Dynamic data privacy protection evaluation method and system based on big data analysis
The dynamic data privacy protection assessment method based on big data analysis comprehensively considers multiple factors of information and dynamically allocates encryption methods, solving the problem of incomplete assessment in existing technologies and achieving more scientific information security protection and resource optimization.
Patent Information
- Application Number
- CN202511454970.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-13
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2045-10-13
AI Technical Summary
Existing information security protection methods fail to comprehensively consider multiple factors such as the type of information privacy, the correlation and deduction, the amount of information, the theft situation and the theft methods, resulting in incomplete and inaccurate assessment results, failing to provide a scientific basis for security decision-making, and not optimizing resource utilization.
A dynamic data privacy protection assessment method based on big data analysis is adopted to comprehensively assess the importance, danger, and harm of information theft by considering factors such as the type of privacy, amount of information, the theft situation, and the theft method, and to dynamically allocate encryption methods.
It has achieved more scientific and reasonable information security protection, optimized resource utilization, improved information security, provided more comprehensive encryption assessment indicators, and avoided resource waste.
Smart Images

Figure CN120930170B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of privacy protection, in particular to a dynamic data privacy protection evaluation method and system based on big data analysis. BACKGROUND
[0002] The traditional information security protection method often uses unified encryption means to protect all information to the same degree. This method has some shortcomings. On the one hand, for some less important and less dangerous information, using high-level encryption means will cause waste of resources. On the other hand, for some important and dangerous information, simple encryption means may not be able to provide sufficient security protection. In addition, the existing information security evaluation method often only focuses on one or several aspects of information, such as information importance, danger, etc., without considering multiple factors such as information privacy type, correlation derivation, information quantity, theft, theft means and harm caused by theft, which leads to an incomplete and inaccurate evaluation result, and cannot provide a scientific basis for information security decision-making.
[0003] Therefore, a more scientific and reasonable information security protection method is needed, which can dynamically evaluate and dynamically allocate encryption means according to the actual situation of information. The information theft harm evaluation and encryption means dynamic allocation method proposed in the present application comprehensively analyzes and evaluates multiple factors such as information privacy type, correlation derivation, information quantity, theft, theft means and harm caused by theft, realizes the dynamic allocation of encryption means, and can effectively improve the security of information while optimizing the use of resources. SUMMARY
[0004] In order to overcome the defects and shortcomings of the prior art, the present application provides a dynamic data privacy protection evaluation method and system based on big data analysis.
[0005] In order to achieve the above purpose, the present application adopts the following technical scheme:
[0006] In a first aspect, the present application provides a dynamic data privacy protection evaluation method based on big data analysis, comprising the following steps:
[0007] Step S1, obtaining the privacy type and information quantity of the information, and obtaining the theft of the corresponding information under the scene;
[0008] Step S2, analyzing the importance of information based on the privacy type, correlation derivation and information quantity of the information under the corresponding scene;
[0009] Step S3, evaluating the danger of the corresponding information by analyzing the theft of the corresponding information under the scene and the theft means under the scene;
[0010] Step S4, information theft harm assessment is performed by the information importance analysis result, the information risk assessment result and the harm situation caused by theft;
[0011] Step S5, dynamic allocation of encryption means is performed according to the information theft harm assessment results of different levels.
[0012] In an implementation manner of the present application, the step S1 includes the following specific contents: file information needing encryption is acquired, the file information is classified by information category through a natural language extraction terminal, information categories needing encryption in a set encryption category are extracted, including name, ID, transaction record, ID number and telephone number, etc., the set encryption category is acquired by setting the private information category needing encryption in a scene, and is stored in a corresponding storage module, meanwhile, the information amount of each information category needing encryption is acquired, the theft situation of the corresponding information is the attack times and attack means situation of each information category needing encryption in a corresponding scene in history, which is acquired through historical data, wherein the attack means situation is the theft path occurring in the scene in history.
