Outgoing event information processing method and device, computer equipment, storage medium and computer program product

By monitoring the working status duration and timestamp of the client device, the problem of forensic data loss when the terminal device is unexpectedly shut down or disconnected from the network after a data outbound event is solved, ensuring the integrity of the evidence and the adaptability of the system.

CN120705003AActive Publication Date: 2025-09-26HANGZHOU YIGE CLOUD TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510771505.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-09-26
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

In the prior art, when a terminal device unexpectedly shuts down or loses network connection after a data outgoing event occurs, the forensic data may be cleared after the expiration time has expired, resulting in the loss of forensic data.

Method used

By periodically monitoring the working status of the client device, generating the working status duration and timestamp, caching the running information, and determining whether to clear the cached running information based on the working status duration and timestamp after determining that the pending information has been processed successfully.

Benefits of technology

It effectively avoids the loss of forensic data after the user shuts down or disconnects from the network, ensures that evidence is not lost due to unsuccessful reporting in the data outbound scenario, and improves the reliability of evidence preservation and system adaptability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120705003A_ABST
    Figure CN120705003A_ABST
Patent Text Reader

Abstract

The invention relates to an outgoing event information processing method and device, computer equipment, a storage medium and a computer program product. The method comprises the following steps: periodically determining whether client equipment is in a working state and updating the duration of the working state; under the condition that the outgoing event is triggered, current operation information is cached, and a working state timestamp of the operation information is generated according to the current working state duration; generating to-be-processed information based on the operation information, and processing the to-be-processed information; and periodically traversing all the operation information cached locally, and for the traversed current operation information, determining whether to clean the current operation information based on the difference between the current working state duration and the working state timestamp under the condition of determining that the to-be-processed information corresponding to the current operation information is successfully processed. By adopting the method, the probability that the running information of the local cache is mistakenly cleaned can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method, apparatus, computer equipment, storage medium, and computer program product for processing outgoing event information. Background Art

[0002] With the continuous advancement of informatization, enterprises and organizations face an increasingly severe risk of data leakage. As the primary means of data transmission, the security of terminal devices is particularly important. Data leakage prevention systems with screenshot forensics capabilities are commonly used to record data outflows, providing a basis for subsequent tracing and auditing.

[0003] To conserve local storage space, related technologies typically set an expiration date for locally stored forensic data and purge the data after the system time exceeds the expiration date. However, if a user intentionally shuts down the device or disconnects from the network when a data outbound event occurs and the forensic data has not yet been reported, the system time may have exceeded the expiration date when the device is turned on again or reconnected to the network. This may cause the forensic data to be purged before it is reported, resulting in the loss of forensic data. Summary of the Invention

[0004] Based on this, it is necessary to provide a method, apparatus, computer equipment, storage medium and computer program product for processing outgoing event information in response to the above technical problems.

[0005] In a first aspect, the present application provides a method for processing outgoing event information. The method comprises:

[0006] periodically determining whether the client device is in a working state, and updating a working state duration based on whether the client device is in a working state;

[0007] When an outgoing event is triggered, the current operation information is cached, and a working state timestamp of the operation information is generated according to the current working state duration;

[0008] generating information to be processed based on the operation information, and processing the information to be processed;

[0009] Periodically traverse all the operation information in the local cache, and for the current operation information traversed, when it is determined that the pending information corresponding to the current operation information has been processed successfully, determine whether to clear the current operation information based on the current working status duration and the difference between the working status timestamp of the current operation information.

[0010] In one embodiment, the method further comprises:

[0011] When the client device is currently in a working state, a screen capture process is performed to obtain an operating screen image, and the operating screen image is used as the operating information.

[0012] In one embodiment, the performing of screen capture to obtain an operation screen image and using the operation screen image as the operation information includes:

[0013] Determining a preset screenshot mode and an alternative screenshot mode based on device information of the client device;

[0014] In the case that the preset screenshot mode conflicts with the application currently running on the client device, a first target screenshot mode is determined from the alternative screenshot modes, and the first target screenshot mode is used to perform screenshot processing to obtain the running screen image.

[0015] In one embodiment, the method further comprises:

[0016] In the case where the preset screenshot mode does not conflict with the application currently running on the client device, adopting the preset screenshot mode to perform screenshot processing;

[0017] In the event that an error occurs during the screenshot processing using the preset screenshot mode, determining a second target screenshot mode from the alternative screenshot modes, performing screenshot processing using the second target screenshot mode to obtain the running screen image, and setting the second target screenshot mode as the preset screenshot mode;

[0018] When the working state of the client device changes, the preset screenshot mode is restored to the initial preset screenshot mode.

[0019] In one embodiment, the periodically determining whether the client device is in a working state includes:

[0020] Register a first callback function and a second callback function; the first callback function is used to be called when the screen power state changes and output the current screen power state; the second callback function is used to be called when the login state changes and output the current login state;

[0021] Periodically determining whether the client device is in a working state based on at least one of the screen power state output by the first callback function, the login state output by the second callback function, and whether a screen saver is running.

[0022] In one embodiment, determining whether the client device is in a working state based on at least one of the screen power state output by the first callback function, the login state output by the second callback function, and whether a screen saver process is running includes:

[0023] When the login state indicates that the client device is in a remote login state and the screen is unlocked, determining that the client device is in a working state;

[0024] In a case where the login state represents that the client device is in a locally logged-in state and the screen is unlocked, if the screen power state represents that the screen of the client device is awakened, it is determined that the client device is in a working state.

[0025] In one embodiment, the processing of the information to be processed includes:

[0026] Storing the information to be processed in a first database;

[0027] Periodically traversing the information to be processed in the first database, and for the current information to be processed found, if it is determined that the external event corresponding to the current information to be processed is a leak event, moving the current information to be processed to the second database, or if it is determined that the external event corresponding to the current information to be processed is not the leak event, deleting the current information to be processed;

[0028] Periodically traverse the information to be processed in the second database, and report the traversed information to be processed.

