Data classification and grading method and device, electronic equipment and storage medium

By obtaining contextual information of user data operations, combining risk assessment rules to calculate comprehensive contextual risk values, dynamically adjusting data levels and implementing security management strategies, the problem of data security levels being unable to be adjusted in real time in existing technologies is solved, thereby improving the effectiveness and flexibility of data security protection.

CN120804832APending Publication Date: 2025-10-17GUANGDONG SOUTHERN INFORMATION SECURITY RES INST
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511026370.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-24
Publication Date
2025-10-17

AI Technical Summary

Technical Problem

The existing data classification and grading system is unable to perceive, evaluate and adjust data security levels and management strategies in real time under dynamic situations, resulting in the underestimation of the real data risks and the failure to trigger matching protection measures.

Method used

By obtaining the user's contextual information during data operations, combining the preset risk assessment rules to calculate the comprehensive contextual risk value, dynamically adjusting the data level, and executing matching security management and control strategies, including comprehensive assessment of access, transmission, query and external threat intelligence information.

Benefits of technology

It achieves real-time perception and dynamic adjustment of data security levels in dynamic situations, improves the effectiveness and flexibility of data security protection, and avoids data leakage and compliance issues.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120804832A_ABST
    Figure CN120804832A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of data security, and discloses a data classification and grading method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining situation information of a user during data operation, calculating a comprehensive situation risk value of the data operation according to the situation information in combination with a preset risk assessment rule, and determining a temporary security level of the data operation based on the comprehensive situation risk value, and executing a data security management and control strategy matched with the temporary security level. According to the method, the temporary security level of the data operation is determined through the comprehensive situation risk value of the user during the data operation calculated based on the preset risk assessment rule, so that the data level is dynamically adjusted, and the effectiveness and the flexibility of data security protection are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data security, in particular to a data classification and grading method and device, electronic equipment and storage medium. BACKGROUND

[0002] In the enterprise data asset management platform, with the increasing complexity and dynamic of data application scenarios, the existing data classification and grading system generally faces challenges. These systems usually rely on pre-set static rules and fixed permission configurations, which are difficult to adapt to the dynamic changes of user access context, data transmission path, data aggregation method and external threat intelligence. When the user performs data operations, such as accessing, transmitting or querying data, the context information (such as access source, time, behavior pattern, data correlation, etc.) is constantly changing.

[0003] However, the traditional classification and grading method cannot real-time perceive and comprehensively evaluate the risks brought by these dynamic contexts, resulting in that the real security risks of data are seriously underestimated when it is in an unexpected access environment, abnormal behavior pattern, uncontrolled transmission path and faces potential threats. This lag makes the system fail to trigger the protection measures matching the current risk level in time, which may lead to a series of serious security challenges such as data leakage, violation of compliance requirements and complex security audit process.

[0004] Therefore, in order to solve the technical problem that the existing data classification and grading method cannot real-time perceive, evaluate and adjust the data security level and control strategy in the dynamic context, resulting in that the real risk of data is underestimated and the protection measures matching the risk cannot be triggered, it is urgent to provide a data classification and grading method, device, electronic equipment and storage medium. SUMMARY

[0005] The purpose of the present application is to provide a data classification and grading method, device, electronic equipment and storage medium, which determines the temporary security level of data operation by the comprehensive context risk value of the user in data operation calculated based on the pre-set risk evaluation rules, dynamically adjusts the data level, solves the problem that the existing data classification and grading method cannot real-time perceive, evaluate and adjust the data security level and control strategy in the dynamic context, resulting in that the real risk of data is underestimated and the protection measures matching the risk cannot be triggered, can dynamically determine the temporary security level of data operation, and execute the matching security control strategy accordingly, improves the effectiveness and flexibility of data security protection.

[0006] In a first aspect, the present application provides a data classification and grading method for dynamically adjusting the data level, comprising the steps of: obtaining the context information of the user in data operation; According to the context information, a comprehensive context risk value of the data operation is calculated in combination with a preset risk assessment rule; Based on the comprehensive context risk value, a temporary security level of the data operation is determined; A data security management strategy matching the temporary security level is executed.

[0007] The data classification and grading method provided in the application can dynamically adjust the data level, determine the temporary security level of the data operation based on the comprehensive context risk value of the user during data operation calculated based on the preset risk assessment rule, dynamically adjust the data level, solve the problem that the existing data classification and grading method cannot perceive, assess and adjust the data security level and management strategy in a dynamic context, leading to underestimation of the real risk of data and failure to trigger the protection measures matching the risk, and dynamically determine the temporary security level of the data operation and execute the matching security management strategy accordingly, thereby improving the effectiveness and flexibility of data security protection.

[0008] Optionally, the context information includes access context information, data transmission context information, data query context information and external threat intelligence information; and the preset risk assessment rule includes a preset basic context risk assessment rule and a preset data correlation reasoning risk assessment rule.

[0009] Optionally, according to the context information, a comprehensive context risk value of the data operation is calculated in combination with a preset risk assessment rule, including: According to the access context information, the data transmission context information and the external threat intelligence information, a basic context risk score of the data operation is calculated in combination with the preset basic context risk assessment rule; According to the data query context information, a data correlation reasoning risk score of the data operation is calculated in combination with the preset data correlation reasoning risk assessment rule; The basic context risk score and the data correlation reasoning risk score are fused to calculate the comprehensive context risk value of the data operation.

[0010] Optionally, according to the access context information, the data transmission context information and the external threat intelligence information, a basic context risk score of the data operation is calculated in combination with the preset basic context risk assessment rule, including: Risk factors corresponding to each risk dimension in the access context information, the data transmission context information and the external threat intelligence information are extracted; According to the risk factor and a risk factor weight adjustment strategy in the preset basic context risk assessment rule, a basic context risk calculation weight of each risk factor is determined; According to the risk factor and the basic situation risk, a weight of the basic situation risk of the data operation is calculated.

[0011] The data classification and grading method provided in the application can realize dynamic adjustment of data levels, and through introduction of extraction of risk factors, dynamic determination of weights, and score calculation based on the weights, it is ensured that the calculated basic situation risk score can highly match the actual risk status of the data operation, thereby providing a solid and accurate basis for subsequent calculation of comprehensive situation risk values and determination of temporary security levels.

[0012] Optionally, according to the data query situation information, a data correlation and reasoning risk score of the data operation is calculated in combination with the preset data correlation and reasoning risk assessment rule, including: A plurality of data fields are extracted from a query statement in the data query situation information; Based on metadata information, data content features, and historical query co-occurrence patterns of each data field, explicit association relationships and implicit association relationships between the data fields are identified to obtain association relationships between the data fields; According to the association relationships between the data fields, in combination with the preset data correlation and reasoning risk assessment rule, a data correlation and reasoning risk score of the data operation is calculated.

