Method and device for automatically executing data leakage prevention strategy, equipment and medium
By monitoring multi-dimensional information from devices in real time and using rule engines or machine learning models to automatically select and smoothly transition switching strategies, the problem of poor adaptability of traditional static strategies in mobile office environments is solved. This achieves a dynamic balance between security and convenience, prevents data leakage, and ensures user efficiency.
Patent Information
- Application Number
- CN202511200045.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-26
- Publication Date
- 2025-12-12
AI Technical Summary
Traditional static data leakage prevention strategies cannot adapt to the complex and ever-changing mobile office environment, making it difficult to balance security and efficiency. Manually switching strategies is cumbersome and error-prone, and cannot achieve accurate matching.
By monitoring multi-dimensional information from devices, the system uses a rule engine or machine learning model to determine the current scenario type, automatically selects the target policy template from the policy template library, calculates intermediate policy states, and achieves a smooth transition to switch anti-leakage policies.
It achieves a dynamic balance between security and convenience in a dynamic mobile office environment, effectively preventing data leakage while ensuring user work efficiency.
Smart Images

Figure CN121125192A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a method, apparatus, device, and storage medium for automatically implementing data leakage prevention strategies. Background Technology
[0002] With the increasing popularity of mobile work, the demand for employees to process company data using mobile devices in various scenarios such as the office, home, public places, and business trips is constantly growing. However, traditional data leakage prevention (DLP) strategies at rest or solutions that rely on users manually selecting modes are no longer suitable for this complex and ever-changing mobile work environment, exposing many problems.
[0003] First, the limitations of rigid policies are becoming increasingly apparent. In a secure office environment, overly strict policies may unnecessarily restrict employee operations and reduce work efficiency. Conversely, in insecure network environments such as public Wi-Fi, overly lenient policies can lead to serious data breach risks. This "one-size-fits-all" approach cannot be flexibly adjusted according to actual scenarios, making it difficult to balance security and efficiency.
[0004] Secondly, the drawbacks of manually switching policies are also quite obvious. Relying on users to manually select policy modes is not only cumbersome and prone to being forgotten or selected incorrectly, but also results in delays in policy adjustments, making it impossible to respond promptly when risks occur. For example, when employees use mobile devices in public places, they may forget to switch to a stricter security policy, leading to the risk of data leakage.
[0005] Furthermore, existing solutions lack scenario-based judgment. They lack the comprehensive, real-time ability to assess the device's network and physical environment, as well as the user's current operational intent, making it impossible to accurately match strategies. For example, they cannot accurately determine whether the device is on a company intranet, whether it is being used during work hours, or whether the user is processing sensitive data. Such strategies, lacking precise judgment, are ill-suited to effectively address the complex and ever-changing mobile office scenarios and cannot provide reliable protection for data security.
[0006] In conclusion, traditional static DLP strategies and manual switching modes are no longer sufficient to meet the needs of modern mobile work. They not only limit work efficiency but also increase the risk of data leakage and cannot be accurately matched to actual scenarios. Summary of the Invention
[0007] The main objective of this invention is to provide a method, apparatus, device, and storage medium for automatically executing data leakage prevention strategies, aiming to solve the problems of poor adaptability of traditional static strategies in dynamic mobile office environments, cumbersome manual switching, and easy errors, and to achieve a dynamic balance between security and convenience.
[0008] To achieve the above objectives, the present invention provides a method for automatically implementing a data leakage prevention strategy, comprising: Monitor and acquire multi-dimensional information about the device; The current scene type is determined based on the multidimensional feature information; The current scenario type is compared with the scenario type at the previous moment. When the scenario changes, the target strategy template is selected from the strategy templates according to the current scenario type. Calculate the intermediate policy state based on the target policy template and the current policy template to obtain a smooth transition switching path; The leakage prevention strategy is switched gradually based on the intermediate strategy state and the smooth transition switching path.
[0009] In one embodiment, monitoring and acquiring multi-dimensional information about the device includes: Real-time acquisition of network environment characteristics; Scan and analyze the physical environment in which the device is located to obtain physical environment information; Acquire user operation patterns and behavior data, analyze the operation patterns and behavior data, and obtain behavioral feature data; The feature information, physical environment information, and behavioral feature data are aggregated to generate multi-dimensional information.
[0010] In one embodiment, determining the current scene type based on the multidimensional feature information includes: The feature information of the network environment, the physical environment information, and the behavioral feature data are vector-integrated to generate a multi-dimensional feature vector. By comprehensively calculating and analyzing multi-dimensional feature vectors, the scenario judgment result is output; The current scene type is determined based on the scene judgment result, and the current scene type label is output.
[0011] In one embodiment, comparing the current scene type with the scene type at the previous moment, and selecting a target strategy template from the strategy templates based on the current scene type when the scene changes, includes: Predefine strategy templates for each scenario type and generate a strategy template library; The scene types are labeled to generate a scene label set; Retrieve the scene type from the previous moment in historical data; The current scene type is compared with the scene type at the previous moment to determine whether the scene has changed; When the scenario changes, a target strategy template is selected from the strategy template library using the current scenario type label and the scenario label set.
[0012] In one embodiment, calculating the intermediate policy state based on the target policy template and the current policy template to obtain a smooth transition switching path includes: Get the current policy template for the current scenario; Perform a difference analysis on the current strategy template and the target strategy template to obtain the difference analysis results; Calculations are performed based on the current policy template and the target policy template to obtain one or more intermediate policy states; A smooth transition switching path is obtained by calculating based on the difference data and the intermediate strategy state.
