Data leakage behavior checking method and device, computer device and storage medium
By using intelligent behavior analysis and machine learning, user behavior data is acquired and processed to generate visualized risk profiles, which solves the problem of insufficient monitoring of internal threats by traditional security protection systems and achieves precise prevention and efficient management of data leakage.
Patent Information
- Application Number
- CN202511352622.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-22
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2045-09-22
AI Technical Summary
Traditional security systems lack effective monitoring and analysis of internal threats, making it difficult to warn and prevent data breaches. They also suffer from problems such as data silos, alarm fatigue and false alarms, and a lack of intelligent analysis.
By using intelligent behavior analysis, machine learning, and association rules, raw user behavior data is obtained, cleaned, parsed, and normalized. Machine learning algorithms are then used for real-time risk rule matching to generate a visual risk profile and output alarm information.
It enables precise prevention and control of internal data leakage risks, improves threat detection efficiency, breaks down data silos, provides early warning and in-process intervention capabilities, and safeguards the company's brand reputation and customer trust.
Smart Images

Figure CN120880778B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data security protection in the logistics industry, and in particular relates to a data leakage behavior checking and controlling method and device, computer equipment and a storage medium. BACKGROUND
[0002] Traditional security protection systems mainly target external attacks, while threats from the inside are more harmful due to their legitimate permissions and difficulty in preventing. Malicious operations by internal personnel, account theft, data theft, and unintentional violations are one of the core reasons for data leakage. At present, there is a lack of effective technical means to continuously monitor and analyze the behavior of internal personnel, and it is impossible to achieve early warning and intervention. Moreover, most enterprises currently rely on traditional security devices (such as firewalls, IDS) logs and system logs for post-auditing, which has the following pain points:
[0003] Data island problem: Logs are scattered in various systems, formats are different, and it is difficult to correlate and analyze, with extremely low investigation efficiency.
[0004] Alarm fatigue and false positives: Traditional rule alarms are mostly single-point, low-level events, lack of context association, and produce a large amount of noise, which hides real threats.
[0005] Lack of intelligent analysis: Mainly rely on fixed rules, which cannot effectively identify unknown threats and slow, latent attacks, and other problems. SUMMARY
[0006] The embodiments of the present application provide a data leakage behavior checking and controlling method, device, computer equipment and storage medium, which aims to accurately prevent and control data leakage risks through intelligent behavior analysis, machine learning and association rules, risk profiling, protect the core value of enterprises, and maintain brand reputation and customer trust.
[0007] The technical solutions are as follows:
[0008] In a first aspect, the embodiments of the present application provide a data leakage behavior checking and controlling method, comprising:
[0009] including obtaining user original behavior data from VPN, bastion host, database, office OA, cloud platform, and terminal, wherein the obtained user original data includes abnormal behavior of the user obtaining data through operating documents, screenshots, and shooting videos, and the abnormal behavior includes sensitive data access, unauthorized operation, and abnormal time login;
[0010] Pretreatment of the obtained user original behavior data, including cleaning, parsing, enriching, and normalizing storage;
[0011] According to the preset risk rule, the acquired preprocessed data is matched in real time by a machine learning algorithm, a risk score is obtained according to the matching condition, whether there is a violation risk is judged according to the risk score, and a visual risk portrait is generated according to the violation risk;
[0012] According to the alarm rule, alarm information is output.
[0013] Further, the pre-processing of the acquired user original behavior data includes cleaning, parsing, enriching and normalized storage, and also includes cleaning, parsing, enriching and normalized storage of the acquired user original behavior data by means of log parsing, field standardization, invalid data filtering, IP address reverse resolution, and information completion by associating user and asset metadata.
[0014] Further, the real-time risk rule matching of the acquired preprocessed data according to the preset risk rule by the machine learning algorithm, the risk score obtained according to the matching condition, the judgment of whether there is a violation risk according to the risk score, and the generation of a visual risk portrait according to the violation risk, includes:
[0015] Further, the real-time risk rule matching of the acquired preprocessed data according to the preset risk rule by the machine learning algorithm, the risk score obtained according to the matching condition, the judgment of whether there is a violation risk according to the risk score, and the generation of a visual risk portrait according to the violation risk, includes:
[0016] Each user triggers a risk scene, and a first risk score configured according to the risk scene is obtained;
[0017] Based on the first risk score, a second risk score of the user attenuated over time according to the attenuation rule under the risk scene is obtained;
[0018] According to the second risk score, a risk ranking list sorted according to the second risk score is generated and displayed in the form of a visual risk portrait.
[0019] Further, the acquisition of each user triggering a risk scene and the acquisition of a first risk score configured according to the risk scene includes:
[0020] The event types triggered under the risk scene and the weight scores assigned to the corresponding types are obtained;
[0021] Based on the weight score, a comprehensive score related to the number of times triggered in the time sequence of various triggering events and in the time sequence is obtained under the risk scene, the number of times triggered includes the number of times triggered in sequence according to the order of various triggering events or the number of times a single triggering event is triggered repeatedly, and the comprehensive score is the first risk score.