[0013] The data classification and grading method provided in the application can realize dynamic adjustment of data levels, and through introduction of extraction of risk factors, dynamic determination of weights, and score calculation based on the weights, it is ensured that the calculated basic situation risk score can highly match the actual risk status of the data operation, thereby providing a solid and accurate basis for subsequent calculation of comprehensive situation risk values and determination of temporary security levels.

[0014] Optionally, according to the association relationships between the data fields, in combination with the preset data correlation and reasoning risk assessment rule, a data correlation and reasoning risk score of the data operation is calculated, including: An association path constituted by the association relationships is identified, and a path length, a path type, and a sensitive level of a data field involved in the association path are analyzed; According to the path length, the path type, and the sensitive level of the data field of the association path, in combination with a preset data correlation and reasoning risk assessment rule, an initial risk score of the association path is calculated; User behavior patterns, query frequencies, operation times, and user permission information of the data operation are acquired to correct the initial risk score in combination with a preset dynamic situation risk correction rule, thereby obtaining a data correlation and reasoning risk score of the data operation.

[0015] Optionally, the user behavior mode, query frequency, operation time and user permission information of the data operation are acquired to modify the initial risk score in combination with a preset dynamic context risk modification rule, to obtain a data correlation inference risk score of the data operation, including: The user behavior mode, query frequency, operation time and user permission information of the data operation are acquired as dynamic context factors; According to the dynamic context factors, the initial risk score is modified in combination with a preset dynamic context risk modification rule, to obtain a data correlation inference risk score of the data operation.

[0016] In a second aspect, the present application provides a data classification and grading device for dynamically adjusting the data level, including: An acquisition module is configured to acquire context information of a user during data operation; A calculation module is configured to calculate a comprehensive context risk value of the data operation in combination with a preset risk assessment rule according to the context information; A determination module is configured to determine a temporary security level of the data operation based on the comprehensive context risk value; A control module is configured to execute a data security control strategy matching the temporary security level.

[0017] The data classification and grading device determines the temporary security level of the data operation based on the comprehensive context risk value of the user during data operation calculated in combination with the preset risk assessment rule, to dynamically adjust the data level, solves the problem that the existing data classification and grading method cannot realize real-time perception, assessment and adjustment of the data security level and control strategy in a dynamic context, leading to underestimation of the data real risk and failure to trigger the protection measures matching the risk, can dynamically determine the temporary security level of the data operation, and accordingly execute the matching security control strategy, and improves the effectiveness and flexibility of data security protection.

[0018] In a third aspect, the present application provides an electronic device including a processor and a memory, wherein the memory stores a computer program executable by the processor, and when the processor executes the computer program, the steps in the data classification and grading method described above are run.

[0019] In a fourth aspect, the present application provides a computer readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps in the data classification and grading method described above are run. Advantageous effects

[0020] The data classification grading method, device, electronic equipment and storage medium provided by the application determine the temporary security level of data operation by the comprehensive situation risk value of the user in data operation calculated based on the preset risk assessment rule, dynamically adjust the data level, solve the problem that the existing data classification grading method cannot realize real-time perception, assessment and adjustment of the data security level and control strategy in a dynamic situation, leading to underestimation of the real risk of data and failure to trigger the protection measures matching the risk, and can dynamically determine the temporary security level of data operation and execute the matching security control strategy accordingly, improving the effectiveness and flexibility of data security protection. BRIEF DESCRIPTION OF DRAWINGS

[0021] Figure 1 The flowchart of the data classification grading method provided by the embodiment of the application.

[0022] Figure 2 The structural schematic diagram of the data classification grading device provided by the embodiment of the application.

[0023] Figure 3 The structural schematic diagram of the electronic equipment provided by the embodiment of the application.

[0024] Label explanation: 1, acquisition module; 2, calculation module; 3, determination module; 4, control module; 301, processor; 302, memory; 303, communication bus. DETAILED DESCRIPTION

[0025] The technical solutions in the embodiments of the application will be clearly and completely described below with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are only part of the embodiments of the application, rather than all the embodiments of the application. The components of the embodiments of the application described and shown in the drawings can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the application provided in the drawings is not intended to limit the scope of the claimed application, but only represents selected embodiments of the application. Based on the embodiments of the application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of the application.

[0026] It should be noted that: similar labels and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. Meanwhile, in the description of the application, the terms "first", "second" and the like are only used to distinguish the description, and cannot be understood as indicating or implying relative importance.

[0027] Please refer to Figure 1 , Figure 1The data classification grading method is a data classification grading method in some embodiments of the present application, which is used for dynamically adjusting the data level, comprising: Step S101, obtaining the context information of the user during data operation; Step S102, calculating the comprehensive context risk value of the data operation according to the context information and combining the preset risk assessment rule; Step S103, determining the temporary security level of the data operation based on the comprehensive context risk value; Step S104, executing the data security management and control strategy matched with the temporary security level.

[0028] The data classification grading method determines the temporary security level of the data operation through the comprehensive context risk value of the user during data operation calculated based on the preset risk assessment rule, dynamically adjusts the data level, solves the problem that the existing data classification grading method cannot realize real-time perception, assessment and adjustment of the data security level and control strategy in a dynamic context, leading to underestimation of the real risk of data and failure to trigger the protection measures matched with the risk, can dynamically determine the temporary security level of the data operation, and execute the matched security control strategy accordingly, thereby improving the effectiveness and flexibility of data security protection.

[0029] Specifically, in step S101, the context information of the user during data operation, the context information includes access context information, data transmission context information, data query context information and external threat intelligence information. Among them, the access context information includes access time, source address, device identification, access frequency, access data volume and operation type; the data transmission context information includes transmission source area, target area and transmission protocol; the data query context information includes the data table, data field and association relationship between the data table and data field involved in the query statement; the external threat intelligence information includes attack indicator, known vulnerability information and risk address information.

[0030] Specifically, the preset risk assessment rule includes a preset basic context risk assessment rule and a preset data association reasoning risk assessment rule; in step S102, the comprehensive context risk value of the data operation is calculated according to the context information and combining the preset risk assessment rule, including: According to the access context information, the data transmission context information and the external threat intelligence information, combining the preset basic context risk assessment rule, the basic context risk score of the data operation is calculated; According to the data query context information, combining the preset data association reasoning risk assessment rule, the data association reasoning risk score of the data operation is calculated; Fusing the basic context risk score and the data association reasoning risk score, the comprehensive context risk value of the data operation is calculated.

[0031] In step S102, the preset risk assessment rules include preset basic context risk assessment rules and preset data correlation inference risk assessment rules. The preset risk assessment rules refer to a set of logic and standards defined in advance before system operation for assessing data operation risks, which can be constructed in the form of expert rule library, machine learning model, risk scoring matrix, decision tree, etc. The preset basic context risk assessment rules refer to rules for assessing risks of direct context factors such as access, transmission and external threats, which can assess risks according to pre-defined risk factor weights, threshold values or risk level mapping tables. The preset data correlation inference risk assessment rules refer to rules specially used for assessing potential risks caused by correlation between data fields in data query operations, which can define risk assessment logic based on sensitive levels of data fields, complexity of correlation paths, possibility of inference and historical leakage events, etc.