[0013] In one embodiment, the stepwise switching of the anti-leakage strategy based on the intermediate strategy state and the smooth transition switching path includes: Execution instructions are issued based on the intermediate strategy status and smooth transition switching path, and the anti-leakage strategy is switched step by step according to the execution instructions; Real-time monitoring to ensure that switching leakage prevention strategies is effective as expected; If the leakage prevention strategy does not work as expected, a rollback mechanism is activated to switch back to the leakage prevention strategy from the previous moment.
[0014] In one embodiment, the step of issuing execution instructions based on the intermediate strategy state and the smooth transition switching path, and executing the switching anti-leakage strategy step by step according to the execution instructions, specifically includes: Receive the execution instruction; Dynamically adjust user access permissions for files with different sensitivity levels based on the target policy template; Dynamically manage device usage rights according to the target strategy template; The network permissions of the device are dynamically adjusted according to the target policy template.
[0015] In one embodiment, to achieve the above objective, the present invention provides an apparatus for automatically implementing a data leakage prevention strategy, comprising: The multi-dimensional scene perception module is used to monitor and acquire multi-dimensional information about the device; The scene evaluation and determination module is used to determine the current scene type based on the multi-dimensional feature information; The strategy decision module is used to compare the current scenario type with the scenario type at the previous moment. When the scenario changes, the target strategy template is selected from the strategy template according to the current scenario type. The strategy switching triggering module is used to calculate the intermediate strategy state based on the target strategy template and the current strategy template, and obtain a smooth transition switching path. A progressive strategy switching module is used to switch the anti-leakage strategy based on the intermediate strategy state and a smooth transition switching path.
[0016] In one embodiment, to achieve the above objective, the present invention also provides a computer device, the computer device including a memory, a processor, and a program stored in the memory and executable on the processor for automatically executing a data leakage prevention strategy, wherein when the program for automatically executing a data leakage prevention strategy is executed by the processor, it implements the steps of the method for automatically executing a data leakage prevention strategy as described above.
[0017] In one embodiment, to achieve the above objective, the present invention also provides a computer-readable storage medium storing a program for automatically executing a data leakage prevention strategy, wherein the program for automatically executing a data leakage prevention strategy, when executed by a processor, implements the steps of a method for automatically executing a data leakage prevention strategy as described above.
[0018] Beneficial Effects: This invention relates to the field of network security technology and discloses a method for automatically executing data leakage prevention strategies, including: monitoring and acquiring multi-dimensional information of the device; determining the current scenario type based on the multi-dimensional feature information; comparing the current scenario type with the scenario type at the previous moment; when the scenario changes, selecting a target strategy template from the strategy templates based on the current scenario type; calculating an intermediate strategy state based on the target strategy template and the current strategy template to obtain a smooth transition switching path; and gradually switching the leakage prevention strategy based on the intermediate strategy state and the smooth transition switching path. This invention uses real-time monitoring of the device's network environment, physical environment, and user behavior, among other multi-dimensional information, and utilizes a rule engine or machine learning model to determine the current scenario type. When the scenario changes, the system automatically selects a target strategy template matching the new scenario from the strategy template library and calculates the intermediate strategy state through a progressive algorithm to achieve a smooth transition from the current strategy to the target strategy. The entire process includes steps such as multi-dimensional information collection, scenario type determination, strategy template selection, intermediate strategy calculation, strategy switching execution, and effectiveness verification, aiming to dynamically balance security and convenience, effectively prevent data leakage, and simultaneously ensure user work efficiency. Attached Figure Description
[0019] The present invention will be further described below with reference to the accompanying drawings and embodiments. In the accompanying drawings: Figure 1 This is a schematic diagram of an application environment for a method of automatically executing a data leakage prevention strategy according to an embodiment of the present invention; Figure 2 This is a flowchart illustrating an embodiment of a method for automatically executing a data leakage prevention strategy according to the present invention; Figure 3 This is a schematic diagram of the functional modules of a preferred embodiment of the device for automatically executing a data leakage prevention strategy according to the present invention; Figure 4 This is a schematic diagram of the structure of a computer device according to an embodiment of the present invention; Figure 5 This is another structural schematic diagram of a computer device according to one embodiment of the present invention. Detailed Implementation
[0020] It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the invention.
[0021] The present invention provides a method for automatically implementing data leakage prevention strategies, which can be applied to, for example... Figure 1 In this application environment, the user terminal communicates with the server via a network. The server can monitor and obtain multi-dimensional information about the device through the client, determine the current scenario type based on the multi-dimensional feature information, compare the current scenario type with the scenario type at the previous moment, and when the scenario changes, select a target policy template from the policy templates based on the current scenario type; calculate the intermediate policy state based on the target policy template and the current policy template to obtain a smooth transition switching path; and gradually switch the anti-leakage policy based on the intermediate policy state and the smooth transition switching path. This invention uses real-time monitoring of the device's network environment, physical environment, and user behavior, among other multi-dimensional information, and utilizes a rule engine or machine learning model to determine the current scenario type. When the scenario changes, the system automatically selects a target policy template matching the new scenario from the policy template library and calculates the intermediate policy state through a progressive algorithm to achieve a smooth transition from the current policy to the target policy. The entire process includes steps such as multi-dimensional information collection, scenario type determination, policy template selection, intermediate policy calculation, policy switching execution, and effectiveness verification, aiming to dynamically balance security and convenience, effectively prevent data leakage, and ensure user work efficiency. The user terminal can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and portable wearable devices. The server can be implemented using a standalone server or a server cluster consisting of multiple servers. The invention will now be described in detail through specific embodiments.
