain a target sample code set containing sensitive information.
[0047] Specifically, the user set that needs to be monitored is composed of the user IDs marked by users when uploading their codes to GitHub.
[0048] Sort all user IDs in the user set from recent to farthest based on the time when the user ID last uploaded a code file to obtain a user sequence to be monitored.
[0049] First, select the first N user IDs from the user sequence to be monitored as candidate user IDs, or select the first x1% user IDs as candidate user IDs. N or x1 are both preset values. x1 can be set to 30. The result obtained by multiplying the proportion value by the total number of user IDs can be used as the value of N.
[0050] Then, the most recently uploaded K code files are selected from the code files uploaded by each candidate user ID as the initial sample code. Alternatively, the first x2% of the most recently uploaded code files can be selected as the initial sample code. K or x2 are both preset values. x2 can be set to 10. The result obtained by multiplying the ratio value by the total number of code files uploaded by each candidate user ID can be used as the value of K.
[0051] The code files here are selected from different files. That is, if a code file has multiple versions uploaded, such as version 1.0 and version 2.0, these two versions are considered a single code file. The file with the most recent upload time is selected. This means that the above steps select a certain percentage of completely independent (non-iterative) code files from each candidate user ID, ensuring that the selected code files fully reflect the business operations covered by the candidate user's code.
[0052] After execution, you can get an initial sample code set, which covers K code files of N user IDs, or x2% code files of x1% users.
[0053] Furthermore, in the initial sample code set, based on the sensitive information search terms updated in the current monitoring process, it is determined whether each initial sample code includes sensitive information, and the initial sample code containing sensitive information is determined as the target sample code, and finally a target sample code set is obtained.
[0054] The embodiment of the present invention selects initial sample code from the code file uploaded by the monitored user ID based on the most recent time, and performs precise retrieval in combination with dynamically updated sensitive information search terms to obtain target sample code containing sensitive information. This sample is representative of leaked sensitive information and reflects the latest code characteristics. The initial search terms determined based on this sample are more accurate.
[0055] In some embodiments, based on a target sample code set containing sensitive information, an initial search term is obtained through analysis and processing. The initial search term is achieved by: Performing word segmentation processing on each target sample code in the target sample code set containing sensitive information to obtain multiple word segments of each target sample code; Calculating the probability of each segmentation in the target sample code set according to the number of target sample codes containing segmentations, the number of times the segmentation appears in the target sample codes containing segmentations, the total number of target sample codes, and the total number of segmentations; Select the top M segmentations with the highest probability from multiple segmentations of each target sample code as candidate segmentations; Integrate each candidate participle of each target sample code with the remaining candidate participles to obtain an integrated search term for each candidate participle of each target sample code; the remaining candidate participles are the remaining candidate participles in the multiple candidate participles of the target sample code except the candidate participle; The integrated search terms of each candidate segmentation of each target sample code are merged into an initial search term.
[0056] Specifically, each target sample code containing sensitive information is segmented to obtain multiple different segmented words. These segmented words are then preprocessed, such as removing symbols (e.g., :), keywords (e.g., if, else), and obviously non-sensitive segmented words (e.g., by performing semantic recognition on the segmented words to identify non-sensitive semantics), to obtain multiple preprocessed segmented words.
[0057] Calculate the probability of each different word i. The formula is as follows: Where J is the total number of target sample codes containing segmentation i; j is the identifier of the target sample code containing segmentation i; is the number of times segmentation i appears in the target sample code j containing segmentation i; is the total number of occurrences of each participle in the final sample code j containing participle i; is the total number of target sample codes in the target sample code set; is the total number of word segments in the target sample code set.
[0058] Then, the top M segmentations with the highest probability are selected from the multiple segmentations of each target sample code as candidate segmentations. Alternatively, the top x3% segmentations can be selected as candidate segmentations. M or x3 are both preset values. x3 can be set to 50. The result obtained by multiplying the proportion value by the total number of segmentations can be used as the value of M.