[0029] In one embodiment, the method further comprises:

[0030] If the information to be processed is successfully reported, deleting the information to be processed from the second database;

[0031] In a case where the to-be-processed information corresponding to the current operation information does not exist in either the first database or the second database, it is determined that the to-be-processed information corresponding to the current operation information has been successfully processed.

[0032] In a second aspect, the present application further provides an outgoing event information processing device. The device comprises:

[0033] A first determining module is configured to periodically determine whether the client device is in a working state, and update a working state duration based on whether the client device is in a working state;

[0034] A generating module, configured to cache current operation information and generate a working state timestamp of the operation information according to the current working state duration when an outgoing event is triggered;

[0035] a processing module, configured to generate information to be processed based on the operation information, and process the information to be processed;

[0036] A cleaning module is used to periodically traverse all the operation information in the local cache. For the current operation information traversed, when it is determined that the pending information corresponding to the current operation information has been processed successfully, it is determined whether to clean the current operation information based on the current working status duration and the difference between the working status timestamp of the current operation information.

[0037] In one embodiment, the apparatus further comprises:

[0038] The first screenshot module is used to perform screenshot processing to obtain an operating screen image when the client device is currently in a working state, and use the operating screen image as the operating information.

[0039] In one embodiment, the screenshot module is further configured to:

[0040] Determining a preset screenshot mode and an alternative screenshot mode based on device information of the client device;

[0041] In the case that the preset screenshot mode conflicts with the application currently running on the client device, a first target screenshot mode is determined from the alternative screenshot modes, and the first target screenshot mode is used to perform screenshot processing to obtain the running screen image.

[0042] In one embodiment, the apparatus further comprises:

[0043] A second screenshot module is configured to perform screenshot processing using the preset screenshot mode when the preset screenshot mode does not conflict with the application currently running on the client device;

[0044] a third screenshot module configured to, if an error occurs during the screenshot processing using the preset screenshot mode, determine a second target screenshot mode from the alternative screenshot modes, perform screenshot processing using the second target screenshot mode to obtain the running screen image, and set the second target screenshot mode as the preset screenshot mode;

[0045] The restoration module is used to restore the preset screenshot mode to the initial preset screenshot mode when the working state of the client device changes.

[0046] In one embodiment, the first determining module is further configured to:

[0047] Register a first callback function and a second callback function; the first callback function is used to be called when the screen power state changes and output the current screen power state; the second callback function is used to be called when the login state changes and output the current login state;

[0048] Periodically determining whether the client device is in a working state based on at least one of the screen power state output by the first callback function, the login state output by the second callback function, and whether a screen saver is running.

[0049] In one embodiment, the first determining module is further configured to:

[0050] When the login state indicates that the client device is in a remote login state and the screen is unlocked, determining that the client device is in a working state;

[0051] In a case where the login state represents that the client device is in a locally logged-in state and the screen is unlocked, if the screen power state represents that the screen of the client device is awakened, it is determined that the client device is in a working state.

[0052] In one embodiment, the processing module is further configured to:

[0053] Storing the information to be processed in a first database;

[0054] Periodically traversing the information to be processed in the first database, and for the current information to be processed found, if it is determined that the external event corresponding to the current information to be processed is a leak event, moving the current information to be processed to the second database, or if it is determined that the external event corresponding to the current information to be processed is not the leak event, deleting the current information to be processed;

[0055] Periodically traverse the information to be processed in the second database, and report the traversed information to be processed.

[0056] In one embodiment, the apparatus further comprises:

[0057] a deleting module, configured to delete the information to be processed from the second database if the information to be processed is successfully reported;

[0058] The second determining module is configured to determine that the processing of the information to be processed corresponding to the current operation information is successful when the information to be processed corresponding to the current operation information does not exist in the first database and the second database.

[0059] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements any of the above methods when executing the computer program.

[0060] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements any of the above methods when executed by a processor.

[0061] In a fifth aspect, the present application further provides a computer program product, comprising a computer program, which implements any of the above methods when executed by a processor.

[0062] The above-mentioned external event information processing method, apparatus, computer device, storage medium, and computer program product determine an operating state duration, which indicates the total time a client device has been in an operating state. When an external event is triggered, the operating state timestamp is set for the operation information collected as evidence based on the operating state duration. When the client device determines whether to clear the locally cached operation information, it uses the operating state duration and the operating state timestamp of the operation information to determine whether the operation information has expired. When it is determined that the operation information has expired and the corresponding pending information has been successfully processed, the operation information is cleared. Because the embodiments of the present application use the actual time the client device has been in an operating state to determine whether the operation information has expired, the embodiments of the present application can accurately calculate whether the operation information has expired in scenarios where the user immediately shuts down the device after triggering an external event, avoiding the situation where the client device automatically clears the local operation information after the user turns on the device after a long interval, causing the loss of evidence. Moreover, when clearing expired operation information, the embodiments of the present application also determine whether the corresponding pending information has been successfully processed. Therefore, in scenarios where the user immediately disconnects from the network after triggering an external event, the embodiments of the present application can also retain the operation information even if it is verified that the pending information was not successfully processed due to network reasons. It can reduce the probability of evidence being lost when it is not successfully reported in the data outbound scenario. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 1 is a flow chart of a method for processing outgoing event information in one embodiment;

[0064] Figure 2 A schematic diagram of a process for obtaining operation information in one embodiment;

[0065] Figure 3 A schematic diagram of a process for determining a preset screenshot mode in one embodiment;

[0066] Figure 4Schematic diagram of a flow chart for determining a processing method based on an error returned by a screenshot in one embodiment;

[0067] Figure 5 A schematic diagram of a flow chart of a registration function determining whether a client device is in a working state in one embodiment;

[0068] Figure 6 A schematic diagram of a process for determining whether a client device is in a working state based on different information returned by a function in one embodiment;

[0069] Figure 7 A schematic diagram of a process for processing information to be processed in one embodiment;

[0070] Figure 8 A flowchart of determining whether to clear local cached operation information in one embodiment;

[0071] Figure 9 is a schematic diagram of an outgoing event information processing system in one embodiment;

[0072] Figure 10 is a structural block diagram of an outgoing event information processing device in one embodiment;

[0073] Figure 11 FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0074] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0075] In one embodiment, Figure 1 As shown, a method for processing outgoing event information is provided. This embodiment is described by applying this method to a client device that involves confidentiality and needs to monitor whether the user is sending outgoing events on the device, where the client device can be a server or a terminal. In this embodiment, the method includes the following steps:

[0076] Step 102: periodically determine whether the client device is in a working state, and update the working state duration based on whether the client device is in a working state.