[0032] For example, the preset basic context risk assessment rules can be configured as follows: if a user logs in from a non-company internal IP address, the basic risk score (risk factor value) increases; if the data transmission protocol is not encrypted, the basic risk score further increases; if the client IP address hits a malicious IP blacklist, the basic risk score greatly increases. Meanwhile, the preset data correlation inference risk assessment rules can be configured as follows: if the query statement contains both the "employee name" and "salary" fields, and both the fields are marked as high sensitivity in the metadata, the data correlation inference risk score increases; if the query statement can indirectly deduce sensitive information through multi-table correlation (for example, by correlating "employee ID" and "department" tables, and then correlating "department" and "salary" tables, finally deducing the salary of all employees in a certain department), the data correlation inference risk score also increases accordingly. In this way, a more accurate and comprehensive data operation comprehensive context risk value can be calculated according to context information of different dimensions and targeted risk assessment rules, thereby providing fine-grained decision basis for subsequent data security management and control.

[0033] Specifically, in step S102, according to the access context information, the data transmission context information and the external threat intelligence information, and in combination with the preset basic context risk assessment rules, a basic context risk score of the data operation is calculated, including: extracting risk factors corresponding to each risk dimension in the access context information, the data transmission context information and the external threat intelligence information; determining basic context risk calculation weights of the risk factors according to the risk factors and risk factor weight adjustment strategies in the preset basic context risk assessment rules; calculating the basic context risk score of the data operation according to the risk factors and the basic context risk calculation weights.

[0034] In step S102, by deeply analyzing the access context information, data transmission context information and external threat intelligence information, the original context information (original data in the context information) in the access context information, data transmission context information and external threat intelligence information is standardized and processed, and "quantifiable characteristic parameters (i.e. risk factors)" directly reflecting the risk level are extracted. Each risk dimension corresponding to the risk factor can be extracted in detail, and according to the preset basic context risk assessment rule, the risk factor is given a corresponding score (usually set to 0 to 5 points), which is the risk factor value. For example, the risk factor is "whether it is external network access". If the access context information shows yes, a higher score (i.e. 5 points) is given, and if no, a lower score (i.e. 0 points) is given. This step is the basis of risk assessment, which ensures that all possible elements that may affect data security are identified, avoiding the risk of omission or underestimation caused by rough assessment.

[0035] Among them, the risk factor refers to the smallest and quantifiable element that may affect the data security risk level during data operation. These factors can include but are not limited to user identity, access time, access location, data sensitivity, transmission protocol, transmission destination, external attack type, threat intelligence level, etc. Risk dimension refers to different perspectives or aspects for classifying and assessing risks, such as access risk dimension, transmission risk dimension, external threat risk dimension, etc. Each dimension contains multiple specific risk factors.

[0036] For example, the "access timestamp" obtained from the access log monitoring module can be converted into the risk factor "whether it is non-working hours"; "source IP address" and "access device identification" can be converted into the risk factors "whether it is external network access" or "whether it is personal device access"; "data access frequency" and "access data volume" can be converted into the behavior pattern risk factors "whether it is bulk download" or "whether it is high-frequency access". Similarly, the "transmission target network area" identified by the network traffic analysis module can be converted into the risk factor "whether it is external non-controlled network transmission"; the "data table, data field and their mutual relationship" identified by the data query analysis module can be converted into the risk factor "whether there is potential associated reasoning risk"; and the "attack indicators, known vulnerability information, high-risk IP addresses" obtained by the threat intelligence interface module are directly used as external threat risk factors.

[0037] After identifying these risk factors, the base context risk calculation weight of each risk factor is dynamically determined according to these risk factors and the risk factor weight adjustment strategy in the preset base context risk assessment rule. This step is the key to realizing dynamic risk assessment. It recognizes that the importance of different risk factors in different contexts is not constant, and the preset base context risk assessment rule defines the risk weight adjustment weight threshold (i.e. risk factor weight adjustment strategy) corresponding to different context feature combinations and the risk level promotion threshold corresponding to different context feature combinations, for example, the rule base may define the combination of "non-working hours access + personal device + external network", which will increase the value of the base context risk calculation weight of the corresponding risk factor; "large amount of high-sensitivity data downloaded in a short time" will make the corresponding risk factor score increase by a certain number of points; when a specific high-risk external threat is detected, the risk factor weight related to the threat should be significantly increased. By introducing the weight adjustment strategy, the influence of each risk factor can be flexibly adjusted according to the changes in real-time context, so that each risk factor can be given a weight that matches its current context relevance and potential impact when calculating the base context risk score. This dynamic weight determination method makes risk assessment no longer static, but can flexibly adjust the influence of each risk factor according to the changes in real-time context, thereby more accurately reflecting the true risk situation of the current data operation.

[0038] Among them, the risk factor weight adjustment strategy refers to a set of pre-set rules or algorithms for adjusting the importance or influence of different risk factors in the calculation of the base context risk score according to the dynamic changes of the current context. This strategy can be based on machine learning models, expert experience rule bases, or real-time context analysis results, for example, when a high-risk external threat is detected, the weight of the risk factor related to the external threat can be dynamically increased.

[0039] Based on the risk factor corresponding score (risk factor value) and weight, the base context risk score of the data operation is calculated by weighted summation, combining the fine-grained risk factors extracted above, the dynamically adjusted weights, and the original context information. This step combines the fine-grained risk factors extracted above, the dynamically adjusted weights, and the original context information, and obtains a comprehensive base context risk score through quantitative methods. This score not only considers the presence of risk factors, but more importantly, it incorporates the relative importance of these factors in the current context, ensuring that the calculated base context risk score closely matches the actual risk situation of the data operation.

[0040] Specifically, in step S102, based on the data query context information and in combination with the preset data association reasoning risk assessment rules, the data association reasoning risk score of the data operation is calculated, including: Extracting multiple data fields from the query statement in the data query context information; Based on the metadata information, data content characteristics and historical query co-occurrence patterns of each data field, the explicit and implicit association relationships between the data fields are identified to obtain the association relationships between the data fields; According to the association relationship between each data field and the preset data association reasoning risk assessment rules, the data association reasoning risk score of the data operation is calculated.

[0041] In step S102, multiple data fields are extracted from the query statement in the data query context information. This initial step ensures that the subsequent analysis is based on the context of the user's actual operation, thereby capturing potential risk points in dynamic situations.

