File desensitization method and device
By using system calls and sensitive information identification technology in the desensitization device at the application layer, the desensitization of disk storage files is achieved, solving the problem of invasive modification of application code in the existing technology and ensuring data security.
Patent Information
- Application Number
- CN202510934201.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-07
- Publication Date
- 2025-10-17
AI Technical Summary
The existing technology requires intrusive modification of application code when desensitizing log files stored on disk, which is cumbersome and may affect the functionality of the application process.
By setting up a desensitization device at the application layer and using system calls, files to be stored on disk can be identified and desensitized without modifying the application code and kernel layer, including the use of sensitive file lists and sensitive word dictionaries, to achieve desensitization of files.
Without affecting the functionality of the application process, it effectively identifies and desensitizes files stored on disk to ensure data security and prevent sensitive information leakage.
Smart Images

Figure CN120805184A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a file desensitization method and device. BACKGROUND
[0002] Disk is the main way of data persistence storage. Files such as log files are stored in the disk in the form of text, that is, the file content of these files exists in the disk in plaintext form.
[0003] Log files may contain sensitive information, such as authentication passwords, database login passwords, etc. If the file stored to the disk is not desensitized, sensitive information may be leaked through the disk. For example, an attack on the disk causes sensitive information to be leaked.
[0004] The current file desensitization scheme needs to modify the code of the application (APP) invasively, which is cumbersome and may affect the function of the application process. SUMMARY
[0005] The present application provides a file desensitization method and device, which can desensitize the file to be stored to the disk without invasively modifying the code of the application, so as to ensure that the file stored to the disk does not contain sensitive information.
[0006] In a first aspect, a disk file desensitization method performed by a desensitization device is provided. The computing system where the desensitization device is located further includes an application layer, a kernel layer and a device layer; wherein the desensitization device is arranged in the application layer, the application layer further arranges an application buffer and an application process, the kernel layer is arranged with a system call, and the device layer includes at least one disk, and the system call is used to store a file to the at least one disk; the method includes: the desensitization device acquires at least one file in the application buffer, and the at least one file is from the application process; the desensitization device identifies a target file containing sensitive information and to be stored to the at least one disk in the at least one file; the desensitization device desensitizes the sensitive information in the target file; and the desensitization device calls the system call to store the desensitized target file to the at least one disk through the system call. Exemplarily, the at least one file is a log file.
[0007] Through the method, the desensitization device desensitizes the file to be stored to the disk in the application layer, and the desensitization device acquires the file needing desensitization from the application buffer layer, so that the desensitization of the file to be stored to the disk can be realized without invasively modifying the code of the application, without modifying the kernel layer and the device layer, and without sensitive data in the file stored to the disk, thereby ensuring data security.
[0008] In a possible implementation, the method further includes: obtaining, by the desensitization device, a sensitive file list corresponding to the application type of the application process; and identifying, by the desensitization device, the target file containing sensitive information and to be stored in the at least one disk from the at least one file, including: identifying, by the desensitization device, the file included in the sensitive file list from the at least one file to obtain the target file.
[0009] In the implementation, the file containing or possibly containing sensitive information can be identified through the white list (sensitive file list), so that the target file can be efficiently obtained.
[0010] In a possible implementation, the method further includes: obtaining, by the desensitization device, a sensitive word dictionary; and identifying, by the desensitization device, the target file containing sensitive information and to be stored in the at least one disk from the at least one file, including: identifying, by the desensitization device, the file containing at least one sensitive word in the sensitive word dictionary from the at least one file to obtain the target file.
[0011] In the implementation, the target file can be identified through the sensitive word dictionary, and the identification efficiency of the target file is improved.
[0012] In a possible implementation, the desensitization device is started by the application process through an LD_PRELOAD environment variable. When the application process is started, the desensitization device can be started along with the starting of the application process through the LD_PRELOAD environment variable, so that the desensitization of the file of the application process is guaranteed.
[0013] In a possible implementation, the system call is a write system call; and the desensitization device calls the system call to store the target file after the desensitization in the at least one disk through the system call, including: the desensitization device calls the write system call through a write function to store the target file after the desensitization in the at least one disk through the write system call.