[0013] In an implementation manner of the present application, the analysis of information importance in the step S2 includes the following specific steps:
[0014] S21, the data amount situation of various encryption information categories and the various data situations of encrypted file information are acquired, the probability of the content of each encryption information category appearing in the corresponding information category in historical encrypted files is acquired, and the Shannon entropy of the content of the corresponding encryption information category is calculated by substituting into an entropy calculation formula, wherein the Shannon entropy calculation formula is: wherein N is the number of the content of the encryption information category, p(xi) is the probability of the i-th content of the encryption information category appearing in the corresponding information category in the historical encrypted files, and log is a logarithmic function; this step can quantify the uncertainty of the content of the encryption information category, through the calculation of the Shannon entropy, the confusion degree and complexity of each encryption information category content can be clearly understood, the higher the entropy value, the more uncertain and more difficult to predict the content of the encryption information category, which means that it may contain more valuable information or be more vulnerable to attack;
[0015] S22, obtain the Shannon entropy of the content of each encryption information category, and combine the contents of any two or more encryption information categories, and calculate the Shannon entropy of the combined category content by substituting the combined category content into the entropy calculation formula, sum the Shannon entropy of the combined category content with one same encryption information category, divide by the sum of the Shannon entropy of all encryption information categories corresponding to the combined category content, to obtain the correlation anomaly value of the corresponding encryption information category, which reflects the possible privacy leakage after combination, some fields may leak privacy after combination with other fields although the entropy of the single field is low, the information importance of the corresponding encryption information category is obtained by the ratio of the Shannon entropy of the corresponding encryption information category to the set security Shannon entropy, the correlation importance of the corresponding encryption information category is obtained by dividing the set correlation anomaly threshold by the correlation anomaly value of the corresponding encryption information category, and the protection importance of the corresponding encryption information category is obtained by weighted sum of the information importance and the correlation importance of the corresponding encryption information category, this step not only considers the Shannon entropy of the content of a single encryption information category, but also deeply analyzes the Shannon entropy of the combined content of any two or more encryption information categories, through the calculation of the correlation anomaly value, those encryption information categories with low individual entropy but possible privacy leakage after combination with other fields can be identified, which is crucial for protecting the privacy and sensitive information of users, because in practical applications, attackers may obtain valuable private data by combining different information, at the same time, by calculating the information importance and the correlation importance and performing weighted sum to obtain the protection importance, the uncertainty of the information itself and the privacy risk brought by information combination can be considered comprehensively, providing a more comprehensive and accurate evaluation index for the protection of encrypted information, which can help enterprises and organizations better allocate resources and pay more attention to and protect the encryption information categories with higher protection importance;
[0016] S23, divide the information quantity of the corresponding encryption information category by the information quantity threshold to obtain the information quantity importance of the corresponding encryption information category, this process evaluates the encryption information category from the perspective of information quantity;
[0017] S24, sum the information quantity importance and the protection importance of the corresponding encryption information category to obtain the information importance of the corresponding encryption information category, this process comprehensively considers the uncertainty of the information, the privacy risk and the information quantity, etc., through this comprehensive evaluation, a more accurate and comprehensive encryption information category importance index can be obtained.
[0018] In an implementation manner of the present application, the evaluation of information risk in step S3 includes the following specific contents:
[0019] S31, obtain the attack times and attack means of each information type to be encrypted in the corresponding historical scene, obtain the danger degree of the corresponding attack means by dividing the average success rate of the historical attack means by the overall average attack success rate;
[0020] S32, obtain the type of attack means, obtain the complexity of the attack means by weighted summation of the number of standardized attack means and the change frequency of the standardized attack means, obtain the danger of the single attack means by adding the danger degree of the corresponding attack means and the complexity of the attack means, the more the types of attack means, the richer the strategies that the attacker may adopt;
[0021] S33, obtain the attack times and the danger of the single attack means in the set time period, obtain the information danger of the corresponding information type to be encrypted by summing the danger of the attack means in the set time period, which can comprehensively evaluate the security risk of a certain information type to be encrypted from a macro perspective, this evaluation method considers the frequency of attack and the danger of each attack, and can reflect the overall threat degree of the information type in a period of time, the attack times in the set time period reflect the frequency of attacks on the information type, and the danger of the single attack means reflects the harm caused by each attack, and by summing the danger of the attack means in the set time period, the overall security risk of the information type in the time period can be accurately measured.
[0022] In an implementation manner of the present application, the information stealing harm evaluation in the step S4 comprises the following specific contents:
[0023] S41, obtain the average loss of each information type to be encrypted after being stolen per unit data amount, which can be economic loss or other loss, obtain the loss influence value by the ratio of the average loss of the corresponding information type to be encrypted after being stolen to the loss threshold value, which can present the consequences of information being stolen in the form of specific numerical value, and the economic loss or other loss can be clearly measured, which helps the organization to clearly understand the severity of different information types after being stolen, and avoids the fuzzy cognition of loss, for example, for an enterprise, the theft of customer financial information may cause direct economic loss, and the theft of enterprise research and development data may affect future market competitiveness and innovation ability, by quantifying the average loss, different types of losses can be intuitively compared;
[0024] S42, the loss influence value corresponding to the information category needing to be encrypted, the information importance analysis result and the information risk assessment result are weighted and summed to obtain an information theft hazard assessment result, which can comprehensively consider the influence of multiple factors on information security, the loss influence value reflects the actual loss after the information is stolen, the information importance analysis result reflects the core position and value of the information in the organization, and the information risk assessment result considers the possibility and threat degree of the information being attacked, and the factors are integrated together through the weighted sum, so that the harm degree of the information theft can be more comprehensively and accurately evaluated.