[0077] In the embodiment of the present application, the client device can determine whether it is in a working state based on its own screen information, whether it has received input from an external device, etc. The screen information is used to represent the current state of the display device of the client device, such as: off, awake, locked, etc.

[0078] The embodiments of the present application do not limit what information the screen information includes, nor how the client device determines whether it is in a working state based on the screen information. For example, the client device can take a screenshot, use the screenshot image as screen information, and perform image recognition on the screen information. When the screenshot image is identified as a screen saver or a login interface, it determines that it is in a non-working state, or when the screenshot image is identified as an application interface, it determines that it is in a working state. Alternatively, the client device can also register a callback function, use the callback function to receive a notification message when the screen state changes, and then use the notification message as screen information, and determine whether it is in a working state based on the content of the notification message.

[0079] The client device can then update the currently recorded working state duration based on whether it is in working state. The working state duration refers to the total time the client device is in working state from a certain initial moment to the current moment. The initial moment can be the moment the client device is started or the moment the client device begins monitoring external events.

[0080] If the client device is in an active state, the client device may add the length of one cycle to the current active state duration to obtain an updated active state duration. If the client device is in an inactive state, this indicates that the client device may have entered the inactive state at some point between the previous cycle and the current cycle. In order to minimize the amount of time the client device was actually in the inactive state during the active state duration, the current active state duration may not be changed in this case.

[0081] When updating the working state duration, it is also possible to refer to whether the client device was in the working state in the previous cycle. If the client device is in the non-working state in the current cycle, then the client device will not change the current working state duration regardless of the state of the client device in the previous cycle. If the client device is in the working state in the current cycle and was also in the working state in the previous cycle, it can be considered that even if the client device enters the non-working state between the two cycles, the time it enters the non-working state may be short. Therefore, in this case, the client device can add the length of one cycle to the current working state duration to obtain the updated working state duration. If the client device is in the working state in the current cycle and was in the non-working state in the previous cycle, it means that the client device may have entered the working state at some point between the previous cycle and the current cycle. Similar to the reason why the client device is in the non-working state in the current cycle, in this case, the current working state duration can be left unchanged.

[0082] Step 104: When an outgoing event is triggered, cache the operation information of the client device and generate a working status timestamp of the operation information according to the current working status duration;

[0083] In the embodiments of the present application, an outgoing event can be any event that indicates that a user may intend to disclose confidential data externally, for example: a user copies, prints, or sends a file with a confidentiality mark on a client device via a network; a user takes a screenshot or records the screen of a client device when the application currently running on the client device includes an application for displaying files with a confidentiality mark; identifying that data attempted by a user to send via a network may contain confidential data through keyword matching, data classification, etc. The specific events included in outgoing events can be determined by those skilled in the art based on actual needs, and the embodiments of the present application do not specifically limit this.

[0084] When an outgoing event is triggered, the client device caches its current operating information, which may include applications currently running on the client device, data transmitted by the client device on the network, content currently displayed on the client device screen, etc., which is not limited in the present embodiment.

[0085] The client device may then generate a working status timestamp for the cached operation information based on the currently recorded working status duration, and the working status timestamp may be subsequently used to determine whether the cached operation information is expired.

[0086] Step 106: Generate information to be processed based on the operation information, and process the information to be processed.

[0087] In the embodiments of the present application, the information to be processed is information generated after further processing of the operating information, such as screening, integration, and labeling. The client device or server can determine whether the outgoing event is a leakage event that causes a substantial leakage of information based on the information to be processed. The embodiments of the present application do not limit how to determine whether the outgoing event is a leakage event based on the information to be processed. For example, a classification model that can classify the information to be processed can be trained, and whether the outgoing event is a leakage event can be determined based on the output of the classification model. Alternatively, whether the outgoing event is a leakage event can be determined based on rule matching, etc.

[0088] In one embodiment, the client device may determine whether to provide a screenshot of the client device in the pending information based on the working status, specifically including:

[0089] When the client device is currently in a working state, a screen capture process is performed to obtain an operating screen image, and the operating screen image is used as the operating information.

[0090] In an embodiment of the present application, after an outgoing event is triggered, the client device obtains its own status. If the client device is in a non-operating state, taking a screenshot will not obtain valid information, but may affect the judgment of whether the outgoing event is a leak, and will also occupy the local cache of the client device. Therefore, when the client device is in a non-operating state, the operation information may not include the operation screen image. If the client device is in an operating state, the client device can take a screenshot to obtain the operation screen image, and include the operation screen image as one of the contents included in the operation information.

[0091] If the client device can locally determine whether an outgoing event is a leak, then processing the pending information means that the client device determines whether the outgoing event is a leak based on the pending information, and if so, sends the pending information to a server or database for storage, or deletes the pending information if not. If the client device needs to send the pending information to a server, and the server determines whether the outgoing event is a leak, then processing the pending information means that the client device sends the pending information to the server.

[0092] Step 108, periodically traverse all the operation information in the local cache, and for the current operation information traversed, when it is determined that the pending information corresponding to the current operation information has been processed successfully, determine whether to clear the current operation information based on the current working status duration and the difference between the working status timestamp of the current operation information.