[0042] The relationships between data fields are not limited to explicit relationships clearly defined in the database; implicit relationships based on business logic, data lineage, or semantics may also exist. Therefore, based on the metadata information, data content characteristics, and historical query co-occurrence patterns of each data field, explicit and implicit relationships between data fields are identified to obtain the relationships between data fields. Explicit relationships refer to direct connections between data fields established through clear structural definitions or preset logical rules. These can be identified through methods such as database schema analysis and data model definition. Implicit relationships refer to potential connections between data fields that, while not clearly defined structurally, are indirectly manifested through data content, semantic context, or user behavior. These can be identified through methods such as semantic analysis, machine learning, and behavioral pattern analysis. Metadata information refers to data that describes the data and can be expressed in the form of data dictionaries, data schema definitions, data types, data lengths, data sources, data owners, security labels, and sensitivity levels. Data content features refer to the semantics, patterns, or statistical properties inherent in the data itself. They can be expressed through data value distribution, data format, data type, keywords, text similarity, data entropy, and other methods. Historical query co-occurrence patterns refer to the frequency and regularity with which different data fields appear simultaneously in the same query statement or related queries during past data query operations. These patterns can be identified using techniques such as query log analysis, association rule mining, and graph analysis.

[0043] For example, for data content features, there is an "ID number" field in the "employee table" and an "ID number" field in the "salary table", although there is no explicit association between them, but by analyzing the data content of the two fields (such as data format, value range, uniqueness, etc.), those skilled in the art can infer that they represent the same entity, thereby identifying the implicit association between them. This analysis based on data content features can discover data associations that are not directly reflected in the database structure but actually exist, greatly expanding the scope of association relationship identification and improving the comprehensiveness of risk assessment; or for historical query co-occurrence patterns, users may frequently query "customer name" and "customer phone" at the same time, even if the two fields may be scattered in different tables and have no direct database association, but by analyzing a large number of historical query logs, identifying which data fields often appear together in query statements can infer that there is an implicit association between these fields at the user level. This identification based on historical behavior patterns can reveal potential reasoning paths that users may use, thereby more accurately assessing the acquisition of sensitive information through legal query combinations.

[0044] Once these explicit and implicit association relationships are identified, the data association reasoning risk score of the data operation needs to be calculated according to these association relationships in combination with the preset data association reasoning risk assessment rules.

[0045] Specifically, in step S102, the data association reasoning risk score of the data operation is calculated according to the association relationships between the data fields in combination with the preset data association reasoning risk assessment rules, including: identifying the association path formed by the association relationships, and analyzing the path length, path type, and sensitive level of the data fields involved in the path of the association path; calculating the initial risk score of the association path according to the path length of the association path, the path type of the association path, and the sensitive level of the data fields in combination with the preset data association reasoning risk assessment rules; obtaining user behavior patterns, query frequency, operation time, and user permission information of the data operation to modify the initial risk score in combination with the preset dynamic context risk modification rules to obtain the data association reasoning risk score of the data operation.

[0046] In step S102, on the basis of identifying the explicit and implicit association relationships between the data fields, further identify the association paths formed by these association relationships. This involves in-depth analysis of the internal characteristics of each association path, including its path length, path type, and the sensitivity level of the data fields involved in the path. For example, a short path involving multiple sensitive fields and a long path involving non-sensitive fields may have completely different risk levels. By analyzing the path length, the complexity of data leakage or inference can be evaluated; by analyzing the path type, the risk difference between direct association and indirect association can be distinguished; by analyzing the sensitivity level of the data fields involved in the path, the sensitivity of the potential leaked data can be directly quantified. This detailed path analysis enables the evaluation of data association inference risk to be upgraded from simply "whether there is an association" to "how risky the association is", providing a more solid foundation for subsequent risk quantification.

[0047] On this basis, according to the path length of the association path, the type of the association path, and the sensitivity level of the data fields obtained by the above analysis, and in combination with the preset data association inference risk evaluation rule, the initial risk score of the association path is calculated. This step quantifies the results of the aforementioned detailed analysis of the association path by using the preset risk weight rule, thereby obtaining an initial risk assessment based on the inherent characteristics of the association path. This ensures that the initial risk score objectively reflects the inherent risk of the association path, avoiding the limitations of relying solely on experience or static rules, and providing a reliable benchmark for subsequent dynamic correction.

[0048] The preset risk weight rule is provided with a preset rule set for quantifying the risk contribution of different association paths, which can be implemented by using a weight table based on expert experience, risk factor weights trained by a machine learning model, or a scoring mechanism based on a risk matrix.

[0049] Specifically, in step S102, the user behavior pattern, query frequency, operation time, and user permission information of the data operation are obtained to modify the initial risk score in combination with the preset dynamic context risk modification rule, to obtain the data association inference risk score of the data operation, including: Obtain the user behavior pattern, query frequency, operation time, and user permission information of the data operation as dynamic context factors; According to the dynamic context factors, in combination with the preset dynamic context risk modification rule, the initial risk score is modified to obtain the data association inference risk score of the data operation.

[0050] In step S102, the user behavior pattern, query frequency, operation time and user permission information of the data operation are acquired. These information are collected systematically and classified uniformly as dynamic context factors. Specifically, the context information of the user when performing the data operation is monitored and extracted in real time or quasi-real time, for example, by analyzing the user historical operation log to identify the regular behavior pattern thereof, counting the number of queries within a specific time period to obtain the query frequency, recording the time point at which the data operation occurs, and querying the permission level of the user in the current system. These acquired user behavior pattern, query frequency, operation time and user permission information collectively constitute the dynamic context factors, which provide structured and quantifiable inputs for subsequent risk correction. Subsequently, according to these dynamic context factors, the initial risk score calculated previously is corrected in combination with the preset dynamic context risk correction rule. The preset dynamic context risk correction rule is a set of defined logic or algorithm, which can increase or decrease the initial risk score according to the specific value or state of the dynamic context factor. For example, if the dynamic context factor shows that the user performs high-frequency queries at non-working hours and has high permission, the correction rule can increase the initial risk score; on the contrary, if the user behavior pattern is normal, the query frequency is moderate, and the operation time is within the regular working hours, the correction rule can maintain or slightly reduce the risk score. It is through this correction based on the dynamic context factor and the correction rule that the final data correlation reasoning risk score of the data operation can more accurately reflect the real risk level of the data operation in the current context. This dynamic correction mechanism enables the data correlation reasoning risk assessment to no longer rely solely on the static correlation path of the data itself, but can fully consider the risk changes brought by dynamic factors such as the operator and the operation environment.

