Data sensitivity security grading evaluation method and device

By extracting sensitivity impact factors from access logs and using quantification rules to calculate data sensitivity levels, the inconsistency and lag in data sensitivity classification in existing technologies are resolved, enabling real-time dynamic updates and efficient calculation of data sensitivity classification.

CN120910889AActive Publication Date: 2025-11-07ZHONGZHENG EVALUATION (SHENYANG) TECHNOLOGY CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202511092059.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-05
Publication Date
2025-11-07
Estimated Expiration
2045-08-05

AI Technical Summary

Technical Problem

In existing technologies, data sensitivity classification relies on subjective human judgment and static models, resulting in inconsistent and delayed classification results that cannot respond promptly to changes in business scenarios and the external environment.

Method used

By extracting sensitivity factors from access logs and using quantitative rules to calculate data sensitivity levels, real-time dynamic classification is achieved, including quantitative assessment of access personnel, timing, source, and frequency, and a security classification report is generated.

Benefits of technology

It achieves quantifiable, reproducible, and real-time updates of data sensitivity grading, reduces subjective judgment bias, adapts to business changes, reduces computational and I/O overhead, and supports high-concurrency grading in large-scale data environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120910889A_ABST
    Figure CN120910889A_ABST
Patent Text Reader

Abstract

The invention provides a data sensitivity security grading evaluation method and device. The method comprises the steps that log content associated with sensitive influence factors is read from an access log of a data system at a time, and the sensitive influence factors at least comprise access personnel, access opportunity, access sources and access frequency; the log content is classified according to a preset influence item classification rule, corresponding influence item scores are given, and the influence item classification rule gives a unique and determined score interval for each influence item; calculating a sensitive value of each influence factor; calculating a data sensitive value of the accessed data; and comparing the data sensitive value with a uniquely determined numerical value interval in a preset sensitivity grading rule table, and marking a corresponding security grade for the accessed data. According to the method, the data sensitivity level is dynamically calculated and marked by using the real-time access log through the one-time loading quantification rule, and reproducible, automatic and real-time updating data sensitivity grading is realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of access control, encryption or marking based on data sensitivity grading, and in particular, relates to a data sensitivity security grading evaluation method and device. BACKGROUND

[0002] In the digital environment, data has become a key production factor, and its leakage or misuse can directly lead to exposure of personal privacy, damage to business interests of enterprises, and even risk to national security. In order to reduce the above risks, the industry generally adopts the "data sensitivity grading" mechanism, that is, different sensitivity levels are assigned to data according to its content and use scenario, and differential management, protection and utilization strategies are matched, so as to realize controllable privacy and security in the whole data flow process.

[0003] The current typical data sensitivity grading process includes three core links: first, a sensitivity grading model is established to set the sensitivity level of data and develop management strategies corresponding to the level; second, data is classified and marked according to data content and attributes, so as to facilitate subsequent grading and access control; and finally, differential access control and encryption measures are implemented for different sensitivity levels, for example, more stringent permission management and multi-layer encryption are adopted for high-sensitivity data, and relatively relaxed protection is adopted for low-sensitivity data.

[0004] However, the existing technology still has obvious deficiencies: first, the determination of the sensitivity level highly depends on manual or organizational subjective experience, and combined with the differences in laws and regulations and industry standards of different countries, it is difficult to form a unified and quantifiable grading standard; second, data sensitivity dynamically evolves with time, business scenarios and external environment, while the existing static model lacks a real-time updating mechanism and cannot timely reflect the changes in sensitivity, thereby causing lag in grading results and invalidation of protection strategies. SUMMARY

[0005] According to the above technical problems, a data sensitivity security grading evaluation method and device are provided. The present application dynamically calculates and marks the data sensitivity level by using real-time access logs through one-time loading of quantization rules, so as to realize reproducible, automated and real-time updated data sensitivity grading.