[0059] Furthermore, each candidate participle of each target sample code is integrated with the remaining candidate participles, where the remaining candidate participles are the candidate participles remaining in the multiple candidate participles of the current target sample code except the current candidate participle. In this way, the integrated search terms of each candidate participle of each target sample code can be obtained, and then the integrated search terms of each candidate participle of each target sample code are merged into the initial search terms.
[0060] The embodiment of the present invention performs intelligent word segmentation and probability analysis on the target code sample to screen out the most representative candidate word segmentations, further integrates each candidate word segmentation with the remaining candidate word segmentations, and merges all the integrated search terms obtained into initial search terms. It can be accurate and have a certain degree of coverage, providing a reliable data basis for the subsequent sensitive information search terms and the continuous updating of target search terms. Finally, by searching the monitored objects through the continuously optimized and updated search word library, it can effectively avoid missed detections due to the inability to exhaustively enumerate.
[0061] According to the above content, when integrating each candidate segmentation of each target sample code with the remaining candidate segmentations to obtain the integrated search term of each candidate segmentation of each target sample code, the following steps are performed for each candidate segmentation of each target sample code: Determine the leftmost character of the candidate word segmentation as the starting comparison character; Determine the position of the starting comparison character in each of the remaining candidate segmentations as the starting comparison position; Starting from the starting comparison position, determine the longest character string with the same characters at each consecutive position between the remaining candidate participles and the candidate participle; The shortest character string among the plurality of longest character strings is determined as an integrated search term of the candidate word segmentations.
[0062] Specifically, the current candidate word x is For example, the leftmost character of the candidate word x Determine the starting alignment character.
[0063] Determine the remaining candidate word segments, including the starting comparison character The position is determined as the starting comparison position, which marks the starting position for subsequent comparison with the candidate segmentation x.
[0064] For example, another candidate word y1 is , then it contains 3 starting comparison characters , each starting alignment character The positions are the starting positions for comparison, namely the first position on the left side of y1, the third position on the left side of y1, and the fourth position on the left side of y1. The subsequent comparison process needs to start from the first position on the left side of y1, the third position on the left side of y1, and the fourth position on the left side of y1 respectively.
[0065] Starting from the starting comparison position, determine at least one string with the same characters in each consecutive position between the remaining candidate segmentations and the candidate segmentation x. If there are multiple strings, select the longest string.
[0066] For example, the candidate word x is , if the remaining candidate word y1 is , then the strings with the same characters in each consecutive position between y1 and x include 、 , then the longest string of y1 relative to x is , because the two subsequent starting alignment positions only have same; For example, the candidate word x is , if the remaining candidate word y2 is , then the string with the same characters in each consecutive position between y2 and x is only , then the longest string of y2 relative to x is ; For example, the candidate word x is , if the remaining candidate word y3 is , then the longest string of y3 relative to x is .
[0067] Then, the shortest character string among all the longest character strings is used as the integrated search term of the current candidate participle x relative to the remaining candidate participles.
[0068] For example, the longest string of y1 relative to x is , the longest string of y2 relative to x is , the longest string of y3 relative to x is , then the integrated search term of candidate participle x is .
[0069] The embodiment of the present invention integrates the candidate segmentation with the remaining candidate segmentation to obtain the integrated search term of each candidate segmentation, and then merges them into the initial search term, which can further expand the keywords of sensitive information and ensure that the keywords are accurate and can cover the largest code.
[0070] In some embodiments, associated user IDs are expanded based on the risky user ID. The associated user IDs specifically include a first type of associated user ID, a second type of associated user ID, and a third type of associated user ID. It should be noted that the number of risky user IDs determined based on the first step is not limited. Each risky user ID must be expanded to its corresponding associated user ID, and ultimately all of them are monitored. For ease of description, the expansion process for the following three types of associated user IDs is described using a risky user ID as ID1.
[0071] The first type of associated user ID is determined in the following manner: The user ID that has updated the code file uploaded by the risky user ID is determined as the first type of associated user ID of the risky user ID.