[0051] Specifically, in step S102, the calculated basic context risk score and data correlation reasoning risk score are fused to calculate a comprehensive context risk value of the data operation, for example, a weighted average method can be used for fusion, different weights (the sum of the weights is 1) are respectively assigned to the basic context risk score and the data correlation reasoning risk score, and the comprehensive context risk value is calculated according to the weights and the corresponding scores. This step-by-step calculation and final fusion mechanism ensures that the final risk assessment result is multi-dimensional and comprehensive, considering both the security risk of the data operation in the basic environment and the hidden reasoning risk that may be caused by complex data queries. In this way, the present application can more accurately and comprehensively reflect the real risk situation of the data operation in a specific context, providing a more reliable and fine basis for subsequent determination of the temporary security level based on the comprehensive context risk value and execution of the matching data security management strategy, thereby effectively improving the dynamic adaptability and risk response capability of the data classification and grading system.

[0052] Specifically, in step S103, the comprehensive situation risk value is compared with a preset dynamic security level threshold value, and according to the score range corresponding to each security level in the preset dynamic security level threshold value, a temporary security level to which the current data operation should be promoted is determined, reflecting the real risk level of the current data operation in a specific situation. The preset dynamic security level threshold value can be set according to actual needs.

[0053] Specifically, in step S104, according to the temporary security level of the comprehensive situation risk value, the data operation is forced to execute a data security management strategy corresponding to the temporary security level, such as forced secondary verification, download restriction, encrypted transmission, transmission audit and real-time alarm, to ensure that the data security management strategy can match the real risk of the data in a specific situation in real time and accurately, avoid data leakage or compliance loopholes caused by risk underestimation, and improve the effectiveness and flexibility of data security protection.

[0054] For example, when the temporary security level is promoted to a high-risk level, the blocking of the user query operation is automatically triggered, the access permission is temporarily frozen, and a real-time alarm is sent to the security administrator, and detailed operation logs are recorded for subsequent audit.

[0055] As can be seen from the above, the data classification and grading method obtains the situation information of the user during data operation, calculates the comprehensive situation risk value of the data operation according to the situation information and in combination with a preset risk assessment rule, determines a temporary security level of the data operation based on the comprehensive situation risk value, and executes a data security management strategy matched with the temporary security level; thereby, the comprehensive situation risk value of the user during data operation calculated based on the preset risk assessment rule is used to determine the temporary security level of the data operation, so as to dynamically adjust the data level, solve the problem that the existing data classification and grading method cannot realize real-time perception, assessment and adjustment of the data security level and management strategy in a dynamic situation, the real risk of the data is underestimated and the protection measures matched with the risk cannot be triggered, the temporary security level of the data operation can be dynamically determined, and the matched security management strategy is executed accordingly, and the effectiveness and flexibility of data security protection are improved.

[0056] Reference Figure 2 The application provides a data classification and grading device for dynamically adjusting the data level, which comprises: An acquisition module 1 is configured to acquire situation information of a user during data operation; A calculation module 2 is configured to calculate a comprehensive situation risk value of the data operation according to the situation information and in combination with a preset risk assessment rule; A determination module 3 is configured to determine a temporary security level of the data operation based on the comprehensive situation risk value; The control module 4 is used for executing a data security control strategy matched with the temporary security level.

[0057] The data classification and grading device determines the temporary security level of the data operation through the comprehensive situation risk value of the user in the data operation calculated based on the preset risk assessment rule, dynamically adjusts the data level, solves the problem that the existing data classification and grading method cannot realize real-time perception, assessment and adjustment of the data security level and control strategy in a dynamic situation, and the real risk of data is underestimated and the protection measures matched with the risk cannot be triggered, can dynamically determine the temporary security level of the data operation, and execute the matched security control strategy accordingly, and improves the effectiveness and flexibility of the data security protection.

[0058] Specifically, the acquisition module 1 acquires the situation information of the user in the data operation when executed, and the situation information includes access situation information, data transmission situation information, data query situation information and external threat intelligence information. The access situation information includes access time, source address, device identifier, access frequency, access data volume and operation type; the data transmission situation information includes transmission source area, target area and transmission protocol; the data query situation information includes data tables, data fields and the association relationship between the data tables and the data fields involved in the query statement; and the external threat intelligence information includes attack indicators, known vulnerability information and risk address information.

[0059] Specifically, the preset risk assessment rule includes a preset basic situation risk assessment rule and a preset data association reasoning risk assessment rule; when the calculation module 2 calculates the comprehensive situation risk value of the data operation according to the situation information and in combination with the preset risk assessment rule, the following is executed: According to the access situation information, the data transmission situation information and the external threat intelligence information, and in combination with the preset basic situation risk assessment rule, a basic situation risk score of the data operation is calculated; According to the data query situation information, and in combination with the preset data association reasoning risk assessment rule, a data association reasoning risk score of the data operation is calculated; The basic situation risk score and the data association reasoning risk score are fused to calculate the comprehensive situation risk value of the data operation.

[0060] The preset risk assessment rules include preset basic context risk assessment rules and preset data correlation inference risk assessment rules when the computing module 2 is executed. The preset risk assessment rules refer to a set of logic and standards defined in advance for assessing the risk of data operation, which can be constructed in the form of an expert rule base, a machine learning model, a risk scoring matrix, a decision tree, etc. The preset basic context risk assessment rules refer to rules for assessing the risk of direct context factors such as access, transmission and external threats, which can assess the risk according to a pre-defined risk factor weight, threshold or risk level mapping table. The preset data correlation inference risk assessment rules refer to rules specifically used to assess the potential risk caused by the correlation between data fields in data query operations, which can define risk assessment logic based on the sensitivity level of data fields, the complexity of correlation paths, the possibility of inference and historical leakage events, etc.

[0061] For example, the preset basic context risk assessment rules can be configured as follows: if the user logs in from a non-company internal IP address, the basic risk score (risk factor value) increases; if the data transmission protocol is not encrypted, the basic risk score further increases; if the client IP address hits a malicious IP blacklist, the basic risk score increases significantly. At the same time, the preset data correlation inference risk assessment rules can be configured as follows: if the query statement contains both the "employee name" and "salary" fields, and both fields are marked as high sensitivity in the metadata, the data correlation inference risk score increases; if the query statement can indirectly derive sensitive information through multi-table correlation (for example, by correlating "employee ID" and "department" tables, and then correlating "department" and "salary" tables, finally deriving the salary of all employees in a certain department), the data correlation inference risk score also increases accordingly. In this way, a more accurate and comprehensive data operation comprehensive context risk value can be calculated according to different dimensions of context information and targeted risk assessment rules, thereby providing a fine-grained decision basis for subsequent data security management and control.

[0062] Specifically, when the computing module 2 calculates the basic context risk score of the data operation according to the access context information, the data transmission context information and the external threat intelligence information, and in combination with the preset basic context risk assessment rules, it performs the following steps: Extracting risk factors corresponding to each risk dimension in the access context information, the data transmission context information and the external threat intelligence information; Determining the basic context risk calculation weight of each risk factor according to the risk factor and the risk factor weight adjustment strategy in the preset basic context risk assessment rules; Calculating the basic context risk score of the data operation according to the risk factor and the basic context risk calculation weight.