[0025] In an implementation manner of the present application, the dynamic allocation of the encryption means in the step S5 comprises the following specific contents.
[0026] The information theft hazard assessment result is compared with a set information theft hazard assessment threshold to obtain a theft hazard assessment value, if the assessment value is less than 0.3, it is low risk, between 0.3 and 0.7, it is medium risk, and greater than 0.7, it is high risk.
[0027] In a second aspect, the present application further provides a dynamic data privacy protection evaluation system based on big data analysis, comprising:
[0028] A data acquisition module acquires the privacy category and the information amount of the information, and simultaneously acquires the theft situation of the corresponding information under the scene;
[0029] An information importance analysis module analyzes the information importance based on the privacy category, the correlation derivation and the information amount of the corresponding information under the scene;
[0030] An information risk assessment module assesses the risk of the corresponding information through the theft situation of the corresponding information under the scene and the analysis of the theft means under the scene;
[0031] A theft hazard assessment module assesses the information theft hazard through the information importance analysis result, the information risk assessment result and the hazard situation caused by the theft;
[0032] A dynamic allocation module dynamically allocates the encryption means according to the information theft hazard assessment result of different levels.
[0033] In a third aspect, the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores a computer program which can be called by the processor, and the processor executes a dynamic data privacy protection evaluation method based on big data analysis by calling the computer program stored in the memory.
[0034] In a fourth aspect, the present application provides a computer readable storage medium storing instructions, which, when executed on a computer, cause the computer to perform the method for dynamic data privacy protection evaluation based on big data analysis.
[0035] Compared with the prior art, the present application has the following advantages and beneficial effects:
[0036] Based on the analysis of information importance according to the privacy category, correlation derivation and information amount in the corresponding scene, the information danger is evaluated according to the information theft in the corresponding scene and the analysis of the theft means in the scene, the information theft harm is evaluated according to the information importance analysis result, the information danger evaluation result and the harm caused by the theft, and the encryption means is dynamically allocated according to the information theft harm evaluation result of different levels, so that the waste of resources can be avoided.
[0037] In the analysis of information importance, the uncertainty of information itself and the privacy risk caused by information combination can be comprehensively considered by analyzing the information importance and the correlation importance, so that more comprehensive and accurate evaluation indexes are provided for the protection of encrypted information. BRIEF DESCRIPTION OF DRAWINGS
[0038] Other features, objects and advantages of the present application will become more apparent from the following detailed description of non-limiting embodiments with reference to the attached drawings:
[0039] Figure 1 The figure is a schematic diagram of the overall process of the method embodiment 1 of the present application.
[0040] Figure 2 The figure is a schematic diagram of the content of the S2 step of the method embodiment 1 of the present application.
[0041] Figure 3 The figure is a schematic diagram of the S3 step of the method embodiment 1 of the present application.
[0042] Figure 4 The figure is a schematic diagram of the structure of the system embodiment 2 of the present application. DETAILED DESCRIPTION
[0043] In order to make the above-mentioned purposes, features and advantages of the present application more apparent and easy to understand, the specific embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0044] In the following description, many specific details are set forth in order to provide a thorough understanding of the present application, but the present application can also be implemented in other ways different from the description, and those skilled in the art can make similar generalizations without departing from the scope of the present application, therefore the present application is not limited to the specific embodiments disclosed below.
[0045] Second, the "one embodiment" or "an embodiment" referred to herein means a specific feature, structure, characteristic, or combination of features and characteristics described herein that can be included in at least one implementation of the present application. The various appearances of "in one embodiment" or "an embodiment" in the specification are not necessarily all referring to the same embodiment.