[0014] In the implementation, the desensitization device can call the system call through the write function, and the file after the desensitization can be stored in the disk without changing the kernel layer.
[0015] In a second aspect, a desensitization device is provided. A computing system in which the device is located includes an application layer, a kernel layer, and a device layer. The desensitization device is disposed in the application layer. The application layer further includes an application buffer and an application process. The kernel layer includes a system call. The device layer includes at least one disk. The system call is configured to store a file in the at least one disk. The device includes: an obtaining module configured to obtain at least one file in the application buffer, the at least one file being from the application process; an identifying module configured to identify, from the at least one file, a target file that contains sensitive information and is to be stored in the at least one disk; a desensitization module configured to desensitize the sensitive information in the target file; and a calling module configured to call the system call to store the desensitized target file in the at least one disk via the system call.
[0016] In a third aspect, a computing device cluster is provided. The computing device cluster includes at least one computing device. Each computing device includes a processor and a memory. The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device to cause the computing device cluster to perform the method of the first aspect.
[0017] In a fourth aspect, a computer-readable storage medium is provided. The computer-readable storage medium includes computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster performs the method of the first aspect.
[0018] In a fifth aspect, a computer program product including instructions is provided. When the instructions are executed by a computing device cluster, the computing device cluster performs the method of the first aspect.
[0019] The beneficial effects of the second aspect to the fifth aspect can refer to the beneficial effects of the first aspect described above, and will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS
[0020] Figure 1 is a schematic diagram of a computing system provided by an embodiment of the present application;
[0021] Figure 2 is a schematic diagram of a computing system provided by an embodiment of the present application;
[0022] Figure 3 is a flowchart of a file desensitization method provided by an embodiment of the present application;
[0023] Figure 4 is a flowchart of a file desensitization method provided by an embodiment of the present application;
[0024] Figure 5 is a structural schematic diagram of a desensitization device provided by an embodiment of the present application;
[0025] Figure 6is a structural schematic diagram of a computing device provided by an embodiment of the present application.
[0026] Figure 7 is a structural schematic diagram of a computing device cluster provided by an embodiment of the present application.
[0027] Figure 8 is a structural schematic diagram of another computing device cluster provided by an embodiment of the present application. DETAILED DESCRIPTION
[0028] The scheme provided by the embodiments of the present application will be described below with reference to the drawings. In the embodiments of the present application, "multiple" refers to two or more, and "multiple types" refers to two or more types. "First", "second", and the like are only used to distinguish similar objects, and do not necessarily describe a specific order or number of objects.
[0029] To facilitate understanding of the scheme provided by the embodiments of the present application, the technical terms that may be involved in the embodiments of the present application are introduced first.
[0030] Process: an instance of an executing program, is the basic unit of resource allocation and scheduling by the operating system. A process can be regarded as a collection of all relevant information of a program in its life cycle, including program code, data, open files, environment variables, etc. Detailed information of a process can be viewed through a process status command, such as process identifier (ID), user belonging to, command line parameters when starting the process, etc.
[0031] Application process: an instance of an executing application program.
[0032] Application layer: also known as user mode, is a user-oriented layer in a computing system. Processes in the application layer have no direct access to hardware or sensitive memory and do not directly operate hardware, but rely on resources provided by the kernel layer. Among them, the application process runs in the application layer.
[0033] Kernel space: also known as kernel mode, is located between the application layer and the device layer, is the core hub of the operating system, and can operate hardware and all memory.
[0034] Device layer: also known as hardware layer, is composed of physical hardware such as processors, memories, disks, network cards, and their firmware.
[0035] System call (Syscall): An interface provided by the operating system to applications, allowing them to request services from the operating system kernel, such as file input from disk, process control, communication, and other services.
[0036] Write system call: The core system call of the Linux operating system, used to write data from the application buffer to kernel-managed objects (files, pipes, sockets, etc.). It is the basis of the POSIX standard input / output (I / O) operation function, and the write function in the glibc library will eventually trigger this system call.
[0037] Buffer: A temporary storage area for storing data.