[0022] Further, the generating a risk ranking list according to the second risk score and displaying the risk ranking list in the form of a visual risk portrait comprises: generating a visual risk portrait of each user in the first cascade personal risk detail visual portrait when generating the visual risk portrait of the risk ranking list according to the second risk score, and the content of the visual risk portrait comprises: organizational structure information, a risk summary, a risk composition analysis, a self-data leakage risk, a key risk event list, a triggered risk scenario name, a data source, and a risk score contributed by a single event of the user; wherein the organizational structure information comprises a user name, a department, a position, and a post; the risk summary comprises a current total risk score, a risk ranking in the enterprise, and a recent risk trend graph; the risk composition analysis comprises a risk score source composition of the user in the form of a pie chart or a column chart; the self-data leakage risk comprises a permission abuse risk and a rule violation risk; and the key event list comprises all high-risk events triggered by the user in a time descending order, including an event time, a triggered risk scenario name, a data source, and a risk score contributed by a single event.
[0023] Further, the first cascade personal risk detail visual portrait of each user further comprises a deep investigation button window in the first cascade personal risk detail visual portrait page of each user, and a second cascade personal risk detail visual portrait can be cascaded through the window, and the content of the second cascade personal risk detail visual portrait comprises a behavior track and alarm details, wherein the behavior track comprises all operation logs of the user at a specific time, and the alarm details comprise alarm records generated by the risk behavior of the user and a processing state thereof.
[0024] Further, the outputting alarm information according to the alarm rule comprises outputting alarm notification including a notification mode, alarm assignment, alarm publishing time, and time limit time according to the alarm triggering condition, and displaying a processing result including a processing opinion, evidence uploading condition, and state tracking condition.
[0025] In a second aspect, an embodiment of the present application further provides a data leakage behavior control device, comprising:
[0026] An original data acquisition unit is configured to acquire user original behavior data from a VPN, a bastion host, a database, an office OA, a cloud platform, and a terminal, wherein the acquired user original data comprises abnormal behavior of a user in data acquisition through operation of a document, a screenshot, and a shooting video, and the abnormal behavior comprises sensitive data access, unauthorized operation, and abnormal time login;
[0027] A data preprocessing unit is configured to preprocess the acquired user original behavior data, including cleaning, parsing, enriching, and normalizing storage;
[0028] The violation risk judgment unit is configured to perform real-time risk rule matching on the obtained preprocessed data according to a preset risk rule through a machine learning algorithm, obtain a risk score according to the matching result, judge whether there is a violation risk according to the risk score, and generate a visual risk portrait according to the violation risk.
[0029] The alarm unit is configured to determine and output alarm information according to an alarm rule.
[0030] In a third aspect, the embodiment further provides a computer storage medium storing a plurality of instructions, which are suitable for being loaded and executed by a processor to perform the method steps.
[0031] In a fourth aspect, the embodiment further provides a computer device, including a processor and a memory, wherein the memory stores a computer program, which is suitable for being loaded and executed by the processor to perform the method steps.
[0032] The technical scheme provided by some embodiments of the present application has at least the following beneficial effects:
[0033] The user original behavior data is obtained from a VPN, a bastion host, a database, an office OA, a cloud platform and a terminal, wherein the obtained user original data includes abnormal behaviors of the user in obtaining data through operations on documents, screenshots and video shooting, and the abnormal behaviors include sensitive data access, unauthorized operation and abnormal time login; the obtained user original behavior data is preprocessed, including cleaning, parsing, enriching and normalized storage; real-time risk rule matching is performed on the preprocessed data according to a preset risk rule through a machine learning algorithm, a risk score is obtained according to the matching result, whether there is a violation risk is judged according to the risk score, a visual risk portrait is generated according to the violation risk, and alarm information is output according to an alarm rule, so that the precise prevention and control of data leakage risk is realized, the core value of the enterprise is protected, the brand reputation is maintained, and the customer's high trust is obtained. BRIEF DESCRIPTION OF DRAWINGS
[0034] In order to more clearly illustrate the technical schemes in the embodiments of the present application or the prior art, the drawings needed in the embodiment or prior art description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0035] Figure 1 is a method flowchart provided by the embodiment of the present application;
[0036] Figure 2 is a visual portrait of a first-level personal risk detail of a certain user provided by the embodiment of the present application;
[0037] Figure 3 is a structural schematic diagram of a data leakage behavior check and control device provided by an embodiment of the present application;
[0038] Figure 4 is a structural schematic diagram of a data leakage behavior check and control device provided by an embodiment of the present application;
[0039] Figure 5 is a schematic diagram of a computer storage medium provided by an embodiment of the present application. DETAILED DESCRIPTION
[0040] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some of the embodiments of the present application, but not all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.