[0063] The computing module 2, when executed, performs in-depth analysis on the access context information, data transmission context information, and external threat intelligence information, standardizes the original context information (original data in the context information) in the access context information, data transmission context information, and external threat intelligence information, and extracts "quantifiable characteristic parameters (i.e., risk factors)" that can directly reflect the risk level. The risk factors corresponding to each risk dimension can be extracted in detail, and according to the preset basic context risk assessment rules, the risk factors are assigned corresponding scores (usually set to 0 to 5 points), which are the risk factor values. For example, the risk factor is "whether it is external network access". If the access context information shows yes, a higher score (i.e., 5 points) is given, and if no, a lower score (i.e., 0 points) is given. This step is the basis of risk assessment, which ensures that all possible elements that may affect data security are identified, avoiding the risk of omission or underestimation caused by rough assessment.

[0064] Among them, the risk factor refers to the smallest and quantifiable element that may affect the data security risk level during data operation. These factors can include but are not limited to user identity, access time, access location, data sensitivity, transmission protocol, transmission destination, external attack type, threat intelligence level, etc. The risk dimension refers to different perspectives or aspects for classifying and assessing risks, such as access risk dimension, transmission risk dimension, external threat risk dimension, etc. Each dimension contains multiple specific risk factors.

[0065] For example, the "access timestamp" obtained from the access log monitoring module can be converted into the risk factor "whether it is non-working hours"; "source IP address" and "access device identification" can be converted into the risk factors "whether it is external network access" or "whether it is personal device access"; "data access frequency" and "access data volume" can be converted into the behavior pattern risk factors "whether it is bulk download" or "whether it is high-frequency access". Similarly, the "transmission target network area" identified by the network traffic analysis module can be converted into the risk factor "whether it is external non-controlled network transmission"; the "data table, data field, and their mutual relationship" identified by the data query analysis module can be converted into the risk factor "whether there is potential associated reasoning risk"; and the "attack indicators, known vulnerability information, high-risk IP addresses" obtained by the threat intelligence interface module are directly used as external threat risk factors.

[0066] After identifying these risk factors, the base context risk calculation weight of each risk factor is dynamically determined according to these risk factors and the risk factor weight adjustment strategy in the preset base context risk assessment rule. This step is the key to realizing dynamic risk assessment. It recognizes that the importance of different risk factors in different contexts is not constant, and the preset base context risk assessment rule defines the risk weight adjustment weight threshold (i.e. risk factor weight adjustment strategy) corresponding to different context feature combinations and the risk level promotion threshold corresponding to different context feature combinations, for example, the rule base may define the combination of "non-working hours access + personal device + external network", which will increase the value of the base context risk calculation weight of the corresponding risk factor; "large amount of high-sensitivity data downloaded in a short time" will make the corresponding risk factor score increase by a certain number of points; when a specific high-risk external threat is detected, the risk factor weight related to the threat should be significantly increased. By introducing the weight adjustment strategy, the influence of each risk factor can be flexibly adjusted according to the changes in real-time context, so that each risk factor can be given a weight that matches its current context relevance and potential impact when calculating the base context risk score. This dynamic weight determination method makes risk assessment no longer static, but can flexibly adjust the influence of each risk factor according to the changes in real-time context, thereby more accurately reflecting the true risk situation of the current data operation.

[0067] Among them, the risk factor weight adjustment strategy refers to a set of pre-set rules or algorithms for adjusting the importance or influence of different risk factors in the calculation of the base context risk score according to the dynamic changes of the current context. This strategy can be implemented based on machine learning models, expert experience rule bases, or real-time context analysis results, for example, when a high-risk external threat is detected, the weight of the risk factor related to the external threat can be dynamically increased.

[0068] Based on the risk factor corresponding score (risk factor value) and weight, the base context risk score of the data operation is calculated by weighted summation, combining the fine-grained risk factors extracted above, the dynamically adjusted weights, and the original context information. This step combines the fine-grained risk factors extracted above, the dynamically adjusted weights, and the original context information, and obtains a comprehensive base context risk score through quantitative methods. This score not only considers the presence of risk factors, but more importantly, it incorporates the relative importance of these factors in the current context, ensuring that the calculated base context risk score closely matches the actual risk situation of the data operation.

[0069] Specifically, when calculating the data correlation inference risk score of the data operation according to the data query context information and in combination with the preset data correlation inference risk assessment rule, the computing module 2 performs the following steps: extracts a plurality of data fields from the query statement in the data query context information; recognizes explicit association relationships and implicit association relationships between the data fields based on the metadata information, data content features, and historical query co-occurrence patterns of the data fields, to obtain the association relationships between the data fields; calculates the data correlation inference risk score of the data operation according to the association relationships between the data fields and in combination with the preset data correlation inference risk assessment rule.

[0070] When the computing module 2 is executed, a plurality of data fields are extracted from the query statement in the data query context information. This initial step ensures that the subsequent analysis is based on the context of the user's actual operation, thereby capturing potential risk points in the dynamic context.

[0071] The association relationships between the data fields are not limited to explicit association relationships defined in the database, but can also include implicit association relationships based on business logic, data lineage, or semantic levels. Therefore, the explicit association relationships and the implicit association relationships between the data fields are recognized based on the metadata information, the data content features, and the historical query co-occurrence patterns of the data fields, to obtain the association relationships between the data fields. The explicit association relationship refers to a direct association between data fields established through explicit structural definition or preset logical rules, which can be recognized by database schema analysis, data model definition, and the like. The implicit association relationship refers to a potential association between data fields that is not explicitly defined by structure, but is indirectly reflected through data content, semantic context, or user behavior habits, which can be recognized by semantic analysis, machine learning, behavior pattern analysis, and the like. The metadata information refers to data that describes data, which can be embodied in the form of data dictionary, data schema definition, data type, data length, data source, data owner, security label, sensitivity level, and the like. The data content features refer to the semantics, patterns, or statistical properties inherent in the data, which can be embodied in the form of data value distribution, data format, data type, keywords, text similarity, data entropy, and the like. The historical query co-occurrence pattern refers to the frequency and regularity of different data fields appearing simultaneously in the same query statement or associated queries in past data query operations, which can be recognized by query log analysis, association rule mining, graph analysis, and the like.

[0072] For example, for data content features, there is an "ID number" field in the "employee table" and an "ID number" field in the "salary table", although there is no explicit association between them, but by analyzing the data content of the two fields (such as data format, value range, uniqueness, etc.), those skilled in the art can infer that they represent the same entity, thereby identifying the implicit association between them. This analysis based on data content features can discover data associations that are not directly reflected in the database structure but actually exist, greatly expanding the scope of association relationship identification and improving the comprehensiveness of risk assessment; or for historical query co-occurrence patterns, users may frequently query "customer name" and "customer phone" at the same time, even if the two fields may be scattered in different tables and have no direct database association, but by analyzing a large number of historical query logs, identifying which data fields often appear together in query statements can infer that there is an implicit association between these fields at the user level. This identification based on historical behavior patterns can reveal potential reasoning paths that users may use, thereby more accurately assessing the acquisition of sensitive information through legal query combinations.

