A data privacy protection and compliance usage method and system
By acquiring access permission characteristics and data characteristics, filtering characteristic access terminals, constructing data access risk curves, and determining whether isolation is necessary, the problem of not being able to quickly identify abnormal risks in existing technologies is solved, and the efficiency and reliability of data privacy protection and compliant use systems are improved.
Patent Information
- Application Number
- CN202511318217.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-16
- Publication Date
- 2026-01-23
- Estimated Expiration
- 2045-09-16
AI Technical Summary
Existing technologies fail to quickly identify access terminals with abnormal risks based on their actual access characteristics, resulting in reduced processing efficiency and reliability of data privacy protection and compliant use systems.
The system acquires access permission features and access data features through the data acquisition module, filters access terminals based on these features using the terminal preprocessing module, constructs a data access risk curve using the terminal analysis module, and determines whether data isolation should be performed using the terminal identification module. This enables rapid identification and adaptive handling of abnormal risks.
It has improved the processing efficiency and reliability of the data privacy protection and compliant use system, reduced the risk of misjudgment and missed judgment, and enabled timely prevention and control of internal personnel abusing their authority.
Smart Images

Figure CN120850347B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, in particular to a data privacy protection and compliance use method and system. BACKGROUND
[0002] In today's digital era, data has become the core asset of enterprise and organization operation and development. From user behavior data to business secrets, the value of data is increasingly prominent, and the problem of data privacy protection and compliance use has become increasingly serious. With the rapid development of information technology, internal data leakage incidents occur frequently. Many internal personnel with legal data access rights may misuse their rights, export or spy on private data that is not necessary for their business due to interest-driven or lack of security awareness. These behaviors not only seriously infringe the privacy rights of users, but also cause great reputation loss and legal risks to enterprises and organizations. Traditional data access monitoring methods are mostly based on simple permission control and limited log recording, which cannot accurately detect the hidden behaviors of internal personnel misusing their rights. Internal personnel may export data under the cover of legal rights, which is difficult to discover in time through conventional means, resulting in misjudgment and omission, making it difficult to lock and handle the real risks in time. Therefore, improving the processing efficiency and reliability of the data privacy protection and compliance use system is a technical problem to be solved.
[0003] For example, Chinese Patent No. CN118981797B discloses a personal information security protection method and device, which designs the field of personal information security protection technology. The method includes: verifying the identity information of the information collector, and judging whether the information collector has the collection qualification according to the identity information; verifying the compliance of the collection request through a compliance checking algorithm, and requesting authorization from the user after verification; encrypting the data in the data card using a data card encryption algorithm, and decrypting and interfacing the data by the encryption center after the user's authorized access; monitoring the collection behavior of the information collector in real time, and issuing a warning to the user and terminating the collection behavior immediately if abnormal collection behavior is found; periodically updating the compliance checking algorithm and the data card encryption algorithm. The method automatically identifies and verifies the legality of data collectors, enhances the protection barrier of user data cards, and improves the security and privacy of user personal information.
[0004] The existing technology also has the following problems:
[0005] The existing technology does not consider that internal personnel with legal data access rights may misuse their rights and export or spy on private data that is not necessary for their business. The existing technology cannot quickly identify access terminals with abnormal risks according to the actual access characteristics of the access terminals, and cannot adaptively adjust the data processing method for access terminals with abnormal risks, affecting the processing efficiency and reliability of the data privacy protection and compliance use system. SUMMARY
[0006] To this end, the present application provides a data privacy protection and compliance use method and system to overcome the problem that the prior art cannot quickly identify access terminals with abnormal risks according to the actual access characteristics of the access terminals, cannot adaptively adjust the data processing mode of the access terminals with abnormal risks, and affects the processing efficiency and reliability of the data privacy protection and compliance use system.
[0007] To achieve the above-mentioned purpose, the present application provides a data privacy protection and compliance use method and system, comprising:
[0008] a data acquisition module configured to acquire access permission characteristics, access data characteristics, and access data traffic parameters of each access terminal, wherein the access permission characteristics include non-permission associated data access frequency and data export quantity deviation parameters, and the access data characteristics include non-permission data access growth parameters and privacy data access time length proportion;
[0009] a terminal preprocessing module connected to the data acquisition module and configured to acquire access permission characteristics of each access terminal within a preset monitoring period, determine access deviation tendency parameters of the access terminal according to the access permission characteristics, and screen a plurality of characteristic access terminals;
[0010] a terminal analysis module connected to the data acquisition module and the terminal preprocessing module and configured to construct a data access risk curve for a single characteristic access terminal based on a plurality of data disorder tendency parameters, wherein each data disorder tendency parameter is determined by the access data characteristics of a single characteristic access terminal within a corresponding characteristic sub-period, and each characteristic sub-period is determined based on the use deviation tendency parameter of the characteristic access terminal;
[0011] a terminal identification module connected to the data acquisition module and the terminal analysis module and configured to determine a risk representation coefficient according to the data access risk curve, and determine whether to perform data isolation on the characteristic access terminal based on the risk representation coefficient of the characteristic access terminal.
[0012] Further, the terminal preprocessing module is configured to determine the access deviation tendency parameter based on a weighted sum of a first access deviation characteristic and a second access deviation characteristic, wherein
[0013] the first access deviation characteristic is a ratio of non-permission associated data access frequency to a non-permission associated data access frequency threshold value;
[0014] the second access deviation characteristic is a ratio of data export quantity deviation parameter to a data export quantity deviation parameter threshold value.
[0015] Further, the terminal preprocessing module is further configured to screen the access terminal as a feature access terminal based on a determination result that the access offset tendency parameter of the access terminal meets a feature access terminal condition, wherein
[0016] The feature access terminal condition is that the access offset tendency parameter of the access terminal exceeds a preset access offset tendency parameter threshold.