[0041] The flowcharts shown in the drawings are only exemplary descriptions, and do not necessarily include all the contents and operations / steps, nor are they necessarily executed in the described order. For example, some operations / steps can be further decomposed, combined or partially merged, so the actual execution order can be changed according to the actual situation.
[0042] It should be understood that, in order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, the terms “first”, “second”, etc. are used to distinguish the same or similar items with basically the same functions and effects. Those of ordinary skill in the art can understand that the terms “first”, “second”, etc. do not limit the quantity and execution order, and the terms “first”, “second”, etc. also do not necessarily mean different.
[0043] It should be understood that the terms used in the present application specification are only for the purpose of describing specific embodiments and do not intend to limit the present application. As used in the present application specification and the appended claims, unless otherwise clear from the context, the singular forms “a”, “an” and “the” are intended to include the plural forms.
[0044] It should also be understood that the term “and / or” used in the present application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes these combinations.
[0045] In the digital economy era, the core assets of enterprises are increasingly data-based, and the internal operating environment is becoming increasingly complex. The security threats from internal personnel, such as unauthorized operations, data leakage, and malicious destruction, have become one of the weakest links in the enterprise security system due to their high privileges, high trustworthiness, and difficulty in prevention. The traditional security protection system mainly focuses on responding to external attacks and lacks effective perception, analysis, and response capabilities for internal threats, which has the pain points of "invisible, unclear, and uncontrollable". The present application aims to build an enterprise-level internal security intelligent hub and a comprehensive solution that integrates real-time stream computing, machine learning modeling, correlation graph analysis, and multi-modal content recognition. By integrating, standardizing, and intelligently analyzing user behavior logs scattered in various isolated systems, a full-dimensional behavior trajectory and risk portrait centered on "users" is constructed, realizing real-time early warning, active discovery, deep tracing, and efficient auditing of internal potential threats, thereby evolving the enterprise's security defense line from "passive response" to "active defense" and from post-investigation to intervention in the process and even prediction. The present application integrates real-time data collection, intelligent behavior analysis, accurate risk early warning, and visualized tracing and auditing, and can provide powerful technical weapons for internal control compliance departments, security operation centers (SOC), and IT administrators. It can accurately depict the digital behavior context of employees, quantify the security situation through a multi-dimensional risk weight model, and intelligently capture and alarm abnormal behaviors that deviate from the normal baseline. Ultimately, it breaks down data silos, correlates and integrates cross-system behavior data, improves threat discovery efficiency, changes "needle in a haystack" to "precise fishing", and solidifies the auditing process to provide a complete evidence chain and decision support throughout the pre-event, in-event, and post-event processes.
[0046] Referring to Figure 1 , Figure 1 is a schematic flowchart of a data leakage behavior control method provided by an embodiment of the present application. The data leakage behavior control method can be implemented by a computer device, which can be deployed on a single server or a server cluster. It can also be deployed on a handheld terminal, a notebook computer, a wearable device, or a robot, etc.
[0047] It should be noted that the acquisition of any information involved in the provided method is in compliance with relevant regulations and with the consent of the user, and does not infringe on the privacy of the user or violate relevant laws and regulations.
[0048] The present application adopts a micro-service architecture, which ensures high cohesion and low coupling of the system. Each core component, including data collection, stream processing, rule engine, and API service, can be independently developed, deployed, extended, and upgraded.
[0049] Specifically, as shown in Figure 1 , the data leakage behavior control method provided by the present embodiment can include the following steps:
[0050] S101, obtain user original behavior data from VPN, bastion host, database, office OA, cloud platform, terminal, wherein the obtained user original data includes abnormal behavior of the user obtaining data through operation of a document, screenshot, and shooting video, and the abnormal behavior includes sensitive data access, unauthorized operation, and abnormal time login.
[0051] The acquisition of the user original behavior is based on Apache Kafka, which is initially developed by the LinkedIn company and is a distributed, partitioned, multi-replica, multi-subscriber, and distributed log system (which can also be regarded as an MQ system) based on zookeeper coordination. It can be commonly used for web / nginx logs, access logs, and message services. The main application scenarios are a log collection system and a message system. Kafka has the feature of providing message persistence capability with a time complexity of O(1), which can guarantee constant-time access performance even for TB-level data. High throughput. Even on very cheap commercial machines, it can support single-machine transmission of 100K messages per second, support message partitioning between Kafka servers, and distributed consumption while guaranteeing the sequential transmission of messages within each partition. It also supports offline data processing and real-time data processing, and supports online horizontal expansion.
