Risk management and control method and device in file transfer operation process
By capturing the target events of file transfer operations, determining the classification labels and data flow paths of target files, identifying risk events and implementing management and control strategies, the problem of difficult tracking and control of file outflow behaviors in existing technologies is solved, and dynamic monitoring and security protection are achieved.
Patent Information
- Application Number
- CN202510774140.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2025-09-19
AI Technical Summary
Existing technologies make it difficult to dynamically track and control file outbound behavior in enterprise outbound scenarios. Traditional DLP technology is unable to cope with the full-link correlation between dynamic data and user behavior, making file outbound actions difficult to track and control.
By capturing the target events generated by file transfer operations, determining the classification labels and data flow paths of the target files, identifying risk events, and implementing corresponding management and control strategies based on risk levels, the flow of files can be dynamically monitored and analyzed.
It realizes dynamic monitoring and intelligent management of file transfer operations, ensures file security and compliance, and improves data security.
Smart Images

Figure CN120671185A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data security technology, and more specifically, to a method and device for risk management during a file transfer operation. Background Art
[0002] In related technologies, enterprises have increasingly stringent requirements for the management and control of terminal data in outbound scenarios. However, terminal data loss prevention (DLP) technology relies on a preset rule base to protect data security, making it difficult to handle dynamic data and to correlate the entire chain of user behavior. For example, when a terminal network sends data to other terminals, it is impossible to trace the source. In addition, the data flow diagrams used in related technologies to protect data security are mostly manually drawn, which has significant limitations. The main limitation is that the current solution is not feasible for downloading and sending data types such as files, making file sending difficult to track and control.
[0003] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0004] The embodiments of the present application provide a method and device for risk management during a file transfer operation, so as to at least solve the technical problem in the related art that it is difficult to dynamically track data when a terminal performs security protection on outbound data.
[0005] According to one aspect of an embodiment of the present application, a risk management method for a file transfer operation is provided, comprising: capturing a target event generated by executing a target operation, wherein the target operation is used to indicate an operation related to file transfer; determining a target file corresponding to the target event, and determining a classification label of the target file, wherein the target file is an object on which the target operation is executed, and the classification label records the confidentiality level of the target file; determining a data flow path based on the target event and the classification label, and identifying risk events in the data flow path, wherein the flow path is used to record a multi-level transfer process of the target file, and a risk event is an event that causes a change in the confidentiality level; determining the risk level of the risk event, and executing a management and control strategy corresponding to the risk level.
[0006] Optionally, capturing a target event generated by executing a target operation includes: when a target operation is detected, or when an execution order is detected between multiple target events, determining a terminal device that executes the target operation; and sending a probe to an operating system of the terminal device, wherein the probe is used to capture the target event.
[0007] Optionally, determining a classification label for each target file includes: for each target file, obtaining the storage information and access records of the target file after executing the target event; determining the storage location and confidentiality level of the target file based on the content, storage information and access records of the target file; and determining the label recording the storage location and confidentiality level as the classification label of the target file, wherein the target file has a classification label under each corresponding target event.
[0008] Optionally, a data flow path is determined based on target events and classification labels, including: for each target file, determining multiple target events corresponding to the target file, and determining the generation time of the target event; arranging the multiple target events into an event sequence in order of generation time from earliest to latest; determining multiple storage locations for storing the target file in the process of performing a target operation on the target file, and the change order of the multiple storage locations based on the event sequence and the classification label corresponding to each target event; generating a data flow path based on the multiple storage locations and the change order of the multiple storage locations, wherein each node in the data flow path represents a storage location, and each edge in the data flow path represents the change order of the storage locations.
[0009] Optionally, identifying risk events in the data flow path includes: for each target file, generating a dynamic behavior fingerprint of the target file based on the target event corresponding to the target file, wherein the dynamic behavior fingerprint is used to describe the process of performing the target operation on the target file, and updating the dynamic behavior fingerprint when the target event is updated; comparing the dynamic behavior fingerprint with the behavior baseline corresponding to the target file to obtain a comparison result, wherein the behavior baseline is used to describe the routine operation process of the target file, and the behavior baseline is determined based on the historical operation information of the target file; when the comparison result indicates that the deviation value of the dynamic behavior fingerprint relative to the behavior baseline is greater than a preset deviation value, determining that there is a risk event in the data flow path; when it is determined that there is a risk event in the data flow path, determining the risk score of each target event, and determining multiple target events corresponding to multiple risk scores greater than the preset score value as risk events.
[0010] Optionally, a dynamic behavior fingerprint of the target file is generated based on the target event corresponding to the target file, including: generating an event sequence from multiple target events in order of generation time from early to late; extracting feature information of the event sequence, wherein the feature information includes at least: the type of target operation, the target object performing the target operation, and the target object includes a user and a device; encrypting the feature information to obtain a character string, wherein the character string is a dynamic behavior fingerprint, and the length of the character string is a preset length.
