Data leakage prevention method, device and equipment based on large model, medium and product
By using a content and behavior recognition intelligent agent based on a large model, data flow behavior is automatically analyzed, solving the problems of high false alarm rate and secondary leakage in existing technologies, and achieving accurate identification of data leakage behavior and improved security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING ZITIAO NETWORK TECH CO LTD
- Filing Date
- 2025-08-05
- Publication Date
- 2026-05-29
AI Technical Summary
Existing technologies for data leakage prevention suffer from high false alarm rates and the potential for secondary leaks due to human intervention, making it difficult to achieve accurate identification and effective protection.
By employing content recognition and behavior recognition intelligent agents based on large models, and generating content recognition and behavior recognition strategies, the flow behavior of target data is automatically analyzed to identify abnormal behaviors.
It enables accurate identification of data leakage behavior, avoids false alarms and secondary leakage, and improves data security.
Smart Images

Figure CN120934817B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of data security technology, specifically to data leakage prevention methods, devices, equipment, media, and products based on large models. Background Technology
[0002] Currently, data leakage prevention mainly relies on methods such as file source, file lineage tracking, and terminal channel management. However, these are all based on engine-created rule definitions, and the specified configurations are difficult to generalize, resulting in a large number of false alarms. If manual intervention is involved, it may even trigger secondary data leaks. Therefore, how to identify data leakage behavior urgently needs to be addressed. Summary of the Invention
[0003] In view of this, this disclosure provides a data leakage prevention method, apparatus, device, medium and product based on a large model to solve the problem of difficulty in identifying data leakage behavior.
[0004] In a first aspect, this disclosure provides a data leakage prevention method based on a large model, comprising: acquiring target data to be analyzed; generating a content recognition strategy corresponding to the target data in response to a first configuration operation for a content recognition agent; analyzing the flow behavior corresponding to the target data according to the content recognition strategy to determine the flow data corresponding to the target data; generating a behavior recognition strategy corresponding to the target data in response to a second configuration operation for a behavior recognition agent; and analyzing the flow data according to the behavior recognition strategy to identify abnormal behaviors that cause data leakage.
[0005] Secondly, this disclosure provides a data leakage prevention device based on a large model, comprising: a data acquisition module for acquiring target data to be analyzed; a content recognition configuration module for generating a content recognition strategy corresponding to the target data in response to a first configuration operation for a content recognition agent; a content analysis module for analyzing the flow behavior corresponding to the target data according to the content recognition strategy to determine the flow data corresponding to the target data; a behavior recognition configuration module for generating a behavior recognition strategy corresponding to the target data in response to a second configuration operation for a behavior recognition agent; and a behavior analysis module for analyzing the flow data according to the behavior recognition strategy to identify abnormal behaviors that cause data leakage.
[0006] Thirdly, this disclosure provides an electronic device, including: a memory and a processor, which are communicatively connected to each other. The memory stores computer instructions, and the processor executes the computer instructions to perform the data leakage prevention method based on a large model as described in the first aspect or any corresponding embodiment.
[0007] Fourthly, this disclosure provides a computer-readable storage medium storing computer instructions for causing a computer to execute the large-model-based data leakage prevention method described in the first aspect or any corresponding embodiment thereof.
[0008] Fifthly, this disclosure provides a computer program product, including computer instructions for causing a computer to execute the data leakage prevention method based on a large model as described in the first aspect or any corresponding embodiment thereof.
[0009] The data leakage prevention method, apparatus, device, medium, and product based on a large model provided in this disclosure configures a content recognition agent and a behavior recognition agent. The content recognition agent identifies the flow behavior of target data according to a configured content recognition strategy to determine the flow data of the target data. Subsequently, the behavior recognition agent analyzes the flow data according to a configured behavior recognition strategy to identify abnormal behaviors that could cause data leakage. Thus, by combining content recognition and behavior recognition dimensions for automated judgment of abnormal behavior, false alarms are avoided, and the accuracy of data leakage behavior identification is improved. Simultaneously, no human intervention is required, preventing secondary leakage and further enhancing data security. Attached Figure Description
[0010] To more clearly illustrate the technical solutions in the specific embodiments or related technologies of this disclosure, the accompanying drawings used in the description of the specific embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1 This is a diagram illustrating data leakage behavior identification based on relevant technologies;
[0012] Figure 2 This is a schematic diagram illustrating an application scenario according to an embodiment of this disclosure;
[0013] Figure 3 This is a flowchart illustrating a data leakage prevention method based on a large model according to an embodiment of the present disclosure;
[0014] Figure 4 This is a flowchart illustrating another data leakage prevention method based on a large model according to an embodiment of this disclosure;
[0015] Figure 5 This is a schematic diagram illustrating the configuration of a content recognition agent according to an embodiment of the present disclosure;
[0016] Figure 6This is a schematic diagram illustrating the correction of the recognition result of the content recognition agent according to an embodiment of this disclosure;
[0017] Figure 7 This is a flowchart illustrating another data leakage prevention method based on a large model according to an embodiment of the present disclosure;
[0018] Figure 8 This is a schematic diagram of the configuration of a behavior recognition intelligent agent according to an embodiment of the present disclosure;
[0019] Figure 9 This is a schematic diagram illustrating the correction of the reasoning results of the behavior recognition intelligent agent according to an embodiment of the present disclosure;
[0020] Figure 10 This is a schematic diagram illustrating the specific identification process of data leakage behavior according to embodiments of this disclosure;
[0021] Figure 11 This is a structural block diagram of a data leakage prevention device based on a large model according to an embodiment of the present disclosure;
[0022] Figure 12 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of the present disclosure. Detailed Implementation
[0023] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.
[0024] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.
[0025] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application, server, or storage medium performing the operations of this disclosed technical solution, based on the prompt message.
[0026] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0027] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.
[0028] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.
[0029] While there are corresponding data loss prevention (DLP) tools for preventing data leakage, DLP tools face challenges such as low accuracy in identifying sensitive data, low operational efficiency of log alerts (a large number of audit logs are generated every day, requiring efficient operational analysis to discover the real leakage risks), and secondary leakage (security personnel download and view the original files for manual analysis and confirmation, which may lead to secondary data leakage risks), making it difficult to truly implement data leakage prevention.