[0022] Please see Figure 2 , Figure 2 This is a flowchart illustrating an embodiment of a method for automatically implementing a data leakage prevention strategy provided by the present invention. It should be noted that although a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than that shown here.
[0023] like Figure 2 As shown, the method for automatically implementing a data leakage prevention strategy proposed in this invention includes the following steps: S100: Monitor and acquire multi-dimensional information about the device; S200. Determine the current scene type based on the multi-dimensional feature information; S300: Compare the current scene type with the scene type at the previous moment. When the scene changes, select the target strategy template from the strategy templates according to the current scene type. S400: Calculate the intermediate policy state based on the target policy template and the current policy template to obtain a smooth transition switching path; S500: Gradually switch the anti-leakage strategy according to the intermediate strategy state and the smooth transition switching path.
[0024] In this embodiment, the system monitors and collects multi-dimensional information from devices in real time (including network environment characteristics, physical environment characteristics, and user behavior characteristics), and uses a preset rule engine or machine learning model to comprehensively analyze this information to determine the current scenario type and output a clear scenario type label (such as "Company Secure Office Area - Document Editing", "Home Trusted Network - R&D", "Public Place - High Risk", etc.). The system compares the current scenario type with the scenario type at the previous moment. If the scenario changes, it selects the target policy template that best matches the current scenario type from a preset policy template library. Next, the system calculates intermediate policy states based on the target policy template and the current policy template to obtain a smooth transition switching path. Specifically, by comparing the differences between the current policy and the target policy, the system determines the policy rules that need to be adjusted and calculates one or more intermediate policy states to form a smooth transition switching path. Finally, the system issues instructions to the execution control module step by step according to the calculated path to gradually apply the new policy rules. The anti-leakage policy is switched according to the intermediate policy states and the smooth transition switching path, and the policy rules are adjusted step by step to avoid the impact of policy abrupt changes on users. After each step of execution, the system monitors whether the policy takes effect as expected and collects execution feedback. If an anomaly is detected, the rollback mechanism is automatically triggered to restore the device to the stable state of the previous step. After all intermediate steps are completed, the target policy takes full effect, and the device enters the new security policy state.
[0025] The system continuously repeats the above steps, and through collecting data on scene recognition, policy switching, execution effects, and user feedback, it learns offline or online to continuously optimize the scene recognition model, policy template configuration, and switching algorithm. The system continuously monitors device status and perceives scene changes in real time. Through machine learning algorithms, it continuously optimizes the accuracy of scene recognition and the efficiency of policy switching.
[0026] Through dynamic sensing, intelligent decision-making, and gradual switching, the system achieves a dynamic balance between security and convenience in different mobile office scenarios, effectively preventing data leakage while ensuring users' work efficiency.
[0027] In one embodiment, S100 includes: S101. Real-time acquisition of network environment characteristic information; S102. Scan and analyze the physical environment in which the equipment is located to obtain physical environment information; S103. Obtain user operation mode and behavior data, analyze the operation mode and behavior data, and obtain behavior feature data; S104. The feature information, physical environment information and behavioral feature data are collected to generate multi-dimensional information.
[0028] In this embodiment, characteristic information related to the network environment is acquired in real time to determine the trustworthiness of the network. Specifically, the Wi-Fi SSID is acquired by detecting the Service Set Identifier (SSID) of the currently connected wireless network to determine whether the network is a company intranet, home network, or public network. For example, the SSID of a company intranet usually has a specific naming rule, while the SSID of a public network may contain words such as "public". The DNS server address is detected to further verify the legitimacy of the network environment. Company intranets usually use internal DNS servers, while public networks may use general DNS servers (such as Google's 8.8.8.8). Network latency is measured to assess the stability and security of the network connection. Lower latency usually means a more stable network connection, while high latency may indicate network instability or potential security risks. VPN connection status is detected to determine whether the network connection is in a secure state by detecting whether the device is connected to an encrypted VPN tunnel. VPN connections are often used for remote work to ensure the security of data transmission. By collecting these network characteristics, the security of the network environment can be accurately determined, providing a basis for subsequent strategy selection. For example, if a device is connected to the company's intranet and encrypted via VPN, the system may consider the network environment to be relatively secure and thus apply a relatively lenient security policy; however, if the device is connected to a public network, the system will apply a stricter security policy.
[0029] The system scans and analyzes the physical environment information of the device. Specifically, it scans for nearby Bluetooth devices to identify trusted devices (such as company-issued Bluetooth devices) or unknown devices. The presence of trusted devices enhances security, while unknown devices may indicate the device is in a potentially risky environment. It also acquires geolocation information to determine if the device is within a pre-defined area such as a company fence or home address. For example, if the device is within a company fence, the system considers it to be in a secure physical environment. Furthermore, it analyzes the device's usage scenario by considering the current time period (working hours or non-working hours). For example, device use during working hours may be related to office work, while use outside of working hours may require stricter security measures. Finally, it analyzes the device's posture (whether it is stably placed on a desktop, etc.) to determine if it is in a secure physical environment. For example, a device stably placed on a desktop may indicate the user is in a working state, while a frequently moved device may indicate the user is working remotely. This physical environment awareness allows for further refinement of scenario judgments, such as distinguishing between "working in the office" and "working outside the office." This information helps the system more accurately match security policies, ensuring that appropriate security protection is provided in different physical environments.