[0011] Optionally, determining the risk level of a risk event includes: determining a risk score of the risk event based on multi-dimensional operational information of the risk event, wherein the multi-dimensional operational information includes: frequency of access to sensitive data and amount of outbound data; determining the risk level of the risk event based on the risk score, wherein the risk score is positively correlated with the risk level.
[0012] According to another aspect of an embodiment of the present application, a risk management device during a file transfer operation is also provided, including: an acquisition module for capturing a target event generated by executing a target operation, wherein the target operation is used to indicate an operation related to file transfer; a first determination module for determining a target file corresponding to the target event, and determining a classification label of the target file, wherein the target file is the object on which the target operation is executed, and the classification label records the confidentiality level of the target file; a second determination module for determining a data flow path based on the target event and the classification label, and identifying risk events in the data flow path, wherein the flow path is used to record the multi-level transfer process of the target file, and the risk event is an event that causes a change in the confidentiality level; an execution module for determining the risk level of the risk event, and executing a management and control strategy corresponding to the risk level.
[0013] According to another aspect of an embodiment of the present application, a non-volatile storage medium is further provided, in which a computer program is stored, wherein a risk management method is performed during the above-mentioned file transfer operation by running the computer program on a device where the non-volatile storage medium is located.
[0014] According to another aspect of an embodiment of the present application, an electronic device is also provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the risk management method during the above-mentioned file transfer operation through the computer program.
[0015] According to another aspect of an embodiment of the present application, a computer program product is further provided, including computer instructions, which, when executed by a processor, implement the steps of the risk management method in the above-mentioned file transfer operation process.
[0016] In an embodiment of the present application, a target event generated by executing a target operation is obtained, wherein the target operation is used to indicate an operation related to file transfer; a target file corresponding to the target event is determined, and a classification label of the target file is determined, wherein the target file is the object of the target operation, and the classification label records the confidentiality level of the target file; a data flow path is determined based on the target event and the classification label, and a risk event is identified in the data flow path, wherein the flow path is used to record the multi-level transfer process of the target file, and the risk event is an event that causes a change in the confidentiality level; a risk level of the risk event is determined, and a management and control strategy corresponding to the risk level is executed. By capturing events related to the file transfer operation and drawing the data flow path according to the dynamically generated events, the purpose of effectively monitoring and analyzing the flow of files in different environments is achieved; by identifying and evaluating risk events and taking corresponding management and control measures in a timely manner, the purpose of ensuring the compliance of the file transfer operation and the security of the file is achieved, thereby realizing the technical effect of dynamically controlling and tracking the outbound operation of the file and improving data security, thereby solving the technical problem of difficulty in dynamically tracking data when the terminal performs security protection on the outbound data in the related technology. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0018] Figure 1 This is a hardware structure block diagram of a computer terminal for implementing a risk management method during a file transfer operation according to an embodiment of the present application;
[0019] Figure 2 This is a flowchart of a method for risk management during a file transfer operation according to an embodiment of the present application;
[0020] Figure 3 is a structural diagram of a risk management device during a file transfer operation according to an embodiment of the present application;
[0021] Figure 4 This is a schematic diagram of the workflow of a risk management device during a file transfer operation according to an embodiment of the present application. DETAILED DESCRIPTION
[0022] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.
[0023] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0024] In order to better understand the embodiments of the present application, the technical terms involved in the embodiments of the present application are explained as follows:
[0025] Data Loss Prevention (DLP) is a terminal device-based data leakage prevention technology that prevents sensitive data leakage by monitoring file operations, network transmission and other behaviors. It is different from the boundary protection mode of traditional network layer DLP.
[0026] Probe: A lightweight application used to collect network packets, monitor network activity, or detect software running status.
[0027] In the related art, data flow diagrams are mostly drawn manually, lacking the ability to be dynamically updated, and the scheme for constructing data flow diagrams has great limitations. The main limitation is that the current scheme is not very feasible for downloading and sending data types such as files, which makes it difficult to track and control file sending actions. Therefore, there is a problem of not being able to dynamically update the data flow diagram. In addition, the traditional network layer DLP relies on a preset rule base to control file outbound behavior, which has the problem of difficulty in dealing with dynamic data; the terminal DLP log separation makes it difficult to associate the entire link of user behavior, such as sending from the terminal network to other terminals, which cannot be traced; and, the file outbound behavior control in the related art relies on post-audit, lacks real-time risk prediction, and has the problem of difficulty in building the flow path of data across terminals, users, and protocols. In order to solve the above problems, relevant solutions are provided in the embodiments of the present application, which are described in detail below.
[0028] According to an embodiment of the present application, a method embodiment of a risk management method during a file transfer operation is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0029] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 The hardware structure block diagram of a computer terminal for implementing a risk control method during a file transfer operation is shown. Figure 1 As shown, the computer terminal 10 may include one or more (illustrated as 102a, 102b, ..., 102n in the figure) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply and / or a camera. It will be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown.