[0030] While some solutions exist, they primarily rely on methods such as file source tracking, file lineage tracing, and terminal channel management. These solutions are all based on engine-defined rules, specifically including whether the sent file is particularly sensitive, whether the recipient is a prohibited entity, and whether there are any anomalies in contextual behavior (including continuous outgoing transmission and file transfer). Because these configuration rules are difficult to generalize and generate numerous false alarms, manual intervention could potentially lead to secondary data leaks, such as... Figure 1 As shown, it is still difficult to achieve good data leakage prevention.
[0031] Based on this, this disclosure combines content recognition and behavior recognition to automatically determine abnormal behavior, avoiding false alarms and improving the accuracy of identifying data leakage. At the same time, it eliminates the need for human intervention, preventing secondary leaks and further enhancing data security.
[0032] As one optional application scenario of this disclosure embodiment, such as Figure 2As shown, this application scenario includes a content recognition agent 101, a behavior recognition agent 102, and a data monitoring platform 103. The content recognition agent 101 and the behavior recognition agent 102 can be agents trained based on a large language model. The content recognition agent 101 and the behavior recognition agent 102 are deployed in the data monitoring platform 103, which can be deployed on an electronic device 104.
[0033] Electronic device 104 can be a device with computing capabilities. For example, electronic device 104 may be equipped with a processor and memory, and may also be equipped with a dedicated accelerator (such as a graphics processing unit (GPU)). In addition, electronic device 104 can store and maintain data.
[0034] Examples of electronic device 104 may include supercomputers, personal computers, laptop computers, in-vehicle computing devices, mobile devices (such as smartphones, tablets, etc.), or combinations thereof. It should be understood that the electronic devices described herein are merely exemplary and not limiting; other different types of electronic devices may also be employed.
[0035] According to the embodiments of this disclosure, a data leakage prevention method based on a large model is provided. It should be noted that the steps shown in the flowcharts of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowcharts, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0036] This embodiment provides a data leakage prevention method based on a large model, which can be used in the aforementioned electronic devices, such as computers and servers. Figure 3 This is a flowchart of a data leakage prevention method based on a large model according to an embodiment of this disclosure, such as... Figure 3 As shown, the process includes the following steps:
[0037] Step S201: Obtain the target data to be analyzed.
[0038] The target data refers to the data for which data breach detection needs to be performed. The target data includes the original data files being transferred and the transfer logs for these original data files. The original data files can be unstructured data such as free text, contracts, and source code, as well as image data and context-aware data. The type of the original data files is not limited here.
[0039] Specifically, the data monitoring platform monitors the raw data files flowing through various business lines, collects the flow behavior of these raw data files, and generates corresponding flow logs. The flow of raw data files and their corresponding flow logs are then identified as target data for data leakage risk detection.
[0040] Step S202: In response to the first configuration operation for the content recognition agent, a content recognition strategy corresponding to the target data is generated.
[0041] The content recognition agent is used to identify the data content and flow behavior of target data. Specifically, the content recognition agent is deployed in the data monitoring platform and is equipped with corresponding activation controls and configuration interfaces. Specifically, the content recognition agent consists of a pre-trained content recognition model. This model can be trained based on a large language model architecture or a multimodal large language model architecture. The large language model architecture is not limited here, as long as it can achieve data content recognition.
[0042] The first configuration operation is the operation by which data monitoring personnel set the content recognition strategy through the configuration interface; the content recognition strategy is a rule used to identify the data content contained in the data file, such as the category and classification to which the data file belongs.
[0043] Specifically, when it is necessary to investigate data leaks targeting specific data, data monitoring personnel can enable the content recognition function of the content recognition agent and configure the content recognition strategy. Correspondingly, the data monitoring platform can respond to the configuration operation triggered by the data monitoring personnel and obtain the content recognition strategy corresponding to the target data.
[0044] Step S203: Analyze the flow behavior corresponding to the target data according to the content recognition strategy to determine the flow data corresponding to the target data.
[0045] Flow data is used to characterize the data information carried by the target data and the operational behaviors generated in response to the target data, such as sending the target data to external business lines or uploading the target data to cloud storage. Specifically, the data monitoring platform inputs the target data into a content recognition intelligent agent for data information recognition and flow behavior analysis. The content recognition intelligent agent can then extract the data information carried by the target data and the corresponding flow behavior according to the configured content recognition strategy.
[0046] Step S204: In response to the second configuration operation for the behavior recognition agent, a behavior recognition strategy corresponding to the target data is generated.
[0047] The behavior recognition agent is used to identify the flow of target data to determine whether there is a risk of data leakage. Specifically, the behavior recognition agent is deployed in a data monitoring platform and equipped with corresponding activation controls and configuration interfaces. This behavior recognition agent consists of a pre-trained behavior recognition model, which can be trained based on a large language model architecture or a multimodal model architecture. The large language model architecture is not limited here, as long as it can achieve risk identification of the flow behavior.
[0048] The second configuration operation is the operation by which data monitoring personnel set data leakage behavior identification strategies through the configuration interface; the behavior identification strategy is a rule used to identify whether there is a risk of data leakage during the flow of target data, such as the scope of analysis and the frequency of insight.
[0049] Specifically, when investigating data breaches targeting specific data, data monitoring personnel can activate the behavior recognition function of the behavioral recognition agent and configure the behavior recognition strategy. Correspondingly, the data monitoring platform can respond to the configuration operation triggered by the data monitoring personnel and obtain the behavior recognition strategy corresponding to the target data.
[0050] Step S205: Analyze the flow data according to the behavior recognition strategy to identify abnormal behaviors that could lead to data leakage.
[0051] Abnormal behavior indicates that the flow of target data may involve data leakage. Specifically, the data monitoring platform inputs the flow data corresponding to the target data into a behavior recognition intelligent agent for data leakage assessment. The behavior recognition intelligent agent can then perform data leakage inference on the flow data according to the configured behavior recognition strategy. Based on the data leakage inference results, it determines whether the flow behavior corresponding to the flow data has a risk of leakage. If the flow behavior has a risk of leakage, it is identified as abnormal behavior and marked for display so that data monitoring personnel can locate the abnormal behavior that may involve data leakage.