[0072] Specifically, the code files uploaded by users on the hosting platform can be updated by other users. Each update will record the updated ID and updated content. Users who have updated any code file uploaded by ID1 are users who have a business relationship with ID1, and there may also be problems with sensitive information leakage.
[0073] Therefore, the user ID that has updated the code file uploaded by ID1 is determined as the first type of associated user ID of ID1.
[0074] Furthermore, the second type of associated user ID is determined by: The user ID to which the code file modified by the risky user ID belongs is determined as the second type of associated user ID of the risky user ID.
[0075] Specifically, based on the same principle as above, the user ID to which the code file modified by ID1 belongs is also a user who has a business relationship with ID1, and there may also be sensitive information leakage issues.
[0076] Therefore, the user ID to which the code file modified by ID1 belongs is determined as the second type of associated user ID of ID1.
[0077] Furthermore, the third type of associated user ID is determined by: Determine a user ID that has appeared in any network address identical to the risk user ID as a candidate associated user ID; Calculate the similarity between each candidate associated user ID and the risk user ID based on the total size of the code files uploaded by the user ID, the frequency of the uploaded code files, and the IP address to which the code files were uploaded; The candidate associated user IDs whose similarity is greater than a preset threshold are determined as associated user IDs of the third type of the risky user ID.
[0078] Specifically, every time a user uploads a code file on the hosting platform, the Internet Protocol (IP) address of the upload will be recorded. Here, all IP addresses involved in uploading all code files by ID1 can be obtained.
[0079] Since IP address = network address + host address, the network address can be obtained from the IP address. The user ID that has appeared in any network address that is the same as ID1 is determined as a candidate associated user ID.
[0080] Calculate the similarity between each candidate associated user ID and ID1. The formula is as follows: in, The identifier of the candidate user ID; The total size of the code files uploaded for the u-th candidate user ID; The total size of the code file uploaded for ID1; Frequency of code files uploaded for the u-th candidate user ID (upload here includes uploading own files as well as updating code files uploaded by other user IDs); Frequency of code file uploads for ID1 (uploads here include uploading your own files and updating code files uploaded by other user IDs).
[0081] The maximum number of identical digits between the IP addresses of the u-th candidate user ID and the IP addresses of ID1. For example, an IP address of the u-th candidate user ID is 192.168.255.xx, and an IP address of ID1 is 192.168.255.yyy. First, the groups that are less than 3 digits are supplemented, and the high bits are supplemented with 0. For example, the fourth group of 192.168.255.xx is xx, which is less than 3 digits, so the high bits (i.e. the left bits) are supplemented with 0 to get 192.168.255.0xx. Each supplemented bit is then compared with the corresponding bit of 192.168.255.yyy to determine that the total number of identical bits is 9, that is, the 9 bits of 192.168.255 are the same. In this way, each IP address of the u-th candidate user ID will be compared with each IP address of ID1 to obtain the total number of identical bits, and the maximum number of identical bits is determined as . The larger the value, the more similar the locations of the two are, the closer the business relationship is, and the more likely there is a problem of sensitive information leakage.
[0082] Then, the candidate associated user IDs with similarities greater than a preset threshold are determined as associated user IDs of the third type of ID1.
[0083] Among them, the preset threshold is an empirical value, which is determined according to the monitoring intensity and the required calculation speed. The higher the intensity, the lower the preset threshold, and the more associated user IDs there will be. However, the execution efficiency of the second part will be reduced. Therefore, it can be determined comprehensively based on the monitoring speed and monitoring effect.
[0084] This embodiment of the present invention constructs a multi-dimensional correlation analysis method based on code collaboration relationships and network behavior characteristics. This method not only covers explicit code interaction behaviors but also identifies potential associated accounts through implicit characteristics such as IP addresses and upload modes. This multi-dimensional correlation analysis method can accurately identify user groups at risk of leakage as much as possible, providing a reliable target range for subsequent precision retrieval, thereby significantly improving the ability to monitor sensitive information leaks.