[0030] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry." The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuitry may be a single, independent processing module, or may be incorporated in whole or in part into any of the other components of the computer terminal 10. As described in the embodiments of the present application, the data processing circuitry serves as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).
[0031] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the method for managing file transfer operations in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implementing the above-mentioned method for managing file transfer operations. The memory 104 may include a high-speed random access memory and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0032] The transmission device 106 is configured to receive or transmit data via a network. A specific example of the aforementioned network may include a wireless network provided by the communications provider of the computer terminal 10. In one embodiment, the transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, the transmission device 106 may be a radio frequency (RF) module, which is configured to communicate with the Internet wirelessly.
[0033] The display may be, for example, a touch screen liquid crystal display (LCD) that enables a user to interact with a user interface of the computer terminal 10 .
[0034] The embodiment of the present application provides a risk management method for the file transfer operation process that can be run in the above operating environment. Figure 2 This is a flowchart of a risk management method during a file transfer operation according to an embodiment of the present application. Figure 2 As shown, the method includes the following steps:
[0035] Step S202: capturing a target event generated by executing a target operation, wherein the target operation is used to indicate an operation related to file transfer.
[0036] The embodiment of the present application provides an efficient risk control method during the file transfer operation process, which realizes dynamic monitoring and intelligent control of file transfer operations through the steps of terminal DLP monitoring, data asset management and labeling, data flow diagram generation and security policy control. In step S202, the operations performed on the file type data on the terminal are monitored in real time. When the operation performed on the file type data on the terminal is monitored to be an operation related to file transfer (i.e., target operation), the event (i.e., target event) generated by the execution of the file transfer-related operation (i.e., target operation) is captured in real time; wherein, the above-mentioned operations related to file transfer (i.e., target operation) include: file reading, writing, downloading, outbound (such as sending files from the currently monitored terminal device to a mailbox, cloud disk) and other operations. For example, when a user attempts to transfer a document containing sensitive information (such as employee personal information or company project information) from the company's internal network to a personal mailbox, this operation is considered a target operation, which will generate a target event that records the specific details of the file transfer, such as the file name, size, transfer time, initiator, etc.; in step S202, when it is detected that a document containing sensitive information is being sent out, this target event generated by the outgoing document with sensitive information will be captured.
[0037] Optionally, capturing a target event generated by executing a target operation includes: when a target operation is detected, or when an execution order is detected between multiple target events, determining a terminal device that executes the target operation; and sending a probe to an operating system of the terminal device, wherein the probe is used to capture the target event.
[0038] The behavior of capturing the target event in step S202 can be triggered by the following two situations: 1) when it is detected that any user downloads data from the internal system of the terminal device (i.e., the target operation) or performs an outbound operation on the data (i.e., the target operation); 2) when it is detected that there is an execution order between multiple events generated on the terminal device, or in other words, when the terminal device applies an operation sequence mode to the data. Both of the above situations will trigger the sending of a probe to the operating system of the terminal device, and the probe will capture the kernel and input / output (I / O) events (i.e., target events) occurring on the terminal device. In this embodiment, a lightweight probe is used to capture kernel-level I / O events in real time, record terminal file operations in real time, associate user and process information, receive and respond to security policies, continuously scan terminal sensitive data, and record directory paths, file attributes, and other related information of the target operation.
[0039] Step S204: determining the target file corresponding to the target event and determining a classification label of the target file, wherein the target file is the object on which the target operation is executed, and the classification label records the confidentiality level of the target file.
[0040] In step S204, after capturing the event (i.e., target event) generated by the file transfer operation performed on the terminal, the file to be transferred (i.e., target file) is determined by parsing the target event. Multiple target operations may be performed concurrently on the terminal device at the same time. Therefore, multiple target events can be captured simultaneously in step S202. In this case, each target event is parsed separately to determine the file to be transferred on the terminal (i.e., target file). In step S204, after determining each file on which the transfer operation is performed (i.e., target file), the classification label of each target file is further determined, wherein the classification label records the confidentiality level of the file on which the transfer operation is performed (i.e., target file). In the embodiment of the present application, the confidentiality level can be divided into the following three types from high to low: "core business secrets", "ordinary business secrets", and "non-sensitive". For example, for the target event of sending a document to a personal mailbox in the previous example, the document sent to the personal mailbox is the target file. In step S204, its classification label is further determined to understand its confidentiality level.
[0041] Optionally, determining a classification label for each target file includes: for each target file, obtaining the storage information and access records of the target file after executing the target event; determining the storage location and confidentiality level of the target file based on the content, storage information and access records of the target file; and determining the label recording the storage location and confidentiality level as the classification label of the target file, wherein the target file has a classification label under each corresponding target event.
