Data security protection method and device, equipment, storage medium and program product
By identifying and analyzing network traffic data, constructing correlated data and situation assessment results, the problem of inaccurate identification of sensitive data and lagging situation awareness in existing technologies is solved, realizing accurate identification and real-time protection of sensitive data and reducing the risk of data leakage.
Patent Information
- Application Number
- CN202511709560.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-20
- Publication Date
- 2026-02-10
AI Technical Summary
Existing technologies struggle to accurately identify sensitive data amidst massive amounts of network traffic, and the timeliness of situational awareness is poor, making it impossible to promptly block data leaks or attacks.
By acquiring network traffic data, identifying sensitive data information, constructing related data, obtaining security situation assessment results, and conducting correlation analysis, attack paths can be identified, enabling in-depth tracing and protection.
It enables accurate identification and real-time situational awareness of sensitive data, reduces the risk of data leakage, lowers the probability of security incidents, and provides dynamic and intelligent data security protection solutions for multiple industries.
Smart Images

Figure CN121508987A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of big data and the field of financial technology, and in particular to a data security protection method and device, equipment, a storage medium and a program product. BACKGROUND
[0002] Under the background of high development of digitization and networking, the business operation of enterprises, government agencies and financial institutions highly depends on network transmission and data interaction. For example, in the financial industry, sensitive data such as customer identity card numbers, bank card numbers and transaction records need to be frequently transmitted through the network in the scenarios of transaction processing, customer information management and risk control analysis; in the internal links of enterprises such as R&D, production and supply chain management, the transmission of confidential information such as technical documents, business plans and financial statements also faces the risk of data leakage. In addition, with the popularity of the Internet of Things, cloud computing and edge computing, the complexity and scale of network traffic grow exponentially, and attackers may implement attacks through hidden traffic characteristics such as sensitive data in encrypted traffic or long-term lurking threat behaviors such as low-frequency but continuous data leakage.
[0003] However, the prior art cannot accurately identify sensitive data in a large amount of traffic, the timeliness of situation awareness is poor, the causal relationship or hierarchical relationship of data is ignored, which leads to insufficient deep mining, resulting in lag in responding to threats, and unable to timely block data leakage or attack behaviors. SUMMARY
[0004] The present application provides a data security protection method, device, equipment, storage medium and program product to solve the technical problem of lag in responding to threats, and unable to timely block data leakage or attack behaviors.
[0005] In a first aspect, the present application provides a data security protection method, comprising:
[0006] obtaining network traffic data; the network traffic data includes plaintext traffic data and encrypted traffic data;
[0007] based on the network traffic data, identifying sensitive data information in the network traffic data, and constructing associated data of the sensitive data information; the associated data includes transmission information, port information and protocol of the sensitive data information;
[0008] based on the sensitive data information, the associated data and traffic characteristics, obtaining a security situation assessment result; the traffic characteristics include the distribution of traffic rate and packet size;
[0009] based on the sensitive data information and the security situation assessment result, performing correlation analysis to obtain a correlation analysis result; the correlation analysis result is used to identify an attack path associated with the sensitive data information;
[0010] Based on the correlation analysis result, data security protection is performed.
[0011] In one of the embodiments, based on the network traffic data, sensitive data information in the network traffic data is identified, specifically including:
[0012] Feature extraction is performed on the plaintext traffic data to generate a plaintext feature vector sequence;
[0013] Statistical features of the ciphertext are extracted from the encrypted traffic data;
[0014] The plaintext feature vector sequence and the ciphertext statistical features are fused by logistic regression to generate sensitive data information.
[0015] In one of the embodiments, feature extraction is performed on the plaintext traffic data to generate a plaintext feature vector sequence, specifically including:
[0016] The plaintext traffic data is matched by regular expression and dictionary to obtain text features in the plaintext traffic data;
[0017] The text features are generated into a plaintext feature vector sequence through a multi-head attention mechanism.