[0052] Kafka is adopted as a unified message queue and plays the role of a "log data bus". Various data sources (such as network devices, application systems, security products, terminals, etc.), specifically such as VPN, bastion host, database, office OA, cloud platform, mobile phone, etc., push log data in real time to the corresponding Topic of Kafka through Agent, Syslog, API, etc. Decoupling of data collection and processing is achieved. The data producer does not need to care about who the downstream consumer is, and changes or expansion of the data processing process will not affect the normal reporting of the data source, greatly improving the flexibility and robustness of the system. Through the acquisition of various types of original data on multiple platforms and terminals, the coverage of data leakage control is wider, and the analysis and control are more accurate.
[0053] In addition, by providing standardized APIs (such as RESTful), supporting general data protocols (such as Syslog, JDBC, Kafka), and developing lightweight collection agents, it can be connected with most existing business systems, network devices, and security products.
[0054] The data source access is changed from a "hard-coded" development mode to a "configured" management operation, so that the data processing has strong adaptive ability and flexibility. Meanwhile, by configuring the connection information, data structure definition and parsing rules of the data source through a management interface, most of the codes of the data acquisition and processing task can be automatically generated, so that the access cost and development cycle of a new data source are greatly reduced.
[0055] The obtained user original data includes abnormal behaviors of the user in acquiring data by operating documents, taking screenshots and shooting videos, and the abnormal behaviors include sensitive data access, unauthorized operation and abnormal time login. The implementation includes deep fusion of user behavior log analysis and multi-modal content deep insight. The non-structured data objects such as pictures and documents involved in the operation behaviors are automatically processed in real time. The OCR (Optical Character Recognition) technology is integrated to extract the text information in the pictures; the NLP (Natural Language Processing) technology is combined to identify sensitive information and analyze semantics of the text content. The embodiment solves the detection difficulty of sensitive information leakage by means of screenshot, screen shooting and other ways by obtaining the user original behavior data, realizes a qualitative leap from "behavior monitoring" to "behavior + content monitoring", and fills the key blind spot of content security audit.
[0056] S102, preprocessing the obtained user original behavior data, including cleaning, parsing, enriching and normalizing storage;
[0057] The processing of the data in this embodiment can be implemented based on a hybrid architecture of "Flink for Real-Time + Spark for Batch". Apache Flink is a framework and distributed processing engine for stateful computation over data streams. Apache Flink is designed to run in all common cluster environments to perform computations at memory speed and at any scale. Compared with other stream processing frameworks (such as Spark Streaming), Apache Flink has significant advantages in low latency, high throughput, Exactly-Once semantics, and powerful state management. Its EventTime and Processing Time models can perfectly cope with the scenario of log disorderly arrival, ensuring the accuracy of risk calculation. Its active community and rich ecosystem (such as Flink CDC) provide strong support for complex data source integration, with very low technical risk. Apache Spark is a fast and general-purpose computing engine designed for large-scale data processing. Apache Spark has three main features: first, the high-level API eliminates the concern for the cluster itself, and Apache Spark application developers can focus on the computation that the application needs to do. Second, Apache Spark is fast, supporting interactive computing and complex algorithms. Finally, Apache Spark is a general-purpose engine that can be used to perform a variety of operations, including SQL queries, text processing, machine learning, etc.
[0058] The pre-processing of the obtained user original behavior data in this embodiment includes cleaning, parsing, enriching, and normalizing storage, including consuming the original logs in Kafka based on Apache Flink, performing a series of stream ETL (Extract, Transform, Load) operations, including log parsing, field standardization, invalid data filtering, IP address reverse resolution, and information completion by associating user / asset metadata (from CMDB or HR system). The cleaned and standardized data is written back to a new Topic of Kafka for subsequent consumption.
[0059] In S103, the pre-processed data obtained is matched with real-time risk rules based on a machine learning algorithm according to preset risk rules, a risk score is obtained according to the matching condition, whether there is a violation risk is determined according to the risk score, and a visual risk portrait is generated according to the violation risk.
[0060] The embodiment meets the needs of real-time rule matching and second-level alarm by Apache Flink processing real-time stream data; Apache Spark performs batch processing on full historical data at regular intervals, which is used for machine learning model training, deep correlation analysis and periodic report generation and other complex computing tasks. Through the combination of the two, both low-latency real-time response and complex deep analysis capabilities are taken into account, realizing the optimal solution to different computing needs, higher resource utilization efficiency and more robust system architecture.
[0061] S104, outputting alarm information according to the violation risk situation.
[0062] The embodiment establishes a standardized workflow from alarm triggering to disposal ending. Alarm notification including notification method, alarm assignment, alarm release time, time limit and validity period is output according to the alarm triggering condition, and the processing result including processing opinion, evidence uploading situation and state tracking situation is displayed, forming an effective closed-loop risk alarm. The disposal result record can be used for subsequent audit and analysis. The notification method includes multiple ways such as email, short message and instant messaging tool.