[0042] In the method provided in the embodiment of the present application, the classification label of each target file not only records the confidentiality level of the target file, but also records the business system affiliation of the target file (that is, the storage location of the target file, used to indicate in which business system / device the target file is currently stored), that is, the information recorded in the classification label is "confidentiality level + business system affiliation". In this embodiment, when a file transfer operation is detected, the storage information and access records of the target file on which the transfer operation is performed are obtained, wherein the storage information includes: the storage path, file size, file type, creation time, etc. of the target file, and the access record is a historical access record generated by accessing the target file before executing the target operation, including information such as access frequency, access time, and visitor identity. Next, the storage location (that is, business system affiliation) of the target file is determined based on the acquired storage information, and the confidentiality level of the target file is determined based on the access record, and finally a classification label recording "confidentiality level + business system affiliation" is generated. When determining classification labels based on stored information and access records, a trained classifier can be used. When training the classifier, unlabeled documents and their correct classification labels are used as training data. Unsupervised machine learning is used to analyze massive amounts of unlabeled documents, automatically clustering them to generate themes (such as confidentiality levels and business system affiliations). The similarity threshold can be manually adjusted to optimize the classification results. The clustering results are used as sample input into a supervised model to extract semantic features (short sentences / compound words) to train the classifier and generate an algorithm rule base. The recognition results are defined to identify files as multi-classification labels (such as "financial data + core commercial secrets"), linking them to enterprise data classification and grading specifications, and outputting classification and grading information to a third-party platform.
[0043] In this embodiment, the classifier can be loaded into the memory. For example, the raw data of the classifier can be loaded from the non-volatile memory into the volatile memory, so that the processor can run the classifier. The raw data of the classifier refers to unprocessed data, which generally includes parameters and structural data of the classifier. The structural data can be a calculation relationship based on the parameters, such as the forward propagation calculation relationship between intermediate layers or neurons. Specifically, the structural data can include code related to the structure of the classifier, such as code for performing related calculations between intermediate layers or neurons.
[0044] In one embodiment, a memory area for loading the classifier can be divided, including a structure data storage area and a parameter storage area. The structure data storage area is used to store structure-related code, and the parameters referenced by it can point to the addresses of specific parameters in the parameter storage area through pointers. During the classifier training process, parameters may need to be frequently updated, and the parameter values in the parameter storage area can be simply updated.
[0045] Step S206, determine the data flow path based on the target event and the classification label, and identify risk events in the data flow path, wherein the flow path is used to record the multi-level transfer process of the target file, and the risk event is an event that causes a change in the confidentiality level.
[0046] After identifying each target file to be transferred in step S204 and determining the classification label of each target file, in step S206, for each target file, a data flow path representing the process of transferring the target file is constructed based on the target event generated by the transfer operation on the target file and the classification label of the target file. The data flow path records the entire process of the file from the source (such as the terminal device where the file is originally stored) to the end point (such as the outbound channel, the target device of the transfer), that is, it records each device that the file passes through during the transfer process; each transfer process of the file from one device to another corresponds to a target event. Therefore, when multiple target events are generated during the transfer operation on the target file, there are multiple target events in the data flow path corresponding to the target file; otherwise, if only one target event is generated during the transfer operation on the target file (for example, during the entire transfer process, when the file is only stored in the terminal device where the file is originally stored and the destination device of the transfer, there is only one target event), there is only one target event in the data flow path; in step S206, after constructing the data flow path for recording the file transfer process, combined with terminal behavior characteristics (such as Universal Serial Bus (USB) device use, clipboard operation) and network protocol analysis, possible risk events in the flow path are marked. For example, when a target event such as a file is transferred from a low-level confidentiality area to a high-level confidentiality area, or from a high-level confidentiality area to a low-level confidentiality area, which causes a change in the confidentiality level of the file, is identified, such target event is marked as a risk event; for another example, when the target event includes behaviors such as using an abnormal protocol for transmission or sending a large number of files out in a short period of time, the target event is also marked as a risk event. The data flow path generated in step S206 can also be visualized. For example, key information such as the illegal data flow direction, timeline, operation type, involved files, and transmission protocol obtained from the data flow path analysis can be displayed on a visualization screen. The method provided in the embodiments of the present application is particularly suitable for multi-stage file transfer operations (i.e., file transfer operations that generate multiple target events).
[0047] According to some optional embodiments of the present application, a data flow path is determined based on target events and classification labels, including: for each target file, determining multiple target events corresponding to the target file, and determining the generation time based on the target event; arranging the multiple target events into an event sequence in order from early to late according to the generation time; determining multiple storage locations for storing the target file in the process of performing a target operation on the target file, and the change order of the multiple storage locations based on the event sequence and the classification label corresponding to each target event; generating a data flow path based on the multiple storage locations and the change order of the multiple storage locations, wherein each node in the data flow path represents a storage location, and each edge in the data flow path represents the change order of the storage locations.