[0052] The data leakage prevention method based on a large model provided in this embodiment configures content recognition and behavior recognition agents. The content recognition agent identifies the flow behavior of target data according to the configured content recognition strategy to determine the flow data of the target data. Then, the behavior recognition agent analyzes the flow data according to the configured behavior recognition strategy to identify abnormal behaviors that could cause data leakage. Thus, by combining content recognition and behavior recognition dimensions for automated abnormal behavior determination, false alarms are avoided, and the accuracy of data leakage behavior identification is improved. At the same time, no human intervention is required, avoiding secondary leakage and further enhancing data security.
[0053] This embodiment provides a data leakage prevention method based on a large model, which can be used in the aforementioned electronic devices, such as computers and servers. Figure 4 This is a flowchart of a data leakage prevention method based on a large model according to an embodiment of this disclosure, such as... Figure 4 As shown, the process includes the following steps:
[0054] Step S301: Obtain the target data to be analyzed. For details, please refer to the relevant descriptions of the corresponding steps in the embodiments shown above; they will not be repeated here.
[0055] Step S302: In response to the first configuration operation for the content recognition agent, a content recognition strategy corresponding to the target data is generated.
[0056] Specifically, the content recognition strategy includes a data classification strategy and a target analysis scope. The data classification strategy indicates the data security level of the target data under its category; the target analysis scope is the scope of analysis of the target data, such as analyzing the data flow under business line A.
[0057] Accordingly, step S302 above includes:
[0058] Step S3021: In response to the activation operation for the content recognition agent, the content recognition configuration interface is displayed based on the activation operation. The content recognition configuration interface includes a hierarchical editing area and an analysis scope editing area.
[0059] Enabling the content recognition agent is an operation performed by data monitoring personnel to activate the content recognition agent. Specifically, such as... Figure 5 As shown, the data monitoring platform's interactive interface includes a data monitoring menu bar, which contains a content recognition menu item. Accessing the content recognition interface via this menu item leads to the content recognition interface, which contains a control 40 corresponding to the content recognition agent. This control 40 can respond to triggering operations by data monitoring personnel, displaying a content recognition agent activation control 41; correspondingly, the content recognition agent activation control 41 can respond to triggering operations by data monitoring personnel, displaying a content recognition configuration interface 42.
[0060] The content recognition configuration interface 42 includes a hierarchical editing area 421 and an analysis range editing area 422. The hierarchical editing area 421 is used to edit data hierarchical information, while the analysis range editing area is used to edit the data analysis range.
[0061] Step S3022: In response to the behavior hierarchical configuration operation triggered in the hierarchical editing area, determine the data hierarchical strategy corresponding to the target data.
[0062] The hierarchical editing area 421 includes a hierarchical selection control 423 and a custom control 424. The hierarchical selection control 423 is used to select a template for data classification and grading, while the custom control 424 is used to upload a custom data classification and grading template. The data classification and grading template is used to determine the category and grading of the target data according to its content; that is, by selecting the data classification and grading template, the corresponding data decomposition strategy is determined.
[0063] Specifically, the hierarchical selection control 423 in the hierarchical editing area 421 can respond to the click operation triggered by the data monitoring personnel, display the data classification and grading template set, and respond to the selection operation triggered by the data monitoring personnel to select the data classification and grading template for the target data from the data classification and grading template set, and determine the data grading strategy for the target data.
[0064] Of course, if a custom data classification and grading template is required, the data monitoring personnel can trigger the custom control 424 to upload the custom data classification and grading template. Accordingly, the custom control 424 can respond to the upload operation triggered by the data monitoring personnel to determine the custom data classification and grading template as the data classification and grading template for the target data, and determine the data grading strategy for the target data in combination with the custom data classification and grading template.
[0065] Step S3023: In response to the analysis range configuration operation triggered in the analysis range editing area, determine the target analysis range corresponding to the target data.
[0066] The analysis scope editing area 422 is equipped with a scope selection control 425, which is used to select the scope of data analysis, such as selecting a specific business line or a specific business person.
[0067] Specifically, the range selection control 425 in the analysis range editing area 422 can respond to click operations triggered by data monitoring personnel to display the business line architecture, which includes various business lines and the business personnel under each business line. Then, responding to business line (or business personnel) selection operations triggered by data monitoring personnel on the business line architecture, the target analysis range for the target data is determined.
[0068] In some alternative implementations, the method further includes: in response to an activation operation for the behavior screenshot, acquiring a screenshot of the behavior event that generated the target data.
[0069] Specifically, such as Figure 5As shown, the content recognition configuration interface 42 has a screenshot enable control 426 for behavior screenshots. This screenshot enable control 426 can respond to the trigger operation of the data monitoring personnel, take a screenshot of the flow behavior corresponding to the target data, and obtain the behavior event screenshot corresponding to the flow behavior.
[0070] By supporting behavioral screenshots, screenshots can be taken when data flows, generating corresponding behavioral screenshot events. This facilitates the determination of data leakage behavior through behavioral screenshot events, enhancing the credibility and traceability of data leakage behavior determination.
[0071] Step S303: Analyze the behavior that generates target data according to the content recognition strategy to determine the flow data corresponding to the target data.
[0072] Specifically, the data in circulation includes target data content, target data type, and target data security level. Target data content represents the theme and content overview that the target data is intended to represent; target data type includes general personal data, sensitive personal data, and business data; target data security level is the level of secrecy of the target data, with higher security levels indicating greater importance of the target data.
[0073] Accordingly, step S303 above includes:
[0074] Step S3031: Use a content recognition strategy to parse the content of the target data and determine the target data content corresponding to the target data.
[0075] As described above, the target data includes the original data file and the corresponding flow behavior of the original data file. When the data monitoring platform inputs the target data into the content recognition agent, the content recognition agent identifies the data content of the original data file in the target data under the content recognition strategy and generates a file summary for the original data file. The file summary includes the data topic and a data content overview. The content of the file summary is the target data content.