[0017] Further, the terminal preprocessing module is configured to determine a use offset tendency parameter of each monitoring sub-period in sequence based on a difference between a maximum value and a minimum value of the access data traffic parameter in the monitoring sub-period, wherein each monitoring sub-period is obtained by dividing a preset monitoring period by the terminal preprocessing module.
[0018] Further, the terminal preprocessing module is configured to determine a feature sub-period based on a determination result that the use offset tendency parameter of the monitoring sub-period meets a feature sub-period condition, wherein
[0019] The feature sub-period condition is that the use offset tendency parameter exceeds a preset use offset tendency parameter threshold.
[0020] Further, the terminal analysis module is configured to obtain an access data feature of the feature access terminal within the feature sub-period, and determine the data imbalance tendency parameter based on a sum of a first imbalance tendency feature and a second imbalance tendency feature, wherein
[0021] The first imbalance tendency feature is a ratio of a non-permission data access growth parameter to a non-permission data access growth parameter threshold;
[0022] The second imbalance tendency feature is a ratio of a privacy data access time length proportion to a privacy data access time length proportion threshold;
[0023] The non-permission data access growth parameter is a ratio of a difference between a non-permission associated data access number at a last time in the feature sub-period and a non-permission associated data access number at a first time in the feature sub-period to a duration of the feature sub-period, and the privacy data access time length proportion is a ratio of a privacy data access time length to a duration of the feature sub-period.
[0024] Further, the terminal analysis module is configured to fit each of the access risk fluctuation points to construct the data access risk curve, wherein the access risk fluctuation points are determined according to the data imbalance tendency parameter and the feature sub-period in which the data imbalance tendency parameter is located, and a coordinate system in which the data access risk curve is located has a time as a horizontal axis and a numerical value of the data imbalance tendency parameter as a vertical axis.
[0025] Further, the terminal identification module is configured to determine a first risk representation coefficient and a second risk representation coefficient based on the data misalignment tendency parameter of each access risk fluctuation point on the data access risk curve, wherein,
[0026] The first risk representation coefficient is a difference between the data misalignment tendency parameter of a later access risk fluctuation point and the data misalignment tendency parameter of an earlier access risk fluctuation point in adjacent two access risk fluctuation points.
[0027] The second risk representation coefficient is an absolute value of a slope difference between adjacent access risk fluctuation points.
[0028] Further, the terminal identification module is configured to determine whether to perform data isolation on the feature access terminal based on a determination result of whether the risk representation coefficient of the feature access terminal meets a data isolation condition.
[0029] The data isolation condition is that the first risk representation coefficient exceeds a preset first risk representation coefficient threshold value and the second risk representation coefficient exceeds a preset second risk representation coefficient threshold value.
[0030] The application further provides a data privacy protection and compliance use method, comprising:
[0031] Accessing access permission features of each access terminal within a preset monitoring period, determining an access offset tendency parameter of the access terminal according to the access permission features, and screening a feature access terminal;
[0032] Determining a feature sub-period according to the use offset tendency parameter of the feature access terminal;
[0033] Determining a data misalignment tendency parameter according to an access data feature of the feature access terminal within the feature sub-period, and determining a data access risk curve;
[0034] Determining a risk representation coefficient according to the data access risk curve, and determining whether to perform data isolation on the feature access terminal based on the risk representation coefficient of the feature access terminal.
[0035] Compared with the prior art, the present application has the beneficial effects that the present application is provided with a data acquisition module, a terminal preprocessing module, a terminal analysis module, and a terminal identification module, the access permission features, access data features, and access data traffic parameters of each access terminal are acquired through the data acquisition module, the access permission features of each access terminal are acquired within a preset monitoring period through the terminal preprocessing module, the access offset tendency parameters of the access terminal are determined according to the access permission features, so as to screen a plurality of feature access terminals, the data access risk curve is constructed for a single feature access terminal based on a plurality of data imbalance tendency parameters through the terminal analysis module, each data imbalance tendency parameter is determined through the access data features of the single feature access terminal within a corresponding feature sub-period, each feature sub-period is determined based on the use offset tendency parameter of the feature access terminal, the risk representation coefficient is determined according to the data access risk curve through the terminal identification module, and whether the feature access terminal is subjected to data isolation is determined based on the risk representation coefficient of the feature access terminal, thereby realizing the rapid identification of the access terminal with abnormal risk according to the actual access features of the access terminal, adaptively adjusting the data processing mode of the access terminal with abnormal risk, and improving the processing efficiency and reliability of the data privacy protection and compliance use system.
[0036] Especially, the present application determines the access offset tendency parameters of the access terminal according to the access permission features through the terminal preprocessing module to screen the feature access terminals, it can be understood that the first access offset feature determined by the non-permission associated data access frequency and the second access offset feature determined by the data export quantity deviation parameter comprehensively consider two key access permission features, more comprehensively reflect the abnormality degree of the access terminal, reduce the misjudgment or omission caused by the fluctuation of a single parameter, make the screened feature access terminals more consistent with the actual risk situation, the risk of abusing the right of these terminals is more targeted, the further analysis of these terminals can focus on high-risk objects, improve the credibility, improve the efficiency of the risk identification of the whole system, provide reliable support for the final risk judgment and data isolation decision, the present application determines the access offset tendency parameters of the access terminal according to the access permission features to screen the feature access terminals, thereby realizing the rapid identification of the access terminal with abnormal risk according to the actual access features of the access terminal, improving the processing efficiency and reliability of the data privacy protection and compliance use system.