[0046] Embodiment 1
[0047] As shown in the figure, the embodiment provides a dynamic data privacy protection evaluation method based on big data analysis, which specifically includes the following steps: Figures 1 to 3
[0048] Step S1, acquire the privacy category and information amount of the information, and acquire the stealing situation of the corresponding information in the scene;
[0049] In this embodiment, step S1 includes the following specific contents: acquiring file information that needs to be encrypted, classifying the file information by a natural language extraction terminal, extracting the information category that needs to be encrypted in the set encryption category, including name, ID, transaction record, ID number, and phone number, etc., and setting the encryption category to obtain the privacy information category required to be encrypted in the scene by human setting. The specific steps of classifying the file information by the natural language extraction terminal are as follows: the terminal first parses images, PDF, and other unstructured files by OCR, or directly reads the text content in Word, Excel, and other structured documents to ensure complete extraction of the original information; then, the extracted text is denoised (such as removing random codes, special symbols), segmented (Chinese and English segmentation), filtered for stop words, and unified in coding format (such as UTF-8) to provide standardized input for subsequent analysis; finally, combining rules (regular expression matching ID, phone number, etc.) and deep learning models (such as BERT-NER), identifying the names, institutions, dates, amounts, and other entities in the text, and labeling their types, and storing them in the corresponding storage module, while acquiring the information amount of each information category that needs to be encrypted, and the stealing situation of the corresponding information is the number of attacks and the means of attack of each information category that needs to be encrypted in the historical corresponding scene, which is obtained through historical data. The means of attack is the stealing path (such as SQL injection, man-in-the-middle attack, etc.) that has occurred in the scene in the past;
[0050] Step S2, analyze the importance of information based on the privacy category, correlation derivation, and information amount of the information in the corresponding scene;
[0051] In this embodiment, the analysis of the importance of information in step S2 includes the following specific steps:
[0052] S21, acquire the data amount of various encryption information categories and the various data of encrypted file information, acquire the probability of the content of each encryption information category appearing in the corresponding information category in the historical encrypted file, and substitute into the entropy calculation formula to calculate the Shannon entropy of the content of the corresponding encryption information category, wherein the Shannon entropy calculation formula is: wherein N is the number of the content of the encryption information category, p(xi) is the probability of the i th content of the encryption information category appearing in the corresponding information category in the historical encrypted file, and log is a logarithmic function; this step can quantify the uncertainty of the content of the encryption information category, and through the calculation of the Shannon entropy, the confusion degree and the complexity of each encryption information category content can be clearly understood, the higher the entropy value, the more uncertain and more difficult to predict the content of the encryption information category, which means that it may contain more valuable information or be more vulnerable to attack, which helps to take different protection strategies for encryption information categories with different entropy values in the information protection process, and improves the pertinence and effectiveness of information protection; it should be noted that the Shannon entropy theory is an important concept in information theory, which measures the uncertainty of information based on the method of probability statistics, in the scene of encrypted information, the probability of each encryption information category content appearing in the historical encrypted file is different, these probabilities reflect the frequency of the appearance of the content, substituting these probabilities into the Shannon entropy calculation formula can accurately calculate the entropy value of the content of the encryption information category, this calculation method has a solid mathematical theoretical basis and can objectively reflect the essential characteristics of information;
[0053] S22, obtain the Shannon entropy of the content of each encryption information category, and combine the contents of any two or more encryption information categories, and calculate the Shannon entropy of the combined category content by substituting the combined category content into the entropy calculation formula. By obtaining the Shannon entropy of the content of each encryption information category, summing the Shannon entropy of the combined category content with one same encryption information category, and dividing by the sum of the Shannon entropy of all encryption information categories corresponding to the combined category content, the correlation anomaly value corresponding to the encryption information category is obtained. The correlation anomaly value reflects the possible privacy leakage after combination. Some fields have low individual entropy, but may leak privacy when combined with other fields (for example, individual entropy is low, but joint positioning of personal identity is possible). The information importance of the corresponding encryption information category is obtained by the ratio of the Shannon entropy of the corresponding encryption information category to the set security Shannon entropy. The correlation importance of the corresponding encryption information category is obtained by dividing the set correlation anomaly threshold by the correlation anomaly value of the corresponding encryption information category. The information importance and correlation importance of the corresponding encryption information category are weighted and summed to obtain the protection importance of the corresponding encryption information category. This step not only considers the Shannon entropy of the content of a single encryption information category, but also deeply analyzes the Shannon entropy of the combined content of any two or more encryption information categories. By calculating the correlation anomaly value, it can identify those encryption information categories with low individual entropy but may leak privacy when combined with other fields. This is crucial for protecting user privacy and sensitive information, because in practical applications, attackers may obtain valuable private data by combining different information. At the same time, by calculating the information importance and correlation importance and weighting and summing to obtain the protection importance, the uncertainty of the information itself and the privacy risk brought by information combination can be considered comprehensively, providing a more comprehensive and accurate evaluation index for the protection of encrypted information. This can help enterprises and organizations better allocate resources and pay more attention to and protect encryption information categories with high protection importance. In the field of information security, the privacy leakage of information not only depends on the characteristics of individual information, but also closely related to the correlation between information. Some information may not have high value alone, but when combined with other information, they may pose unexpected privacy leakage risks. Therefore, by calculating the Shannon entropy of the combined category content and the correlation anomaly value, potential privacy risks can be effectively discovered. The calculation of information importance and correlation importance is based on the quantitative evaluation of information uncertainty and privacy risk. By weighting and summing, the protection importance of the encryption information category can be more reasonably reflected.