[0038] Application buffer: Also known as user space buffer, it is a buffer set in the application layer, used to temporarily store data from the application process, such as files.
[0039] Function: A block of code that encapsulates a specific function, used to receive input parameters, perform logical operations, and return results. Among them, the write function is one of the underlying file operation functions provided by glibc (GNU C library), which is essentially a wrapper for the Linux / Unix system call write(), and is used to write data to the target pointed by the file descriptor (file descriptor, FD). It is suitable for implementing network communication, file system tools, and high-performance services.
[0040] LD_PRELOAD environment variable: An environment variable in the Linux system, used to force the loading of specified shared libraries when executing programs. When the LD_PRELOAD environment variable is set and a program is run, the dynamic linker will first load the library specified by LD_PRELOAD, and then load other libraries. The library functions in the shared library pointed by LD_PRELOAD will overwrite the same functions in the original library. The LD_PRELOAD environment variable plays a key role in the Linux system, mainly used for dynamic link library loading. When a program starts, the Linux system will load the dynamic link library (.so file) under the path specified by the LD_PRELOAD environment variable first. This means that if a library function that the program depends on also exists in the library specified by LD_PRELOAD, the program will use the version in the library specified by LD_PRELOAD when running, rather than the system default library.
[0041] Dynamic Link Library (DLL): A library that is loaded dynamically at runtime. DLLs are loaded at program startup or runtime, allowing multiple programs to share the same library file, saving memory and disk space. In a DLL, the dynamic link library is usually a.so file, which is a shared object file.
[0042] glibc Library (GNU C library): A key library that implements standard C library functions for GNU systems and GNU-based Linux systems, serving as the foundation for many Linux applications. It provides basic system functions such as memory allocation, process control, and input / output.
[0043] Sensitive Information: Data that, if leaked, tampered with, or used illegally, could cause substantial harm to individual rights, organizational interests, or national security.
[0044] Sensitive File: A file that may contain sensitive information.
[0045] De-sensitization: Data de-sensitization, also known as data de-identification or data anonymization. De-sensitization is a technical means to modify, mask, replace, or delete sensitive data in a data set to protect privacy and sensitive information from being leaked.
[0046] Since log files and other files exist in text form on the disk, when the disk is poorly maintained or attacked, the log files on the disk may be leaked. Therefore, it is necessary to de-sensitize the log files to be stored on the disk. In one scheme, a custom log filter is added to the log framework in the application code to filter sensitive information in the log file. In another scheme, the application code or the running environment of the application is scanned to find code that can generate log files containing sensitive information, and the discovered code is rectified. The aforementioned schemes require invasive modifications to the application code, which not only is cumbersome to operate, but also may affect the functionality of the application process.
[0047] The file desensitization method provided by the embodiments of the present application can desensitize the file to be stored in the disk without modifying the code of the application. In the method, first, at least one file in the application buffer is obtained, and the at least one file is from an application process. Second, a target file containing sensitive information and to be stored in the disk is identified in the at least one file. Third, the sensitive information of the target file is desensitized. Then, a system call is invoked to store the desensitized target file in the disk through the system call. Thus, the file to be stored in the disk is desensitized without modifying the code of the application, the kernel layer and the device layer, so that the file stored in the disk does not contain sensitive data, and the data security is ensured.
[0048] Next, the file desensitization method provided by the embodiments of the present application is introduced.
[0049] The method can be implemented in a computing system, for example, Figure 1 The computing system. The computing system includes an application layer, a kernel layer and a device layer. The application layer is provided with a desensitization device, an application process and an application buffer. The kernel layer is provided with a system call. The device layer is provided with at least one disk. The system call can be used to store a file in the at least one disk, and the application layer desensitization device can store a file in the at least one disk through the system call. In some embodiments, the system call can be a write system call.
[0050] The file issued by the application process can be temporarily stored in the application buffer. That is, the application buffer stores the file from the application process. The file in the application buffer can include the file of the disk, such as the log file.