[0093] In an embodiment of the present application, the client device periodically traverses locally cached operational information. If the client device determines that the pending information corresponding to the currently traversed operational information (hereinafter referred to as the current operational information) has been successfully processed, the client device further determines whether the operational information has expired. If so, the client device clears the operational information, or retains the operational information if not expired. If the client device determines that the pending information corresponding to the operational information has not been successfully processed, the client device may re-execute step 106 to re-process the pending information.

[0094] The embodiments of the present application do not limit how the client device determines that the pending information has been successfully processed. For example, the client device can add a successful processing mark to the operation information after the pending information has been successfully processed, and determine whether the pending information has been successfully processed by checking whether the current operation information has a successful processing mark. When the client device processes the pending information locally, the successful processing of the pending information means that the client device successfully identifies whether the outgoing event is a leak event, and receives a response message from the server for the report of the received leak event when the outgoing event is identified as a leak event; when the server processes the pending information, the successful processing of the pending information means that the client device receives a response message from the server for the report of the received pending information.

[0095] Alternatively, the client device may also communicate with the server regularly to determine which pending information or leakage events reported by the client devices have been received by the server. The client device may compare this information with the pending information or leakage events it has sent to the server to determine which pending information or leakage events it has sent have successfully reached the server (i.e., successfully processed) and which pending information or leakage events it has sent have not reached the server (i.e., failed to process).

[0096] If the client device determines that the pending information has been successfully processed, the client device clears the locally cached operation information after it expires to conserve storage space. Whether the operation information is expired is determined based on the difference between the current working state duration and the working state timestamp of the current operation information. For example, the operation information may be determined to be expired when the difference between the current working state duration and the current operation information is greater than a preset threshold.

[0097] If the client device determines that the pending information has not been processed successfully, the client device may regenerate the pending information based on the running information and update the working status timestamp of the running information according to the current working status duration to extend the expiration time of the running information.

[0098] The method for processing outgoing event information provided in an embodiment of the present application determines an outgoing state duration, which indicates the total time a client device has been in an outgoing state. When an outgoing event is triggered, the method sets an outgoing state timestamp for the operation information collected as evidence based on the outgoing state duration. When the client device determines whether to clear locally cached operation information, it uses the outgoing state duration and the outgoing state timestamp of the operation information to determine whether the operation information has expired. If it is determined that the operation information has expired and the corresponding pending information has been successfully processed, the operation information is cleared. Because the embodiment of the present application uses the actual time the client device has been in an outgoing state to determine whether the operation information has expired, it can accurately calculate whether the operation information has expired in scenarios where the user immediately shuts down the device after triggering an outgoing event, avoiding the situation where the client device automatically clears local operation information after the user turns the device back on after a long interval, causing evidence to be lost. Furthermore, when clearing expired operation information, the embodiment of the present application also determines whether the corresponding pending information has been successfully processed. Therefore, in scenarios where the user immediately disconnects from the network after triggering an outgoing event, the embodiment of the present application can also retain the operation information even if it is verified that the pending information was not successfully processed due to network reasons. It can reduce the probability of evidence being lost when it is not successfully reported in the data outbound scenario.

[0099] In one embodiment, Figure 2 As shown, a screen capture process is performed to obtain a running screen image, and the running screen image is used as running information, including:

[0100] Step 202: determining a preset screenshot mode and an alternative screenshot mode based on device information of the client device;

[0101] Step 204 : when the preset screenshot mode conflicts with the application currently running on the client device, a first target screenshot mode is determined from the candidate screenshot modes, and the first target screenshot mode is used to perform screenshot processing to obtain a running screen image.

[0102] In embodiments of the present application, a client device may determine a screenshot mode that matches the client device based on device information. The preset screenshot mode is the screenshot mode that best matches the client device, and the alternative screenshot mode is the screenshot mode available on the client device. Device information may include, but is not limited to, the client device's operating system version, graphics card model, and graphics card driver version.

[0103] In one embodiment, Figure 3 As shown, determining a preset screenshot mode based on device information of the client device includes:

[0104] If the client device's graphics card model is not NVIDIA, or the client device's operating system version is not Windows 8.1 or later, use GDI (Graphics Device Interface) screenshot as the default screenshot mode.

[0105] If the graphics card model of the client device is NVIDIA and the operating system version of the client device is Windows 8.1 or later, DXGI (DirectX Graphics Infrastructure) screenshot is used as the default screenshot mode.

[0106] Among them, GDI has strong compatibility and supports client devices with lower operating system versions. DXGI screenshots have better image quality, so if the operating system and graphics card support DXGI screenshots, DXGI screenshots can be used first. In addition to GDI and DXGI, other third-party tools or other interfaces of the operating system can also be used to obtain running screen images. The embodiments of this application do not limit the specific screenshot modes.

[0107] The client device may determine whether the preset screenshot mode is likely to conflict with an application currently running on the client device based on the conflict relationship between the pre-configured application and the screenshot mode. If the preset screenshot mode conflicts with the currently running application, the client device may replace the preset screenshot mode with a first target screenshot mode in the alternative screenshot mode that explicitly states that it does not conflict with each application, or at least does not state that it has a conflict relationship with each application, based on the conflict relationship between the pre-configured application and the screenshot mode, and use the first target screenshot mode to capture the running screen image.

[0108] If no error occurs when taking a screenshot using the first target screenshot mode, the client device may record that there is no conflict between the first target screenshot mode and each currently running application, which is equivalent to updating the conflicting application whitelist. If an error occurs when taking a screenshot using the first target screenshot mode, the client device may correspondingly record that there may be a conflict between the first target screenshot mode and each currently running application, which is equivalent to updating the conflicting application blacklist.