[0085] The sensitive information leakage monitoring device provided by the present invention is described below. The sensitive information leakage monitoring device described below and the sensitive information leakage monitoring method described above can be referenced to each other.
[0086] Reference Figure 2 , Figure 2 It is a structural diagram of the sensitive information leakage monitoring device provided by the present invention.
[0087] The sensitive information leakage monitoring device includes: The search term generation module 210 is used to determine the target search term based on the sensitive information search term updated in the current monitoring process and the initial search term; the initial search term is determined based on the target sample code set containing sensitive information; the sensitive information search term updated in the current monitoring process is determined based on the target search term and supplementary search term of the previous round of monitoring process.
[0088] The first retrieval module 220 is configured to search the set of code files to be monitored based on the target search term to obtain an initial code file containing sensitive information.
[0089] The second retrieval module 230 is used to search all code files uploaded by the monitoring object set based on the target search term to obtain target code files containing sensitive information; the monitoring object set includes the risk user ID that uploaded the initial code file and the associated user ID of the risk user ID.
[0090] The sensitive information leakage monitoring device provided by the present invention determines the target search term based on the dynamically updated sensitive information search term and the initial search term determined by the target sample code containing sensitive information, realizes the continuous updating of the search term, and makes it have the semantic expansion capability while maintaining the semantic accuracy. It performs precise search based on the target search term to obtain the initial code file containing sensitive information, and determines the risk user who leaks sensitive information on this basis. The risk user and its associated users are used as monitoring objects, which can ensure the accuracy of the search object and greatly reduce the number of search objects. Therefore, all code files uploaded by the monitoring object are searched based on the target search term to obtain the target code file containing sensitive information, thereby ensuring the efficiency and effect of the re-search, thereby realizing real-time and precise monitoring of sensitive information.
[0091] Furthermore, the sensitive information leakage monitoring device is also used to: Sort multiple user IDs to be monitored according to the time sequence of the last code file uploaded by the user ID to obtain a user sequence to be monitored; Select the first N user IDs from the sequence of users to be monitored as candidate user IDs; Select the K most recently uploaded code files from the code files uploaded by each candidate user ID as the initial sample code; Based on the sensitive information search terms updated in the current monitoring process, multiple initial sample codes are searched to obtain a target sample code set containing sensitive information.
[0092] Furthermore, the sensitive information leakage monitoring device is also used to: Performing word segmentation processing on each target sample code in the target sample code set containing sensitive information to obtain multiple word segments of each target sample code; Calculating the probability of each segmentation in the target sample code set according to the number of target sample codes containing segmentations, the number of times the segmentation appears in the target sample codes containing segmentations, the total number of target sample codes, and the total number of segmentations; Select the top M segmentations with the highest probability from multiple segmentations of each target sample code as candidate segmentations; Integrate each candidate participle of each target sample code with the remaining candidate participles to obtain an integrated search term for each candidate participle of each target sample code; the remaining candidate participles are the remaining candidate participles in the multiple candidate participles of the target sample code except the candidate participle; The integrated search terms of each candidate segmentation of each target sample code are merged into an initial search term.
[0093] Furthermore, the sensitive information leakage monitoring device is also used to: Determine the leftmost character of the candidate word segmentation as the starting comparison character; Determine the position of the starting comparison character in each of the remaining candidate segmentations as the starting comparison position; Starting from the starting comparison position, determine the longest character string with the same characters at each consecutive position between the remaining candidate participles and the candidate participle; The shortest character string among the plurality of longest character strings is determined as an integrated search term of the candidate word segmentations.
[0094] Furthermore, the sensitive information leakage monitoring device is also used to: The user ID that has updated the code file uploaded by the risky user ID is determined as the first type of associated user ID of the risky user ID.
[0095] Furthermore, the sensitive information leakage monitoring device is also used to: The user ID to which the code file modified by the risky user ID belongs is determined as the second type of associated user ID of the risky user ID.