[0054] It should be noted that the weight here needs to be determined according to the actual scene in the information itself uncertainty and information combination privacy risk of the importance degree. For example, if the enterprise pays more attention to the uncertainty of the information itself, the weight of the information importance degree can be set to 0.7, and the weight of the correlation importance degree is set to 0.3; on the contrary, if more worried about the privacy risk brought by information combination, the weight of the correlation importance degree can be set to 0.6, and the weight of the information importance degree is set to 0.4;
[0055] S23, divide the information amount corresponding to the encrypted information category by the information amount threshold to obtain the information amount importance degree corresponding to the encrypted information category; this process evaluates the encrypted information category from the perspective of information amount, and information amount is an important indicator of information value. By calculating the information amount importance degree, the relative importance of each encrypted information category in terms of information amount can be intuitively understood, which helps to sort and prioritize different encrypted information categories according to the size of information amount in the information protection process. The secure Shannon entropy is a pre-set standard value for measuring the security level of the content of the encrypted information category. The distribution of the Shannon entropy of the content of different encrypted information categories can be obtained by analyzing a large number of historical encrypted files, and a suitable quantile can be taken as the secure Shannon entropy, for example, the 20th quantile of the Shannon entropy of the content of all encrypted information categories is taken as the secure Shannon entropy. Assuming that after analysis, the secure Shannon entropy of a certain type of encrypted information is set to 2.5;
[0056] S24, sum the information amount importance degree and the protection importance degree corresponding to the encrypted information category to obtain the information importance of the encrypted information category. This process comprehensively considers the uncertainty, privacy risk and information amount of the information, and through this comprehensive evaluation, a more accurate and comprehensive encrypted information category importance index can be obtained, which helps enterprises and organizations to allocate resources more scientifically in the information protection process, and take more stringent protection measures for encrypted information categories with higher information importance,
[0057] Step S3, evaluate the information danger of the corresponding information by analyzing the stealing situation of the corresponding information under the scene and the stealing means under the scene;
[0058] In this embodiment, the evaluation of information danger in step S3 includes the following specific contents:
[0059] S31, obtain the attack times of each kind of information to be encrypted and the attack means in the corresponding historical scene, obtain the danger degree of the corresponding attack means by dividing the average success rate of historical attack means by the overall attack success rate average, which can give each attack means a specific quantitative index, which helps security personnel to intuitively understand the potential threat size of different attack means, so as to prevent the key attack means, for example, for the attack means with high danger degree, more resources can be invested for monitoring and defense, and the security of the information system is improved, the historical scene of the present application is within two months or recently, without considering the defense measure improvement and attack technology iteration, but not long-term history, in order to reflect the dynamic balance of current attack and defense;
[0060] S32, obtain the kind of attack means, obtain the complexity of attack means by weighted sum of the number of standardized attack means and the change frequency of standardized attack means, obtain the danger of single attack means by adding the danger degree of single attack means and the complexity of attack means, which comprehensively considers the diversity and variability of attack means, the more the kinds of attack means, the more the strategies the attacker may use; the higher the change frequency of attack means, the more difficult the defense, this comprehensive evaluation can more comprehensively reflect the complexity of attack means, wherein, the standardization process is to divide the corresponding parameter by the standard value of the corresponding parameter type, in step S32, the complexity of attack means is obtained by weighted sum of the number of standardized attack means and the change frequency of standardized attack means, the determination of the weight can be determined according to the influence degree of the kind and change frequency of attack means on the complexity of attack, if the kind of attack means is considered to have greater influence on the complexity, the weight of the number of kinds can be set to 0.6, and the weight of the change frequency is set to 0.4; on the contrary, if more attention is paid to the change frequency of attack means, the weight of change frequency can be set to 0.7, and the weight of the number of kinds is set to 0.3;
[0061] S33, obtain the number of attacks and the danger of single attack means in the set time period, sum the danger of attack means in the set time period to obtain the information danger corresponding to the information category needing encryption, which can comprehensively evaluate the security risk faced by a certain information category needing encryption from a macro perspective. This evaluation method considers the frequency of attacks and the danger of each attack, and can reflect the overall threat degree of the information category in a period of time. The number of attacks in the set time period reflects the frequency of attacks on the information category, and the danger of single attack means reflects the harm caused by each attack. By summing the danger of attack means in the set time period, the overall security risk faced by the information category in the time period can be accurately measured. The overall attack success rate average is a standard value for calculating the danger degree of corresponding attack means. A large amount of historical attack data can be collected to calculate the success rate of all attack means, and then the average value is obtained. For example, 1000 attack data are collected, and the overall attack success rate average is calculated as 30%. The standard value of the type and frequency of the attacked means: these two standard values are used in the standardization process. The average value or median of the corresponding parameter can be taken as the standard value according to the statistical result of the historical data. For example, it is found that the average value of the type of the attacked means is 5, so the standard value of the type can be set to 5. The median of the change frequency of the attacked means is 2 times per hour, so the standard value of the change frequency can be set to 2 times per hour.