[0076] Step S3032: Analyze the data type of the target data using a content recognition strategy to determine the target data type.
[0077] The content recognition strategy includes a data classification strategy for data categorization and grading. Different types of data correspond to different data content. The content recognition agent identifies the data type of the original data file in the target data according to the data classification strategy, determining whether the original data file is business data, general personal data, or sensitive personal data.
[0078] Step S3033: Analyze the data level of the target data using a content recognition strategy to determine the target data security level.
[0079] After determining the target data type to which the original data file belongs, the content recognition agent infers the data level of the original data file according to the data classification strategy under the target data type to determine the target data security level under the target data type.
[0080] In some optional implementations, the data flow also includes the data flow direction and the data operation type. The data flow direction includes internal flow and external flow. Internal flow means that the target data is flowed between internal personnel, and external flow means that the target data is flowed to non-internal personnel. The data operation type includes human operation and program background operation. Human operation means that the flow of the target data is generated by human operation, and program background operation means that the flow of the target data is automatically triggered by the program background.
[0081] Accordingly, the above method also includes: identifying the data flow direction and data operation type corresponding to the screenshot of the behavioral event that generated the target data.
[0082] The screenshots of behavioral events record the operational information of business personnel when the target data is transferred. By analyzing the information in the screenshots of behavioral events, we can help determine the direction and type of data transfer corresponding to the data transfer behavior.
[0083] For example, if the behavior event screenshot shows that the business personnel are currently performing other operations when data file transfer occurs, it can be inferred that the data file transfer behavior is automatically triggered in the background of the program; if the behavior event screenshot shows that the business personnel triggered the sending of the data file when data file transfer occurs, and the sending is information communication between internal business personnel, it can be inferred that the data file transfer behavior is a manually triggered internal transfer; if the behavior event screenshot shows that the business personnel sent the data file to external personnel when data file transfer occurs, it can be inferred that the data file transfer behavior is a manually triggered external transfer.
[0084] By identifying screenshots of behavioral events, the corresponding data flow direction and data operation type can be determined. This allows for the simulation of the real data flow process based on the data flow direction and data operation type, thereby improving the accuracy of data flow behavior identification.
[0085] In some optional implementations, the method further includes: in response to a correction operation on the circulating data, correcting the circulating data based on the correction operation to obtain corrected circulating data, and generating a correction marker.
[0086] After the content recognition agent completes the flow analysis of the target data, the flow data obtained from the analysis can be displayed on the content recognition interface. Simultaneously, there are corresponding viewing controls 43 for the flow data, such as... Figure 6 As shown. This viewing control 43 can respond to the triggering operation of data monitoring personnel and display the inference details interface 431 for generating and circulating data.
[0087] If data monitoring personnel discover misjudgments in the data flow, they can correct the data. Specifically, for example... Figure 6 As shown, a correction control 432 is provided in the inference details interface 431. This correction control 432 can respond to correction operations triggered by data monitoring personnel, correct the flow data, obtain the corrected flow data, and display the corrected flow data in the content recognition interface. At the same time, corresponding correction marks can be displayed for the corrected flow data.
[0088] By supporting manual corrections and generating corresponding correction markers after correction, it is easy to compare the before and after corrections.
[0089] In some alternative implementations, the method further includes: generating first correction attribution information for the circulating data in response to an attribution editing operation for the correction operation.
[0090] After the data monitoring personnel triggers a correction operation on the circulating data, the attribution editing area 433 associated with the correction control 432 can be displayed. The attribution editing area 433 is used by the data monitoring personnel to edit the correction reason, and the first correction attribution information is the reason for correcting the circulating data.
[0091] Specifically, such as Figure 6 As shown, after the correction control 432 responds to the correction operation triggered by the data monitoring personnel, the attribution editing area 433 is displayed. This attribution editing area 433 can respond to the attribution editing operation of the data monitoring personnel and generate the first corrected attribution information corresponding to the correction operation. This first corrected attribution information can be synchronously displayed with the corrected flow data in the content recognition interface.
[0092] Meanwhile, after detecting the correction operation and correction attribution information, the content recognition agent will store the correction reason in the content recognition agent's knowledge base, so that the content recognition agent can automatically learn the correction attribution information corresponding to the correction operation, so that it can accurately identify similar flow behavior in the future. At the same time, the historical knowledge of previous feedback on similar behaviors can be displayed in the inference chain in the inference details interface 431, thereby further enhancing the analysis credibility of the content recognition agent.
[0093] Step S304: In response to the second configuration operation for the behavior recognition agent, a behavior recognition strategy corresponding to the target data is generated. For details, please refer to the relevant descriptions of the steps in the embodiments shown above, which will not be repeated here.
[0094] Step S305: Analyze the flowing data according to the behavior recognition strategy to identify abnormal behaviors that could lead to data leakage. For details, please refer to the relevant descriptions of the corresponding steps in the embodiments shown above; they will not be repeated here.
[0095] The data leakage prevention method based on a large model provided in this embodiment supports the configuration of data classification strategies and target analysis scope, enabling flexible configuration of content recognition according to actual application scenarios. This improves the generalization ability of the content recognition agent in different application scenarios and overcomes the problem that fixed rules are not conducive to generalization. By analyzing the target data content, target data type, and target data security level according to the content recognition strategy, a comprehensive analysis of the circulating data files is achieved, improving the accuracy of data information recognition in the circulating data files. This facilitates accurate identification of data leakage behavior in the future, avoids false judgments, and helps improve the accuracy of data leakage behavior identification.
[0096] This embodiment provides a data leakage prevention method based on a large model, which can be used in the aforementioned electronic devices, such as computers and tablets. Figure 7 This is a flowchart of a data leakage prevention method based on a large model according to an embodiment of this disclosure, such as... Figure 7 As shown, the process includes the following steps:
[0097] Step S401: Obtain the target data to be analyzed. For details, please refer to the relevant descriptions of the corresponding steps in the embodiments shown above, which will not be repeated here.