[0051] The file to be stored in the disk in the application buffer needs to be processed or allowed by the desensitization device before it can be stored in the disk in the device layer. The desensitization device can obtain at least one file of the application buffer. The at least one file is from the application process. For example, the at least one file can be all the files currently stored in the application buffer. The desensitization device can identify a file containing sensitive information and to be stored in the disk in the at least one file. For convenience of description, the file containing sensitive information and to be stored in the disk can be referred to as a target file. The desensitization device can desensitize the target file and invoke a system call in the kernel layer to store the desensitized target file in the disk through the system call. The desensitized target file refers to the target file whose content is desensitized.
[0052] In some embodiments, as Figure 2As shown, the application processes can be pulled from an application code repository and set up in the application layer through continuous integration / continuous deployment (CI / CD). The code in the application code repository can be submitted by developers. The application code repository can be an application code Git repository, for example.
[0053] In some embodiments, as shown, Figure 2 As shown, the de-sensitization device can obtain at least one file from the application buffer. The application type, file descriptor, buffer address, etc. of each file in the at least one file can be obtained. The application type of a file is the application type of the application process that issues the file.
[0054] The de-sensitization device can determine whether a file is a file to be stored to disk according to the file descriptor of the file. Thus, the de-sensitization device can identify the file to be stored to disk from the at least one file.
[0055] If a file is a file to be stored to disk, the de-sensitization device determines whether the file is a sensitive file. The de-sensitization device can obtain a list of sensitive files according to the application type of the file (i.e., the application type of the application process described above). Then, it is determined whether the file is included in the list of sensitive files. If the file is included in the list of sensitive files, it means that the file is a sensitive file. Thus, the de-sensitization device can identify the sensitive file. In some embodiments, the list of sensitive files can come from a configuration file. In some embodiments, the list of sensitive files can come from a security rule set repository. The de-sensitization device can pull the list of sensitive files from the security rule set repository according to the application type of the application process. The security rule set repository can be continuously and dynamically updated and uniformly maintained. The security rule set repository can be a security rule set Git repository, for example.
[0056] If a file is a sensitive file, the de-sensitization device can identify sensitive information in the sensitive file. The sensitive information can be a sensitive word. In some embodiments, the de-sensitization device can obtain a sensitive word dictionary. Then, it is determined whether the de-sensitized file contains at least one sensitive word in the sensitive word dictionary to identify sensitive information in the sensitive file. In some embodiments, the sensitive word dictionary can come from a configuration file. In some embodiments, the sensitive word dictionary can come from a security rule set repository. The de-sensitization device can pull the sensitive word dictionary, such as a general sensitive word dictionary, from the security rule set repository. The security rule set repository can be continuously and dynamically updated and uniformly maintained. The security rule set repository can be a security rule set Git repository, for example.
[0057] In this way, the desensitization device can identify the file containing sensitive information and to be stored in the disk, i.e., identify the target file.
[0058] The desensitization device can desensitize the sensitive information in the target file.
[0059] The desensitization device can store the desensitized target file into at least one disk in the device layer by invoking the system call. The related method can be as follows.
[0060] In some embodiments, as shown in Figure 2 The system call can be a write system call, and the desensitization device can include a write() function. The desensitization device can invoke the write system call through the write() function to store the desensitized target file to the disk. As an example, as shown in Figure 2 The application layer is provided with a Clib buffer, and the write system call can store the file in the Clib buffer to be stored in the disk to the disk in the device layer. The desensitization device can store the desensitized target file in the Clib buffer so that the write system call stores the target file to the disk in the device layer.
[0061] In some embodiments, as shown in Figure 2 The kernel layer is provided with a page cache, an IO queue, and a driver. The system call can store the target file from the Clib buffer to the page cache. The Linux operating system usually invokes the write system call of the operating system by executing the write function in the glibc library in the application layer to switch to the kernel state and write data to the page cache of the kernel. Through this mechanism, the target file can be written to the page cache. Then, the target file is from the page cache to the IO queue. The driver stores the file in the IO queue to the disk in the device layer, thereby storing the target file to the disk. As shown in Figure 2 The driver can store the file to the disk through the disk cache.