[0109] If the preset screenshot mode does not conflict with the currently running application, the above method also includes: using the preset screenshot mode for screenshot processing; if an error occurs during the screenshot processing using the preset screenshot mode, determining a second target screenshot mode from the alternative screenshot modes, using the second target screenshot mode for screenshot processing to obtain a running screen image, and setting the second target screenshot mode to the preset screenshot mode; if the working status of the client device changes, restoring the preset screenshot mode to the initial preset screenshot mode.

[0110] In the embodiment of this application, Figure 4 As shown, when taking a screenshot using the preset screenshot mode, the client device monitors whether an error occurs. If an error occurs, the client device can determine a second target screenshot mode from the candidate screenshot modes in the same manner as described above for selecting the first target screenshot mode from the candidate screenshot modes. The client device can also set the second target screenshot mode as the preset screenshot mode of the client device to avoid errors during subsequent screenshots.

[0111] In one embodiment, the client device may also determine whether to change the preset screenshot mode or adopt other processing methods based on the error code when the error occurs, including:

[0112] If the error code indicates that the error is an expected error, deinitialize and initialize the component that performs the screenshot;

[0113] When the error code indicates that the error is an unexpected error, a second target screenshot mode is determined from the alternative screenshot modes.

[0114] If the error is expected, the screenshot error may not be caused by a conflict between the screenshot mode and the currently running application. The client device can first try to restart the screenshot component to resolve the screenshot error. If the error is unexpected, the client device can replace the preset screenshot mode.

[0115] The client device may also restore the preset screenshot mode to the initially determined preset screenshot mode (i.e., the initial preset screenshot mode) at an appropriate time. This time may be when the working state of the client device changes, where the working state change may include a user restarting the client device, a user re-logging into the operating system, a user restarting the application used to execute the outgoing event information processing method, etc.

[0116] The method for processing outgoing event information provided in the embodiment of the present application automatically selects an appropriate preset screenshot mode for screenshot based on the device information of the client device, and maintains the conflict relationship between the screenshot mode and the application. When it is determined that the preset screenshot mode and the application conflict, it automatically switches to other screenshot modes to complete the screenshot, and switches to the preset screenshot mode when an error is reported during screenshot in the preset screenshot mode. This can achieve adaptation to multiple operating environments and improve the stability of screenshots.

[0117] In one embodiment, Figure 5 As shown, periodically determining whether the client device is in a working state includes:

[0118] Step 502: register a first callback function and a second callback function; the first callback function is used to be called when the screen power state changes and output the current screen power state; the second callback function is used to be called when the login state changes and output the current login state;

[0119] Step 504 : periodically determining whether the client device is in a working state based on at least one of the screen power state output by the first callback function, the login state output by the second callback function, and whether the screen saver is running.

[0120] In an embodiment of the present application, a client device may register a first callback function and a second callback function in the operating system to receive notifications of changes in the screen power state and login state. When executing the outgoing event information processing method, the client device may create an invisible window in the operating system for receiving notification messages. The first callback function will send notification messages to the invisible window when the screen is triggered to wake up or turn off. The second callback function will send notification messages to the invisible window when the operating system triggers login, logout, remote login, remote logout, screen lock, and screen unlock of a user session.

[0121] The client device can also obtain the name of the screen saver process and determine whether it is running by checking the process list. In Windows, if the screen saver process exists in the process list, it is necessary to further determine that the screen saver is running after determining that its parent process is winlogon (the process responsible for user login and logoff operations). For other operating systems, those skilled in the art can also configure the conditions for determining whether the screen saver is running based on actual needs.

[0122] The client device can be determined to be in an active state when the screen is triggered to wake up, unlock, or the operating system triggers a user session login or remote login. The client device can be determined to be in an inactive state when the screen is triggered to turn off, lock, run a screen saver, or log out of the user session triggered by the operating system or remote login.

[0123] Alternatively, the client device can also make more detailed distinctions and judgments based on the login and remote login status, including:

[0124] When the login state indicates that the client device is in a remote login state and the screen is unlocked, determining that the client device is in a working state;

[0125] In a case where the login state represents that the client device is in a locally logged-in state and the screen is unlocked, if the screen power state represents that the screen of the client device is awakened, it is determined that the client device is in a working state.

[0126] In the embodiment of the present application, if the client device is in a remote login state, the client device does not need to pay attention to whether the screen is awakened or turned off, and can determine that the client device is in a working state when the screen is unlocked and the user is logged in. If the client device is in a local login state, the client device can only determine that the client device is in a working state when the combination of screen awakening, screen unlocking, and user login is met.

[0127] For a flowchart of determining whether a client device is in working state, see Figure 6 As shown in the figure, the standards for determining whether a client device is in an inoperative state or an operative state according to different login states are as follows:

[0128] For locally logged-in client devices:

[0129] (1) The screen is off or locked, indicating that it is not in working state;

[0130] (2) The screen is awake and unlocked, indicating that it is in working state;

[0131] (3) Triggering remote login and unlocking the screen indicates that the system is in working state and there is no need to pay attention to the screen wake-up and screen off messages.

[0132] (4) The screen saver is running, which means it is not working.

[0133] For client devices with an existing RDP session:

[0134] (1) Ignore screen wake-up and screen off messages;

[0135] (2) The screen is unlocked, indicating that it is in working state;

[0136] (3) The screen is locked, indicating that it is not in working state;

[0137] (4) Triggering remote login and unlocking the screen indicates that the system is in working state;

[0138] (5) The screen saver is running, which means it is not working.

[0139] The outgoing event information processing method provided in the embodiment of the present application determines whether the client device is in a working state based on the screen power state and login state, and can distinguish between local login and remote login scenarios, thereby improving the accuracy of judging the working state.

[0140] In one embodiment, Figure 7 As shown, the information to be processed is processed, including:

[0141] Step 702, storing the information to be processed in the first database;

[0142] Step 704: Periodically traverse the pending information in the first database. For the current pending information found, if it is determined that the outgoing event corresponding to the current pending information is a leak event, move the current pending information to the second database; or if it is determined that the outgoing event corresponding to the current pending information is not a leak event, delete the current pending information.