[0018] In one of the embodiments, based on the sensitive data information, the correlation data, and the traffic features, a security posture assessment result is obtained, specifically including:
[0019] Based on the sensitive data information, the correlation data, and the traffic features, a traffic anomaly score is calculated;
[0020] Based on the traffic anomaly score, the sensitive data information density, the intelligence relevance, and the corresponding weight values of the traffic anomaly score, the sensitive data information density, and the intelligence relevance, a judgment matrix is constructed; the intelligence relevance is the matching degree between the current traffic features and the known threat intelligence;
[0021] The security posture assessment result is obtained through the judgment matrix.
[0022] In one of the embodiments, based on the sensitive data information and the security posture assessment result, correlation analysis is performed to obtain a correlation analysis result, specifically including:
[0023] Based on the sensitive data information and the security posture assessment result, threat events and asset information are obtained;
[0024] An association rule and a time series analysis model are used to generate a prediction result of the sensitive data information; the prediction result is used to predict the development trend of the sensitive data information;
[0025] And based on the prediction result, a correlation analysis result is generated.
[0026] In one of the embodiments, a prediction result of the sensitive data information is generated by using an association rule and a time sequence analysis model, and specifically includes:
[0027] A graph model of an attack path of the sensitive data information is constructed, and a key node in the attack path is determined based on the graph model;
[0028] Based on the key node, the prediction result of the sensitive data information is generated.
[0029] In one of the embodiments, before the network traffic data is acquired, the method further includes:
[0030] The network traffic data is directly mapped to the memory by using a zero-copy technology, and the traffic features are structured parsed by using a columnar storage format.
[0031] In a second aspect, an embodiment of the present application provides a data security protection device, including:
[0032] A data acquisition module is configured to acquire network traffic data, wherein the network traffic data includes plaintext traffic data and encrypted traffic data;
[0033] A sensitive data identification module is configured to identify sensitive data information in the network traffic data based on the network traffic data, and construct association data of the sensitive data information, wherein the association data includes transmission information, port information and a protocol of the sensitive data information;
[0034] A situation awareness analysis module is further configured to acquire a security situation assessment result based on the sensitive data information, the association data and traffic features, wherein the traffic features include a traffic rate and a distribution of packet sizes;
[0035] An association analysis module is configured to perform association analysis based on the sensitive data signal and the security situation assessment result, to obtain an association analysis result, wherein the association analysis result is used to identify an attack path associated with the sensitive data information;
[0036] A processing module is configured to perform data security protection based on the association analysis result.
[0037] In a third aspect, an embodiment of the present application provides an electronic device, including a processor and a memory connected with the processor in communication;
[0038] The memory stores computer execution instructions;
[0039] The processor executes the computer execution instructions stored in the memory, to implement the method as any of the above.
[0040] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, wherein the computer readable storage medium stores computer execution instructions, and the computer execution instructions are executed by the processor to implement the method as any of the above.
[0041] In a fifth aspect, an embodiment of the present application provides a computer program product, comprising a computer program, which, when executed by a processor, implements any of the above methods.
[0042] The data security protection method, device, equipment, storage medium and program product provided by the present application, the method comprises: obtaining network traffic data; the network traffic data comprises plaintext traffic data and encrypted traffic data; based on the network traffic data, sensitive data information in the network traffic data is identified, and associated data of the sensitive data information is constructed; the associated data comprises transmission information, port information and protocol of the sensitive data information; based on the sensitive data information, the associated data, and traffic characteristics, a security posture assessment result is obtained; the traffic characteristics comprise the distribution of traffic rate and packet size; based on the sensitive data information and the security posture assessment result, correlation analysis is performed to obtain a correlation analysis result; the correlation analysis result is used to identify an attack path associated with the sensitive data information; and data security protection is performed based on the correlation analysis result. Through deep analysis of network traffic, accurate identification of sensitive data, real-time perception of security posture, and deep tracing of attack paths are realized, accurate identification of sensitive data is realized, data leakage risk is reduced, privacy is protected, and a dynamic and intelligent data security protection solution for multiple industries is provided. Real-time monitoring, threat early warning and emergency response requirements in high security level scenarios are met. BRIEF DESCRIPTION OF DRAWINGS
[0043] The accompanying drawings, which are incorporated herein and form a part of the specification, illustrate embodiments consistent with the present application and, together with the description, further serve to explain the principles of the present application.