[0030] Analyze users' current operation patterns and behavioral characteristics. Specifically, identify user operation patterns by recognizing primary operation modes (such as document editing, code development, instant messaging, web browsing, etc.) to understand current user needs. For example, users may require more flexible file operation permissions when editing documents. Analyze frequently used applications to understand users' frequently used tools. For example, if a user frequently uses code development tools, the system can infer that the user may be in a research and development scenario. Analyze sensitive file access patterns by analyzing recent access patterns and frequencies of sensitive files to determine if the user is processing important data. For example, users who frequently access sensitive files may require stricter security policies. Through user behavior analysis, user needs and security policies can be matched more accurately. For example, more flexible file operation permissions can be provided when users are editing documents, while stricter security policies can be applied when users access sensitive files. This dynamic adjustment approach can effectively balance security and user experience.
[0031] By aggregating the aforementioned feature information, physical environment information, and behavioral feature data, multi-dimensional information is generated. Integrating this multi-dimensional information allows the system to more comprehensively and accurately perceive the device's environment and the user's usage status, thus providing a more reliable basis for subsequent scenario judgments and strategy selection. This multi-dimensional information integration method effectively improves the system's intelligence level and adaptability.
[0032] In one embodiment, step S200 includes: S201 performs vector integration on the feature information of the network environment, the physical environment information, and the behavioral feature data to generate a multi-dimensional feature vector; S202 outputs scene judgment results by comprehensively calculating and analyzing multi-dimensional feature vectors; S203 determines the current scene type based on the scene judgment result and outputs the current scene type label.
[0033] In this embodiment, network environment characteristics include Wi-Fi SSID, DNS server address, network latency, VPN connection status, etc. Physical environment characteristics include surrounding Bluetooth devices, geographical location information, current time period, device posture, etc. User behavior characteristics include the user's current operation mode (such as document editing, code development, instant messaging, web browsing, etc.), frequently used applications, access patterns and frequencies of sensitive files, etc. These multi-dimensional feature data are integrated to form a comprehensive feature vector. This feature vector contains information about the device's network environment, physical location, and user behavior.
[0034] Scenario determination is based on a pre-defined rule base or machine learning model. The rule base consists of a series of "if-then" rules developed by security experts based on experience and business needs. For example, if the network environment is a company intranet (verified via Wi-Fi SSID and DNS server address) and the user is editing a document (identified by the user behavior analysis unit), the scenario is determined to be "secure company office area - document editing". If the network environment is a home network and the user is using development tools (such as an IDE), the scenario is determined to be "trusted home network - R&D". If the network environment is a public network (such as coffee shop Wi-Fi), the scenario is determined to be "public place - high risk".
[0035] The feature vectors are classified using a pre-trained classification model (such as a decision tree, support vector machine, or neural network). The model is trained on historical data and can automatically learn feature patterns from different scenarios, thus more intelligently determining the current scenario type. For example, inputting a feature vector into a pre-trained model, the model outputs a scenario type label, such as "Company Safe Office Area - Document Editing" or "Public Place - High Risk".
[0036] Based on the judgment results of the rule engine or machine learning model, a clear scenario type label is output. These labels are standardized and can be directly mapped to preset policy templates. For example, "Company Secure Office Area - Document Editing": This indicates that the device is on the company intranet, the user is editing a document, and a more lenient security policy can be applied to improve work efficiency. "Home Trusted Network - R&D": This indicates that the device is on a home network, the user is engaged in R&D work, and a moderate security policy can be applied to ensure data security without affecting development efficiency. "Public Place - High Risk": This indicates that the device is in a public network environment, which may pose a high security risk. A strict security policy should be applied to restrict access to and transmission of sensitive data.
[0037] Complex data from multiple dimensions (network, physical environment, user behavior, etc.) is comprehensively analyzed through a rule engine or machine learning model, ultimately transforming it into a standardized scenario label. This standardization process makes subsequent policy selection more explicit and efficient. The rule engine can make quick and accurate judgments based on preset rules, suitable for scenarios with clearly defined rules. The machine learning model can automatically learn and adapt to new scenario patterns, improving the accuracy and flexibility of scenario judgment, especially when facing complex and dynamically changing mobile office environments. The output scenario type label directly corresponds to the preset policy template, enabling the policy management module to quickly and accurately select the security policy that best matches the current scenario. This automated scenario judgment and policy selection mechanism avoids the tedium and errors of manual configuration, improving the system's intelligence level and user experience. By continuously collecting and analyzing multi-dimensional data, the system can perceive changes in the environment and user behavior in real time, adjust the scenario judgment results in a timely manner, and dynamically select and switch security policies to ensure a balance between security and convenience in different scenarios.
[0038] Specifically, assuming a user is currently in a "secure office area - document editing" scenario, the corresponding policy allows the user to freely edit and transfer documents. When the user leaves the company and enters a public area, the scenario type changes to "public area - high risk," and the corresponding policy template may include stricter security rules, such as restricting the outward transmission of sensitive files and enabling encrypted transmission. Through this comprehensive assessment and judgment mechanism, the system can accurately identify the current scenario and provide a direct basis for subsequent policy selection, thereby achieving dynamic and intelligent security policy management.