[0006] The technical means adopted by the present application are as follows: A data sensitivity security grading evaluation method, comprising: S1, reading the log content associated with the sensitivity influence factor from the access log of the data system at one time, the sensitivity influence factor at least including access personnel, access time, access source and access frequency; S2, classifying the log content according to preset influence item classification rules and assigning corresponding influence item scores, wherein each influence item is given a unique and determined score interval by the influence item classification rules; S3, calculating a sensitivity value of each influence factor; S4, calculating a data sensitivity value of the accessed data; S5, comparing the data sensitivity value with a unique and determined numerical interval in a preset sensitivity classification rule table, and marking a corresponding security classification for the accessed data.

[0007] Further, the sensitivity classification rule table, the influence item classification rules, the calculation formula of the sensitivity value of each influence factor, and the calculation formula of the data sensitivity value of the accessed data are stored in a sensitivity influence factor rule model database and read once before step S1.

[0008] Further, the sensitivity influence factors of the access personnel at least include identity level, permission level, and authorized access situation, and the score and weight value of each influence item are uniquely determined in the influence item classification rules.

[0009] Further, the sensitivity influence factors of the access time at least include major event guarantee period, normal working hours, and non-working hours, and the score and weight value of each influence item are uniquely determined in the influence item classification rules.

[0010] Further, in step S3, the calculation formula of the sensitivity value of each influence factor is as follows:

[0011] wherein, is the number of influence items with valid values, is the total number of influence items, is the influence item corresponding weight value, is the influence item score, is the influence full score value.

[0012] Further, in step S4, the calculation formula of the data sensitivity value of the accessed data is as follows:

[0013] wherein, is the sensitivity value of the sensitivity influence factor, is the influence item corresponding weight value.

[0014] Further, the calculation of the data sensitivity value is triggered at any time to realize dynamic and real-time classification of data sensitivity.

[0015] Further, after step S5, it further includes: S6, sorting the calculated data sensitivity values from high to low, and generating a data sensitivity analysis report containing the sensitivity scores and security classification.

[0016] The application also provides a data sensitivity security classification evaluation device, comprising: The acquisition module is configured to read access logs from a data system and read a sensitivity classification rule table, influence item classification rules, a calculation formula of a sensitivity value of each influence factor, and a calculation formula of a data sensitivity value of the accessed data from a sensitivity influence factor rule model database at one time. The processing module comprises an influence item calculation submodule, an influence factor calculation submodule, and a sensitivity value calculation submodule, wherein the influence item calculation submodule is configured to perform the step S2, the influence factor calculation submodule is configured to perform the step S3, and the sensitivity value calculation submodule is configured to perform the step S4. The generation module is configured to perform the step S5 and the step S6 to output a data security classification mark and a data sensitivity analysis report.

[0017] Further, the processing module triggers the calculation of the data sensitivity value in real time to realize dynamic and real-time classification of the data sensitivity.

[0018] Further, the acquisition module, the processing module, and the generation module are integrated in the same computing device.

[0019] Compared with the prior art, the application has the following advantages: 1. The data sensitivity security classification evaluation method provided by the application shields the deviation of the classification results caused by subjective judgments of different people and organizations and insufficient understanding of regulations, and replaces subjective judgments caused by manual or regulatory differences with quantifiable numerical calculations, thereby achieving consistency and reproducibility of the classification results.

[0020] 2. The data sensitivity security classification evaluation method provided by the application triggers sensitivity value recalculation at any time point, adjusts the classification strategy in real time according to changes in business scenarios, external events, or access patterns, and avoids the problem of lagging failure of traditional static models, 3. The data sensitivity security classification evaluation method provided by the application reads the rule library at one time, batch analyzes logs, and streamlines calculations, thereby significantly reducing I / O and calculation overhead and supporting high-concurrency classification requirements in a large-scale data environment.

[0021] 4. The data sensitivity security classification evaluation method provided by the application realizes full-link automation from log input to classification mark and analysis report output through the three hardware devices of the acquisition module, the processing module, and the generation module, and achieves the engineering effects of pluggability and easy deployment. BRIEF DESCRIPTION OF DRAWINGS

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings described below are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor.

[0023] Figure 1 The flow chart of the method of the present application.