[0037] Especially, the application determines the feature sub-period by the terminal analysis module according to the use deviation tendency parameter of the feature access terminal, which can be understood as that the feature sub-period can be located to the specific period in which the feature access terminal has abnormal data access behavior in the monitoring period, avoiding indiscriminate analysis on the whole monitoring period, reducing the interference of invalid data, making the subsequent data analysis of the feature sub-period more focused, greatly improving the efficiency of risk analysis, the feature sub-period is the period in which the data flow of the feature access terminal fluctuates abnormally, and the sharp fluctuation of data flow is often closely related to the behavior of internal personnel abusing authority, such as batch data export and a large amount of non-authorized data peeking in a short time. Taking these feature sub-periods as analysis objects can more specifically capture the characteristics of risk behavior and provide high-quality analysis samples for subsequent calculation of data imbalance tendency parameters and drawing of data access risk curves. At the same time, the monitoring period is refined into sub-periods and the feature sub-period is screened out, so that the system can track the change of risk behavior of the feature access terminal from the time dimension, and through the analysis of different feature sub-periods, the occurrence rule and duration of risk behavior can be mastered, providing accurate basis for dynamic risk assessment and timely intervention measures from the time dimension, and then, the feature sub-period is determined according to the actual access characteristics of the access terminal, improving the processing efficiency and reliability of the data privacy protection and compliance use system.
[0038] Especially, the application determines the data imbalance tendency parameter according to the access data characteristics of the feature access terminal in the feature sub-period by the terminal analysis module to determine the data access risk curve, which can be understood as that the risk degree is accurately quantified and the objectivity of risk assessment is improved, the data imbalance tendency parameter is determined by the first imbalance tendency characteristic and the second imbalance tendency characteristic, the abnormal degree of two key access data characteristics is quantitatively integrated, avoiding the deviation of subjective judgment, so that the risk degree can be objectively and accurately measured, providing a comparable quantitative index for subsequent risk analysis, the data access risk curve takes time as the horizontal axis and data imbalance tendency parameter as the vertical axis, and is fitted by the access risk fluctuation points of multiple feature sub-periods, directly showing the risk change of the feature access terminal at different times, and the development trend of the risk can be tracked in real time by the waveform characteristics of the curve, so that the signs of risk intensification can be discovered in time, providing timely basis for rapid response and intervention. Analyzing these features in the feature sub-period can accurately capture the intensity and duration of risk behavior, and the risk curve constructed based on this can further extend the pertinence to the time dimension, so that the analysis is always focused on the core risk point, improving the effectiveness of risk analysis, and then, the data access risk curve is determined according to the actual access characteristics of the access terminal, improving the processing efficiency and reliability of the data privacy protection and compliance use system.
[0039] Especially, the application determines whether to perform data isolation on the feature access terminal based on the terminal risk representation coefficient of the terminal identification module, it can be understood that the first risk representation coefficient represents the increase or decrease amplitude of the risk through the difference value of the data disorder tendency parameter of the adjacent access risk fluctuation point, the second risk representation coefficient represents the fluctuation intensity of the risk curve through the average value of the absolute value of the slope difference value of the adjacent feature sub-period, the combination of the two can capture the dynamic characteristics of the risk from different dimensions, not only considering the growth trend of the risk, but also paying attention to the volatility stability of the risk, which can effectively avoid the misjudgment of isolation due to accidental risk fluctuations, or the loss caused by the risk continuing to intensify without timely isolation, improve the accuracy of risk response, make the risk judgment more scientific and comprehensive, the data isolation operation triggered based on this can timely block before the risk behavior causes substantial harm, accurately respond to high-risk terminals, minimize the risk of data leakage, and enhance the timeliness and pertinence of risk prevention and control, and further, adaptively adjust the data processing mode of the access terminal with abnormal risk according to the actual access characteristics of the access terminal, improve the processing efficiency and reliability of the data privacy protection and compliance use system. BRIEF DESCRIPTION OF DRAWINGS
[0040] Figure 1 The functional block diagram of the data privacy protection and compliance use system of the embodiment of the application is shown in the figure.
[0041] Figure 2 The logic flow chart of the terminal preprocessing module of the embodiment of the application for screening feature access terminals is shown in the figure.
[0042] Figure 3 The logic flow chart of the terminal preprocessing module of the embodiment of the application for determining the feature sub-period is shown in the figure.
[0043] Figure 4 The step chart of the data privacy protection and compliance use method of the embodiment of the application is shown in the figure. DETAILED DESCRIPTION
[0044] In order to make the purpose and advantages of the application more clear and obvious, the application will be further described below in combination with embodiments; it should be understood that the specific embodiments described herein are only used to explain the application, and do not limit the application.
[0045] The preferred embodiments of the application will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the application, and are not intended to limit the protection scope of the application.
[0046] It should be noted that in the description of the present application, the terms indicating the direction or positional relationship of "upper", "lower", "inner", "outer" and the like are based on the direction or positional relationship shown in the drawings, which is only for the convenience of description, and does not indicate or imply that the device or element must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation on the present application.
[0047] In addition, it should be noted that in the description of the present application, unless otherwise explicitly specified and limited, the terms "mounting", "connection" should be understood broadly, for example, it can be fixed connection, or detachable connection, or integral connection; it can be mechanical connection, or electrical connection; it can be directly connected, or indirectly connected through intermediate medium, or internal communication of two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.
[0048] Please refer to Figure 1 As shown in the figure, it is a functional block diagram of the data privacy protection and compliance use system of the embodiment of the present application, the data privacy protection and compliance use system of the present application comprises:
[0049] The data acquisition module is used to acquire the access permission characteristics, access data characteristics and access data traffic parameters of each access terminal, the access permission characteristics include non-permission associated data access frequency and data export amount deviation parameter, the access data characteristics include non-permission data access growth parameter and privacy data access time length proportion;
[0050] Specifically, the structure of the data acquisition module in the embodiment of the present application is not limited, preferably, it can be a traffic mirroring device deployed in a network node and a terminal proxy program, which is used to acquire the access permission characteristics, access data characteristics and access data traffic parameters of each access terminal, which will not be repeated here.