[0039] In one embodiment, S300 includes: S301 predefines strategy templates for each scenario type and generates a strategy template library; S302 Tag the scene type to generate a scene tag set; S303 retrieves the scene type from the previous moment in historical data; S304 compares the current scene type with the scene type of the previous moment to determine whether the scene has changed; S305 When the scenario changes, a target strategy template is selected from the strategy template library using the current scenario type label and the scenario label set.
[0040] In this embodiment, the administrator predefines policy templates associated with different scenario types, generating a policy template library. A unique tag is defined for each scenario type for quick identification and matching. These tags are standardized, facilitating logical judgment by the system. Policy templates are collections of specific security rules applied by the system in different scenarios, ensuring the system can dynamically adjust security policies according to the current scenario. Each policy template contains a set of specific control rules covering multiple aspects such as file permissions, device disabling, and network rules. Specifically, file permissions define user permissions for reading, writing, copying, pasting, and sharing files of different sensitivity levels. Device disabling defines the usage permissions of peripheral devices (such as USB storage devices, cameras, microphones, etc.). Network rules define the access permissions of devices to different network targets (such as intranet servers, specific websites, cloud services, etc.) and the encryption level of data transmission. Furthermore, a policy conflict detection mechanism is provided to avoid conflicts between different policies. For example, if one policy template allows the use of USB storage devices while another policy template disables them, the system will detect this conflict and prompt the administrator to make adjustments. Priority management rules are provided to clearly define the policy that takes precedence in case of conflict. For example, if a user simultaneously meets the characteristics of both "secure office area - document editing" and "public place - high risk," the system will select the stricter security policy based on priority rules. Flexible policy configuration is provided for different scenarios to ensure the rationality and effectiveness of the policies. Through policy conflict detection mechanisms and priority management rules, compatibility and consistency between policies are ensured, avoiding security issues caused by policy conflicts.
[0041] The system retrieves the scenario type from historical data at the previous moment and compares the current scenario type with the scenario type from the previous moment in the historical data to determine if the scenario has changed. For example, if a user moves from the "Company Secure Office Area - Document Editing" scenario to the "Public Place - High Risk" scenario, the system will detect this change. If the scenario has changed, the system queries the preset policy template library in the policy configuration unit and selects the target policy template that best matches the new scenario. For example, when a user enters the "Public Place - High Risk" scenario, the system will select a policy template that matches this scenario from the policy template library. This template may contain stricter security rules, such as disabling USB storage devices and enabling encrypted transmission. Automated policy selection allows the system to automatically select the most suitable policy template based on environmental changes without manual intervention. Timely policy adjustments ensure that security policies can be adjusted promptly to adapt to environmental changes, improving the system's adaptability and security.
[0042] In one embodiment, S400 includes: S401 retrieves the current policy template for the current scenario; S402 performs a difference analysis on the current strategy template and the target strategy template to obtain the difference analysis results; S403 calculates one or more intermediate policy states based on the current policy template and the target policy template; S404 calculates a smooth transition switching path based on the difference data and the intermediate strategy state.
[0043] In this embodiment, the current policy template for the current scenario is obtained. The current policy template refers to the security policy template that the system is currently executing in the current scenario. It is the policy template corresponding to the previous scenario type and contains the specific security rules for the current scenario. Assuming the current scenario is "Company Secure Office Area - Document Editing", the current policy template allows users to freely edit and transfer documents, but restricts access to external networks.
[0044] A difference analysis is performed on the current policy template and the target policy template to obtain the results. The target policy template refers to the policy template selected based on the new scenario type, and it contains specific security rules applicable to the new scenario. The system will compare the differences between the current policy template and the target policy template in detail. These differences may include multiple aspects such as file permissions, device usage permissions, network access permissions, and encryption levels. Example: The current policy template allows read and write permissions for USB storage devices.
[0045] The target policy template disables USB storage devices.
[0046] Based on the current policy template and the target policy template, one or more intermediate policy states are calculated. To achieve a smooth transition, the system calculates one or more intermediate policy states. These intermediate states serve as transitional states between the current policy and the target policy, used to gradually adjust the policy rules. Example: First intermediate policy state: Restrict write permissions for USB storage devices.
[0047] Second intermediate policy state: Restrict read permissions for USB storage devices.
[0048] Third intermediate policy state: Completely disable USB storage devices.
[0049] Based on the difference data and the intermediate policy state, a smooth transition path is calculated. The system will plan a smooth transition path based on the difference analysis results and the intermediate policy state. This path defines the gradual change process from the current policy to the target policy. Example: Step 1: Restrict write permissions on the USB storage device.
[0050] Step 2: Restrict read permissions for USB storage devices.
[0051] Step 3: Completely disable USB storage devices.
[0052] Through this step-by-step transition path, the system can gradually apply new policy rules, avoiding the impact of policy changes on users and improving the stability and acceptability of policy switching.
[0053] By applying new policy rules step by step, the sudden impact on users from policy abrupt changes is avoided. Through step-by-step execution and monitoring feedback mechanisms, the system can confirm at each step whether the policy is effective as expected, ensuring the stability of the policy transition process. Users have time to adapt to the new policy rules, reducing user resistance to policy adjustments. By gradually adjusting policy rules, the system can minimize disruption to users' normal work while ensuring security.