[0062] In some embodiments, the desensitization device can be started by an application process through the LD_PRELOAD environment variable. The Linux operating system preferentially loads the same function in different dynamic link libraries (a custom dynamic link library file can be specified) specified by LD_PRELOAD. As an example, the signature of the desensitization device can be set as the signature of the native write function, and the desensitization device can be started through the LD_PRELOAD environment variable when the application process is started.
[0063] The above examples introduce the functions of the computing system and the desensitization apparatus provided in the embodiments of the present application. Next, in combination with the above content, the execution flow of the file desensitization method provided in the embodiments of the present application is introduced. The method is executed by the desensitization apparatus. As shown in Figure 3 the method includes the following steps.
[0064] In step 301, the desensitization apparatus acquires at least one file in the application buffer, the at least one file being from the application process.
[0065] In some embodiments, the at least one file can be a log file, such as an operating system log, an application running log, an audit log, or the like. In some embodiments, all or part of the at least one file can be generated by the application process. In some embodiments, all or part of the at least one file can be received by the application process.
[0066] After the application process generates or receives the at least one file, the application process can store the at least one file in the application buffer. The desensitization apparatus can read the file from the application buffer, thereby obtaining the at least one file.
[0067] In step 302, the desensitization apparatus identifies a target file containing sensitive information and to be stored in the at least one disk from the at least one file.
[0068] In some embodiments, whether each file in the at least one file is a file to be stored in the at least one disk can be determined according to the file descriptor of the file.
[0069] In some embodiments, the desensitization apparatus can acquire a sensitive file list corresponding to the application type of the application process. The related manner can refer to the above introduction, and details are not described herein. In step 302, the desensitization apparatus can identify a file included in the sensitive file list from the at least one file, thereby obtaining the target file. For example, a file included in the sensitive file list and to be stored in the at least one disk can be used as the target file.
[0070] In some embodiments, the desensitization apparatus can also acquire a sensitive word dictionary. The related manner can refer to the above introduction, and details are not described herein. In step 303, the desensitization apparatus identifies a file containing at least one sensitive word in the sensitive word dictionary from the at least one file, thereby obtaining the target file. For example, the file containing at least one sensitive word in the sensitive word dictionary can be identified by a regular matching manner.
[0071] In some embodiments, the desensitization apparatus can first identify the file to be stored to the at least one disk in the at least one file to obtain a first identification result. Then, identify the file included in the sensitive file list in the first identification result to obtain a second identification result. Then, identify the file containing at least one sensitive word in the sensitive word dictionary in the second identification result to obtain the target file.
[0072] In step 303, the desensitization apparatus desensitizes the sensitive information in the target file. The target file after the sensitive information in the target file is desensitized can be referred to as the desensitized target file.
[0073] In step 304, the desensitization apparatus calls a system call to store the desensitized target file to the at least one disk through the system call.
[0074] In some embodiments, the system call is a write system call. In step 304, the desensitization apparatus calls the write system call through the write function to store the desensitized target file to the at least one disk through the write system call. The related implementation can refer to the above description, and will not be repeated here.
[0075] In summary, the file desensitization method provided by the embodiments of the present application can desensitize the file to be stored to the disk without the need for invasive modification of the application code, without the need for modification of the kernel layer and the device layer, so as to desensitize the file to be stored to the disk, so that the file stored to the disk does not contain sensitive data, and the data security is guaranteed. In addition, the method decouples the business code, and the business can be used out of the box, and is not limited by programming languages, Linux versions, and Linux distributions.
[0076] The file desensitization method provided by the embodiments of the present application can further include the steps as shown in Figure 4
[0077] In step 401, the operating system can start an application process using the LD_PRELOAD environment variable. In the command for starting the application process, the value of the environment variable LD_PRELOAD is specified as the path of the libDesens.so dynamic link library, which contains a desensitization apparatus for desensitizing data implemented by the user. The desensitization apparatus can be the write function of the libSecurityStarter.so dynamic link library.
[0078] In step 402, the application process can write a file (such as a log) to the disk.
[0079] The de-sensitization device can intercept a file written to a disk by an application process, and perform step 402 to determine whether the file is included in a sensitive file list. In step 402, the de-sensitization device can determine whether a file descriptor of the file matches the sensitive file list to determine whether the file is included in the sensitive file list.