[0051] Specifically, the non-permission associated data access frequency is the total number of times that the access terminal accesses the non-business associated data outside its own permission range in a preset monitoring period, and the data export amount deviation parameter is the deviation degree between the actual data export amount of the access terminal in a single session and the normal single session data export benchmark value in the business scenario, the benchmark value can be the average value of the data amount in the historical data,
[0052] The determination manner of the access terminal self permission range data and the sensitive privacy data is not specifically limited in the embodiments of the present application, and a permission feature library can be established by using a preset keyword or field library specific to the access terminal self permission range, a sensitive privacy feature library can be established by using a preset keyword or field library specific to the sensitive privacy data, and a text analysis tool is used to scan the transmission data content and match and identify the content of the transmission data, which will not be repeated here.
[0053] The terminal preprocessing module is connected with the data acquisition module, and is used to acquire the access permission features of each access terminal within a preset monitoring period, determine the access deviation tendency parameters of the access terminal according to the access permission features, and screen a plurality of feature access terminals;
[0054] Specifically, the structure of the terminal preprocessing module is not specifically limited in the embodiments of the present application, and preferably, it can be a microprocessor, which is used to determine the access deviation tendency parameters of the access terminal and screen a plurality of feature access terminals, which will not be repeated here.
[0055] Specifically, the preset monitoring period can be set by a person skilled in the art according to the accuracy requirement of the data privacy protection and compliance use system, the higher the accuracy requirement, the shorter the preset monitoring period, and the preset monitoring period can be [10, 20] with the interval unit being min, and preferably, the preset monitoring period can be 15 min.
[0056] The terminal analysis module is connected with the data acquisition module and the terminal preprocessing module respectively, and is used to construct a data access risk curve for a single feature access terminal based on a plurality of data disorder tendency parameters, wherein each data disorder tendency parameter is determined by the access data features of a single feature access terminal within a corresponding feature sub-period, and each feature sub-period is determined based on the use deviation tendency parameters of the feature access terminal.
[0057] Specifically, the structure of the terminal analysis module is not specifically limited in the embodiments of the present application, and preferably, it can be a processor used in a computer, which is used to construct a data access risk curve for a single feature access terminal based on a plurality of data disorder tendency parameters, and screen a plurality of feature access terminals, which will not be repeated here.
[0058] The terminal identification module is connected with the data acquisition module and the terminal analysis module respectively, and is used to determine a risk representation coefficient according to the data access risk curve, and determine whether to perform data isolation on the feature access terminal based on the risk representation coefficient of the feature access terminal.
[0059] Specifically, the terminal identification module is not specifically limited in structure, and preferably, it can be a microprocessor used to determine a risk representation coefficient and determine whether to perform data isolation on a feature access terminal, which will not be described again.
[0060] Specifically, the terminal preprocessing module is used to determine the access offset tendency parameter based on a weighted sum of the first access offset feature and the second access offset feature.
[0061] The first access offset feature is a ratio of a non-permission associated data access frequency to a non-permission associated data access frequency threshold value.
[0062] The second access offset feature is a ratio of a data export quantity deviation parameter to a data export quantity deviation parameter threshold value.
[0063] Specifically, in an actual data access scenario, the data export quantity deviation parameter can more directly reflect whether a terminal has a risk behavior of batch exporting non-business data, and it has a more direct threat to data privacy security and a possibly wider impact range, and under this premise, it can better reflect a decisive influence on access permission deviation. In addition, the size of the weight value is selected according to the influence degree of the non-permission associated data access frequency and the data export quantity deviation parameter in the historical data on the calculation result, so in implementation, the risk weight of the data export behavior is given priority, and therefore a slightly higher weight is given to the second access offset feature. When performing weighted sum, the weight of the first access offset feature can be set to 0.4, and the weight of the second access offset feature can be set to 0.6.
[0064] In this embodiment, the purpose of setting the non-permission associated data access frequency threshold value and the data export quantity deviation parameter threshold value is to represent a case where an access behavior poses a greater threat to data privacy security. By calling historical access data several times, non-permission associated data access frequency historical data and data export quantity deviation parameter historical data of an access terminal in a same preset monitoring period are obtained, a non-permission associated data access frequency mean value and a data export quantity deviation parameter mean value are solved, and based on the purpose of setting the two threshold values, the non-permission associated data access frequency threshold value is determined as a product of the non-permission associated data access frequency mean value and a first deviation coefficient, and the data export quantity deviation parameter threshold value is determined as a product of the data export quantity deviation parameter mean value and a second deviation coefficient. The value range of the first deviation coefficient can be [1.1, 1.3], and the value range of the second deviation coefficient can be [1.2, 1.4]. Preferably, the first deviation coefficient can be 1.2, and the second deviation coefficient can be 1.3.
[0065] Please refer to Figure 2As shown, it is a logical flow diagram of the terminal preprocessing module of the embodiment of the application screening the feature access terminal, the terminal preprocessing module is also used to screen the access terminal as a feature access terminal based on the determination result that the access offset tendency parameter of the access terminal meets the feature access terminal condition, wherein,
[0066] If the access offset tendency parameter of the access terminal does not meet the feature access terminal condition, the terminal preprocessing module does not screen the access terminal;
[0067] The feature access terminal condition is that the access offset tendency parameter of the access terminal exceeds the preset access offset tendency parameter threshold.
[0068] Specifically, the preset access offset tendency parameter threshold is the product of the access offset tendency parameter reference value and the access offset coefficient, the access offset tendency parameter reference value is the average value of the access offset tendency parameter in the historical data, the access offset coefficient can be set by the person skilled in the art according to the accuracy requirement of the data privacy protection and compliance use system, the higher the accuracy requirement, the smaller the access offset coefficient, the value range of the access offset coefficient can be [1.1, 1.4], preferably, it can be 1.2.