[0054] In one embodiment, step S500 includes: S501 issues an execution instruction based on the intermediate strategy state and smooth transition switching path, and executes the switching anti-leakage strategy step by step according to the execution instruction; S502 monitors in real time whether the switching of leakage prevention strategies is effective as expected; S503 If the leakage prevention strategy does not work as expected, the fallback mechanism is activated to switch to the leakage prevention strategy of the previous moment.
[0055] In this embodiment, execution instructions are issued based on the intermediate strategy state and the smooth transition switching path, and the anti-leakage strategy is executed step by step according to the execution instructions. The system issues specific execution instructions to the execution control module based on the calculated intermediate strategy state and smooth transition switching path. These instructions define the strategy rules to be applied at each step. The execution control module applies the new strategy rules progressively according to the issued instructions. Each step of execution is gradual, avoiding sudden impact on the user. Example: Step 1: Restrict write permissions on the USB storage device.
[0056] Step 2: Restrict read permissions for USB storage devices.
[0057] Step 3: Completely disable USB storage devices.
[0058] Step 4: Prompt the user to enable the encrypted transmission option.
[0059] Step 5: Mandate that all data transmissions must be encrypted.
[0060] The system monitors in real-time whether the anti-leakage strategy is effective as expected. After each step of the process, the system monitors the strategy in real-time to ensure it is effective as intended. Monitoring includes, but is not limited to: whether the strategy is applied correctly (e.g., whether USB storage devices are disabled); whether system performance is affected (e.g., whether network transmission is normal); and whether user operations are unreasonably restricted (e.g., whether it affects normal work). Through real-time monitoring, the system can promptly detect potential problems during the strategy switching process, ensuring the stability and security of the strategy switching.
[0061] If the leakage prevention strategy fails to take effect as expected, a rollback mechanism is activated, switching back to the previous leakage prevention strategy. The system has an anomaly detection mechanism to identify abnormal situations that occur during strategy switching. For example, if the policy application causes system instability, severely hinders user operations, or the security policy fails to take effect. Once an anomaly is detected, the system automatically triggers the rollback mechanism, reversing the current policy change and restoring the stable policy state from the previous moment. Example: If, during step three (completely disabling USB storage devices), the system detects that the user is not functioning properly, it will automatically revert the policy change from step three and revert to the stable state of step two (restricting read permissions for USB storage devices). This rollback mechanism ensures the security and reliability of the policy switching process, preventing system failures or security vulnerabilities caused by incorrect policy configurations.
[0062] By implementing the strategy step-by-step and monitoring in real time, the system ensures the stability of the strategy switching process, avoiding system instability caused by sudden policy changes. Through anomaly detection and rollback mechanisms, the system can promptly identify and correct problems during the strategy switching process, ensuring its security. Through gradual switching and rollback mechanisms, the system can minimize disruption to users' normal work while ensuring security, thus optimizing the user experience.
[0063] In one embodiment, step S501 specifically includes: S5011, Receive the execution instruction; S5012. Dynamically adjust the user's operation permissions for files with different sensitivity levels according to the target policy template; S5013. Dynamically manage the right to use the device according to the target strategy template; S5014. Dynamically adjust the network permissions of the device according to the target policy template.
[0064] In this embodiment, specific and dynamic control commands are received from the policy management module and enforced on the device. It is responsible for dynamically adjusting the user's file access permissions, device usage rights, and network permissions based on the target policy template, ensuring strict policy enforcement.
[0065] The system dynamically adjusts user access permissions for files of different sensitivity levels based on the target policy template. Specifically: File permission adjustment: Based on the target policy template, the system adjusts user permissions for reading, writing, copying, pasting, and saving as files. For example, the target policy might restrict users from copying and sharing sensitive files. Transparent encryption / decryption: The system adjusts the strength of transparent encryption / decryption for sensitive files to ensure file security during transmission and storage. For example, the target policy might require encryption of sensitive files. External distribution control: The system controls file distribution via email, cloud storage, instant messaging tools, USB, etc. For example, the target policy might prohibit the distribution of sensitive files via USB devices.
[0066] The system dynamically manages device usage rights based on the target policy template. Specifically: Peripheral management manages usage permissions for peripherals such as USB storage devices, cameras, microphones, and Bluetooth transmission. For example, the target policy might disable USB storage devices to prevent data leakage. Printer management adjusts printer usage permissions and watermarking policies. For example, the target policy might require adding watermarks when printing sensitive documents. Screenshot and screen recording functions are dynamically enabled or disabled. For example, the target policy might disable screenshot functionality to prevent sensitive information from being captured. By dynamically managing device usage rights, the system ensures that device usage in different scenarios complies with security policies, preventing the leakage of sensitive information through peripherals or screenshots.
[0067] The network permissions of the device are dynamically adjusted based on the target policy template. Specifically, this includes: network access permissions, adjusting the device's access permissions to different network targets (internal servers, specific websites, cloud services, etc.). For example, the target policy might restrict the device's access to external networks to prevent data leakage. Data transmission encryption, setting the required encryption level for data transmission (such as upload and download). For example, the target policy might require all data transmission to be encrypted. Application network access, controlling the network access of specific applications (allowing, blocking, limiting bandwidth). For example, the target policy might block certain applications from accessing the network to prevent data leakage. By dynamically adjusting network permissions, the security of network communication is ensured, preventing data from being stolen or tampered with during transmission.