[0098] Step S402: In response to the first configuration operation for the content recognition agent, a content recognition strategy corresponding to the target data is generated. For details, please refer to the relevant descriptions of the corresponding steps in the embodiments shown above, which will not be repeated here.
[0099] Step S403: Analyze the behavior that generates the target data according to the content recognition strategy to determine the corresponding flow data. For details, please refer to the relevant descriptions of the steps in the embodiments shown above; they will not be repeated here.
[0100] Step S404: In response to the second configuration operation for the behavior recognition agent, a behavior recognition strategy corresponding to the target data is generated.
[0101] Specifically, the behavior recognition strategy includes target insight frequency and target insight scope. Target insight frequency refers to the frequency of performing data flow behavior insights, such as 6 hours, 12 hours, 1 day, 1 week, etc.; target insight scope is the scope of performing data flow behavior insights, such as analyzing the data flow behavior under business line A.
[0102] Accordingly, step S404 above includes:
[0103] Step S4041: In response to the activation operation for the behavior recognition agent, the behavior insight configuration interface is displayed based on the activation operation. The content recognition configuration interface includes an insight frequency editing area and an insight range editing area.
[0104] The activation of the behavior recognition intelligent agent is the operation performed by data monitoring personnel to activate the behavior recognition intelligent agent. Specifically, such as... Figure 5 As shown, the data monitoring platform's interactive interface includes a data monitoring menu bar, which contains a behavior recognition menu item. Triggering this menu item leads to the behavior recognition interface, which contains controls 60 corresponding to the behavior recognition intelligent agent. Figure 8 As shown, the control 60 can respond to the trigger operation of the data monitoring personnel and display the behavior recognition intelligent agent activation control 61; correspondingly, the behavior recognition intelligent agent activation control 61 can respond to the trigger operation of the data monitoring personnel and display the behavior recognition configuration interface 62.
[0105] The behavior recognition configuration interface 62 includes an insight frequency editing area 621 and an insight range editing area 622. The insight frequency editing area 621 is used to edit the insight frequency for executing data flow behavior, and the insight range editing area is used to edit the insight range for executing data flow behavior.
[0106] Step S4042: In response to the frequency configuration operation triggered in the insight frequency editing area, determine the target insight frequency corresponding to the target data.
[0107] An insight frequency control 623 is provided in the insight frequency editing area 621. This insight frequency control 623 is used to configure the insight frequency; the frequency configuration operation is the operation performed by data monitoring personnel to configure the insight frequency. Specifically, the insight frequency control 623 can respond to the frequency configuration operation triggered by the data monitoring personnel to configure information such as the insight frequency and time span of the target data, so as to obtain the target insight frequency, the time span of historical flow behavior, etc. corresponding to the target data.
[0108] Step S4043: In response to the range configuration operation triggered in the insight range editing area, determine the target insight range corresponding to the target data.
[0109] An insight scope control 624 is provided in the insight scope editing area 622. This insight scope control 624 is used to configure the insight scope; the scope configuration operation is the operation performed by data monitoring personnel to configure the insight scope. Specifically, the insight scope control 624 can respond to the scope configuration operation triggered by the data monitoring personnel to configure the insight scope for the target data, thereby obtaining the target insight scope corresponding to the target data.
[0110] In some optional implementations, the behavior recognition strategy may further include insight behavior type and data security level corresponding to insight behavior type, wherein insight behavior type is outbound flow behavior and data security level is data classification corresponding to outbound flow behavior.
[0111] Accordingly, the above method also includes: in response to a configuration operation for an insight behavior triggered in the insight scope editing area, determining the insight behavior type corresponding to the target data and the data security level corresponding to the insight behavior type.
[0112] An insight behavior configuration control 625 is provided in the insight scope editing area 622. This insight behavior configuration control 625 is used to configure the insight behavior type and the corresponding data classification. Specifically, the insight behavior configuration control 625 can respond to the configuration operation triggered by the data monitoring personnel to configure the flow behavior type and data security level of the target data, thereby obtaining the insight behavior type and the corresponding data security level of the target data.
[0113] By configuring the insight behavior type corresponding to the target data and the data security level corresponding to the insight behavior type, the behavior recognition model can accurately identify the data leakage risk of the flow behavior.
[0114] Step S405: Analyze the flow data according to the behavior recognition strategy to identify abnormal behaviors that could lead to data leakage.
[0115] Specifically, step S405 includes:
[0116] Step S4051: Use the behavior recognition strategy to reason about the flow data and generate the reasoning result corresponding to the flow data.
[0117] The data monitoring platform inputs the flowing data into the behavior recognition intelligent agent, which can then infer the data leakage behavior in the flowing data under the behavior recognition strategy to obtain the corresponding inference results.
[0118] Step S4052: If the reasoning result indicates that the circulating data has a leakage behavior, then in response to the operation of evaluating the circulating data item by item according to the first evaluation method, the first abnormal behavior is identified.
[0119] The first assessment method is a pre-defined approach to assessing data leakage behavior, such as a rapid, item-by-item assessment; the first abnormal behavior is behavior related to data leakage. Specifically, if the inference result indicates that there is leakage in the circulating data, then data monitoring personnel can perform a rapid, item-by-item assessment of each piece of data in the circulating data to identify abnormal behaviors related to data leakage.
[0120] Step S4053: If the reasoning result indicates that there is suspicious behavior in the flow data, then the flow data is evaluated item by item according to the second evaluation method to identify the second abnormal behavior.
[0121] The second assessment method is a pre-defined approach to assessing suspected data leakage behaviors, such as a detailed assessment of each data item. The second abnormal behavior is behavior related to data leakage. Specifically, if the reasoning result indicates that there is suspicious behavior in the flowing data, that is, it cannot be determined whether it is a data leakage behavior, then the data monitoring personnel can conduct a detailed assessment of each data item in the flowing data to identify abnormal behaviors related to data leakage.
[0122] Step S4054: If the reasoning result indicates that there is no leakage or suspicious behavior in the flow data, then in response to the operation of sampling and evaluating the flow data according to the third evaluation method, the third abnormal behavior is identified.