[0143] Step 706: Periodically traverse the information to be processed in the second database, and report the traversed information to be processed.

[0144] In the embodiment of the present application, when the client device processes the information to be processed, it can first store the information to be processed in a first database set outside the client device. The client device can regularly traverse the first database and determine whether the outgoing event is a leak event based on the information to be processed.

[0145] If the client device determines that the outgoing event is a leak event, the client device moves the information to be processed to the second database. If the client device determines that the outgoing event is not a leak event, the client device deletes the information to be processed from the first database.

[0146] The client device may further periodically traverse the second database and report the pending information still existing in the second database. After receiving the report success message returned by the server, the client device deletes the corresponding pending information in the second database.

[0147] In one embodiment, the above method also includes: when the information to be processed is successfully reported, deleting the information to be processed from the second database; when there is no information to be processed corresponding to the current operation information in the first database and the second database, determining that the information to be processed corresponding to the current operation information is successfully processed.

[0148] In an embodiment of the present application, when the client device periodically checks whether local operating information has expired, it can determine whether the pending information has been successfully processed based on whether pending information corresponding to the operating information exists in the first database and the second database. Because the client device removes the pending information from the first database after determining whether the outgoing event is a leak based on the pending information, and removes the pending information from the second database after reporting the leak, the client device can determine that the pending information has been successfully processed if the pending information does not exist in both the first and second databases.

[0149] like Figure 8 The figure shows a flowchart of a client device determining whether to clear cached operation information. When traversing the operation information, the client device first obtains the current working state duration, and then determines the cache duration of the operation information based on the difference between the working state duration and the working state timestamp. The client device can obtain the cache duration threshold from the server. If the cache duration of the operation information is lower than the duration threshold, the client device does not clear the operation information. Otherwise, the client device further determines whether the to-be-processed information corresponding to the operation information is in the first database or the second database. If the to-be-processed information corresponding to the operation information is in any database, the client device does not clear the operation information. Otherwise, the client device clears the operation information and records the clearing operation in the operation log.

[0150] In one embodiment, Figure 9 As shown, an outgoing event information processing system is provided, including a working status perception module, a management module and a screenshot module, wherein:

[0151] The working state sensing module is used to periodically determine whether the client device is in the working state, and update the working state duration based on whether the client device is in the working state;

[0152] The management module is used to send a screenshot request to the screenshot module when an outgoing event is triggered;

[0153] The screenshot module is used to obtain from the working status perception module whether the client device is in a working state, and if the client device is currently in a working state, perform a screenshot process to obtain a running screen image, and send the running screen image to the management module; or if the client device is currently in a non-working state, do not perform a screenshot, and send a notification message to the management module;

[0154] The management module is used to generate current operation information based on the operation screen image and / or the operation status of the client device, encrypt and cache the operation information, obtain the current operation status duration from the operation status perception module, and generate a working status timestamp of the operation information according to the current working status duration;

[0155] The management module is further configured to generate information to be processed based on the operation information, store the information to be processed in a first database, periodically traverse the first database to determine whether an outgoing event corresponding to the information to be processed is a leak event, move the information to be processed corresponding to the leak event to a second database, and periodically traverse the second database to report and process the information to be processed in the second database;

[0156] The management module is also used to periodically traverse the locally cached operation information. For the current operation information traversed, if there is no pending information corresponding to the current operation information in the first database and the second database, it is determined that the pending information corresponding to the current operation information has been processed successfully, and based on the current working status duration and the difference between the working status timestamp of the current operation information, it is determined whether to clear the current operation information.

[0157] Among them, the working status perception module counts the working status duration in the following way: when the client device is in a non-working state, the updating of the working status duration is suspended; when the client device is in a working state, the incremental time between the current moment and the last statistical moment is calculated, and the incremental time is added to the last working status duration; if the client device was in a non-working state at the time of the last statistics and is in a working state at the time of this statistics, the switching time is recorded as the new last statistical moment.

[0158] The above technical solution can solve the existing problems of evidence preservation reliability, system adaptability, device status identification, network connection instability, and local cache evidence timeliness management. Specifically:

[0159] (1) Solving the problem of reliability of evidence preservation

[0160] This application maintains a dedicated database to track the processing status of each outgoing event in real time, ensuring that the integrity of the evidence is maintained even in the event of a system restart or shutdown.

[0161] Specifically, if a user suddenly shuts down or restarts their computer while an outbound incident occurs and forensic data has not yet been fully reported, the client device can persist the unfinished pending information in the database and automatically resume processing these unfinished tasks after the client device is restored. This mechanism ensures that even if an enterprise user emails multiple sensitive files in a short period of time and then performs a system reboot, the complete forensic data is retained, effectively tracing the entire process of the leak.

[0162] (2) Improving system adaptability

[0163] The screenshot module significantly improves the system's adaptability through the conflict application adapter submodule, graphics card adapter submodule and graphics anomaly tolerance submodule.

[0164] The conflicting application adapter module maintains a signature database of known conflicting applications, monitors running processes in real time, and automatically switches to a non-conflicting screenshot method when a conflicting application is detected. This resolves desktop lag and screen flickering issues caused by conflicts between certain graphics processing software or video players and the screenshot mechanism, significantly improving the user experience.

[0165] The graphics card adapter module automatically identifies the graphics card type, model, and architecture characteristics of the system and matches the optimal screenshot mode based on the graphics card driver version. This allows the system to adapt to the differences in graphics cards on different terminal devices, ensuring stable operation in various hardware environments.

[0166] The graphics exception fault tolerance submodule accurately parses the error codes returned by the screenshot API, classifies the captured exception errors, and automatically switches to the optimal alternative screenshot mode, further enhancing the stability of the system in complex environments.