[0048] The method provided in the embodiment of the present application dynamically constructs a data flow path to understand the complete flow history of data from one storage location to another storage location through the data flow path. In this embodiment, when constructing the data flow path, all target events related to the target file are screened out from all collected operation logs, such as target events such as file creation, reading, modification, moving, deletion, uploading, and downloading; for multiple target events corresponding to each target file, the multiple target events corresponding to the target file are arranged into an event sequence in the order of the generation time of the target event from early to late, so as to restore the order in which each target event occurs during the file transfer operation, as well as the transfer trajectory of the file transfer operation, wherein the generation time of the target event can be determined by the timestamp associated with the target event. Next, for each target event in the event sequence, the classification label of the target file is determined based on the storage location and confidentiality level of the target file after the target event occurs. This is because the storage location of the target file will change during the transfer process. By comparing the classification labels of the target file after the target event occurs, it can be determined when the storage location of the file has changed; the classification label of the target file after each target event occurs can be recorded as the classification label corresponding to the target event; then the classification label corresponding to each target event on the data flow path can be determined by the above method; further, combined with the classification label of each target event, the storage location of the target file after different target events occurs is analyzed, and the change order of multiple storage locations of the file in the entire data flow path is further analyzed. In the flow path generated above, the storage location of the target file after each target event occurs is used as a node that constitutes the data flow path, and the edges of the data flow path are generated according to the change order of the storage location. When generating data flow paths, the embodiments of the present application support immediate or periodic scanning tasks, incrementally update file metadata (such as classification labels), and record sensitive data flow paths, transmission protocols, and file attributes; call terminal DLP logs and network protocol analysis results, dynamically mark the business system to which the file belongs, the confidentiality level (i.e., confidentiality level) change node (such as internal system → user terminal → outbound channel), and trigger asset tag updates.
[0049] According to some other optional embodiments of the present application, risk events are identified in a data flow path, including: for each target file, generating a dynamic behavior fingerprint of the target file according to the target event corresponding to the target file, wherein the dynamic behavior fingerprint is used to describe the process of performing a target operation on the target file, and when the target event is updated, the dynamic behavior fingerprint is updated; the dynamic behavior fingerprint is compared with the behavior baseline corresponding to the target file to obtain a comparison result, wherein the behavior baseline is used to describe the routine operation process of the target file, and the behavior baseline is determined based on the historical operation information of the target file; when the comparison result indicates that the deviation value of the dynamic behavior fingerprint relative to the behavior baseline is greater than a preset deviation value, it is determined that a risk event exists in the data flow path; when it is determined that a risk event exists in the data flow path, a risk score for each target event is determined, and multiple target events corresponding to multiple risk scores greater than the preset score value are determined as risk events.
[0050] In this embodiment, risk events are identified by comparing the dynamic behavioral fingerprint of a target file with a behavioral baseline. The dynamic behavioral fingerprint describes the process of executing a target operation on a target file. It is generated based on all target events associated with the target file and is updated as new events occur in the target file. The behavioral baseline describes the process of executing a regular operation on a target file and is generated based on the target file's historical operation records. The dynamic behavioral fingerprint of the target file is compared with the behavioral baseline, and a deviation value is calculated between the two. This deviation value is used to measure the degree of abnormality in the operation behavior. When the deviation value shown by the dynamic behavioral fingerprint exceeds a preset deviation value, the target event generated during the execution of the target operation on the target file is considered a risk event. Furthermore, for each target event in the data flow path, the degree of deviation from the regular event at the same location on the behavioral baseline is calculated to obtain a risk score for the target event. A higher risk score indicates a greater risk of data leakage when the corresponding operation is executed on the target file. In this embodiment, target events with multiple risk scores exceeding the preset score are identified as risk events.
[0051] The behavioral baseline in the above embodiment can be generated by the following method: Step 1, continuously collect kernel-level I / O events generated by file transfer-related operations performed on the terminal device, such as file creation, reading, modification, deletion, movement, and other network transmission behaviors of files; Step 2, serialize the kernel-level I / O events in the time sequence of event generation to form an event sequence of file transfer, and the event sequence contains detailed information such as operation type, operation timestamp, file metadata, etc.; Step 3, apply unsupervised machine learning algorithms to analyze the user's behavior sequence and identify features under normal behavior patterns, including access frequency, access time distribution, The storage location and transfer path of the file, etc., are used to build a baseline model of user behavior; Step 4, the normal behavior pattern characteristics are hashed to generate a unique identifier for the user behavior baseline, namely the behavior baseline hash value, which is used for subsequent behavior comparison and anomaly detection; Step 5, the constructed behavior baseline hash value (i.e., behavior baseline) is stored and associated with the file identifier (ID) or device ID to form a behavior baseline for the file or device; Step 6, the behavior baseline is automatically updated regularly or based on updates of system events, and the behavior baseline model is automatically adjusted and optimized by analyzing the newly collected operation data to adapt to changes in user behavior and evolution of the environment. In addition, after executing step 1 and before executing step 2, the collected user operation data can also be pre-processed, including data cleaning, deduplication, outlier detection, and conversion of operation data into a unified format.