[0080] Next, in step 403, the de-sensitization device determines whether the file matches a sensitive word dictionary. If it matches, in step 405, the file is de-sensitized according to the sensitive word dictionary.
[0081] After de-sensitizing the file, the de-sensitization device can store the de-sensitized file to the disk by steps 406, 407, and 408, invoking the native write() function of the glibc library and the write system call.
[0082] The sensitive information in the file in the disk has been de-sensitized, and when a malicious attacker views the file in the disk in step 409 (assuming that the malicious attacker has already obtained access to the file in advance through other means), the sensitive information cannot be obtained, and therefore, the sensitive information is not at risk of being leaked.
[0083] Based on the above description, the embodiments of the present application also provide a de-sensitization device 500. The computing system in which the device 500 is located includes an application layer, a kernel layer, and a device layer; wherein the de-sensitization device is arranged in the application layer, the application layer further arranges an application buffer and an application process, the kernel layer is arranged with a system call, and the device layer includes at least one disk, and the system call is used to store a file to the at least one disk. The device 500 includes:
[0084] An obtaining module is configured to obtain at least one file in the application buffer, the at least one file being from the application process;
[0085] An identifying module is configured to identify a target file containing sensitive information and to be stored to the at least one disk in the at least one file;
[0086] A de-sensitization module is configured to de-sensitize the sensitive information in the target file;
[0087] A calling module is configured to call the system call to store the de-sensitized target file to the at least one disk through the system call.
[0088] In some embodiments, the obtaining module is further configured to obtain a sensitive file list corresponding to an application type of the application process; and the identifying module is configured to identify a file included in the sensitive file list in the at least one file to obtain the target file.
[0089] In some embodiments, the obtaining module is further configured to obtain a sensitive word dictionary; and the identifying module is configured to identify, by the desensitization device, a file containing at least one sensitive word in the sensitive word dictionary from the at least one file to obtain the target file.
[0090] In some embodiments, the desensitization device is started by the application process through an LD_PRELOAD environment variable.
[0091] In some embodiments, the system call is a write system call; and the calling module is configured to call the write system call by the desensitization device through a write function, so as to store the target file after the desensitization processing into the at least one disk through the write system call.
[0092] In some embodiments, the at least one file is a log file.
[0093] The obtaining module, the identifying module, the desensitization module, and the calling module can be implemented by software or by hardware. For example, the implementation of the obtaining module is described below. Similarly, the implementation of the identifying module, the desensitization module, and the calling module can refer to the implementation of the obtaining module.
[0094] As an example of a software functional unit, the obtaining module can include code running on a computing instance. The computing instance can include at least one of a physical host (computing device), a virtual machine, and a container. Further, the computing instance can be one or more. For example, the obtaining module can include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers running the code can be distributed in the same region, or can be distributed in different regions. Further, the multiple hosts / virtual machines / containers running the code can be distributed in the same availability zone (AZ), or can be distributed in different AZs, each AZ including one data center or multiple data centers with similar geographical locations. Generally, one region can include multiple AZs.
[0095] Likewise, the plurality of hosts / virtual machines / containers used to run the code can be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Among them, usually one VPC is set in one region, and a communication gateway needs to be set in each VPC for cross-region communication between two VPCs in the same region and between VPCs in different regions, and the interconnection between VPCs is realized through the communication gateway.
[0096] As an example of a hardware functional unit, the obtaining module can include at least one computing device, such as a server, etc. Alternatively, the obtaining module can also be a device implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), etc. Among them, the above-mentioned PLD can be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0097] The plurality of computing devices included in the obtaining module can be distributed in the same region or in different regions. The plurality of computing devices included in the obtaining module can be distributed in the same AZ or in different AZs. Likewise, the plurality of computing devices included in the obtaining module can be distributed in the same VPC or in multiple VPCs. Among them, the plurality of computing devices can be any combination of servers, ASICs, PLDs, CPLDs, FPGAs, and GALs, etc.