[0024] Figure 2 The structure block diagram of the system of the present application.

[0025] Figure 3 The structure block diagram of the computer equipment of the present application. DETAILED DESCRIPTION

[0026] In order to make the technical personnel in the art better understand the present application, the following will combine the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present application.

[0027] It should be noted that the terms "include" and "have" and any variations thereof in the specification and claims of the present application and the above-mentioned drawings are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device containing a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0028] As shown in Figure 1 The present application provides a data sensitivity security grading evaluation method, which comprises: S1, reading the log content associated with the sensitivity impact factor from the access log of the data system at one time, the sensitivity impact factor at least including access personnel, access time, access source and access frequency; S2, classifying the log content according to the preset impact item classification rule and assigning the corresponding impact item score, the impact item classification rule giving a unique and determined score interval for each impact item; S3, calculating the sensitivity value of each impact factor; S4, calculating the data sensitivity value of the accessed data; S5, comparing the data sensitive value with the uniquely determined numerical interval in the preset sensitivity grading rule table, marking the corresponding security classification for the accessed data.

[0029] In implementation, as a preferred embodiment of the present application, the sensitivity grading rule table, the influence item classification rule, the calculation formula of the sensitive value of each influence factor, and the calculation formula of the data sensitive value of the accessed data are stored in a sensitivity influence factor rule model database and read once before step S1.

[0030] In implementation, as a preferred embodiment of the present application, the sensitivity influence factor of the access personnel at least includes an identity level, an authority level, and an authorized access situation, and the score and weight value of each influence item are uniquely determined in the influence item classification rule. In this embodiment, some content influence items are also included in the influence factor, such as the access personnel, after obtaining the content, the content needs to be processed according to the corresponding rule, and the related content is put into the corresponding influence item classification. For example, the identity level of the access personnel (divided according to the importance of the position), the authority level (divided according to the access authority of the personnel), and the authorized access situation (whether the access authority is obtained after approval).

[0031] In implementation, as a preferred embodiment of the present application, the sensitivity influence factor of the access time at least includes a major event guarantee period (such as a major event, a major international activity, etc.), a normal working time, and a non-working time, and the score and weight value of each influence item are uniquely determined in the influence item classification rule.

[0032] In implementation, as a preferred embodiment of the present application, in step S3, the calculation formula of the sensitive value of each influence factor is as follows:

[0033] wherein, is the number of influence items with a value that meets the condition, is the number of all influence items, is the weight value of the influence item, is the influence item score, is the influence full score value.

[0034] In this embodiment, for example, the identity level score of the access personnel is 4, the authority level score is 5, and the authorized access situation score is 1; the identity level score is 4, the authority level weight is 3, the authority level weight value is 5, and the authorized access situation weight value is 3. The full score value of each influence item is 5. Then, the access personnel influence factor sensitive value is:

[0035] The access time influence factor includes major event guarantee period, normal working time and non-working time. The score of the major event guarantee period can be set to 5, the score of the normal working time can be set to 1, and the score of the non-working time can be set to 2. The weight is set to 5, the authority level weight value is 1, and the authorized access condition weight value is 3. The full score of each influence item is 5. The access time influence factor sensitivity value is:

[0036] In the specific implementation, as a preferred embodiment of the present application, in step S4, the calculation formula of the data sensitivity value of the accessed data is as follows:

[0037] wherein, is the sensitivity value of the sensitivity influence factor, is the weight value corresponding to the influence item.

[0038] In the present embodiment, the influence factor scores of the access personnel, access time, access source and access frequency are 0.67, 0.71, 0.86 and 0.33 respectively, and the weights are 5, 3, 5 and 4 respectively. Therefore, the sensitivity value of the corresponding data is:

[0039] In the specific implementation, as a preferred embodiment of the present application, the calculation of the data sensitivity value is triggered at any time to realize the dynamic and real-time classification of data sensitivity.

[0040] In the specific implementation, as a preferred embodiment of the present application, after step S5, the following steps are further included: S6, sorting the calculated data sensitivity value from high to low, and generating a data sensitivity analysis report containing the sensitivity score and the security classification.