[0063] In some implementable embodiments, the preprocessed data obtained is matched in real time according to the preset risk rules through a machine learning algorithm, a risk score is obtained according to the matching situation, it is judged whether there is a violation risk according to the risk score, and a visual risk portrait is generated according to the violation risk, including:
[0064] Obtaining each user triggering a risk scene and obtaining a first risk score configured according to the risk scene;
[0065] Based on the first risk score, a second risk score of the user attenuated over time according to the attenuation rule for the risk scene is obtained;
[0066] According to the second risk score, a risk ranking list sorted according to the second risk score is generated and displayed in the form of a visual risk portrait.
[0067] Through the preprocessed data of each user obtained, according to various consideration factors such as different weight scores given to events, score attenuation values over time, etc., a visual risk portrait of each user is formed. The time attenuation function and situational weight consideration factors abandon the traditional static and cumulative risk scoring mechanism, and a dynamic model closer to human risk cognition is constructed, which greatly reduces the "misjudgment" caused by historical old accounts or one-time misoperation, makes the risk score more accurately reflect the current real threat level, greatly improves the scientificity and accuracy of risk assessment, and displays in the form of a visual risk portrait.
[0068] The acquisition of each user triggers a risk scenario, and the acquisition of a first risk score configured according to the risk scenario includes:
[0069] The acquisition of the event type triggered under the risk scenario and the weight score assigned to the corresponding type;
[0070] Based on the weight score, the time sequence of various triggering events and the comprehensive score related to the number of times triggered according to the time sequence are obtained under the risk scenario, the number of times includes the number of times of repeated triggering according to the sequence of various triggering events or the number of times of repeated triggering of a single triggering event, and the comprehensive score is the first risk score; Different risk scenarios first consider the type of triggering event, and the severity level of different types of risk scenarios is different, and the score weight contributed by the triggering event is also different. For example, the weight of "core database batch export" is much higher than that of "non-working time login OA system". In addition, the risk scenario can not be triggered by a single event, but can be composed of multiple events in a specific event order, time sequence, and triggering times, and the corresponding first risk score is the comprehensive score under the scenario. For example: "the user logs in to the VPN in 5 minutes, then immediately accesses the core financial system, and attempts to query the sensitive data table". This risk scenario mainly includes two risk points, one is to log in to the VPN, and the other is to access the core financial system and query sensitive data, and the severity level of logging in to the VPN and accessing the core financial system is different (the type of triggering event is different), and the risk score is also different, for example, accessing the VPN is assigned a score of 10, accessing the core financial system is assigned a score of 20, and accessing both is assigned a score of 30. On this basis, if the VPN and the core financial system are accessed once within 1 hour, the scenario will have a basic risk score, for example, 30+10, the second triggering score is 30+25, and the third triggering score is 30+50. This score represents the first risk score, that is, the total score under the scenario, so the first risk score is a comprehensive risk evaluation score based on the scenario category or type (i.e. one or more accesses), the number of accesses, and other factors, and the score weight assigned according to each factor is different.
[0071] Different events in the scenario can come from completely different data sources. For example: one event comes from the VPN log (login success), and the next event comes from the database audit log (execute query), which realizes real correlation analysis.
[0072] This embodiment maintains a real-time updated comprehensive risk score for each user. The score is not simply added, but is a comprehensive score obtained according to the above assignment rules. All users will be sorted according to their risk scores to form a "risk ranking list".
[0073] Based on the first risk score, a second risk score of the user is obtained after attenuation according to the attenuation rule over time for the risk scenario; a "decay factor" is introduced, and the risk score of a historical event will automatically decay exponentially over time. Avoiding the user being "on the list" for a long time due to a one-time historical misoperation, making the risk assessment more scientific and fair.
[0074] According to the second risk score, a risk ranking list ranked according to the second risk score is generated and displayed in the form of a visual risk portrait, wherein the generation of the visual risk portrait is different from the traditional log list type audit method. In this embodiment, a dynamic, quantitative and visual risk profile is constructed for each user (including entities such as servers and application accounts) by aggregating multi-source data and applying a risk model. Abstract mass behavior data is converted into a risk situation that can be understood at a glance, enabling security analysts to quickly answer the three key questions: "Who has the highest risk now? Why? What did he do?" Thus, precise positioning and efficient response are achieved.
[0075] For example, the internal risk ranking list of an enterprise is displayed in a list and ranked from top to bottom according to the second risk score, and filtering according to time, scene, organization, etc. is supported. Through multi-condition and multi-event composite logic, false positives caused by single-point event alarms are greatly reduced, making each alarm more valuable for investigation.