[0073] Once these explicit and implicit association relationships are identified, the data association reasoning risk score of the data operation needs to be calculated according to these association relationships in combination with the preset data association reasoning risk assessment rules.

[0074] Specifically, when the calculation module 2 calculates the data association reasoning risk score of the data operation according to the association relationships between the data fields in combination with the preset data association reasoning risk assessment rules, it performs: identifying the association path formed by the association relationships and analyzing the path length, path type and sensitive level of the data fields involved in the path of the association path; calculating the initial risk score of the association path according to the path length of the association path, the type of the association path and the sensitive level of the data fields in combination with the preset data association reasoning risk assessment rules; obtaining user behavior patterns, query frequency, operation time and user permission information of the data operation to modify the initial risk score in combination with the preset dynamic context risk modification rules to obtain the data association reasoning risk score of the data operation.

[0075] The computing module 2, when executed, further identifies the association paths formed by the explicit and implicit association relationships between the data fields on the basis of the identification. This involves in-depth analysis of the internal characteristics of each association path, including its path length, path type, and the sensitivity level of the data fields involved in the path. For example, a short path involving multiple sensitive fields and a long path involving non-sensitive fields may have completely different risk levels. By analyzing the path length, the complexity of data leakage or inference can be evaluated; by analyzing the path type, the risk difference between direct association and indirect association can be distinguished; by analyzing the sensitivity level of the data fields involved in the path, the sensitivity of the potential leaked data can be directly quantified. This detailed path analysis enables the evaluation of data association inference risk to be upgraded from a simple "with or without association" to "how risky the association is", providing a more solid foundation for subsequent risk quantification.

[0076] On this basis, according to the path length of the association path, the type of the association path, and the sensitivity level of the data fields obtained by the above analysis, and in combination with the preset data association inference risk evaluation rule, the initial risk score of the association path is calculated. This step quantifies the results of the aforementioned detailed analysis of the association path by using the preset risk weight rule, thereby obtaining an initial risk evaluation based on the inherent characteristics of the association path. This ensures that the initial risk score can objectively reflect the inherent risk of the association path, avoiding the limitations of relying on experience or static rules for judgment, and providing a reliable benchmark for subsequent dynamic correction.

[0077] The preset risk weight rule is provided with a preset rule set for quantifying the risk contribution of different association paths, which can be implemented by using a weight table based on expert experience, a risk factor weight trained by a machine learning model, or a scoring mechanism based on a risk matrix.

[0078] Specifically, when the computing module 2 obtains the user behavior pattern, query frequency, operation time, and user permission information of the data operation, in order to combine the preset dynamic context risk correction rule to correct the initial risk score and obtain the data association inference risk score of the data operation, it performs: Obtaining the user behavior pattern, query frequency, operation time, and user permission information of the data operation as dynamic context factors; According to the dynamic context factors, in combination with the preset dynamic context risk correction rule, the initial risk score is corrected to obtain the data association inference risk score of the data operation.

[0079] The computing module 2, when executed, obtains the user behavior pattern, query frequency, operation time and user permission information of the data operation. These information are systematically collected and uniformly classified as dynamic context factors. Specifically, the context information of the user when performing the data operation is monitored and extracted in real time or quasi-real time, for example, by analyzing the user historical operation log to identify the regular behavior pattern thereof, counting the number of queries within a specific time period to obtain the query frequency, recording the time point at which the data operation occurs, and querying the permission level of the user in the current system. These obtained user behavior pattern, query frequency, operation time and user permission information collectively constitute the dynamic context factors, which provide structured and quantifiable inputs for subsequent risk correction. Subsequently, according to the dynamic context factors, the initial risk score calculated previously is corrected in combination with the preset dynamic context risk correction rule. The preset dynamic context risk correction rule is a set of defined logic or algorithm, which can increase or decrease the initial risk score according to the specific value or state of the dynamic context factor. For example, if the dynamic context factor shows that the user performs high-frequency queries at non-working hours and has high permission, the correction rule can increase the initial risk score; on the contrary, if the user behavior pattern is normal, the query frequency is moderate, and the operation time is within the regular working hours, the correction rule can maintain or slightly reduce the risk score. It is through this correction based on the dynamic context factor and the correction rule that the final data correlation reasoning risk score of the data operation can more accurately reflect the real risk level of the data operation in the current context. This dynamic correction mechanism enables the data correlation reasoning risk assessment to no longer rely solely on the static correlation path of the data itself, but can fully consider the risk changes brought by dynamic factors such as the operator and the operation environment.

[0080] Specifically, the computing module 2, when executed, fuses the calculated basic context risk score and data correlation reasoning risk score to calculate the comprehensive context risk value of the data operation, for example, the fusion can be performed in a weighted average manner, different weights (the sum of the weights is 1) are respectively assigned to the basic context risk score and the data correlation reasoning risk score, and the comprehensive context risk value is calculated according to the weights and the corresponding scores. This step-by-step calculation and final fusion mechanism ensures that the final risk assessment result is multi-dimensional and comprehensive, considering both the security risk of the data operation in the basic environment and the hidden reasoning risk that may be caused by complex data queries. In this way, the present application can more accurately and comprehensively reflect the real risk situation of the data operation in a specific context, providing a more reliable and fine basis for subsequent determination of the temporary security level based on the comprehensive context risk value and execution of the matched data security management strategy, thereby effectively improving the dynamic adaptability and risk response capability of the data classification and grading system.

[0081] Specifically, the determining module 3, when executed, compares the comprehensive situation risk value with the preset dynamic security level threshold, determines the temporary security level to which the current data operation should be promoted according to the score range corresponding to each security level in the preset dynamic security level threshold according to the comprehensive situation risk value, and reflects the real risk level of the current data operation in the specific situation. Wherein, the preset dynamic security level threshold can be set according to actual needs.

[0082] Specifically, the control module 4, when executed, according to the temporary security level of the comprehensive situation risk value, forcibly executes the data security control strategy corresponding to the temporary security level on the data operation, such as forced secondary verification, download restriction, encrypted transmission, transmission audit and real-time alarm, to ensure that the data security control strategy can match the real risk of the data in the specific situation in real time and accurately, avoid data leakage or compliance loopholes caused by risk underestimation, and improve the effectiveness and flexibility of data security protection.

[0083] For example, when the temporary security level is promoted to a high-risk level, the blocking of the user query operation is automatically triggered, the access permission is temporarily frozen, and a real-time alarm is sent to the security administrator, and detailed operation logs are recorded for subsequent audit.