[0069] Specifically, the embodiment of the application determines the access offset tendency parameter of the access terminal according to the access permission feature through the terminal preprocessing module to screen the feature access terminal, it can be understood that the first access offset feature determined by the non-permission associated data access frequency and the second access offset feature determined by the data export amount deviation parameter comprehensively consider two key access permission features, more comprehensively reflect the abnormality degree of the access terminal, reduce the misjudgment or omission caused by the fluctuation of a single parameter, make the screened feature access terminal more consistent with the actual risk situation, the risk of abusing the right of existence is more targeted, the further analysis of these terminals can focus on high-risk objects, improve the reliability, improve the efficiency of the risk identification of the whole system, provide reliable support for the final risk judgment and data isolation decision, the embodiment of the application determines the access offset tendency parameter of the access terminal according to the access permission feature to screen the feature access terminal, and then, realizes the rapid identification of the access terminal with abnormal risk according to the actual access feature of the access terminal, improves the processing efficiency and reliability of the data privacy protection and compliance use system.
[0070] Specifically, it can be understood that the behavior of internal staff abusing authority mainly embodies two core aspects, one is accessing non-privilege-related data beyond the business scope, and the other is that the amount of exported data deviates from the range required by normal business. The frequency of accessing non-privilege-related data reflects the frequency of accessing non-business data. The higher the frequency, the more likely it is to exist the behavior of peeping unnecessary private data. The deviation of data export quantity reflects the deviation degree of data export behavior from normal business. The larger the deviation, the higher the risk of batch data export. The first access deviation feature and the second access deviation feature respectively quantify the two behavior characteristics as a multiple relationship relative to the respective threshold, realizing the normalization processing of different dimension parameters. The access deviation tendency parameter obtained by weighted summation fuses the influence of the two risk behaviors, so that the parameter can better meet the actual risk assessment needs. The larger the access deviation tendency parameter, the more abnormal the terminal in non-privilege data access or data export, which needs to be focused on. It is screened as a feature access terminal, ensuring that the system can preferentially monitor and analyze high-risk terminals, thereby effectively preventing data privacy leakage risks caused by internal staff abusing authority. Further, it realizes rapid identification of access terminals with abnormal risks according to the actual access characteristics of the access terminal, improves the processing efficiency and reliability of the data privacy protection and compliance use system.
[0071] Specifically, the terminal preprocessing module is configured to determine the use deviation tendency parameter of each detection sub-period in sequence based on the difference between the maximum value and the minimum value of the access data flow parameter in each monitoring sub-period, wherein each monitoring sub-period is obtained by dividing the preset monitoring period by the terminal preprocessing module.
[0072] Specifically, the duration of the monitoring sub-period is the product of the duration of the preset monitoring period and the sub-period division factor. The sub-period division factor can be set by a person skilled in the art according to the accuracy requirement of the data privacy protection and compliance use system. The higher the accuracy requirement, the smaller the sub-period division factor. The value range of the sub-period division factor can be [0.1, 0.3]. Preferably, the sub-period division factor can be 0.2. The monitoring sub-period contains a plurality of monitoring time points. The interval duration between adjacent monitoring time points is the product of the duration of the monitoring sub-period and the time point division factor. The time point division factor can be set by a person skilled in the art according to the accuracy requirement of the data privacy protection and compliance use system. The higher the accuracy requirement, the smaller the time point division factor. The value range of the time point division factor can be [0.2, 0.4]. Preferably, the sub-period division factor can be 0.3.
[0073] Please refer to Figure 3As shown, it is a logic flow diagram for determining a feature sub-period by a terminal preprocessing module of an embodiment of the present application. The terminal preprocessing module determines a monitoring sub-period as a feature sub-period based on a determination result that a use offset tendency parameter of the monitoring sub-period meets a feature sub-period condition, wherein,
[0074] If the use offset tendency parameter of the monitoring sub-period does not meet the feature sub-period condition, the terminal preprocessing module does not screen the monitoring sub-period.
[0075] The feature sub-period condition is that the use offset tendency parameter exceeds a preset use offset tendency parameter threshold.
[0076] Specifically, the preset use offset tendency parameter threshold is a product of a use offset tendency parameter reference value and a use offset coefficient. The use offset tendency parameter reference value is an average value of the use offset tendency parameter in historical data. The use offset coefficient can be set by a person skilled in the art according to the accuracy requirement of the data privacy protection and compliance use system. The higher the accuracy requirement, the smaller the use offset coefficient. The value range of the use offset coefficient can be [1.1, 1.3], and preferably, it can be 1.2.
[0077] Specifically, the embodiment of the present application determines a feature sub-period according to the use offset tendency parameter of the feature access terminal by the terminal analysis module. It can be understood that the determination of the feature sub-period can locate to a specific period of abnormal data access behavior of the feature access terminal in the monitoring period, avoiding indiscriminate analysis of the entire monitoring period, reducing the interference of invalid data, making the subsequent data analysis of the feature sub-period more focused, and greatly improving the efficiency of risk analysis. The feature sub-period is a period of abnormal fluctuation of data traffic of the feature access terminal, and the sharp fluctuation of data traffic is often closely related to the behavior of internal personnel abusing authority, such as bulk data export and a large amount of non-authorized data exploration in a short time. Taking these feature sub-periods as analysis objects can more specifically capture the characteristics of risk behavior, provide high-quality analysis samples for subsequent calculation of data imbalance tendency parameters and drawing of data access risk curves, and at the same time, refine the monitoring period into sub-periods and screen out the feature sub-periods, so that the system can track the change of risk behavior of the feature access terminal from the time dimension. Through analysis of different feature sub-periods, the occurrence law and duration of risk behavior can be mastered, which provides a precise basis for time dimension for dynamic assessment of risk and timely intervention measures, and then, the feature sub-period is determined according to the actual access characteristics of the access terminal, the processing efficiency and reliability of the data privacy protection and compliance use system are improved.