[0123] The third assessment method is a pre-defined method for assessing behaviors that pose no risk of data leakage, such as rapid sampling assessment. Here, "no risk of data leakage" means that there are no leakage behaviors or suspicious behaviors; the third abnormal behavior is behavior related to data leakage.
[0124] Specifically, if the reasoning result indicates that there is no leakage or suspicious behavior in the circulating data, that is, the behavior recognition agent determines that there is no risk of data leakage in the circulating data, then the data monitoring personnel can sample the circulating data to quickly evaluate the sampled data, identify any abnormal behaviors that may exist in the sampled data that are related to data leakage, and avoid misjudgment by the behavior recognition agent that could lead to data leakage.
[0125] In some optional implementations, the above method further includes:
[0126] Step a: Display the reasoning chain for the anomalous behavior.
[0127] Step b: In response to the inference result correction operation generated for the inference chain, the inference result is corrected based on the inference result correction operation.
[0128] Step c: In response to the attribution editing operation for the correction operation of the inference result, generate the second corrected attribution information corresponding to the inference result based on the attribution editing operation.
[0129] After the behavior recognition agent completes the data leakage behavior analysis of the flowing data, the inference results can be displayed on the behavior recognition interface. Simultaneously, there are corresponding result viewing controls 63 for the inference result data, such as... Figure 9 As shown. This result viewing control 63 can respond to triggering actions by data monitoring personnel and display the reasoning chain for abnormal behavior.
[0130] If data monitoring personnel discover errors in the inference chain, they can correct the inference results. Specifically, for example... Figure 9 As shown, a corresponding result correction control 631 is provided for the inference result. This result correction control 631 can respond to the inference result correction operation triggered by the data monitoring personnel and correct the inference result, such as correcting the existence of leakage behavior to no leakage behavior. For the corrected inference result, the corresponding correction mark can be displayed on the behavior recognition interface.
[0131] The second corrected attribution information is the reason for correcting the inference result. Specifically, after the result correction control 631 responds to the correction operation triggered by the data monitoring personnel, the corrected attribution editing area 632 is displayed. This corrected attribution editing area 632 can respond to the attribution editing operation of the data monitoring personnel and generate the second corrected attribution information corresponding to the inference result correction operation. This second corrected attribution information can be synchronously displayed with the corrected inference result in the behavior recognition interface.
[0132] By displaying the reasoning chain, the original evidence for generating the reasoning result is clearly identified, enhancing the credibility of the generated result. When the reasoning result is incorrect, manual correction of the result and editing of attribution information are supported, ensuring that the behavior recognition model can accurately identify similar flow behaviors in the future.
[0133] The data leakage prevention method based on a large model provided in this embodiment supports the configuration of insight frequency and insight scope, enabling flexible configuration of behavior recognition according to actual application scenarios. This improves the generalization ability of the behavior recognition agent in different application scenarios and overcomes the problem that fixed rules are not conducive to generalization. By reasoning about abnormal behaviors in the flowing data according to the behavior recognition strategy, corresponding inference results are obtained. Different inference results are evaluated using different methods, improving the accuracy of abnormal behavior identification and ensuring that behaviors causing data leakage are fully identified to the greatest extent possible, avoiding omissions and misjudgments.
[0134] As a specific application embodiment of this disclosure, such as Figure 10As shown, in the content recognition stage, the content recognition agent's classification and grading functions and screenshot function are enabled, and data classification and grading templates and analysis scope are configured. The classification and grading function is used to determine the file summary, data type (enterprise data, personal general data, personal sensitive data), and data grading of the transferred data files. The screenshot function is used to identify the transfer direction and operation type. Combining the classification and grading results with the screenshot recognition results, a transfer conclusion is generated. This conclusion can be displayed to the user for judgment. If correct, the conclusion is used for further determination of data leakage; if incorrect, it is corrected, and the revised conclusion is used for further determination of data leakage.
[0135] During the behavior identification phase, the data leakage risk insight function is enabled, and the insight frequency and scope are configured. Under the configured insight frequency and scope, the flow behavior data in the flow conclusions is analyzed to identify any abnormal behavior. When abnormal behavior is found, manual judgment can be introduced to determine the accuracy of the abnormal behavior assessment. Identified genuine abnormal behaviors are recorded as cases for subsequent processing.
[0136] This embodiment also provides a data leakage prevention device based on a large model, which is used to implement the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that performs a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0137] This embodiment provides a data leakage prevention device based on a large model, such as... Figure 11 As shown, it includes:
[0138] The data acquisition module 501 is used to acquire the target data to be analyzed.
[0139] The content recognition configuration module 502 is used to generate a content recognition strategy corresponding to the target data in response to a first configuration operation for the content recognition agent.
[0140] The content analysis module 503 is used to analyze the flow behavior corresponding to the target data according to the content recognition strategy, and determine the flow data corresponding to the target data.
[0141] The behavior recognition configuration module 504 is used to generate a behavior recognition strategy corresponding to the target data in response to a second configuration operation for the behavior recognition agent.
[0142] The behavior analysis module 505 is used to analyze the flow data according to the behavior recognition strategy and identify abnormal behaviors that could lead to data leakage.
[0143] In some optional implementations, the content recognition strategy includes a data classification strategy and a target analysis scope; accordingly, the content recognition configuration module 502 includes:
[0144] The content recognition activation unit is used to respond to the activation operation of the content recognition agent and display the content recognition configuration interface based on the activation operation. The content recognition configuration interface includes a hierarchical editing area and an analysis scope editing area.
[0145] The hierarchical configuration unit is used to determine the data hierarchical strategy corresponding to the target data in response to the behavior hierarchical configuration operation triggered in the hierarchical editing area.
[0146] The range configuration unit is used to determine the target analysis range corresponding to the target data in response to the analysis range configuration operation triggered in the analysis range editing area.
[0147] In some optional implementations, the content recognition configuration module 502 further includes:
[0148] The screenshot activation unit is used to respond to the activation operation for behavior screenshots and obtain screenshots of the behavior events that generate the target data.