[0041] The present application also provides a data sensitivity security classification evaluation device, as shown in Figure 2 The device includes: An acquisition module is configured to read the access log from the data system and read the sensitivity classification rule table, the influence item classification rule, the calculation formula of the sensitivity value of each influence factor and the calculation formula of the data sensitivity value of the accessed data from the sensitivity influence factor rule model database at one time. The processing module includes an impact item calculation submodule, an impact factor calculation submodule, and a sensitivity value calculation submodule. The impact item calculation submodule is used to execute step S2 of the dynamic data sensitivity classification method based on access logs. The impact factor calculation submodule is used to execute step S3 of the dynamic data sensitivity classification method based on access logs. The sensitivity value calculation submodule is used to execute step S4 of the dynamic data sensitivity classification method based on access logs. The generation module is used to execute step S5 and step S6 of the data sensitivity dynamic classification method based on access logs, so as to output data security classification markers and data sensitivity analysis reports.

[0042] In a specific implementation, as a preferred embodiment of the present invention, the processing module triggers the calculation of data sensitivity values ​​in real time to achieve dynamic and real-time classification of data sensitivity.

[0043] In a preferred embodiment of the present invention, the acquisition module, processing module and generation module are integrated within the same computing device.

[0044] A computer device, such as Figure 3 As shown, it includes: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the data sensitivity security classification assessment method described in any one of steps S1 to S6.

[0045] Example A typical example is as follows: Step 1: Read the Sensitivity Impact Factor Rule Model Database to obtain the impact factors and impact items.

[0046] Step 2: Based on the content of the influencing factors, read the data access logs of the existing data system and extract the log content associated with the influencing factors according to the configuration, and perform simple dry analysis. This includes sections such as visitor, visit timing, visit source, and visit frequency. Clearly, the content of these influencing factors can be directly extracted and analyzed from the data access logs to obtain the corresponding results.

[0047] Step 3: Read other auxiliary information from the data system, such as visitor identity, permission definition, access approval information, etc. Combine the impact factors and impact items read in step 1) to classify the log content (XX impact factor XX impact item) or calculate (XX data access frequency) and give the impact item score according to the impact item scoring rules.

[0048] In this embodiment, a typical data influence item scoring rule table is as follows:

[0049] Step 4, according to the aggregated information (impact item content in step 3, impact item weight in step 1), the data sensitivity value of the impact factor is calculated by using the formula in step S3.

[0050] Step 5, according to the aggregated information (impact factor sensitivity value in step 4, impact factor weight in step 1), the data sensitivity value of the accessed data is calculated by using the formula in step S4.

[0051] Step 6, the accessed data is marked with a security classification according to the definition of the sensitivity classification rule table, or a classification suggestion is given through information prompts (windows, messages, etc.).

[0052] In this embodiment, a typical data sensitivity classification rule table is as follows:

[0053] Step 7, optionally, the calculated sensitivity values of the specified accessed data are sorted from high to low, and a data sensitivity analysis report is generated.

[0054] In this embodiment, in order to speed up the running efficiency of the system, the sensitivity impact factor rule model data of step 1, step 4 and step 5 can be read at one time. The existing data system of step 2 and step 3 can be read at one time.

[0055] In the above embodiments of the present application, the description of each embodiment has its own emphasis, and the parts not described in detail in a certain embodiment can be referred to the related description of other embodiments.

[0056] In several embodiments provided in the present application, it should be understood that the disclosed technical content can be implemented by other ways. Among them, the device embodiments described above are only schematic, for example, the division of the units can be a logical function division, and actual implementation can have another division way, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed each other can be through some interface, indirect coupling or communication connection between units or modules, which can be electrical or other forms.

[0057] The units described as separate components can or can not be physically separated, and the components displayed as units can or can not be physical units, that is, they can be located in one place, or they can be distributed on multiple units. According to actual needs, part or all of the units can be selected to achieve the purpose of the embodiment scheme.

[0058] In addition, each function unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present separately, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software function unit.