[0096] Furthermore, the sensitive information leakage monitoring device is also used to: Determine a user ID that has appeared in any network address identical to the risk user ID as a candidate associated user ID; Calculate the similarity between each candidate associated user ID and the risk user ID based on the total size of the code files uploaded by the user ID, the frequency of the uploaded code files, and the IP address to which the code files were uploaded; The candidate associated user IDs whose similarity is greater than a preset threshold are determined as associated user IDs of the third type of the risky user ID.
[0097] It should be noted that the sensitive information leakage monitoring device provided by the present invention can execute the sensitive information leakage monitoring method described in any of the above embodiments during specific operation, which will not be described in detail in this embodiment.
[0098] Figure 3 Schematic diagram of the structure of the electronic device provided by the present invention, such as Figure 3 As shown, the electronic device may include: a processor 310, a communications interface 320, a memory 330, and a communications bus 340. The processor 310, the communications interface 320, and the memory 330 communicate with each other via the communications bus 340. The processor 310 may invoke logic instructions in the memory 330 to execute a sensitive information leakage monitoring method. The method includes: determining a target search term based on a sensitive information search term and an initial search term updated during a current monitoring process; the initial search term is determined based on a target sample code set containing sensitive information; the sensitive information search term updated during the current monitoring process is determined based on the target search term and supplementary search term from a previous round of monitoring; searching a set of code files to be monitored based on the target search term to obtain an initial code file containing sensitive information; and searching all code files uploaded by a set of monitored objects based on the target search term to obtain a target code file containing sensitive information; the set of monitored objects includes the ID of the risky user who uploaded the initial code file and the user ID associated with the risky user ID.
[0099] Furthermore, the logic instructions in the aforementioned memory 330 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product, stored in a storage medium, includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0100] On the other hand, the present invention also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the sensitive information leakage monitoring method provided by the above-mentioned embodiments, the method including: determining a target search term based on the sensitive information search term and the initial search term updated in the current monitoring process; the initial search term is determined based on a target sample code set containing sensitive information; the sensitive information search term updated in the current monitoring process is determined based on the target search term and the supplementary search term of the previous round of monitoring process; based on the target search term, searching the code file set to be monitored to obtain the initial code file containing sensitive information; based on the target search term, searching all code files uploaded by the monitoring object set to obtain the target code file containing sensitive information; the monitoring object set includes the risk user ID that uploaded the initial code file and the associated user ID of the risk user ID.
[0101] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the sensitive information leakage monitoring method provided by the above-mentioned embodiments, the method comprising: determining a target search term based on the sensitive information search term and the initial search term updated in the current monitoring process; the initial search term is determined based on a target sample code set containing sensitive information; the sensitive information search term updated in the current monitoring process is determined based on the target search term and the supplementary search term of the previous round of monitoring process; based on the target search term, searching the code file set to be monitored to obtain the initial code file containing sensitive information; based on the target search term, searching all code files uploaded by the monitoring object set to obtain the target code file containing sensitive information; the monitoring object set includes the risk user ID who uploaded the initial code file and the associated user ID of the risk user ID.
[0102] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment. Those skilled in the art can understand and implement the present invention without inventive effort.
[0103] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.
[0104] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A sensitive information leakage monitoring method, characterized in that: The sensitive information leakage monitoring method includes: Determining target search terms based on the sensitive information search terms updated in the current monitoring process and the initial search terms; the initial search terms are determined based on the target sample code set containing sensitive information; the sensitive information search terms updated in the current monitoring process are determined based on the target search terms and supplementary search terms from the previous round of monitoring process; Based on the target search term, searching the set of code files to be monitored to obtain the initial code files containing sensitive information; Based on the target search term, all code files uploaded by the monitoring object set are searched to obtain target code files containing sensitive information; the monitoring object set includes the risk user ID that uploaded the initial code file and the associated user ID of the risk user ID.