[0078] Specifically, it can be understood that when internal personnel abuse their authority to batch export or massively pry non-business necessary private data, the data transmission volume far exceeds the normal business in a short time, resulting in a sharp fluctuation of access data flow parameters. For example, in normal business, the data flow in a certain monitoring sub-period may fluctuate between 10MB and 20MB, while in the presence of batch data export or massive prying of non-business necessary private data, the flow in the sub-period may increase to more than 100MB, and a lower flow value may appear due to the operation gap, so that the difference between the maximum and minimum values of the flow in the sub-period, i.e., the use offset tendency parameter, increases significantly. The larger the use offset tendency parameter, the greater the fluctuation degree of the data flow in the sub-period, and there is a higher risk of abusing authority. When the potential risk period is captured through objective parameter changes, the subsequent data analysis in the feature sub-period focuses on the time window where the risk behavior is most likely to occur, and the results can more truly reflect the risk status of the feature access terminal, providing reliable time dimension support for the risk assessment and decision-making of the entire system. Further, the feature sub-period is determined according to the actual access features of the access terminal, improving the processing efficiency and reliability of the data privacy protection and compliance use system.
[0079] Specifically, the terminal analysis module is configured to obtain access data features of the feature access terminal in the feature sub-period, and determine the data imbalance tendency parameter based on a sum of a first imbalance tendency feature and a second imbalance tendency feature.
[0080] The first imbalance tendency feature is a ratio of a non-authority data access growth parameter to a non-authority data access growth parameter threshold value.
[0081] The second imbalance tendency feature is a ratio of a private data access time length proportion to a private data access time length proportion threshold value.
[0082] The non-authority data access growth parameter is a ratio of a difference between a non-authority associated data access number at a last time in the feature sub-period and a non-authority associated data access number at a first time in the feature sub-period to a duration of the feature sub-period, and the private data access time length proportion is a ratio of a private data access time length to a duration of the feature sub-period.
[0083] In this embodiment, the purpose of setting the non-authorized data access growth parameter threshold and the privacy data access time length proportion threshold is to represent the case that the data access behavior of the feature access terminal deviates from the normal business range in the feature sub-period and there is a risk of data imbalance. By calling the historical access data of the feature access terminal for several times, the non-authorized data access growth parameter historical data and the privacy data access time length proportion historical data under the same feature sub-period length are obtained, and the mean value of the non-authorized data access growth parameter and the mean value of the privacy data access time length proportion are solved. Based on the purpose of setting the above two thresholds, the non-authorized data access growth parameter threshold is determined as the product of the mean value of the non-authorized data access growth parameter and the first imbalance coefficient, and the privacy data access time length proportion threshold is determined as the product of the mean value of the privacy data access time length proportion and the second imbalance coefficient. The value range of the first imbalance coefficient can be [1.2, 1.4], and the value range of the second imbalance coefficient can be [1.3, 1.5]. Preferably, the first imbalance coefficient can be 1.35, and the second imbalance coefficient can be 1.4.
[0084] Specifically, the terminal analysis module is configured to fit each of the access risk fluctuation points to construct the data access risk curve, wherein the access risk fluctuation point is determined according to the data imbalance tendency parameter and the feature sub-period in which the data imbalance tendency parameter is located, and the coordinate system in which the data access risk curve is located has a horizontal axis of time and a vertical axis of the numerical value of the data imbalance tendency parameter.
[0085] Specifically, the way of constructing the data access risk curve is not limited, for example, the data access risk curve can be fitted by matlab related fitting software, which will not be repeated here.
[0086] Specifically, the data access risk curve connects each access risk fluctuation point with a smooth curve, and the access risk fluctuation point is determined according to the data imbalance tendency parameter and the midpoint time of the feature sub-period in which the data imbalance tendency parameter is located.
[0087] Specifically, the embodiment of the present application determines the data access risk curve by determining the data imbalance tendency parameter according to the access data characteristics of the feature access terminal in the feature sub-period through the terminal analysis module. It can be understood that the risk degree is accurately quantified, and the objectivity of risk assessment is improved. The data imbalance tendency parameter is determined by the first imbalance tendency feature and the second imbalance tendency feature, the abnormal degree of two key access data characteristics is quantitatively integrated, the deviation of subjective judgment is avoided, the risk degree can be objectively and accurately measured, and a comparable quantitative index is provided for subsequent risk analysis. The data access risk curve takes time as the horizontal axis and the data imbalance tendency parameter as the vertical axis, and is fitted by the access risk fluctuation points of multiple feature sub-periods. The risk change of the feature access terminal at different times is directly displayed. With the waveform characteristics of the curve, the development trend of the risk can be tracked in real time, and signs of risk intensification can be found in time, providing timely basis for rapid response and intervention. Analyzing these features in the feature sub-period can accurately capture the strength and duration of the risk behavior. The risk curve constructed based on this can further extend this pertinence to the time dimension, so that the analysis always revolves around the core risk point, improving the effectiveness of risk analysis. Furthermore, the data access risk curve is determined according to the actual access characteristics of the access terminal, improving the processing efficiency and reliability of the data privacy protection and compliance use system.
[0088] Specifically, it can be understood that the risk behavior of internal personnel abusing authority will present two typical characteristics in the feature sub-period. One is the rapid growth of non-authorization data access, which is embodied in the frequent expansion of non-business data access range in a short time. The other is the continuous attention to privacy data, which is manifested as a high proportion of time spent accessing privacy data in the feature sub-period. The non-authorization data access growth parameter, which is the ratio of the increment of non-authorization associated data access times to the duration in the feature sub-period, represents the urgency and expansion speed of accessing non-authorization data. The first imbalance tendency feature quantifies the deviation of this growth from the regular level. The privacy data access time ratio, which is the ratio of the privacy data access time to the duration of the feature sub-period, represents the depth of attention to privacy data. The second imbalance tendency feature quantifies the abnormality of this attention relative to regular business. The data access risk curve integrates the data imbalance tendency parameters of multiple feature sub-periods to convert discrete risk quantitative values into a continuous trend curve. The abuse behavior of the feature terminal is often not isolated, but presents continuous and changing characteristics in the time dimension. By constructing the data access risk curve, the trend and characteristics of the change can be directly reflected, and the strength and dynamic change of the risk behavior can be accurately captured, effectively improving the identification and prevention and control capability of the system for the abuse behavior of internal personnel. Furthermore, the data access risk curve is determined according to the actual access characteristics of the access terminal, improving the processing efficiency and reliability of the data privacy protection and compliance use system.