[0059] When the integrated unit is realized in the form of a software function unit and sold or used as an independent product, it can be stored in a computer readable storage medium. Based on this understanding, the technical solutions of the present application or the entire or part of the technical solutions that essentially contribute to the prior art can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.

[0060] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of each embodiment of the present application.

Claims

1. A method for data sensitivity security classification assessment, the method comprising: receiving a data set; determining a data sensitivity classification of the data set; and outputting the data sensitivity classification of the data set. The method comprises the following steps: S1, reading log content associated with a sensitivity impact factor from an access log of a data system at one time, the sensitivity impact factor at least including an access personnel, an access time, an access source and an access frequency; S2, classifying the log content according to a preset impact item classification rule and assigning a corresponding impact item score, the impact item classification rule giving a unique and determined score interval for each impact item; S3, calculating a sensitivity value of each impact factor; S4, calculating a data sensitivity value of the accessed data; S5, comparing the data sensitivity value with a unique and determined numerical interval in a preset sensitivity classification rule table, and marking a corresponding security classification for the accessed data.

2. The method of claim 1, wherein, The sensitivity classification rule table, the impact item classification rule, the calculation formula of the sensitivity value of each impact factor and the calculation formula of the data sensitivity value of the accessed data are stored in a sensitivity impact factor rule model database and read at one time before step S1.

3. The method of claim 1, wherein, The sensitivity impact factor of the access personnel at least includes an identity level, a permission level and an authorized access situation, and the score and weight value of each impact item are uniquely determined in the impact item classification rule.

4. The method of claim 1, wherein, The sensitivity impact factor of the access time at least includes a major event guarantee period, a normal working time and a non-working time, and the score and weight value of each impact item are uniquely determined in the impact item classification rule.

5. The method of claim 1, wherein, In step S3, the calculation formula of the sensitivity value of each impact factor is as follows: wherein, is the number of impact terms having a qualifying value, is the number of all impact terms, is the corresponding weight value of the impact term, is the impact term score, is the impact full score.

6. The method of claim 1, wherein, In step S4, the calculation formula of the data sensitivity value of the accessed data is as follows: wherein, a sensitivity value for a sensitivity influencing factor, is a weight value corresponding to the influencing term.

7. The method of claim 6, wherein, The calculation of the data sensitivity value is triggered at any time to realize dynamic and real-time classification of data sensitivity.

8. The method of claim 1, wherein, After step S5, the following step is further included: S6, sorting the calculated data sensitivity value from high to low, and generating a data sensitivity analysis report containing a sensitivity score and a security classification.

9. A data sensitivity security classification assessment apparatus characterized by, The acquisition module, the processing module and the generation module are integrated in the same computing device, wherein: The acquisition module is used to read the access log from the data system at one time and read the sensitivity classification rule table, the impact item classification rule, the calculation formula of the sensitivity value of each impact factor and the calculation formula of the data sensitivity value of the accessed data from the sensitivity impact factor rule model database; The processing module comprises an impact item calculation submodule, an impact factor calculation submodule and a sensitivity value calculation submodule, the impact item calculation submodule is used to execute step S2 of claim 1, the impact factor calculation submodule is used to execute step S3 of claim 1, and the sensitivity value calculation submodule is used to execute step S4 of claim 1; the processing module triggers the calculation of the data sensitivity value in real time to realize dynamic and real-time classification of data sensitivity; The generation module is used to execute step S5 of claim 1 and step S6 of claim 8 to output the data security classification mark and the data sensitivity analysis report.

10. A computer device comprising: A memory, a processor and a computer program stored on the memory and executable on the processor, when the processor executes the program, the data sensitivity security classification evaluation method in any one of steps S1 to S6 is realized.

Citation Information

Patent Citations

  • Method and device for marking sensitive data, medium and program product

    CN115659396A

  • Enterprise sensitive data security access management method and system

    CN118656870A

  • Sensitive data security compliance processing system and method

    CN120316821A

  • Method, apparatus and computer-readable medium of providing security consulting for introducing a zero trust based security model

    KR102783920B1