[0167] (3) Identify client device status

[0168] The work behavior perception module registers callback functions to intelligently identify special states such as shutdown, restart, hibernation, sleep, screen saver, lock screen, screen off, and logout. Based on this status information, the system intelligently decides whether to take screenshots, avoiding the generation of a large number of meaningless black, blue, or green screen screenshots.

[0169] Especially for RDP session scenarios, this system can distinguish between personal local logins and devices with RDP sessions, and adopt different status judgment logic to ensure that the user's work status can be accurately judged in various complex usage scenarios, avoiding screenshot anomalies caused by status recognition errors.

[0170] (4) Solve the problem of unstable network connection

[0171] The management module's reporting phase management function features a dedicated network anomaly handling mechanism. When a network device node becomes unstable or disconnected, the system stores the pending event information in a database and continuously monitors the data reporting process to address any network anomalies that may arise.

[0172] Even if the user intentionally disconnects from the network during data transmission and reconnects to the network a long time later, the system can maintain the integrity of the forensic data and ensure that the reporting process can continue after the network is restored, avoiding the loss of key evidence.

[0173] (5) Improve local cache timeliness management

[0174] This application uses the work behavior perception module to obtain the duration of the user's current work state, rather than simply relying on the system time. The system calculates the difference between the work state duration and the work state timestamp to obtain the storage duration of cached data in the work state. This calculation method based on actual work time rather than system time can solve the cache management defects of traditional systems.

[0175] Traditional systems rely solely on the system time to set a fixed cache expiration period. When a user triggers an outbound event, puts the device into hibernation for a period of time (perhaps a day or even a week), and then turns it back on, the system time has already passed. This causes the screenshot data to be cleared because it has exceeded the preset cache retention period. However, this invention, by counting the actual operating time, allows the system to accurately identify the actual operating time even if the device is turned on again after a week of hibernation, thus avoiding incorrect clearing based on the system time.

[0176] Furthermore, before executing cleanup, the system verifies that pending information still exists in the database. Only when the cache duration exceeds a threshold and the pending information is no longer in the database will the security cleanup process be executed. This double-check mechanism effectively avoids competition between the cleanup logic and the reporting logic, ensuring that important forensic data is not automatically cleaned up by the system before being reported, thereby ensuring the integrity and validity of the evidence.

[0177] It should be understood that, although the steps in the flowcharts of the above embodiments are shown in sequence as indicated by the arrows, these steps are not necessarily performed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be performed in other orders. Moreover, at least a portion of the steps in the flowcharts of the above embodiments may include multiple steps or multiple stages, and these steps or stages are not necessarily performed at the same time, but can be performed at different times. The execution order of these steps or stages is not necessarily to be performed in sequence, but can be performed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0178] Based on the same inventive concept, the embodiments of the present application also provide an outgoing event information processing device for implementing the outgoing event information processing method involved above. The implementation solution provided by this device is similar to the implementation solution described in the above method. Therefore, the specific limitations in one or more embodiments of the outgoing event information processing device provided below can be found in the above-mentioned limitations on the outgoing event information processing method, and will not be repeated here.

[0179] In one embodiment, Figure 10As shown, an external event information processing device 1000 is provided, comprising: a first determination module 1002, a generation module 1004, a processing module 1006, and a cleaning module 1008, wherein:

[0180] A first determining module 1002 is configured to periodically determine whether the client device is in a working state, and update a working state duration based on whether the client device is in a working state;

[0181] The generating module 1004 is configured to cache the current operation information and generate a working state timestamp of the operation information according to the current working state duration when an external event is triggered;

[0182] The processing module 1006 is configured to generate information to be processed based on the operation information and process the information to be processed;

[0183] The cleaning module 1008 is used to periodically traverse all the operation information in the local cache. For the current operation information traversed, when it is determined that the pending information corresponding to the current operation information has been processed successfully, it is determined whether to clean the current operation information based on the current working status duration and the difference between the working status timestamp of the current operation information.

[0184] In one embodiment, the apparatus further comprises:

[0185] The first screenshot module is used to perform screenshot processing to obtain an operating screen image when the client device is currently in a working state, and use the operating screen image as the operating information.

[0186] In one embodiment, the screenshot module is further configured to:

[0187] Determining a preset screenshot mode and an alternative screenshot mode based on device information of the client device;

[0188] In the case that the preset screenshot mode conflicts with the application currently running on the client device, a first target screenshot mode is determined from the alternative screenshot modes, and the first target screenshot mode is used to perform screenshot processing to obtain the running screen image.

[0189] In one embodiment, the apparatus further comprises:

[0190] A second screenshot module is configured to perform screenshot processing using the preset screenshot mode when the preset screenshot mode does not conflict with the application currently running on the client device;

[0191] a third screenshot module configured to, if an error occurs during the screenshot processing using the preset screenshot mode, determine a second target screenshot mode from the alternative screenshot modes, perform screenshot processing using the second target screenshot mode to obtain the running screen image, and set the second target screenshot mode as the preset screenshot mode;

[0192] The restoration module is used to restore the preset screenshot mode to the initial preset screenshot mode when the working state of the client device changes.

[0193] In one embodiment, the first determining module 1002 is further configured to:

[0194] Register a first callback function and a second callback function; the first callback function is used to be called when the screen power state changes and output the current screen power state; the second callback function is used to be called when the login state changes and output the current login state;

[0195] Periodically determining whether the client device is in a working state based on at least one of the screen power state output by the first callback function, the login state output by the second callback function, and whether a screen saver is running.

[0196] In one embodiment, the first determining module 1002 is further configured to:

[0197] When the login state indicates that the client device is in a remote login state and the screen is unlocked, determining that the client device is in a working state;

[0198] In a case where the login state represents that the client device is in a locally logged-in state and the screen is unlocked, if the screen power state represents that the screen of the client device is awakened, it is determined that the client device is in a working state.