[0062] Step S4, information theft harm assessment is performed by the information importance analysis result, the information danger assessment result and the harm caused by theft;
[0063] In this embodiment, the information theft harm assessment in step S4 includes the following specific contents:
[0064] S41, obtain the average loss of each information category needing encryption after being stolen per unit data amount, which can be economic loss or other loss. The loss influence value is obtained by the ratio of the average loss of the information category needing encryption after being stolen to the loss threshold value, which can present the consequences of information theft in the form of specific numerical value. Whether it is economic loss or other loss can be clearly measured, which helps the organization to clearly understand the severity of different information categories after being stolen, avoiding fuzzy cognition of loss. For example, for an enterprise, the theft of customer financial information may cause direct economic loss, while the theft of enterprise research and development data may affect future market competitiveness and innovation ability. By quantifying the average loss, these different types of loss can be intuitively compared;
[0065] S42, the loss impact value corresponding to the information category needing encryption, the information importance analysis result and the information risk assessment result are weighted and summed to obtain the information theft hazard assessment result, which can comprehensively consider the influence of multiple factors on information security. The loss impact value reflects the actual loss after the information is stolen. The information importance analysis result reflects the core position and value of the information in the organization. The information risk assessment result considers the possibility and threat degree of information attack. These factors are integrated together by weighted summation, which can more comprehensively and accurately evaluate the harm degree of information theft. In step S42, the loss impact value corresponding to the information category needing encryption, the information importance analysis result and the information risk assessment result are weighted and summed to obtain the information theft hazard assessment result. The determination of the weight needs to comprehensively consider the actual loss after the information is stolen, the core value of the information and the possibility and threat degree of attack. For example, if the enterprise considers that the actual loss after the information is stolen is the most important, the weight of the loss impact value can be set to 0.5, the weight of the information importance analysis result is set to 0.3, and the weight of the information risk assessment result is set to 0.2. The loss threshold is a standard value for calculating the loss impact value. It can be determined according to the bearing capacity and historical loss data of the enterprise. For example, the enterprise sets the loss threshold to 100,000 yuan according to its financial situation and risk bearing capacity;
[0066] Step S5, dynamic allocation of encryption means according to different levels of information theft hazard assessment results;
[0067] In this embodiment, the dynamic allocation of encryption means in step S5 includes the following specific contents:
[0068] The information theft hazard assessment result is compared with the set information theft hazard assessment threshold to obtain the theft hazard assessment value. If the assessment value is less than 0.3, it is low risk, between 0.3 and 0.7, it is medium risk, and greater than 0.7, it is high risk. The information theft hazard assessment result is compared with the set information theft hazard assessment threshold to obtain the theft hazard assessment value. The threshold can be determined according to the information security risk bearing capacity of the enterprise;
[0069] For low-risk information: basic security protection measures can be taken, such as regular backup, setting simple access rights, etc. Specifically: take basic security protection measures such as regular backup of forum data to prevent data loss; set simple access rights, only registered users can access the forum to avoid malicious attacks by external personnel;
[0070] For medium-risk information: security protection needs to be strengthened, such as using encryption technology, strengthening access control, and conducting regular security audits. Specifically, encrypted storage of training materials is used to prevent data from being stolen during transmission and storage; access control is strengthened, only authorized employees can access training materials; regular security audits are conducted to check for abnormal access behavior;
[0071] For high-risk information: the most stringent security measures should be taken, such as using advanced encryption algorithms, establishing a multi-layer protection system, and real-time monitoring and early warning. At the same time, an emergency plan should be developed to deal with possible information theft incidents. Specifically, high-level encryption algorithms are used to encrypt and store and transmit code to ensure its security; a multi-layer protection system is established, including firewalls and intrusion detection systems, to prevent external hacker attacks; real-time monitoring and early warning are conducted to promptly detect abnormal access behavior and attack signs; at the same time, an emergency plan is developed, which can quickly take measures such as freezing relevant accounts and notifying the police once the code is stolen;
[0072] It is noted in the present embodiment that the present embodiment has the following advantages: based on the analysis of the importance of information based on the privacy category, correlation derivation, and information quantity of the corresponding information in the scene, the risk of the corresponding information is evaluated based on the analysis of the theft of the corresponding information in the scene and the theft means in the scene, the harm of information theft is evaluated based on the analysis result of the importance of information, the evaluation result of the risk of information, and the harm of theft, and the dynamic allocation of encryption means is performed according to the information theft harm evaluation result of different levels. According to the dynamic allocation of encryption means according to the information theft harm evaluation result of different levels, resource waste can be avoided.