[0149] In some optional implementations, the flowing data includes target data content, target data type, and target data security level. Accordingly, the content analysis module 503 includes:
[0150] The content parsing unit is used to parse the content of the target data using a content recognition strategy to determine the target data content corresponding to the target data.
[0151] The data type analysis unit is used to analyze the data type of the target data using content recognition strategies to determine the target data type.
[0152] The data grading analysis unit is used to analyze the data grading of target data using content recognition strategies to determine the target data security level.
[0153] In some optional implementations, the data flow also includes the data flow direction and data operation type; accordingly, the content analysis module 503 includes:
[0154] The data flow information identification unit is used to identify the data flow direction and data operation type corresponding to the screenshot of the behavior event that generated the target data.
[0155] In some alternative embodiments, the above-described apparatus further includes:
[0156] The first correction module is used to respond to the correction operation on the circulating data, correct the circulating data based on the correction operation, obtain the corrected circulating data, and generate a correction mark.
[0157] The first attribution module is used to generate first correction attribution information for the circulating data in response to the attribution editing operation for the correction operation.
[0158] In some optional implementations, the behavior recognition strategy includes target insight frequency and target insight range, and accordingly, the behavior recognition configuration module 504 includes:
[0159] The behavior recognition activation unit is used to respond to the activation operation of the behavior recognition intelligent agent and display the behavior insight configuration interface based on the activation operation. The content recognition configuration interface includes an insight frequency editing area and an insight range editing area.
[0160] The frequency configuration unit is used to determine the target insight frequency corresponding to the target data in response to a frequency configuration operation triggered in the insight frequency editing area.
[0161] The Insight Scope Configuration Unit is used to determine the target insight scope corresponding to the target data in response to the scope configuration operation triggered in the Insight Scope Editing Area.
[0162] In some optional implementations, the behavior recognition strategy further includes insight into behavior types and the corresponding data security levels. Accordingly, the behavior recognition configuration module 504 includes:
[0163] The Insight Behavior Configuration Unit is used to respond to configuration operations for insight behaviors triggered in the insight scope editing area, and to determine the insight behavior type corresponding to the target data and the data security level corresponding to the insight behavior type.
[0164] In some alternative implementations, the behavior analysis module 505 includes:
[0165] The reasoning unit is used to reason about the flowing data using behavior recognition strategies and generate reasoning results corresponding to the flowing data.
[0166] The first evaluation unit is used to identify the first abnormal behavior by evaluating each piece of the circulating data according to the first evaluation method if the reasoning result indicates that the circulating data has a leakage behavior.
[0167] The second evaluation unit is used to evaluate each piece of the flowing data according to the second evaluation method if the reasoning result indicates that there is suspicious behavior in the flowing data, and to identify the second abnormal behavior.
[0168] The third evaluation unit is used to identify the third abnormal behavior by sampling the data according to the third evaluation method if the reasoning result indicates that there is no leakage or suspicious behavior in the data.
[0169] In some alternative embodiments, the above-described apparatus further includes:
[0170] The display module is used to show the inference chain for abnormal behavior.
[0171] The second correction module is used to respond to the inference result correction operation generated for the inference chain and correct the inference result based on the inference result correction operation.
[0172] The second attribution module is used to respond to the attribution editing operation for the correction operation of the inference result, and generate the second corrected attribution information corresponding to the inference result based on the attribution editing operation.
[0173] The data leakage prevention device based on a large model provided in this disclosure can execute the data leakage prevention method based on a large model provided in any embodiment of this disclosure, and has the corresponding functional modules and beneficial effects of the execution method. By configuring a content recognition agent and a behavior recognition agent, the content recognition agent identifies the flow behavior of the target data according to the configured content recognition strategy to determine the flow data of the target data. Then, the behavior recognition agent analyzes the flow data according to the configured behavior recognition strategy to identify abnormal behaviors that could cause data leakage. Thus, by combining content recognition and behavior recognition dimensions for automated judgment of abnormal behaviors, false alarms are avoided, and the accuracy of data leakage behavior identification is improved. At the same time, no human intervention is required, avoiding secondary leakage and further enhancing data security.
[0174] Further functional descriptions of the above modules and units are the same as those in the corresponding embodiments described above, and will not be repeated here.
[0175] Figure 12 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure.
[0176] The following is a detailed reference. Figure 12This diagram illustrates a suitable structural schematic for implementing an electronic device according to embodiments of the present disclosure. The electronic device may include a processor (e.g., a central processing unit, graphics processor, etc.) 601, which can perform various appropriate actions and processes based on a program stored in read-only memory (ROM) 602 or a program loaded from memory 608 into random access memory (RAM) 603. The RAM 603 also stores various programs and data required for the operation of the electronic device. The processor 601, ROM 602, and RAM 603 are interconnected via a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0177] Typically, the following devices can be connected to I / O interface 605: input devices 606 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 607 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; memory devices 608 including, for example, magnetic tapes, hard disks, etc.; and communication devices 609. Communication device 609 allows electronic devices to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 12 Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown, and more or fewer devices may be implemented or have instead.
[0178] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 609, or installed from a memory 608, or installed from a ROM 602. When the computer program is executed by the processor 601, it performs the functions defined in the large-model-based data leakage prevention method of embodiments of this disclosure.
[0179] Figure 12 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.
[0180] This disclosure also provides a computer-readable storage medium in which the methods described in this disclosure can be implemented in hardware or firmware, or implemented as recordable on a storage medium, or implemented as computer code downloaded over a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and subsequently stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code. When the software or computer code is accessed and executed by the computer, processor, or hardware, the large-model-based data leakage prevention method shown in the above embodiments is implemented.
[0181] A portion of this disclosure can be applied to computer program products, such as computer program instructions, which, when executed by a computer, can invoke or provide methods and / or technical solutions according to this disclosure through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, and installation package files. Accordingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions; the computer compiling the instructions and then executing the corresponding compiled program; the computer reading and executing the instructions; or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.
[0182] Although embodiments of the present disclosure have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of the present disclosure, and such modifications and variations all fall within the scope defined by the appended claims.