[0199] In one embodiment, the processing module 1006 is further configured to:

[0200] Storing the information to be processed in a first database;

[0201] Periodically traversing the information to be processed in the first database, and for the current information to be processed found, if it is determined that the external event corresponding to the current information to be processed is a leak event, moving the current information to be processed to the second database, or if it is determined that the external event corresponding to the current information to be processed is not the leak event, deleting the current information to be processed;

[0202] Periodically traverse the information to be processed in the second database, and report the traversed information to be processed.

[0203] In one embodiment, the apparatus further comprises:

[0204] a deleting module, configured to delete the information to be processed from the second database if the information to be processed is successfully reported;

[0205] The second determining module is configured to determine that the processing of the information to be processed corresponding to the current operation information is successful when the information to be processed corresponding to the current operation information does not exist in the first database and the second database.

[0206] Each module in the above-mentioned apparatus may be implemented in whole or in part by software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in the form of hardware, or may be stored in a memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to each module.

[0207] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 11 As shown. The computer device includes a processor, memory, and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, it implements a method for processing external event information.

[0208] Those skilled in the art will understand that Figure 11 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0209] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.

[0210] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0211] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0212] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0213] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. In particular, any reference to memory, database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The databases involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processors involved in the various embodiments provided herein may be, but are not limited to, general-purpose processors, central processing units (CPUs), graphics processing units (GPUs), digital signal processors (DSPs), programmable logic devices (PLDs), data processing logic devices based on quantum computing, and the like.

[0214] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0215] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A method for processing outgoing event information, characterized in that: The method is applied to a client device and includes: periodically determining whether the client device is in a working state, and updating a working state duration based on whether the client device is in a working state; When an outgoing event is triggered, the current operation information is cached, and a working state timestamp of the operation information is generated according to the current working state duration; generating information to be processed based on the operation information, and processing the information to be processed; Periodically traverse all the operation information in the local cache, and for the current operation information traversed, when it is determined that the pending information corresponding to the current operation information has been processed successfully, determine whether to clear the current operation information based on the current working status duration and the difference between the working status timestamp of the current operation information.

2. The method according to claim 1, characterized in that The method further comprises: When the client device is currently in a working state, a screen capture process is performed to obtain an operating screen image, and the operating screen image is used as the operating information.

3. The method according to claim 2, characterized in that The performing of screen capture processing to obtain an operation screen image, and using the operation screen image as the operation information, includes: Determining a preset screenshot mode and an alternative screenshot mode based on device information of the client device; In the case that the preset screenshot mode conflicts with the application currently running on the client device, a first target screenshot mode is determined from the alternative screenshot modes, and the first target screenshot mode is used to perform screenshot processing to obtain the running screen image.

4. The method according to claim 3, characterized in that The method further comprises: In the case where the preset screenshot mode does not conflict with the application currently running on the client device, adopting the preset screenshot mode to perform screenshot processing; In the event that an error occurs during the screenshot processing using the preset screenshot mode, determining a second target screenshot mode from the alternative screenshot modes, performing screenshot processing using the second target screenshot mode to obtain the running screen image, and setting the second target screenshot mode as the preset screenshot mode; When the working state of the client device changes, the preset screenshot mode is restored to the initial preset screenshot mode.

5. The method according to claim 1, wherein The periodically determining whether the client device is in a working state includes: Register a first callback function and a second callback function; the first callback function is used to be called when the screen power state changes and output the current screen power state; the second callback function is used to be called when the login state changes and output the current login state; Periodically determining whether the client device is in a working state based on at least one of the screen power state output by the first callback function, the login state output by the second callback function, and whether a screen saver is running.

6. The method according to claim 5, characterized in that The determining whether the client device is in a working state based on at least one of the screen power state output by the first callback function, the login state output by the second callback function, and whether the screen saver process is running includes: When the login state indicates that the client device is in a remote login state and the screen is unlocked, determining that the client device is in a working state; In a case where the login state represents that the client device is in a locally logged-in state and the screen is unlocked, if the screen power state represents that the screen of the client device is awakened, it is determined that the client device is in a working state.

7. The method according to claim 1, characterized in that The processing of the information to be processed includes: Storing the information to be processed in a first database; Periodically traversing the information to be processed in the first database, and for the current information to be processed found, if it is determined that the external event corresponding to the current information to be processed is a leak event, moving the current information to be processed to the second database, or if it is determined that the external event corresponding to the current information to be processed is not the leak event, deleting the current information to be processed; Periodically traverse the information to be processed in the second database, and report the traversed information to be processed.

8. The method according to claim 7, characterized in that The method further comprises: If the information to be processed is successfully reported, deleting the information to be processed from the second database; In a case where the to-be-processed information corresponding to the current operation information does not exist in either the first database or the second database, it is determined that the to-be-processed information corresponding to the current operation information has been successfully processed.

9. An outgoing event information processing device, characterized in that: The device is applied to a client device and includes: A first determining module is configured to periodically determine whether the client device is in a working state, and update a working state duration based on whether the client device is in a working state; A generating module, configured to cache current operation information and generate a working state timestamp of the operation information according to the current working state duration when an outgoing event is triggered; a processing module, configured to generate information to be processed based on the operation information, and process the information to be processed; A cleaning module is used to periodically traverse all the operation information in the local cache. For the current operation information traversed, when it is determined that the pending information corresponding to the current operation information has been processed successfully, it is determined whether to clean the current operation information based on the current working status duration and the difference between the working status timestamp of the current operation information.

10. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 8 are implemented.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.

12. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 8 are implemented.

Citation Information

Patent Citations

  • Expired data file processing method, device, electronic device and storage medium

    CN109408469A

  • Cleaning method and device of intelligent device system, storage medium and electronic device

    CN113704198A

  • Data caching method and device, computer equipment and storage medium

    CN119066279A

  • Information leakage prevention program, information leakage preventing method and information leakage preventing device

    JP2007233989A