[0076] In some embodiments, the generation of the risk ranking list ranked according to the second risk score and displayed in the form of a visual risk portrait further includes:
[0077] In some embodiments, the generation of the visual risk portrait of the risk ranking list ranked according to the second risk score further includes generating a first cascaded personal risk detail visualization portrait of each user, including organizational structure information, risk summary, risk composition analysis, self-data leakage risk, key risk event list, triggered risk scene name, data source, and risk score contributed by single event; wherein the organizational structure information includes user name, department, position, and post; the risk summary includes current total risk score, risk ranking in the enterprise, and recent risk change trend graph; the risk composition analysis includes the source composition of the risk score of the user in the form of a pie chart or a column chart; the self-data leakage risk includes permission abuse risk and violation operation risk, such as permission abuse risk accounting for 30% of the total risk, violation operation risk accounting for 20% of the total risk, and various risk proportions, so that the management analysis department can immediately and clearly identify the main risk type of the user; the key event list includes all high-risk events triggered by the user in reverse chronological order, including event time, triggered risk scene name, data source, and risk score contributed by single event. For example,Figure 2 As shown, the first cascading personal risk detail visualization image of a certain user shows the personal information such as on-duty situation, time of entry, job type, and the information such as time of risk occurrence, risk behavior, risk level, risk scene, risk score, and processing status.
[0078] In some embodiments, the cascading personal risk detail visualization image of each user further includes a deep investigation button window in the first cascading personal risk detail visualization image page of each user, through which a second cascading personal risk detail visualization image can be cascaded, and the content of the second cascading personal risk detail visualization image includes behavior track and alarm details, the behavior track includes all operation logs of the user at a specific time, and the alarm details include alarm records generated by the risk behavior of the user and the processing status thereof. For example, the alarm records include the previously set alarm rules, such as alarm notification including notification mode, alarm assignment, alarm publishing time, and time limit, and the processing status includes processing opinions, evidence uploading situation, and state tracking situation. For example, the filter conditions such as time and operation type can be added or changed through the alarm editing box on the second cascading personal risk detail visualization image page, facilitating advanced query. This embodiment realizes a standardized workflow from alarm triggering to disposal ending, ensures that each risk alarm can be effectively closed, and forms a complete disposal record for subsequent audit and analysis.
[0079] The risk evaluation method of this embodiment is a dynamic and quantifiable user risk evaluation method, which not only records single events, but also focuses on the sequence, context and correlation of events. Through the configured scoring rules such as different events being given different weights, scores being decayed over time, and multiple event combinations being given bonus points, a comprehensive risk value is calculated for each user, and a visual risk image is formed. Security personnel can see the high-risk personnel ranking list at a glance, and drill down to view the detailed risk composition, behavior track and associated events.
[0080] In summary, the method of the present application analyzes multi-modal data, first deeply fuses log behavior analysis and picture content recognition (OCR), constructs a dual detection dimension of "behavior + content", and solves the data leakage dead angle problem that cannot be touched by pure behavior analysis. At the same time, through the dynamic scoring algorithm with decay factor, the risk image can not only reflect the historical behavior, but also accurately depict the current risk situation, greatly improving the accuracy of risk assessment, and changing the data access from "hard-coded" development mode to "configurable" management operation, giving the method strong evolution ability and flexibility. The data leakage control realizes online and closed-loop management, and truly transforms the analysis results into security actions.
[0081] The following is an embodiment of the device of the present application, which can be used to execute the method embodiments of the present application. For details not disclosed in the device embodiments of the present application, please refer to the method embodiments of the present application.
[0082] Please refer to Figure 3 which shows a data leakage behavior control device provided by an exemplary embodiment of the present application, comprising:
[0083] The original data acquisition unit 301 is configured to acquire user original behavior data from VPN, bastion host, database, office OA, cloud platform, and terminal, wherein the acquired user original behavior data includes abnormal behavior of the user in acquiring data through operation of documents, screenshot, and shooting video, and the abnormal behavior includes sensitive data access, unauthorized operation, and abnormal time login.
[0084] The data preprocessing unit 302 is configured to preprocess the acquired user original behavior data, including cleaning, parsing, enriching, and normalized storage.
[0085] The violation risk judgment unit 303 is configured to perform real-time risk rule matching on the acquired preprocessed data according to a preset risk rule through a machine learning algorithm, obtain a risk score according to the matching condition, judge whether there is a violation risk according to the risk score, and generate a visual risk portrait according to the violation risk.
[0086] The alarm unit 304 is configured to determine to output alarm information according to an alarm rule.
[0087] Based on the above data leakage behavior control method, as Figure 4 shown, the embodiment of the present application further provides a structural diagram of a data leakage behavior control device, which comprises a processor 41 and a memory 42 coupled with the processor 41. The memory 42 stores a computer program, and the computer program is executed by the processor 41, so that the processor 41 executes the data leakage behavior control method in the above embodiments.
[0088] For other details of the processor 41 in the above data leakage behavior control device for implementing the above technical solutions, please refer to the description of the data leakage behavior control method provided in the above embodiment of the present application, which will not be repeated here.
[0089] The processor 41 can also be referred to as a CPU (Central Processing Unit), and can be an integrated circuit chip with processing capability. The processor 41 can also be a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array) or other programmable logic device, discrete gate or transistor logic device, discrete hardware component, or the like.