[0084] As can be seen from the above, the data classification and grading device obtains the situation information of the user in the data operation, calculates the comprehensive situation risk value of the data operation according to the situation information combined with the preset risk assessment rule, determines the temporary security level of the data operation based on the comprehensive situation risk value, and executes the data security control strategy matched with the temporary security level; thereby, the comprehensive situation risk value of the user in the data operation calculated based on the preset risk assessment rule is used to determine the temporary security level of the data operation, so as to dynamically adjust the data level, solve the problem that the existing data classification and grading method cannot realize real-time perception, evaluation and adjustment of the data security level and control strategy in the dynamic situation, and the real risk of the data is underestimated and the protection measures matched with the risk cannot be triggered, the temporary security level of the data operation can be dynamically determined, and the matched security control strategy is executed accordingly, and the effectiveness and flexibility of data security protection are improved.

[0085] Please refer to Figure 3 , Figure 3A structural schematic diagram of an electronic device provided by an embodiment of the present application, the present application provides an electronic device, comprising: a processor 301 and a memory 302, the processor 301 and the memory 302 are interconnected and communicate with each other through a communication bus 303 and / or other forms of connection mechanism (not marked), the memory 302 stores a computer program executable by the processor 301, when the electronic device runs, the processor 301 executes the computer program to execute the data classification and grading method in any optional implementation manner of the above-mentioned embodiments, to realize the following functions: obtaining the context information of the user in the data operation, according to the context information, combining the preset risk assessment rule, calculating the comprehensive context risk value of the data operation, determining the temporary security level of the data operation based on the comprehensive context risk value, executing the data security management and control strategy matched with the temporary security level.

[0086] The embodiment of the present application provides a computer readable storage medium, which stores a computer program, when the computer program is executed by a processor, the data classification and grading method in any optional implementation manner of the above-mentioned embodiments is executed, to realize the following functions: obtaining the context information of the user in the data operation, according to the context information, combining the preset risk assessment rule, calculating the comprehensive context risk value of the data operation, determining the temporary security level of the data operation based on the comprehensive context risk value, executing the data security management and control strategy matched with the temporary security level. Wherein, the storage medium can be realized by any type of volatile or non-volatile storage device or their combination, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.

[0087] In the embodiments of the present application, it should be understood that the disclosed apparatus and method can be implemented in other manners. The embodiments described above are merely exemplary, for example, the division of the units is only a logical function division, and there can be another division manner in actual implementation; for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.

[0088] In addition, the units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units, and can be located in one position, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments of the present application.

[0089] In addition, the functional modules in the various embodiments of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0090] In this article, the relationship terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations.

[0091] The above only describes the embodiments of the present application, and is not used to limit the protection scope of the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.

Claims

1. A data classification and grading method for dynamically adjusting data levels, characterized in that: Including steps: Obtain contextual information about users when operating data; Calculate the comprehensive situational risk value of the data operation based on the situational information and in combination with preset risk assessment rules; determining a temporary security level for the data operation based on the comprehensive situational risk value; Execute the data security control policy that matches the temporary security level.

2. The data classification and grading method according to claim 1, characterized in that: The context information includes access context information, data transmission context information, data query context information and external threat intelligence information; the preset risk assessment rules include preset basic context risk assessment rules and preset data association reasoning risk assessment rules.

3. The data classification and grading method according to claim 2, characterized in that: Based on the context information and in combination with preset risk assessment rules, a comprehensive context risk value of the data operation is calculated, including: Calculate the basic situational risk score of the data operation based on the access situational information, the data transmission situational information, and the external threat intelligence information in combination with the preset basic situational risk assessment rules; Calculating a data association reasoning risk score for the data operation based on the data query context information and the preset data association reasoning risk assessment rules; The basic situational risk score and the data association reasoning risk score are integrated to calculate a comprehensive situational risk value of the data operation.

4. The data classification and grading method according to claim 3, characterized in that: Calculating a basic situational risk score for the data operation based on the access situational information, the data transmission situational information, and the external threat intelligence information in combination with the preset basic situational risk assessment rules includes: extracting risk factors corresponding to each risk dimension in the access context information, the data transmission context information, and the external threat intelligence information; Determining the basic scenario risk calculation weight of each risk factor according to the risk factor and the risk factor weight adjustment strategy in the preset basic scenario risk assessment rule; The basic situational risk score of the data operation is calculated based on the risk factor and the basic situational risk calculation weight.

5. The data classification and grading method according to claim 3, characterized in that: Calculating the data association reasoning risk score of the data operation based on the data query context information and the preset data association reasoning risk assessment rules includes: Extracting multiple data fields from the query statement in the data query context information; Based on metadata information, data content characteristics, and historical query co-occurrence patterns of each data field, identifying explicit associations and implicit associations between the data fields, and obtaining associations between the data fields; According to the association relationship between each of the data fields, combined with the preset data association reasoning risk assessment rules, the data association reasoning risk score of the data operation is calculated.

6. The data classification and grading method according to claim 5, characterized in that: According to the association relationship between the data fields, combined with the preset data association reasoning risk assessment rules, the data association reasoning risk score of the data operation is calculated, including: Identifying an association path formed by the association relationship, and analyzing the path length, path type, and sensitivity level of data fields involved in the association path; Calculating an initial risk score of the association path based on the path length of the association path, the path type, and the sensitivity level of the data field in combination with a preset data association reasoning risk assessment rule; The user behavior pattern, query frequency, operation time and user authority information of the data operation are obtained, and combined with the preset dynamic situational risk correction rules, the initial risk score is corrected to obtain the data association reasoning risk score of the data operation.

7. The data classification and grading method according to claim 6, characterized in that: Obtaining the user behavior pattern, query frequency, operation time, and user authority information of the data operation, and combining it with a preset dynamic context risk correction rule to correct the initial risk score to obtain a data association reasoning risk score for the data operation, including: Obtaining user behavior patterns, query frequency, operation time, and user authority information of the data operation as dynamic context factors; According to the dynamic situation factor and in combination with a preset dynamic situation risk correction rule, the initial risk score is corrected to obtain a data association reasoning risk score for the data operation.

8. A data classification and grading device for dynamically adjusting data levels, characterized in that: include: The acquisition module is used to obtain the user's context information when operating data; A calculation module, configured to calculate a comprehensive situational risk value of the data operation based on the situational information and in combination with preset risk assessment rules; a determination module, configured to determine a temporary security level of the data operation based on the comprehensive situational risk value; The control module is used to execute a data security control policy that matches the temporary security level.

9. An electronic device, characterized in that: The method comprises a processor and a memory, wherein the memory stores a computer program executable by the processor, and when the processor executes the computer program, the method runs the steps of the data classification and grading method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the data classification and grading method according to any one of claims 1 to 7 are executed.

Citation Information

Cited By

  • A method for auditing classification hierarchy compliance in data flow transformation processes

    CN122529918A