[0073] Embodiment 2
[0074] As shown in Figure 4 The present embodiment provides a dynamic data privacy protection evaluation system based on big data analysis, which is realized based on the dynamic data privacy protection evaluation method based on big data analysis of embodiment 1, comprising: a data acquisition module, which acquires the privacy category and information quantity of information, and simultaneously acquires the theft of corresponding information in the scene;
[0075] An information importance analysis module analyzes the importance of information based on the privacy category, correlation derivation, and information quantity of the corresponding information in the scene;
[0076] An information risk evaluation module evaluates the risk of the corresponding information based on the analysis of the theft of the corresponding information in the scene and the theft means in the scene;
[0077] The theft hazard assessment module assesses the information theft hazard by the information importance analysis result, the information danger assessment result and the hazard situation caused by the theft.
[0078] The dynamic allocation module dynamically allocates the encryption means according to the information theft hazard assessment results of different levels.
[0079] Embodiment 3
[0080] The electronic device of the embodiment of the present application comprises a processor and a memory, wherein the memory stores a computer program that can be called by the processor, and the processor executes the dynamic data privacy protection evaluation method based on big data analysis by calling the computer program stored in the memory. It should be noted that all computer programs of the dynamic data privacy protection evaluation method based on big data analysis are implemented using C language.
[0081] Embodiment 4
[0082] The embodiment provides a computer readable storage medium, which stores an erasable computer program.
[0083] When the computer program runs on the computer device, the computer device executes the dynamic data privacy protection evaluation method based on big data analysis.
[0084] The above embodiments can be realized by software, hardware, firmware or any combination thereof, in whole or in part. When realized by software, the above embodiments can be realized in the form of a computer program product in whole or in part. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the flow or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable devices. The computer instructions can be stored in a computer readable storage medium or transferred from one computer readable storage medium to another, for example, the computer instructions can be transferred from one website, computer, server or data center to another website, computer, server or data center through a wired network or / and a wireless network. The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center and the like containing one or more available medium sets. The available medium can be a magnetic medium (e.g. floppy disk, hard disk, magnetic tape), an optical medium (e.g. DVD) or a semiconductor medium. The semiconductor medium can be a solid state disk.
[0085] Those skilled in the art can clearly understand that the units and algorithm steps of each example described in combination with the embodiments disclosed in the present application can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software mode depends on the specific application of the technical solution and the design constraints. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0086] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.
[0087] In several embodiments provided by the present application, it should be understood that the disclosed system, device and method can be realized by other ways. For example, the device embodiments described above are only schematic, for example, the division of the units is only a kind of, actual implementation can have another division mode, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the coupling or direct coupling or communication connection between the displayed or discussed can be through some interface, indirect coupling or communication connection between devices or units, which can be electrical, mechanical or other forms.
[0088] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e. they can be located in one place or distributed on multiple network units. Part or all of the units can be selected to achieve the purpose of the embodiment according to actual needs.
[0089] In addition, the functional units in each embodiment of the present application can be integrated into a processing unit, or each unit can be physically present separately, or two or more units can be integrated into one unit.
[0090] In the description of the specification, the description of the terms "one embodiment", "example", "specific example" and the like means that the specific features, structures, materials or characteristics described in combination with the embodiment or example are included in at least one embodiment or example of the present application. In the specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0091] The above shows and describes the basic principles and main features of the present application and the advantages of the present application. Those skilled in the art should understand that the present application is not limited to the above embodiments, and the above embodiments and descriptions in the specification are only to illustrate the principles of the present application. Without departing from the spirit and scope of the present application, various changes and improvements can be made to the present application, and these changes and improvements all fall within the scope of the claimed present application. The scope of protection of the present application is defined by the appended claims and their equivalents.