[0068] Based on the target policy template, file operation permissions, device usage rights, and network permissions are dynamically adjusted to ensure strict policy enforcement. This enables fine-grained control over file operations, device usage, and network access, ensuring appropriate security protection in various scenarios. By dynamically adjusting policies, data security is guaranteed without disrupting users' normal work in different situations.
[0069] In one embodiment, an apparatus for automatically executing a data loss prevention strategy is provided, which corresponds one-to-one with the method for automatically executing a data loss prevention strategy in the above embodiments. (Refer to...) Figure 3 , Figure 3 This is a schematic diagram of the functional modules of a preferred embodiment of the device for automatically executing data leakage prevention strategies according to the present invention. The modules include a multi-dimensional scene perception module 10, a scene evaluation and judgment module 20, a strategy decision module 30, a strategy switching trigger module 40, and a progressive strategy switching module 50. Detailed descriptions of each functional module are as follows: The multi-dimensional scene perception module 10 is used to monitor and acquire multi-dimensional information of the device; Scene evaluation and determination module 20 is used to determine the current scene type based on the multi-dimensional feature information; The strategy decision module 30 is used to compare the current scenario type with the scenario type at the previous moment, and when the scenario changes, select the target strategy template from the strategy template according to the current scenario type. The strategy switching triggering module 40 is used to calculate the intermediate strategy state based on the target strategy template and the current strategy template, and obtain a smooth transition switching path. The progressive strategy switching module 50 is used to switch the anti-leakage strategy according to the intermediate strategy state and the smooth transition switching path.
[0070] In one embodiment, the multi-dimensional scene perception module 10 includes: The network environment sensing unit is used to acquire characteristic information of the network environment in real time. The physical environment sensing unit is used to scan and analyze the physical environment in which the device is located and to obtain physical environment information; The user behavior analysis unit is used to acquire user operation patterns and behavior data, analyze the operation patterns and behavior data, and obtain behavioral feature data. A multi-dimensional information unit is used to aggregate the feature information, physical environment information, and behavioral feature data to generate multi-dimensional information.
[0071] In one embodiment, the scene evaluation and determination module 20 includes: The vector integration unit is used to integrate the feature information, physical environment information and behavioral feature data of the network environment to generate a multi-dimensional feature vector. The scene comprehensive evaluation unit is used to output scene judgment results by comprehensively calculating and analyzing multi-dimensional feature vectors; The scene determination unit is used to determine the current scene type based on the scene determination result and output the current scene type label.
[0072] In one embodiment, the strategy decision module 30 includes: The strategy configuration and template unit is used to predefine strategy templates for each scenario type and generate a strategy template library. A scene tagging unit is used to tag the scene type and generate a scene tag set; The scene acquisition unit is used to acquire the scene type from the previous moment in historical data; The scene comparison unit is used to compare the current scene type with the scene type at the previous moment to determine whether the scene has changed. The strategy decision unit is used to select a target strategy template from the strategy template library by means of the current scenario type label and the scenario label set when the scenario changes.
[0073] In one embodiment, the policy switching triggering module 40 includes: The strategy acquisition unit is used to acquire the current strategy template for the current scenario; The strategy switching triggering unit is used to perform a difference analysis on the current strategy template and the target strategy template to obtain the difference analysis results. The strategy state unit is used to calculate one or more intermediate strategy states based on the current strategy template and the target strategy template. The switching path unit is used to calculate, based on the difference data and the intermediate strategy state, a smooth transition switching path.
[0074] In one embodiment, the progressive strategy switching module 50 includes: The strategy execution unit is used to issue execution instructions based on the intermediate strategy state and the smooth transition switching path, and execute the anti-leakage strategy step by step according to the execution instructions; The strategy verification and activation unit is used to monitor in real time whether the switching of anti-leakage strategies takes effect as expected; The strategy rollback unit is used to activate the rollback mechanism and switch to the previous leak prevention strategy when the leak prevention strategy does not take effect as expected.
[0075] In one embodiment, the policy execution unit specifically includes: Receive the execution instruction; Dynamically adjust user access permissions for files with different sensitivity levels based on the target policy template; Dynamically manage device usage rights according to the target strategy template; The network permissions of the device are dynamically adjusted according to the target policy template.
[0076] In one embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 4 As shown. The computer device includes a processor, memory, network interface, and database connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile and / or volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used for communication with external user terminals via a network connection. When the computer program is executed by the processor, it implements a method for automatically executing data leakage prevention strategies, which constitutes server-side functions or steps.
[0077] In one embodiment, a computer device is provided, which may be a user terminal, and its internal structure diagram may be as follows: Figure 5 As shown. The computer device includes a processor, memory, network interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage media. The network interface is used to communicate with an external server via a network connection. When the computer program is executed by the processor, it implements a method for automatically executing data leakage prevention strategies, which are user-side functions or steps. In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to perform the following steps: Monitor and acquire multi-dimensional information about the device; The current scene type is determined based on the multidimensional feature information; The current scenario type is compared with the scenario type at the previous moment. When the scenario changes, the target strategy template is selected from the strategy templates according to the current scenario type. Calculate the intermediate policy state based on the target policy template and the current policy template to obtain a smooth transition switching path; The leakage prevention strategy is switched gradually based on the intermediate strategy state and the smooth transition switching path.
[0078] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, the computer program performing the following steps when executed by a processor: Monitor and acquire multi-dimensional information about the device; The current scene type is determined based on the multidimensional feature information; The current scenario type is compared with the scenario type at the previous moment. When the scenario changes, the target strategy template is selected from the strategy templates according to the current scenario type. Calculate the intermediate policy state based on the target policy template and the current policy template to obtain a smooth transition switching path; The leakage prevention strategy is switched gradually based on the intermediate strategy state and the smooth transition switching path.