[0052] Optionally, a dynamic behavior fingerprint of the target file is generated based on the target event corresponding to the target file, including: generating an event sequence from multiple target events in order of generation time from early to late; extracting feature information of the event sequence, wherein the feature information includes at least: the type of target operation, the target object performing the target operation, and the target object includes a user and a device; encrypting the feature information to obtain a character string, wherein the character string is a dynamic behavior fingerprint, and the length of the character string is a preset length.
[0053] As mentioned in the above embodiment, the dynamic behavior fingerprint is generated based on the target event and is updated as the target event is updated. In this embodiment, an encryption algorithm (such as a hash algorithm) can be used to generate the dynamic behavior fingerprint. For example, after generating the event sequence corresponding to the target file, the characteristic information of each target event in the event sequence is extracted. The characteristic information may include: the type of target operation (such as file reading, modification, and moving), the target object performing the target operation, such as the user ID performing the target operation, the Internet Protocol address (IP) / physical address (MAC address) of the device performing the target operation, and the characteristic information may also include: other important information related to the target operation, such as the size, format, storage location of the file, and details such as whether the operation is successful and the duration of the operation. Next, an encryption algorithm is used to encrypt the above-extracted information. For example, a hash algorithm is used to encrypt the above-mentioned characteristic information to obtain a fixed-length (i.e., preset-length) string. This string is the dynamic behavior fingerprint of the target file corresponding to the target event. Through the method provided in the embodiment of the present application, an encryption algorithm is used to generate a dynamic behavior fingerprint, thereby enhancing the monitoring capability of file operations.
[0054] Step S208: determine the risk level of the risk event and execute the management and control strategy corresponding to the risk level.
[0055] In step S208, the risk level of the risk event marked in step S206 is determined, and the corresponding control policy is executed. For example, in this embodiment, the risk levels are divided into three categories: high risk, medium risk, and low risk. For high-risk events, the corresponding control policy is set to "immediately block the operation"; for medium-risk events, the corresponding control policy is set to "initiate the audit process and notify the administrator"; and for low-risk events, the corresponding control policy is set to "record and observe, and escalate control if necessary." In step S208, the control policy corresponding to the risk level is sent to the original terminal device where the file in step S202 was stored. The terminal device executes the control policy, such as triggering an audit, blocking, approval, or decryption action, thus achieving a closed-loop event.
[0056] According to some optional embodiments of the present application, determining the risk level of a risk event includes: determining a risk score of the risk event based on multi-dimensional operational information of the risk event, wherein the multi-dimensional operational information includes: frequency of access to sensitive data and amount of outbound data; determining the risk level of the risk event based on the risk score, wherein the risk score is positively correlated with the risk level.
[0057] When determining the risk level of a risk event, the risk score of the risk event is first determined based on the multi-dimensional operational information of the risk event, wherein the multi-dimensional operational information used to determine the risk score includes: access frequency of sensitive data (such as data recording user personal information, company project documents), amount of outbound data, frequency of use of abnormal protocols, etc.; a mathematical model constructed based on the multi-dimensional operational information is used to quantify the risk index of the event and determine the risk score of the risk event. For example, the constructed mathematical model is: 80% * sensitive data access frequency score + 10% outbound data volume score + 10% abnormal protocol use frequency score; wherein the sensitive data access frequency score is determined according to the degree of deviation of the sensitive data access frequency in the target event from the sensitive data access frequency in the behavioral baseline, the outbound data volume score is determined according to the amount by which the outbound data volume in the target event exceeds the amount of outbound data in the behavioral baseline, and the abnormal protocol use frequency score is determined according to the degree of deviation of the frequency of use of abnormal protocols in the target event from the frequency of use of abnormal protocols in the behavioral baseline. If the total score is 0-100 points, the risk event with a risk score of 0-20 points is determined as a low-risk event, and the control strategy of "recording and observing, and upgrading control when necessary" is implemented; the risk event with a risk score of 21-50 is determined as a medium-risk event, and the control strategy of "starting the audit process and notifying the administrator" is implemented; the risk event with a score of 51-100 is determined as a high-risk event, and the control strategy of "immediately blocking the operation" is implemented. Through the method provided in the embodiment of the present application, a dynamic risk score is calculated based on the operation of files on the terminal device (frequency of sensitive data access, amount of outbound data, use of abnormal protocols, etc.), risk-prone behavior patterns are identified (such as downloading a large amount of business data in a short period of time, a surge in cross-border transmission, and frequent changes of login accounts), potential data leakage intentions are predicted (such as data theft before employees leave), and corresponding control strategies are adopted in a timely manner to control the target operations to avoid data leakage.
[0058] Through the above steps, it is possible to obtain and apply the latest data flow information and risk events in real time, maintain the advancement of data flow analysis strategies, and dynamically adjust management and control strategies based on the results of data flow analysis so that the data security system can quickly respond to new threats, provide more effective defense, and improve the security of data transmission.