[0089] Specifically, the terminal identification module is configured to determine a first risk characterization coefficient and a second risk characterization coefficient based on the data misalignment tendency parameters of each access risk fluctuation point on the data access risk curve, wherein,
[0090] The first risk characterization coefficient is the difference between the data misalignment tendency parameter of the latter access risk fluctuation point and the data misalignment tendency parameter of the former access risk fluctuation point in the adjacent two access risk fluctuation points.
[0091] The second risk characterization coefficient is the absolute value of the slope difference between adjacent access risk fluctuation points.
[0092] Specifically, the terminal identification module is configured to determine whether to perform data isolation on the feature access terminal based on the determination result of whether the risk characterization coefficient of the feature access terminal meets the data isolation condition.
[0093] If the risk characterization coefficient of the feature access terminal does not meet the data isolation condition, the terminal identification module determines not to perform data isolation on the feature access terminal.
[0094] The data isolation condition is that the first risk characterization coefficient exceeds a preset first risk characterization coefficient threshold, and the second risk characterization coefficient exceeds a preset second risk characterization coefficient threshold.
[0095] Specifically, the preset first risk characterization coefficient threshold is the product of a first risk characterization coefficient reference value and a first risk coefficient, and the preset second risk characterization coefficient threshold is the product of a second risk characterization coefficient reference value and a second risk coefficient. The first risk characterization coefficient reference value is the average of the first risk characterization coefficient in historical data, and the second risk characterization coefficient is the average of the second risk characterization coefficient in historical data. The first risk coefficient and the second risk coefficient can be set by a person skilled in the art according to the accuracy requirement of the data privacy protection and compliance system. The higher the accuracy requirement, the smaller the first risk coefficient and the second risk coefficient are set. The value range of the first risk coefficient can be [1.15, 1.3], and the value range of the second risk coefficient can be [1.2, 1.35]. Preferably, the first risk coefficient can be 1.2, and the second risk coefficient can be 1.3.
[0096] Specifically, the terminal identification module determines whether to perform data isolation on the feature access terminal based on the risk representation coefficient of the feature access terminal, it can be understood that the first risk representation coefficient is obtained by the difference value of the data disorder tendency parameters of adjacent access risk fluctuation points, which can represent the increase and decrease amplitude of the risk, and the second risk representation coefficient is obtained by the average value of the absolute value of the slope difference value of adjacent feature sub-periods, which represents the fluctuation intensity of the risk curve, the combination of the two can capture the dynamic characteristics of the risk from different dimensions, considering both the growth trend of the risk and the fluctuation stability of the risk, which can effectively avoid misjudgment of isolation due to accidental risk fluctuation, or loss caused by not timely isolation due to continuous aggravation of the risk, improve the accuracy of risk response, make the risk judgment more scientific and comprehensive, and the data isolation operation triggered based on this can timely block before the risk behavior causes substantial harm, accurately respond to high-risk terminals, and maximize the reduction of data leakage risk, thereby enhancing the timeliness and pertinence of risk prevention and control, and further, the data processing mode of the access terminal with abnormal risk is adaptively adjusted according to the actual access characteristics of the access terminal, and the processing efficiency and reliability of the data privacy protection and compliance use system are improved.
[0097] Specifically, it can be understood that when the abuse behavior intensifies, the data disorder tendency parameter will continue to rise, and the difference value of adjacent fluctuation points, i.e. the first risk representation coefficient, will increase, and when trying to evade monitoring, the behavior rhythm may be deliberately adjusted, resulting in frequent changes in the slope of the risk curve, and the absolute value of the slope difference value of adjacent sub-periods, i.e. the second risk representation coefficient, will increase. The first risk representation coefficient reflects the growth trend of the risk, and the greater the value, the faster the risk intensifies in a short period of time, and the more likely the abuse behavior is in an active expansion stage, which needs to be intervened. The second risk representation coefficient reflects the stability of the risk curve, and the greater the value, the more intense the fluctuation of the risk behavior, and the more likely there is an attempt to deliberately cover tracks, which also needs to be controlled in time. The data isolation condition is set to be that both coefficients exceed the threshold, because a single coefficient exceeding the threshold may be a misjudgment, for example, only the first coefficient exceeding the threshold may be a short-term operation error, and only the second coefficient exceeding the threshold may be a normal business fluctuation, and both exceeding the threshold represents a systematic abuse of the right to use, which can more accurately lock the high-risk terminal that needs to be isolated, avoid misjudgment, and affect the normal business demand response, thereby, the data processing mode of the access terminal with abnormal risk is adaptively adjusted according to the actual access characteristics of the access terminal, and the processing efficiency and reliability of the data privacy protection and compliance use system are improved.
[0098] Referring to Figure 4 The application also provides a data privacy protection and compliance use method, which comprises the following steps:
[0099] Step S100, access permission features of each access terminal are acquired in a preset monitoring period, an access bias tendency parameter of the access terminal is determined according to the access permission features, and a feature access terminal is screened;
[0100] Step S200, a feature sub-period is determined according to the use bias tendency parameter of the feature access terminal;
[0101] Step S300, a data imbalance tendency parameter is determined according to access data features of the feature access terminal in the feature sub-period, and a data access risk curve is determined;
[0102] Step S400, a risk representation coefficient is determined according to the data access risk curve, and whether to perform data isolation on the feature access terminal is determined based on the risk representation coefficient of the feature access terminal.
[0103] So far, the technical solutions of the present application have been described in combination with the preferred embodiments shown in the drawings, but those skilled in the art can easily understand that the protection scope of the present application is obviously not limited to these specific embodiments. Those skilled in the art can make equivalent changes or replacements to the related technical features without departing from the principles of the present application, and the technical solutions after the changes or replacements will fall within the protection scope of the present application.
[0104] The above description is only the preferred embodiments of the present application and is not used to limit the present application; for those skilled in the art, the present application can have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.