[0098] It should be noted that in other embodiments, the obtaining module can be used to perform Figure 3 any step of the method shown, the identification module can be used to perform Figure 3 any step of the method shown, the de-sensitization module can be used to perform Figure 3 any step of the method shown, the calling module can be used to perform Figure 3 any step of the method shown. The steps responsible for the implementation of the obtaining module, the identification module, the de-sensitization module and the calling module can be specified as needed, and the entire function of the device 500 can be implemented by the obtaining module, the identification module, the de-sensitization module and the calling module respectively Figure 3 implement different steps in the method shown.
[0099] The application also provides a computing device 600. As shown in Figure 6 The computing device 600 includes a bus 602, a processor 604, a memory 606 and a communication interface 608. The processor 604, the memory 606 and the communication interface 608 communicate through the bus 602. The computing device 600 can be a server or a terminal device. It should be understood that the number of processors and memories in the computing device 600 is not limited.
[0100] The bus 602 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 only one line is used, but it does not mean that there is only one bus or one type of bus. The bus 602 can include a path for transmitting information between various components (for example, the memory 606, the processor 604, the communication interface 608) of the computing device 600.
[0101] The processor 604 can include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP), etc.
[0102] The memory 606 can include a volatile memory (for example, a random access memory (RAM)). The memory 606 can also include a non-volatile memory (for example, a read-only memory (ROM), a flash memory, a mechanical hard disk drive (HDD) or a solid state drive (SSD)).
[0103] The memory 606 stores executable program code, and the processor 604 executes the executable program code to respectively implement the functions of the foregoing acquisition module, the identification module, the de-sensitization module and the calling module, thereby implementing the method shown in Figure 3 The memory 606 stores executable program code, and the processor 604 executes the executable program code to respectively implement the functions of the foregoing acquisition module, the identification module, the de-sensitization module and the calling module, thereby implementing the method shown in Figure 3 The memory 606 stores executable program code, and the processor 604 executes the executable program code to respectively implement the functions of the foregoing acquisition module, the identification module, the de-sensitization module and the calling module, thereby implementing the method shown in
[0104] The communication interface 608 enables communication among the computing device 600 and other devices or communication networks using, for example, but not limited to, a transceiver module such as a network interface card, a Bluetooth® transceiver, and the like.
[0105] Embodiments of the present disclosure also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device, such as a desktop computer, a notebook computer, or a smart phone.
[0106] As shown in Figure 7 , the computing device cluster includes at least one computing device 600. The memory 606 in one or more computing devices 600 in the computing device cluster can store the same instructions for performing the method shown in Figure 3 .
[0107] In some possible implementations, the memory 606 in one or more computing devices 600 in the computing device cluster can also respectively store partial instructions for performing the method shown in Figure 3 . In other words, the combination of one or more computing devices 600 can collectively perform the instructions for performing the method shown in Figure 3 .
[0108] It should be noted that the memory 606 in different computing devices 600 in the computing device cluster can store different instructions for respectively performing part of the functions of the apparatus 500. That is, the instructions stored in the memory 606 in different computing devices 600 can implement the functions of one or more of the obtaining module, the identifying module, the de-sensitizing module, and the calling module.
[0109] In some possible implementations, one or more computing devices in the computing device cluster can be connected through a network. The network can be a wide area network, a local area network, or the like. Figure 8 A possible implementation is shown. As shown in Figure 8 , two computing devices 600A and 600B are connected through a network. Specifically, the communication interface in each computing device is connected to the network. In this type of possible implementation, the memory 606 in the computing device 600A stores instructions for performing the functions of the obtaining module and the identifying module. Meanwhile, the memory 606 in the computing device 600B stores instructions for performing the functions of the de-sensitizing module and the calling module.
[0110] It should be understood that Figure 8The functions of the computing device 600A shown in FIG. 6A can also be completed by a plurality of computing devices 600. Similarly, the functions of the computing device 600B shown in FIG. 6B can also be completed by a plurality of computing devices 600.