Claims
1. A data leakage prevention method based on a large model, characterized in that, The method includes: Obtain the target data to be analyzed; In response to a first configuration operation for the content recognition agent, a content recognition strategy corresponding to the target data is generated; Analyzing the flow behavior corresponding to the target data according to the content recognition strategy to determine the flow data corresponding to the target data includes: parsing the content of the target data using the content recognition strategy to determine the target data content corresponding to the target data; analyzing the data type of the target data using the content recognition strategy to determine the target data type corresponding to the target data; and analyzing the data level of the target data using the content recognition strategy to determine the target data security level corresponding to the target data. The flow data includes the target data content, the target data type, and the target data security level. In response to a second configuration operation for the behavior recognition agent, a behavior recognition strategy corresponding to the target data is generated; Analyzing the circulating data according to the behavior recognition strategy to identify abnormal behaviors that could lead to data leakage includes: using the behavior recognition strategy to infer the circulating data and generating inference results corresponding to the circulating data; if the inference results indicate that the circulating data has leakage behavior, then in response to the operation of evaluating the circulating data item by item according to a first evaluation method, identifying a first abnormal behavior; if the inference results indicate that the circulating data has suspicious behavior, then in response to the operation of evaluating the circulating data item by item according to a second evaluation method, identifying a second abnormal behavior; if the inference results indicate that the circulating data does not have the leakage behavior or the suspicious behavior, then in response to the operation of sampling evaluation of the circulating data according to a third evaluation method, identifying a third abnormal behavior.
2. The method according to claim 1, characterized in that, The step of generating a content recognition strategy corresponding to the target data in response to a first configuration operation for the content recognition agent includes: In response to the activation operation of the content recognition agent, a content recognition configuration interface is displayed based on the activation operation. The content recognition configuration interface includes a hierarchical editing area and an analysis range editing area. In response to a behavior hierarchical configuration operation triggered in the hierarchical editing area, a data hierarchical strategy corresponding to the target data is determined; In response to an analysis range configuration operation triggered in the analysis range editing area, the target analysis range corresponding to the target data is determined; The content recognition strategy includes the data classification strategy and the target analysis scope.
3. The method according to claim 2, characterized in that, Also includes: In response to the activation operation for behavior screenshot, a screenshot of the behavior event that generated the target data is obtained.
4. The method according to claim 1, characterized in that, Also includes: Identify the data flow direction and data operation type corresponding to the screenshot of the behavior event that generated the target data; The data flow includes the data flow direction and the data operation type.
5. The method according to claim 1, characterized in that, Also includes: In response to the correction operation on the circulating data, the circulating data is corrected based on the correction operation to obtain the corrected circulating data, and a correction mark is generated; And / or, in response to the attribution editing operation for the correction operation, generate first corrected attribution information for the flow data.
6. The method according to claim 1, characterized in that, In response to a second configuration operation for the behavior recognition agent, a behavior recognition strategy corresponding to the target data is generated, including: In response to the activation operation of the behavior recognition agent, a behavior insight configuration interface is displayed based on the activation operation. The content recognition configuration interface includes an insight frequency editing area and an insight range editing area. In response to a frequency configuration operation triggered in the insight frequency editing area, the target insight frequency corresponding to the target data is determined; In response to a range configuration operation triggered in the insight range editing area, the target insight range corresponding to the target data is determined; The behavior recognition strategy includes the target insight frequency and the target insight range.
7. The method according to claim 6, characterized in that, Also includes: In response to a configuration operation for an insight behavior triggered in the insight scope editing area, the insight behavior type corresponding to the target data and the data security level corresponding to the insight behavior type are determined; The behavior recognition strategy includes the insight behavior type and the data security level corresponding to the insight behavior type.
8. The method according to claim 1, characterized in that, Also includes: Display the reasoning chain for the aforementioned abnormal behavior; In response to the inference result correction operation generated for the inference chain, the inference result is corrected based on the inference result correction operation; In response to the attribution editing operation for the correction operation of the inference result, a second corrected attribution information corresponding to the inference result is generated based on the attribution editing operation.
9. A data leakage prevention device based on a large model, characterized in that, The device includes: The data acquisition module is used to acquire the target data to be analyzed. The content recognition configuration module is used to generate a content recognition strategy corresponding to the target data in response to a first configuration operation for the content recognition agent. The content analysis module is used to analyze the flow behavior corresponding to the target data according to the content recognition strategy, and determine the flow data corresponding to the target data; The behavior recognition configuration module is used to generate a behavior recognition strategy corresponding to the target data in response to a second configuration operation for the behavior recognition agent. The behavior analysis module is used to analyze the flow data according to the behavior recognition strategy and identify abnormal behaviors that could lead to data leakage. The circulating data includes target data content, target data type, and target data security level. The content analysis module includes: a content parsing unit, used to parse the content of the target data using the content recognition strategy to determine the target data content corresponding to the target data; a data type analysis unit, used to analyze the data type of the target data using the content recognition strategy to determine the target data type corresponding to the target data; and a data level analysis unit, used to analyze the data level of the target data using the content recognition strategy to determine the target data security level corresponding to the target data. The behavior analysis module includes: a reasoning unit, used to reason about the circulating data using the behavior recognition strategy, and generate a reasoning result corresponding to the circulating data; a first evaluation unit, used to evaluate the circulating data item by item according to a first evaluation method to identify a first abnormal behavior if the reasoning result indicates that the circulating data has a leakage behavior; a second evaluation unit, used to evaluate the circulating data item by item according to a second evaluation method to identify a second abnormal behavior if the reasoning result indicates that the circulating data has a suspicious behavior; and a third evaluation unit, used to perform a sampling evaluation of the circulating data according to a third evaluation method to identify a third abnormal behavior if the reasoning result indicates that the circulating data does not have the leakage behavior or the suspicious behavior.
10. An electronic device, characterized in that, include: A memory and a processor are interconnected, the memory stores computer instructions, and the processor executes the computer instructions to perform the data leakage prevention method based on a large model as described in any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to execute the data leakage prevention method based on a large model as described in any one of claims 1 to 8.
12. A computer program product, characterized in that, It includes computer instructions for causing a computer to execute the data leakage prevention method based on a large model as described in any one of claims 1 to 8.