Claims
1. A data privacy protection and compliant use system, characterized in that, include: The data acquisition module is used to acquire the access permission characteristics, access data characteristics, and access data traffic parameters of each access terminal. The access permission characteristics include the frequency of access to non-authorized associated data and the deviation parameter of data export volume. The access data characteristics include the growth parameter of non-authorized data access and the proportion of privacy data access time. A terminal preprocessing module, which is connected to the data acquisition module, is used to acquire the access permission characteristics of each access terminal within a preset monitoring period, and determine the access offset tendency parameter of the access terminal based on the access permission characteristics, so as to filter a number of characteristic access terminals. The terminal analysis module is connected to the data acquisition module and the terminal preprocessing module respectively, and is used to construct a data access risk curve for a single characteristic access terminal based on several data imbalance tendency parameters. Each of the data imbalance tendency parameters is determined by the access data characteristics of a single characteristic access terminal in the corresponding characteristic sub-period, and each characteristic sub-period is determined based on the usage offset tendency parameters of the characteristic access terminal. The terminal identification module, together with the data acquisition module and the terminal analysis module, is used to determine the risk characterization coefficient based on the data access risk curve, and to determine whether to isolate the characteristic access terminal based on the risk characterization coefficient.
2. The data privacy protection and compliant use system according to claim 1, characterized in that, The terminal preprocessing module is used to determine the access offset tendency parameter based on a weighted sum of the first access offset feature and the second access offset feature, wherein, The first access offset feature is the ratio of the access frequency of non-authorized associated data to the threshold of the access frequency of non-authorized associated data; The second access offset feature is the ratio of the data export deviation parameter to the data export deviation parameter threshold.
3. The data privacy protection and compliant use system according to claim 2, characterized in that, The terminal preprocessing module is further used to filter the access terminal as a characteristic access terminal based on the determination result that the access offset tendency parameter of the access terminal meets the characteristic access terminal conditions, wherein... The characteristic access terminal condition is that the access offset tendency parameter of the access terminal exceeds a preset access offset tendency parameter threshold.
4. The data privacy protection and compliant use system according to claim 3, characterized in that, The terminal preprocessing module is used to determine the usage offset tendency parameter of each monitoring sub-period based on the difference between the maximum value and the minimum value of the access data traffic parameter in each monitoring sub-period. The monitoring sub-period is obtained by dividing the preset monitoring period through the terminal preprocessing module.
5. The data privacy protection and compliant use system according to claim 4, characterized in that, The terminal preprocessing module determines the monitored sub-period as a characteristic sub-period based on the determination result that the usage offset tendency parameter of the monitored sub-period meets the characteristic sub-period conditions. The characteristic sub-time period condition is that the offset tendency parameter used exceeds a preset offset tendency parameter threshold.
6. The data privacy protection and compliant use system according to claim 5, characterized in that, The terminal analysis module is used to acquire access data characteristics of characteristic access terminals within characteristic sub-time periods, and to determine the data imbalance tendency parameter based on the sum of the first imbalance tendency feature and the second imbalance tendency feature, wherein... The first imbalance tendency feature is the ratio of the non-authorized data access growth parameter to the non-authorized data access growth parameter threshold; The second imbalance tendency feature is the ratio of the percentage of time spent accessing private data to the threshold percentage of time spent accessing private data; The non-authorized data access growth parameter is the ratio of the difference between the number of non-authorized associated data accesses at the last moment of the characteristic sub-period and the number of non-authorized associated data accesses at the first moment of the characteristic sub-period to the duration of the characteristic sub-period. The privacy data access duration percentage is the ratio of the privacy data access duration to the duration of the characteristic sub-period.
7. The data privacy protection and compliant use system according to claim 6, characterized in that, The terminal analysis module is used to fit each of the access risk fluctuation points to construct the data access risk curve. The access risk fluctuation points are determined based on the data imbalance tendency parameter and the characteristic sub-period in which the data imbalance tendency parameter is located. The horizontal axis of the coordinate system in which the data access risk curve is located is time, and the vertical axis is the magnitude of the data imbalance tendency parameter.
8. The data privacy protection and compliant use system according to claim 7, characterized in that, The terminal identification module is used to determine a first risk characterization coefficient and a second risk characterization coefficient based on the data imbalance tendency parameter at each access risk fluctuation point on the data access risk curve, wherein... The first risk characterization coefficient is the difference between the data misalignment tendency parameter of the latter access risk fluctuation point and the data misalignment tendency parameter of the former access risk fluctuation point among two adjacent access risk fluctuation points. The second risk characterization coefficient is the absolute value of the slope difference at adjacent access risk fluctuation points.
9. The data privacy protection and compliant use system according to claim 8, characterized in that, The terminal identification module is used to determine whether the characteristic access terminal meets the data isolation conditions based on the risk characterization coefficient of the characteristic access terminal. The data isolation condition is that the first risk characterization coefficient exceeds a preset first risk characterization coefficient threshold, and the second risk characterization coefficient exceeds a preset second risk characterization coefficient threshold.
10. A method for data privacy protection and compliant use, used in the data privacy protection and compliant use system according to any one of claims 1-9, characterized in that, include: Within a preset monitoring period, the access permission characteristics of each access terminal are acquired, and the access offset tendency parameters of the access terminals are determined based on the access permission characteristics in order to filter characteristic access terminals. The characteristic sub-time period is determined based on the usage offset tendency parameter of the characteristic access terminal; Within the characteristic sub-period, a data misalignment tendency parameter is determined based on the access data characteristics of the characteristic access terminal to determine the data access risk curve; Based on the data access risk curve, a risk characterization coefficient is determined, and based on the risk characterization coefficient of the characteristic access terminal, it is determined whether to isolate the characteristic access terminal.
Citation Information
Patent Citations
A personal information security protection method and device
CN118981797B
Information security protection method based on Internet finance and biological recognition and cloud platform
CN112465503A
Data security protection supervision system
CN119249459A