[0044] Figure 1 A flowchart of a data security protection method according to an embodiment of the present application is provided.
[0045] Figure 2 A structural schematic diagram of a data security protection device according to an embodiment of the present application is provided.
[0046] Figure 3 A flowchart of a data security protection device according to another embodiment of the present application is provided.
[0047] Figure 4 A structural schematic diagram of an electronic device according to the present application is provided.
[0048] Through the above-described drawings, specific embodiments of the present application have been shown, and more detailed descriptions will be provided in the following. These drawings and textual descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. DETAILED DESCRIPTION
[0049] The exemplary embodiments will be described in detail herein with reference to the attached drawings. The following description is made with reference to the accompanying drawings in which like reference numerals refer to like elements, unless the context of use indicates otherwise. The following description of exemplary embodiments is not representative of all embodiments consistent with the present application. Rather, it is merely an example of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0050] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data comply with the relevant laws, regulations and standards of the country and region, necessary security measures are taken, public order and good customs are not violated, and appropriate operation portals are provided for the user to choose to authorize or refuse.
[0051] And the present application involves big data analysis of user information (including but not limited to personal biological characteristics, identity data, consumption data, asset data, electronic terminal operation data, etc.), and uses artificial intelligence technology for automatic decision-making, and makes technical solutions based on the automatic decision-making results that have a significant impact on personal rights and interests, provides the user with appropriate operation portals for the user to choose to agree or refuse the automatic decision-making results; if the user chooses to refuse, the expert decision-making process is entered.
[0052] It should be noted that the data security protection method, device, equipment, storage medium and program product provided by the present application can be used in the field of big data and the field of financial technology, and can also be used in any field other than the field of big data and the field of financial technology. The application field of the data security protection method, device, equipment, storage medium and program product in the present application is not limited.
[0053] This application focuses on the real-time monitoring and security protection needs of enterprises, government agencies, and internet platforms for sensitive information in network traffic. In today's digital age, business data transmitted over the network, such as customer identity information, transaction records, and technical documents, faces multiple security threats: on the one hand, data breaches are frequent, with attackers stealing sensitive data from network traffic, such as ID numbers, bank card numbers, and trade secrets, causing user privacy leaks or corporate losses; on the other hand, network attack methods are becoming increasingly sophisticated, such as APT attacks, ransomware, and DDoS attacks, making it difficult for traditional security measures to detect potential threats in a timely manner. For example, in the financial industry, banks need to monitor customer transaction data streams in real time to prevent the illegal interception of sensitive data such as bank card numbers and account information; in the medical field, patient electronic medical records must be protected when transmitted over the network; and in government agencies, the network transmission of confidential documents must be protected against unauthorized external release by internal personnel or theft by external attacks.
[0054] However, existing technologies struggle to accurately identify sensitive data amidst massive traffic volumes, suffer from poor timeliness in situational awareness, and overlook causal or hierarchical relationships among data items, resulting in insufficient in-depth analysis and a lag in responding to threats, making it impossible to promptly stop data leaks or attacks.
[0055] The data security protection method provided in this application achieves accurate identification of sensitive data, real-time perception of security status, and in-depth tracing of attack paths through deep analysis of network traffic. This accurately identifies sensitive data, reduces the risk of data leakage, and protects privacy. Secondly, it can reflect the security status of the network environment in real time and accurately, provide early warnings of potential threats, and reduce the probability of security incidents. It offers dynamic and intelligent data security protection solutions for multiple industries, meeting the needs of real-time monitoring, threat warning, and emergency response in high-security scenarios, and aims to solve the aforementioned technical problems of existing technologies.
[0056] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0057] like Figure 1 As shown, Figure 1 This is a flowchart illustrating a data security protection method provided in an embodiment of this application. The data security protection method includes the following steps:
[0058] Step S101: Obtain network traffic data; network traffic data includes plaintext traffic data and encrypted traffic data.
[0059] Specifically, at network key nodes, such as switches and routers, full network traffic is captured using network sniffing technology, such as the libpcap library, covering IP addresses, port numbers, protocol types, packet contents, and other information, which is stored in a distributed database or data lake. Clear text traffic data can be directly read and analyzed, while encrypted traffic data requires specific methods, such as decryption or traffic feature analysis, to obtain useful information.