[0059] Figure 3 FIG. 1 is a structural diagram of a risk control device in a file transfer operation process according to an embodiment of the present application. Figure 3As shown, the risk management and control device during the file transfer operation process includes: an acquisition module 30, which is used to capture the target event generated by executing the target operation, wherein the target operation is used to indicate an operation related to the file transfer; a first determination module 32, which is used to determine the target file corresponding to the target event, and determine the classification label of the target file, wherein the target file is the object on which the target operation is executed, and the classification label records the confidentiality level of the target file; a second determination module 34, which is used to determine the data flow path according to the target event and the classification label, and identify risk events in the data flow path, wherein the flow path is used to record the multi-level transfer process of the target file, and the risk event is an event that causes a change in the confidentiality level; an execution module 36, which is used to determine the risk level of the risk event, and execute a management and control strategy corresponding to the risk level.
[0060] Figure 4 This is a workflow diagram of the risk control device during the file transfer operation, such as Figure 4As shown, the method provided by the embodiment of the present application can be applied to file transfer operations occurring in scenarios such as business servers, document servers, and internal systems on terminal devices. When the risk control device during the file transfer operation is applied to manage file transfer operations in the above scenarios, it can manage file transfer operations generated by any type of user (such as partners, corporate employees) in the above scenarios. The terminal DLP module (i.e., the acquisition module 30) has functions such as data monitoring, risk response and control, and data compliance detection. Among them, the acquisition module 30 monitors whether operations related to file transfer (i.e., target operations) occur on the terminal device. When the target operation is detected, it immediately responds to the risk: capturing the target event generated by the execution of the target operation. The data asset management and labeling module (i.e., the first determination module 32) has the capabilities of dynamic data classification and grading, multi-dimensional asset mapping, intelligent discovery and labeling. The first determination module 32 determines a classification label for the target file operated by the above-captured target event, and marks the target file with a classification label, wherein the classification label records the confidentiality level of the target file; at the same time, the classification label determined for the target file in the first determination module can also be used to mark the data flow path, marking the classification label of the target file after each target event occurs in the data flow path. The above-mentioned data flow path is generated by a data flow graph generation module (i.e., the second determination module 34) with the capabilities of full-link topology construction, traceability analysis, and compliance visualization. The second determination module 34 dynamically maps the complete flow path of data across terminal devices and network protocols based on the operation logs and network protocol analysis of the terminal devices. Integrate the data classification and grading results, mark the level and type of risk events in the flow graph, and automatically visualize the illegal flow. Next, a security policy control module (i.e., the execution module 36) with policy configuration, risk management, and policy execution capabilities will perform risk scoring on risk events in the data flow path to predict bad intentions, and determine the risk level based on the risk score, and automatically trigger the issuance of control policies; the control policies (such as triggering audits, blocking, approval, or decryption actions, etc.) will be issued to the terminal DLP module to achieve an event closed loop.
[0061] It should be noted that Figure 3 The preferred implementation of the embodiment shown can be found in Figure 2 The relevant description of the illustrated embodiment will not be repeated here.
[0062] An embodiment of the present application further provides a non-volatile storage medium, in which a computer program is stored. The device where the non-volatile storage medium is located executes the above method for managing file transfer operations by running the computer program.
[0063] The above-mentioned non-volatile storage medium is used to store programs that perform the following functions: capturing target events generated by executing target operations, wherein the target operation is used to indicate operations related to file transfer; determining the target file corresponding to the target event, and determining the classification label of the target file, wherein the target file is the object on which the target operation is executed, and the classification label records the confidentiality level of the target file; determining a data flow path based on the target event and the classification label, and identifying risk events in the data flow path, wherein the flow path is used to record the multi-level transfer process of the target file, and the risk event is an event that causes a change in the confidentiality level; determining the risk level of the risk event, and executing a management and control strategy corresponding to the risk level.
[0064] An embodiment of the present application further provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to execute the above method for managing file transfer operations through the computer program.
[0065] The processor in the above-mentioned electronic device is used to run a program that performs the following functions: capturing a target event generated by executing a target operation, wherein the target operation is used to indicate an operation related to file transfer; determining a target file corresponding to the target event, and determining a classification label of the target file, wherein the target file is the object on which the target operation is executed, and the classification label records the confidentiality level of the target file; determining a data flow path based on the target event and the classification label, and identifying risk events in the data flow path, wherein the flow path is used to record the multi-level transfer process of the target file, and a risk event is an event that causes a change in the confidentiality level; determining the risk level of the risk event, and executing a management and control strategy corresponding to the risk level.
[0066] An embodiment of the present application also provides a computer program product, including computer instructions, which implement the steps of the above method for managing file transfer operations when executed by a processor.
[0067] It should be noted that the various modules in the risk management device during the above-mentioned file transfer operation can be program modules (for example, a set of program instructions that implement a certain specific function) or hardware modules. For the latter, it can be expressed in the following forms, but is not limited to this: the expression form of each of the above-mentioned modules is a processor, or the functions of each of the above-mentioned modules are implemented by a processor.
[0068] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0069] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0070] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only exemplary. For example, the division of the units can be a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0071] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple units. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.