[0111] The embodiments of the present application also provide another computing device cluster. The connection relationship between the computing devices in the computing device cluster can be similar to the connection relationship between the computing devices in the computing device cluster shown in FIG. 6A. Figure 7 and Figure 8 The connection manner of the computing device cluster. The difference is that the memory 606 in one or more computing devices 600 in the computing device cluster can store the same instructions for performing the method shown in FIG. 6A. Figure 3
[0112] In some possible implementation manners, the memory 606 in one or more computing devices 600 in the computing device cluster can also respectively store part of the instructions for performing the method shown in FIG. 6A. In other words, the combination of one or more computing devices 600 can collectively execute the instructions for performing the method shown in FIG. 6A. Figure 3 Figure 3
[0113] The embodiments of the present application also provide a computer program product containing instructions. The computer program product can be software or a program product containing instructions, which can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, the at least one computing device executes the method shown in FIG. 6A. Figure 3
[0114] The embodiments of the present application also provide a computer readable storage medium. The computer readable storage medium can be any available medium that a computing device can store or a host migration device such as a data center containing one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk), etc. The computer readable storage medium contains instructions, which instruct the computing device to execute the method shown in FIG. 6A. Figure 3
[0115] The above embodiments are only used to illustrate the technical solutions of the present application, but not limit the same; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacements to part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the protection scope of the technical solutions of the embodiments of the present application.
Claims
1. A disk file desensitization method, characterized in that: A desensitizing device is applied to a computing system, the computing system comprising an application layer, a kernel layer, and a device layer; wherein the desensitizing device is provided in the application layer, the application layer further comprising an application buffer and an application process, the kernel layer comprising a system call, the device layer comprising at least one disk, the system call being used to store files on the at least one disk; the method comprising: The desensitizing device obtains at least one file in the application buffer, where the at least one file comes from the application process; The desensitizing device identifies a target file in the at least one file that contains sensitive information and is to be stored in the at least one disk; The desensitizing device desensitizes the sensitive information in the target file; The desensitizing device calls the system call to store the desensitized target file to the at least one disk through the system call.
2. The method according to claim 1, characterized in that The method further includes: the desensitizing device obtaining a sensitive file list corresponding to the application type of the application process; The desensitizing device identifies a target file containing sensitive information and to be stored in the at least one disk in the at least one file, including: the desensitizing device identifies a file included in the sensitive file list in the at least one file to obtain the target file.
3. The method according to claim 1 or 2, characterized in that The method further includes: the desensitizing device obtaining a sensitive word dictionary; The desensitizing device identifies a target file containing sensitive information and to be stored in the at least one disk in the at least one file, including: the desensitizing device identifies a file containing at least one sensitive word in the sensitive word dictionary in the at least one file to obtain the target file.
4. The method according to any one of claims 1 to 3, characterized in that The desensitizing device is started by the application process through the LD_PRELOAD environment variable.
5. The method according to any one of claims 1 to 4, characterized in that The system call is a write system call; the desensitizing device calls the system call to store the target file that has undergone the desensitizing processing to the at least one disk through the system call, including: the desensitizing device calls the write system call through the write function to store the target file that has undergone the desensitizing processing to the at least one disk through the write system call.
6. The method according to any one of claims 1 to 5, characterized in that The at least one file is a log file.
7. A desensitization device, characterized in that: The computing system in which the device is located includes an application layer, a kernel layer, and a device layer; wherein the desensitization device is arranged in the application layer, the application layer further includes an application buffer and an application process, the kernel layer is provided with a system call, the device layer includes at least one disk, and the system call is used to store files on the at least one disk; the device includes: an acquisition module, configured to acquire at least one file in the application buffer, where the at least one file comes from the application process; An identification module, configured to identify, from the at least one file, a target file containing sensitive information and to be stored in the at least one disk; A desensitization module, used to desensitize sensitive information in the target file; A calling module is used to call the system call to store the desensitized target file to the at least one disk through the system call.
8. A computing device cluster, characterized in that: comprising at least one computing device, each computing device including a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in a memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that The method comprises computer program instructions, which, when executed by a computing device cluster, cause the computing device cluster to perform the method according to any one of claims 1 to 6.
10. A computer program product comprising instructions, characterized in that When the instructions are executed by a computer device cluster, the computer device cluster is caused to perform the method according to any one of claims 1 to 6.