[0079] It should be noted that the functions or steps that can be implemented by the computer-readable storage medium or computer device described above can be referred to the relevant descriptions on the server side and user side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.
[0080] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, storage, databases, or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), dual data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0081] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional units and modules is used as an example. In practical applications, the above functions can be assigned to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0082] It should be noted that if any software tools or components not belonging to this company appear in the embodiments of this application, they are merely illustrative examples and do not represent actual use. The embodiments described above are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.
Claims
1. A method for automatically executing a data leakage prevention strategy, characterized in that, Includes the following steps: Monitor and acquire multi-dimensional information about the device; The current scene type is determined based on the multidimensional feature information; The current scenario type is compared with the scenario type at the previous moment. When the scenario changes, the target strategy template is selected from the strategy templates according to the current scenario type. Calculate the intermediate policy state based on the target policy template and the current policy template to obtain a smooth transition switching path; The leakage prevention strategy is switched gradually based on the intermediate strategy state and the smooth transition switching path.
2. The method for automatically executing a data leakage prevention strategy as described in claim 1, characterized in that, The monitoring and acquisition of multi-dimensional information about the device includes: Real-time acquisition of network environment characteristics; Scan and analyze the physical environment in which the device is located to obtain physical environment information; Acquire user operation patterns and behavior data, analyze the operation patterns and behavior data, and obtain behavioral feature data; The feature information, physical environment information, and behavioral feature data are aggregated to generate multi-dimensional information.
3. The method for automatically executing a data leakage prevention strategy as described in claim 2, characterized in that, Determining the current scene type based on the multidimensional feature information includes: The feature information of the network environment, the physical environment information, and the behavioral feature data are vector-integrated to generate a multi-dimensional feature vector. By comprehensively calculating and analyzing multi-dimensional feature vectors, the scenario judgment result is output; The current scene type is determined based on the scene judgment result, and the current scene type label is output.
4. The method for automatically executing a data leakage prevention strategy as described in claim 1, characterized in that, The step of comparing the current scene type with the scene type at the previous moment, and selecting a target strategy template from the strategy templates based on the current scene type when the scene changes, includes: Predefine strategy templates for each scenario type and generate a strategy template library; The scene types are labeled to generate a scene label set; Retrieve the scene type from the previous moment in historical data; The current scene type is compared with the scene type at the previous moment to determine whether the scene has changed; When the scenario changes, a target strategy template is selected from the strategy template library using the current scenario type label and the scenario label set.
5. The method for automatically executing a data leakage prevention strategy as described in claim 1, characterized in that, The step of calculating intermediate policy states based on the target policy template and the current policy template to obtain a smooth transition switching path includes: Get the current policy template for the current scenario; Perform a difference analysis on the current strategy template and the target strategy template to obtain the difference analysis results; Calculations are performed based on the current policy template and the target policy template to obtain one or more intermediate policy states; A smooth transition switching path is obtained by calculating based on the difference data and the intermediate strategy state.
6. The method for automatically executing a data leakage prevention strategy as described in claim 1, characterized in that, The stepwise switching of the anti-leakage strategy based on the intermediate strategy state and the smooth transition switching path includes: Execution instructions are issued based on the intermediate strategy status and smooth transition switching path, and the anti-leakage strategy is switched step by step according to the execution instructions; Real-time monitoring to ensure that switching leakage prevention strategies is effective as expected; If the leakage prevention strategy does not work as expected, a rollback mechanism is activated to switch back to the leakage prevention strategy from the previous moment.
7. The method for automatically executing a data leakage prevention strategy as described in claim 1, characterized in that, The step of issuing execution instructions based on the intermediate strategy state and the smooth transition switching path, and executing the switching anti-leakage strategy step by step according to the execution instructions, specifically includes: Receive the execution instruction; Dynamically adjust user access permissions for files with different sensitivity levels based on the target policy template; Dynamically manage device usage rights according to the target strategy template; The network permissions of the device are dynamically adjusted according to the target policy template.
8. An apparatus for automatically executing a data leakage prevention strategy, characterized in that, The device for automatically implementing a data leakage prevention strategy includes: The multi-dimensional scene perception module is used to monitor and acquire multi-dimensional information about the device; The scene evaluation and determination module is used to determine the current scene type based on the multi-dimensional feature information; The strategy decision module is used to compare the current scenario type with the scenario type at the previous moment. When the scenario changes, the target strategy template is selected from the strategy template according to the current scenario type. The strategy switching triggering module is used to calculate the intermediate strategy state based on the target strategy template and the current strategy template, and obtain a smooth transition switching path. A progressive strategy switching module is used to switch the anti-leakage strategy based on the intermediate strategy state and a smooth transition switching path.
9. A computer device, characterized in that, The computer device includes a memory, a processor, and a program stored in the memory and executable on the processor to automatically execute a data leakage prevention strategy. When the program is executed by the processor, it implements the steps of a method for automatically executing a data leakage prevention strategy as described in any one of claims 1-7.
10. A computer-readable storage medium, characterized in that, The storage medium stores a program for automatically executing a data leakage prevention strategy, which, when executed by a processor, implements the steps of a method for automatically executing a data leakage prevention strategy as described in any one of claims 1-7.