[0072] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0073] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the relevant technology or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.
[0074] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A risk management method during a file transfer operation, characterized in that: include: capturing a target event generated by executing a target operation, wherein the target operation is used to indicate an operation related to file transfer; Determining a target file corresponding to the target event and determining a classification label for the target file, wherein the target file is an object on which the target operation is performed, and the classification label records a confidentiality level of the target file; Determining a data flow path based on the target event and the classification label, and identifying a risk event in the data flow path, wherein the flow path is used to record the multi-level transfer process of the target file, and the risk event is an event that causes the confidentiality level to change; Determine the risk level of the risk event and implement a management and control strategy corresponding to the risk level.
2. The method according to claim 1, characterized in that Capturing target events generated by executing the target operation, including: In the case where the target operation is detected, or in the case where an execution sequence is detected between a plurality of target events, determining a terminal device that executes the target operation; A probe is sent to an operating system of the terminal device, wherein the probe is used to capture the target event.
3. The method according to claim 1, characterized in that Determine a classification label for each target file, including: For each target file, obtaining storage information and access records of the target file after executing the target event; determining a storage location and a confidentiality level of the target file according to the content of the target file, the storage information, and the access record; The label recording the storage location and the confidentiality level is determined as the classification label of the target file, wherein the target file has one classification label under each corresponding target event.
4. The method according to claim 1, wherein Determining a data flow path according to the target event and the classification label includes: For each target file, determining a plurality of target events corresponding to the target file, and determining a generation time according to the target event; Arranging the plurality of target events into an event sequence in order of the generation time from earliest to latest; determining, according to the event sequence and the classification label corresponding to each target event, a plurality of storage locations for storing the target file in a process of performing the target operation on the target file, and a change order of the plurality of storage locations; The data flow path is generated according to the multiple storage locations and the change order of the multiple storage locations, wherein each node in the data flow path represents one of the storage locations, and each edge in the data flow path represents the change order of the storage locations.
5. The method according to claim 1, wherein Identifying risk events in the data flow path, including: For each target file, generating a dynamic behavior fingerprint of the target file according to the target event corresponding to the target file, wherein the dynamic behavior fingerprint is used to describe the process of performing the target operation on the target file, and updating the dynamic behavior fingerprint when the target event is updated; Comparing the dynamic behavior fingerprint with a behavior baseline corresponding to the target file to obtain a comparison result, wherein the behavior baseline is used to describe a regular operation process of the target file and is determined based on historical operation information of the target file; If the comparison result indicates that the deviation value of the dynamic behavior fingerprint relative to the behavior baseline is greater than a preset deviation value, determining that the risk event exists in the data flow path; In the case where it is determined that the risk event exists in the data flow path, a risk score of each target event is determined, and multiple target events corresponding to multiple risk scores greater than a preset score value are determined as risk events.
6. The method according to claim 5, characterized in that Generating a dynamic behavior fingerprint of the target file according to the target event corresponding to the target file includes: Generate an event sequence by sequentially generating the target events according to their occurrence time from earliest to latest; Extracting feature information of the event sequence, wherein the feature information at least includes: a type of the target operation and a target object performing the target operation, wherein the target object includes a user and a device; The characteristic information is encrypted to obtain a character string, wherein the character string is the dynamic behavior fingerprint, and the length of the character string is a preset length.
7. The method according to claim 1, characterized in that Determine the risk level of the risk event, including: Determining a risk score for the risk event based on multi-dimensional operational information of the risk event, wherein the multi-dimensional operational information includes: a frequency of access to sensitive data and an amount of outbound data; A risk level of the risk event is determined according to the risk score, wherein the risk score is positively correlated with the risk level.
8. A risk control device during a file transfer operation, characterized in that: include: an acquisition module, configured to capture a target event generated by executing a target operation, wherein the target operation is used to indicate an operation related to file transfer; A first determining module is configured to determine a target file corresponding to the target event and a classification label of the target file, wherein the target file is an object on which the target operation is executed, and the classification label records a confidentiality level of the target file; a second determining module, configured to determine a data flow path based on the target event and the classification label, and identify risk events in the data flow path, wherein the flow path is used to record the multi-stage transfer process of the target file, and the risk event is an event that causes the confidentiality level to change; The execution module is used to determine the risk level of the risk event and execute the management and control strategy corresponding to the risk level.
9. A non-volatile storage medium, characterized in that: The non-volatile storage medium stores a computer program, wherein the device where the non-volatile storage medium is located executes the risk control method during the file transfer operation process described in any one of claims 1 to 7 by running the computer program.
10. An electronic device comprising a memory and a processor, characterized in that: The memory stores a computer program, and the processor is configured to execute the risk management method during the file transfer operation according to any one of claims 1 to 7 through the computer program.
11. A computer program product comprising computer instructions, characterized in that When the computer instructions are executed by the processor, the steps of the risk management method in the file transfer operation process described in any one of claims 1 to 7 are implemented.