2. The sensitive information leakage monitoring method according to claim 1, characterized in that: The target sample code is implemented in the following way: Sort multiple user IDs to be monitored according to the time sequence of the last code file uploaded by the user ID to obtain a user sequence to be monitored; Select the first N user IDs from the sequence of users to be monitored as candidate user IDs; Select the K most recently uploaded code files from the code files uploaded by each candidate user ID as the initial sample code; Based on the sensitive information search terms updated in the current monitoring process, multiple initial sample codes are searched to obtain a target sample code set containing sensitive information.
3. The sensitive information leakage monitoring method according to claim 1 or 2, characterized in that: The initial search term is achieved in the following way: Performing word segmentation processing on each target sample code in the target sample code set containing sensitive information to obtain multiple word segments of each target sample code; Calculating the probability of each segmentation in the target sample code set according to the number of target sample codes containing segmentations, the number of times the segmentation appears in the target sample codes containing segmentations, the total number of target sample codes, and the total number of segmentations; Select the top M segmentations with the highest probability from multiple segmentations of each target sample code as candidate segmentations; Integrate each candidate segmentation of each target sample code with the remaining candidate segmentations to obtain an integrated search term for each candidate segmentation of each target sample code; The remaining candidate participles are the remaining candidate participles in the plurality of candidate participles of the target sample code except the candidate participle; The integrated search terms of each candidate segmentation of each target sample code are merged into an initial search term.
4. The sensitive information leakage monitoring method according to claim 3, characterized in that: When integrating each candidate segmentation of each target sample code with the remaining candidate segmentations to obtain an integrated search term for each candidate segmentation of each target sample code, the following steps are performed for each candidate segmentation of each target sample code: Determine the leftmost character of the candidate word segmentation as the starting comparison character; Determine the position of the starting comparison character in each of the remaining candidate segmentations as the starting comparison position; Starting from the starting comparison position, determine the longest character string with the same characters at each consecutive position between the remaining candidate participles and the candidate participle; The shortest character string among the plurality of longest character strings is determined as an integrated search term of the candidate word segmentations.
5. The sensitive information leakage monitoring method according to claim 1, characterized in that: The associated user ID includes a first type of associated user ID, and the first type of associated user ID is determined in the following manner: The user ID that has updated the code file uploaded by the risky user ID is determined as the first type of associated user ID of the risky user ID.
6. The sensitive information leakage monitoring method according to claim 1, characterized in that: The associated user ID includes an associated user ID of a second type, and the associated user ID of the second type is determined in the following manner: The user ID to which the code file modified by the risky user ID belongs is determined as the second type of associated user ID of the risky user ID.
7. The sensitive information leakage monitoring method according to claim 1, characterized in that: The associated user ID includes an associated user ID of a third type, and the associated user ID of the third type is determined in the following manner: Determine a user ID that has appeared in any network address identical to the risk user ID as a candidate associated user ID; Calculate the similarity between each candidate associated user ID and the risk user ID based on the total size of the code files uploaded by the user ID, the frequency of the uploaded code files, and the IP address to which the code files were uploaded; The candidate associated user IDs whose similarity is greater than a preset threshold are determined as associated user IDs of the third type of the risky user ID.
8. A sensitive information leakage monitoring device, characterized in that: include: A search term generation module is used to determine a target search term based on the sensitive information search term updated in the current monitoring process and the initial search term; The initial search term is determined based on a target sample code set containing sensitive information; the sensitive information search term updated in the current monitoring process is determined based on the target search term and supplementary search term of the previous round of monitoring process; A first retrieval module is configured to search the set of code files to be monitored based on the target search term to obtain an initial code file containing sensitive information; A second retrieval module is used to search all code files uploaded by the monitoring object set based on the target search term to obtain target code files containing sensitive information; The monitoring object set includes the risk user ID that uploaded the initial code file and the associated user ID of the risk user ID.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the steps of the sensitive information leakage monitoring method as described in any one of claims 1 to 7 are implemented.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the sensitive information leakage monitoring method as described in any one of claims 1 to 7 are implemented.
11. A computer program product, comprising a computer program, characterized in that: When the computer program is executed by a processor, the steps of the sensitive information leakage monitoring method as described in any one of claims 1 to 7 are implemented.