[0090] As shown in Figure 5 The present application also provides a structural diagram of a computer readable storage medium, which stores a readable computer program 51; the computer program 51 can be stored in the storage medium in the form of a software product, and includes a plurality of instructions for making a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor execute all or part of the steps of the method described in the various embodiments of the present application. The storage medium mentioned above includes a U disk, a mobile hard disk, a magnetic or optical disk, a ROM (Read-Only Memory), a RAM (Random Access Memory) and other storage media that can store program codes, or a computer, a server, a mobile phone, a tablet and other terminal devices.
[0091] In the several embodiments provided in the present application, it should be understood that the disclosed apparatus, device and method can be implemented in other ways. For example, the apparatus embodiments described above are only schematic. The division of the modules is only a logical function division. There can be another division manner in actual implementation. For example, a plurality of modules or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the modules shown or discussed can be indirect coupling or communication connection through some interface, device or module, and can be electrical, mechanical or other forms.
[0092] The modules described as separate components can or can not be physically separated, and the components shown as modules can or can not be physical modules, i.e. they can be located in one place or distributed on a plurality of network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the present embodiment.
[0093] In addition, each functional module in each embodiment of the present application can be integrated in one processing module, or each module can be physically present alone, or two or more modules can be integrated in one module. The integrated module can be realized in the form of hardware or in the form of a software functional module. When the integrated module is realized in the form of a software functional module and sold or used as an independent product, it can be stored in a computer-readable storage medium.
[0094] In the above embodiments, all or part can be realized by software, hardware, firmware, or any combination thereof. When realized by software, all or part can be realized in the form of a computer program product.
[0095] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another, for example, the computer instructions can be transferred from one website, computer, server or data center to another website, computer, server or data center through a wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that a computer can store or a data storage device such as a server, data center, etc. integrated with one or more available media. The available media can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk (SSD)), etc.
[0096] The above describes the technical solutions provided by the present application in detail. The principles and implementation manners of the present application are described by using specific examples. The above examples are only used to help understand the method and core idea of the present application; at the same time, for those skilled in the art, according to the idea of the present application, the specific implementation manner and application range can be changed; in view of the above, the content of the specification should not be understood as a limitation of the present application.
[0097] Those skilled in the art will appreciate that embodiments of the present application can be devised for a method, a system, or a computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product on one or more computer readable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) embodying computer readable program code.
[0098] The present application is described in reference to the flow diagrams and / or block diagrams of methods, apparatuses, and computer program products according to this application. It will be understood that each block of the flow diagrams and / or block diagrams, and combinations of blocks in the flow diagrams and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flow diagrams and / or block diagrams block or blocks. Figure 1 one or more functions specified in the flow diagram and / or block diagram block or blocks. Figure 1 one or more functions specified in the flow diagram and / or block diagram block or blocks.
[0099] These computer program instructions can also be stored in a computer readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer readable memory produce an article of manufacture including instructions which implement the flow diagrams and / or block diagrams block or blocks. Figure 1 one or more functions specified in the flow diagram and / or block diagram block or blocks. Figure 1 one or more functions specified in the flow diagram and / or block diagram block or blocks.
[0100] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the flow diagrams and / or block diagrams block or blocks. Figure 1 one or more functions specified in the flow diagram and / or block diagram block or blocks. Figure 1 one or more functions specified in the flow diagram and / or block diagram block or blocks.
[0101] Obviously, numerous modifications and variations of the present application are possible in light of the above teachings. It is therefore to be understood that within the scope of the apparent to those skilled in the art that various modifications and changes can be made thereto without departing from the scope and spirit of the present application. It is intended that the scope of the present application be limited only by the appended claims, and their equivalents.
Claims
1. A method for investigating and controlling data leakage behavior, characterized in that: This includes obtaining raw user behavior data from VPNs, bastion hosts, databases, office automation systems, cloud platforms, and terminals. The raw user data obtained includes abnormal behaviors of users obtaining data by operating documents, taking screenshots, or recording videos. These abnormal behaviors include access to sensitive data, unauthorized operations, and login at abnormal times. Preprocessing of acquired raw user behavior data includes cleaning, parsing, enriching, and normalizing storage; According to preset risk rules, a machine learning algorithm is used to perform real-time risk rule matching on the preprocessed data. A risk score is obtained based on the matching results. The risk score is used to determine whether a violation risk exists. A visual risk profile is generated based on the violation risk. The process of performing real-time risk rule matching on the preprocessed data using a machine learning algorithm according to preset risk rules, obtaining a risk score based on the matching results, determining whether a violation risk exists based on the risk score, and generating a visual risk profile based on the violation risk includes: Obtain the risk scenario triggered by each user, and obtain the first risk score configured according to that risk scenario; Based on the first risk score, obtain the second risk score for the user after it has decayed over time according to the decay rule for this risk scenario; Based on the second risk score, a risk ranking list is generated and sorted according to the second risk score, and displayed in the form of a visual risk profile; The step of obtaining each user's triggered risk scenario and obtaining the first risk score configured according to that risk scenario includes: Obtain the types of events triggered in this risk scenario and the corresponding weight scores assigned to each type; Based on the weighted scores, a comprehensive score related to the number of times various triggering events occur in the risk scenario is obtained according to the time sequence of occurrence of various triggering events or the number of times a single triggering event is triggered. The comprehensive score is the first risk score. Output alarm information according to the alarm rules.