[0060] In one embodiment, before step S101, the following steps are also included:
[0061] Zero-copy technology is used to directly map network traffic data to memory, and columnar storage format is used for structured parsing of traffic features.
[0062] Specifically, the zero-copy technology is a technique that reduces the number of data copies by directly mapping data from one buffer to another, avoiding unnecessary data copy operations; when processing network traffic data, zero-copy technology can directly map network traffic data to memory, thereby reducing the burden on the CPU and improving data processing efficiency. Columnar storage format is a data format that stores data by column, compared with traditional row storage format, columnar storage is more efficient in processing specific types of data, such as analysis and aggregation operations; columnar storage format can significantly improve data read speed, as it can only read the required columns, reducing I / O operations. This example combines zero-copy technology and columnar storage format to significantly improve data processing performance and efficiency; zero-copy technology reduces the number of data copies, reducing the burden on the CPU; columnar storage format improves data read and analysis efficiency; suitable for real-time analysis and processing of large-scale network traffic data, helping to quickly identify and respond to potential security threats.
[0063] Step S102, based on network traffic data, identifying sensitive data information in network traffic data, and constructing associated data of sensitive data information; the associated data includes transmission information, port information and protocol of sensitive data information.
[0064] Specifically, sensitive data information is identified from network traffic data, and associated data of these sensitive data is constructed. The associated data includes the transmission information (such as source IP, target IP) of the sensitive data, port information and protocol type, to help analyze the flow path and context of the sensitive data.
[0065] Step S103, based on sensitive data information, associated data, and traffic features, obtaining security posture assessment results; traffic features include traffic rate and packet size distribution.
[0066] Specifically, the security posture of a network is assessed by combining sensitive data information, associated data, and traffic characteristics to reflect whether there are potential security threats in the network. For example: Suppose we have identified sensitive data information and constructed associated data, and now we need to assess the security posture. The traffic characteristics are as follows: the traffic rate is 100 packets per second; the packet size distribution is 64 bytes (30%), 128 bytes (20%), 256 bytes (25%), 512 bytes (15%), and 1024 bytes (10%). By analyzing these data, the traffic rate is within the normal range, but the high proportion of 1024-byte packets in the packet size distribution indicates that a large amount of data may be being transmitted, requiring further investigation to determine if sensitive data leakage is involved; the security posture assessment result is: there is a potential data leakage risk in the network, and further investigation is required.
[0067] Step S104: Based on the sensitive data information and security situation assessment results, perform correlation analysis to obtain the correlation analysis results; the correlation analysis results are used to identify attack paths associated with the sensitive data information.
[0068] Specifically, by combining sensitive data information and security posture assessment results, correlation analysis is performed to identify attack paths associated with the sensitive data information, thereby analyzing possible attack paths and targets. For example: Suppose the security posture assessment results indicate a potential data breach risk. Correlation analysis is performed: Sensitive data information: Data packet 1 contains user login information; Security posture assessment results: There are a large number of 1024-byte data packets, which may involve the transmission of sensitive data; Correlation analysis results may show: The attack path starts from 192.168.1.100, transmits user login information to 192.168.1.200 via HTTPS, and then returns a large amount of data via HTTP, which may involve data breach.
[0069] Step S105: Perform data security protection based on the correlation analysis results.
[0070] Specifically, based on the results of the correlation analysis, corresponding data security protection measures are taken to prevent the leakage of sensitive data or the success of attacks.
[0071] This application achieves accurate identification of sensitive data, real-time awareness of security status, and in-depth tracing of attack paths through deep analysis of network traffic. It accurately identifies sensitive data, reduces the risk of data leakage, and protects privacy. Secondly, it can reflect the security status of the network environment in real time and accurately, provide early warning of potential threats, reduce the probability of security incidents, and provide dynamic and intelligent data security protection solutions for multiple industries, meeting the needs of real-time monitoring, threat warning, and emergency response in high-security scenarios.