Claims
1. A dynamic data privacy protection assessment method based on big data analysis, characterized in that, Includes the following steps: The privacy types and amount of information obtained, as well as the theft of corresponding information in the relevant scenarios; The importance of information is analyzed based on the privacy type, correlation, and information volume of the information in the corresponding scenario; The risk level of the information is assessed by analyzing the theft situation and the theft methods in the scenario. The harm assessment of information theft is conducted based on the results of information importance analysis, information risk assessment, and the harm caused by the theft. The encryption methods are dynamically allocated based on the risk assessment results of information theft at different levels; the analysis of the importance of the information includes the following specific steps: S21. Obtain the data volume of various types of encrypted information and the data of various encrypted file information. Obtain the probability of the content of each type of encrypted information appearing in the corresponding information type in the historical encrypted files. Substitute it into the entropy calculation formula to calculate the Shannon entropy of the content of the corresponding type of encrypted information. S22. Perform correlation analysis on the Shannon entropy of the content of the encrypted information type to obtain the correlation anomaly value of the corresponding encrypted information type. Obtain the information importance of the corresponding encrypted information type by the ratio of the Shannon entropy of the corresponding encrypted information type to the set security Shannon entropy. Obtain the correlation importance of the corresponding encrypted information type by dividing the set correlation anomaly threshold by the correlation anomaly value of the corresponding encrypted information type. Obtain the protection importance of the corresponding encrypted information type by weighted summing of the information importance and correlation importance. S23. Divide the information content of the corresponding encrypted information type by the information content threshold to obtain the information content importance of the corresponding encrypted information type. S24. Summing the information importance and protection importance of the corresponding encrypted information type yields the information importance of the corresponding encrypted information type. The assessment of the information's risk includes the following specific aspects: S31. Obtain the number of times each type of information that needs to be encrypted has been attacked and the methods of attack in the corresponding historical scenarios. Divide the average success rate of historical attack methods by the average success rate of the overall attack to obtain the degree of danger of the corresponding attack method. S32. Obtain the types of attack methods. The complexity of the attack method is obtained by weighted summing the number of types of attack methods after standardization and the frequency of change of the attack methods after standardization. The danger of a single attack method is obtained by adding the danger level of the attack method corresponding to a single attack to the complexity of the attack method. S33. Obtain the number of attacks within a set time period and the risk of each attack method; sum the risks of the attack methods within the set time period to obtain the information risk of the corresponding type of information that needs to be encrypted; The information theft hazard assessment includes the following specific contents: S41. Obtain the average loss after each type of information requiring encryption is stolen per unit data volume, and obtain the loss impact value by the ratio of the average loss after the corresponding type of information requiring encryption is stolen to the loss threshold. S42. Obtain the loss impact value, information importance analysis results and information risk assessment results of the corresponding information types that need to be encrypted, and then perform a weighted summation to obtain the information theft hazard assessment results.
2. The dynamic data privacy protection assessment method based on big data analysis according to claim 1, characterized in that, The association analysis includes the following specific contents: Obtain the Shannon entropy of the content of the encrypted information type. At the same time, combine the content of any two or more encrypted information types and substitute the content of these two or more encrypted information types into the entropy value calculation formula to calculate the Shannon entropy of the combined content. By obtaining the Shannon entropy of the content of the corresponding encrypted information type separately, summing the Shannon entropy of the combined content of one of the same encrypted information type and dividing it by the sum of the Shannon entropy of all encrypted information combination types of the corresponding combined content, the associated anomaly value of the corresponding encrypted information type is obtained.
3. The dynamic data privacy protection assessment method based on big data analysis according to claim 2, characterized in that, The dynamic allocation of the encryption method includes the following specific details: The information theft hazard assessment results are compared with the set information theft hazard assessment threshold to obtain the theft hazard assessment value. If the assessment value is less than 0.3, it is low risk; between 0.3 and 0.7, it is medium risk; and greater than 0.7, it is high risk. For low-risk information: Take basic security precautions; For medium-risk information: enhanced security measures are needed; For high-risk information: Take the strictest security measures.
4. The dynamic data privacy protection assessment method based on big data analysis according to claim 1, characterized in that, The information obtained includes the privacy type and amount of information, as well as the theft situation of the corresponding information in the scenario. This includes the following specific content: obtaining file information that needs to be encrypted, classifying the file information into information types through a natural language extraction terminal, extracting the information types that need to be encrypted from the set encryption types, and the theft situation of the corresponding information is the number of times each type of information that needs to be encrypted has been attacked and the means of attack in the historical corresponding scenario, which is obtained through historical data. The means of attack are the theft paths that have occurred in the scenario in the past.
5. A dynamic data privacy protection assessment system based on big data analysis, used to implement the dynamic data privacy protection assessment method based on big data analysis as described in any one of claims 1-4, characterized in that, in, The system includes: The data acquisition module acquires information on the privacy type and amount of information, and also acquires information on the theft of corresponding information in the given scenario. The information importance analysis module analyzes the importance of information based on the privacy type, correlation inference, and information volume of the information in the corresponding scenario. The information risk assessment module assesses the risk of corresponding information by analyzing the theft situation and the theft methods in a given scenario. The theft hazard assessment module assesses the hazard of information theft based on the results of information importance analysis, information risk assessment, and the resulting harm. The dynamic allocation module dynamically allocates encryption methods based on the information theft hazard assessment results at different levels.
6. An electronic device, comprising: A processor and a memory, wherein the memory stores a computer program that can be called by the processor; characterized in that the processor executes the dynamic data privacy protection assessment method based on big data analysis as described in any one of claims 1-4 by calling the computer program stored in the memory.
Citation Information
Patent Citations
Data security risk assessment method and system
CN116720194A
Privacy evaluation method and system
CN119026171A