2. The data leakage behavior investigation and control method according to claim 1, characterized in that: The preprocessing of the acquired raw user behavior data includes cleaning, parsing, enriching and normalizing the storage. It also includes cleaning, parsing, enriching and normalizing the acquired raw user behavior data by means of log parsing, field standardization, invalid data filtering, reverse IP address resolution and information completion by associating user and asset metadata.
3. The data leakage behavior investigation and control method according to claim 1, characterized in that: The process of generating a risk ranking list based on the second risk score and displaying it in the form of a visual risk profile includes: When generating a visual risk profile of a risk ranking sorted by the second risk score, a first-level personal risk details visual profile is also generated, displaying each user's organizational structure information, risk summary, risk composition analysis, self-data breach risk, list of key risk events, names of triggered risk scenarios, data sources, and risk scores contributed by each event. The organizational structure information includes the user's name, department, position, and job title. The risk summary displays the current total risk score, risk ranking within the company, and a recent risk trend chart. The risk composition analysis shows the source composition of the user's risk score in pie chart or bar chart format. The self-data breach risk includes risks of privilege abuse and unauthorized operations. The list of key risk events includes all high-risk events triggered by the user, listed in reverse chronological order, including event time, names of triggered risk scenarios, data sources, and risk scores contributed by each event.
4. The data leakage behavior investigation and control method according to claim 3, characterized in that: The first-level personal risk details visualization profile for each user also includes a deep investigation button window on the first-level personal risk details visualization profile page for each user. Through this window, a second-level personal risk details visualization profile can be cascaded. The content of the second-level personal risk details visualization profile includes displaying behavioral trajectory and alarm details. The behavioral trajectory includes all operation logs of the user at a specific time. The alarm details include alarm records generated by the user's risky behavior and their processing status.
5. The data leakage behavior investigation and control method according to claim 1, characterized in that: The alarm information is output according to the alarm rules, including outputting alarm notifications based on alarm triggering conditions, including notification method, alarm assignment, alarm release time, and time limit, and displaying processing results including processing opinions, evidence upload status, and status tracking status.
6. A data leakage behavior detection and control device, characterized in that, include: The raw data acquisition unit is used to acquire raw user behavior data from VPN, bastion host, database, office OA, cloud platform, and terminal. The acquired raw user data includes abnormal behaviors of users acquiring data by operating documents, taking screenshots, and shooting videos. The abnormal behaviors include access to sensitive data, unauthorized operations, and login at abnormal times. The data preprocessing unit is used to preprocess the acquired raw user behavior data, including cleaning, parsing, enriching and normalizing the data before storage. The violation risk assessment unit is used to perform real-time risk rule matching on the preprocessed data acquired according to preset risk rules using a machine learning algorithm, obtain a risk score based on the matching results, determine whether a violation risk exists based on the risk score, and generate a visual risk profile based on the violation risk. The step of performing real-time risk rule matching on the preprocessed data acquired according to preset risk rules using a machine learning algorithm, obtaining a risk score based on the matching results, determining whether a violation risk exists based on the risk score, and generating a visual risk profile based on the violation risk includes: Obtain the risk scenario triggered by each user, and obtain the first risk score configured according to that risk scenario; Based on the first risk score, obtain the second risk score for the user after it has decayed over time according to the decay rule for this risk scenario; Based on the second risk score, a risk ranking list is generated and sorted according to the second risk score, and displayed in the form of a visual risk profile; The step of obtaining each user's triggered risk scenario and obtaining the first risk score configured according to that risk scenario specifically includes: Obtain the types of events triggered in this risk scenario and the corresponding weight scores assigned to each type; Based on the weighted scores, a comprehensive score related to the number of times various triggering events occur in the risk scenario is obtained according to the time sequence of occurrence of various triggering events or the number of times a single triggering event is triggered. The comprehensive score is the first risk score. The alarm unit determines the alarm information to output based on the alarm rules.
7. A computer device, characterized in that, include: A processor and a memory; wherein the memory stores a computer program adapted to be loaded by the processor and to execute the steps of the method as described in any one of claims 1 to 5.
8. A computer storage medium, characterized in that, The computer storage medium stores a plurality of instructions, which are adapted to be loaded by a processor and executed by the steps of the method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Method for implementing scalper risk control of internet medical care
CN107147621A
Effective network security event monitoring method and system based on big data model
CN119167358A