[0072] In one embodiment, the correlation analysis results are sent to the user's display interface, where they are displayed as icons, maps, or timelines. Real-time monitoring, historical review, and multi-dimensional display functions are provided to help users quickly grasp the security situation.
[0073] In one embodiment, step S102 specifically includes the following steps:
[0074] Feature extraction is performed on plaintext traffic data to generate a sequence of plaintext feature vectors.
[0075] Specifically, useful features are extracted from plaintext traffic data and these features are organized into a feature vector sequence. The extracted features include the following: source IP address, destination IP address, port number, packet size, content type (such as login information, web page content, etc.).
[0076] Extract ciphertext statistical features from encrypted traffic data.
[0077] Specifically, statistical features are extracted from encrypted traffic data. Since the content of encrypted traffic cannot be read directly, some statistical features are usually extracted, such as packet size distribution, traffic rate, and encryption protocol type.
[0078] Sensitive data information is generated by fusing plaintext feature vector sequences and ciphertext statistical features through logistic regression.
[0079] Specifically, plaintext feature vector sequences and ciphertext statistical features are combined and fused using a logistic regression model to generate sensitive data information. Logistic regression is then used to predict whether the data contains sensitive information. For example, feature vector combinations: Data packet 1: [192.168.1.100,192.168.1.200,80,512,Login information,443,1024,100,Distribution 1]; Data packet 2: [192.168.1.200,192.168.1.100,80,256,Web page content,443,512,100,Distribution 2]; Assuming a pre-trained logistic regression model exists to predict whether data packets contain sensitive information; the model's input is the combined feature vectors, and the output is the probability that a data packet contains sensitive information. The logistic regression model predicts the probability of each data packet containing sensitive information, generating sensitive data information. For example, the model predicts that data packet 1 contains sensitive information with a probability of 0.9, and data packet 2 contains sensitive information with a probability of 0.1. The generated sensitive data information is as follows: Data packet 1: contains sensitive information (probability 0.9); Data packet 2: does not contain sensitive information (probability 0.1).
[0080] In one embodiment, feature extraction is performed on plaintext traffic data to generate a plaintext feature vector sequence, specifically including the following steps:
[0081] We use regular expression matching and dictionary matching to extract text features from plaintext traffic data.
[0082] The text features are used to generate a sequence of plaintext feature vectors through a multi-head attention mechanism.
[0083] In one embodiment, a sensitive data identification model is constructed using deep learning algorithms. This model combines natural language processing techniques (such as word segmentation and word embedding) to extract text features, accurately identifying sensitive data in various formats (such as TXT, PDF, and Word) and encrypted scenarios (such as content after decryption of SSL / TLS encrypted traffic). It supports custom sensitive data types to adapt to different business needs. When using a deep neural network to construct the identification model for deep feature extraction and classification, a multi-head attention mechanism is used to calculate the association weights between words in the text, transforming the input text into a high-dimensional feature vector sequence. ,in, (d is the feature dimension). The formula for calculating the attention score is as follows:
[0084]
[0085] For classification tasks, fully connected layers are used to map feature vectors to the classification probability space, and the model is optimized using the cross-entropy loss function, defined as:
[0086]
[0087] Where N is the sample size. For the true labels of the samples, The model predicts the probability that a sample is sensitive data.
[0088] Feature fusion in encrypted scenarios involves extracting statistical features of ciphertext, such as ciphertext length distribution, from SSL / TLS encrypted traffic. ( The length of the j-th ciphertext segment and the entropy value H (a measure of the degree of ciphertext disorder, reflecting whether it may be encrypted as sensitive plaintext) are calculated using the following formula:
[0089]
[0090] in, Let be the probability of ciphertext byte i appearing. The probability of sensitive data is calculated by fusing the plaintext feature vector sequence and the ciphertext statistical features through logistic regression. Where σ is the Sigmoid function, w1 and w2 are the feature weights, and b is the bias.
[0091] In one embodiment, step S103 specifically includes the following steps:
[0092] Based on sensitive data, related data, and traffic characteristics, anomaly scores are calculated.
[0093] Specifically, the flow rate r (the number of data packets per unit time) is calculated using the following formula: Where N is the number of data packets within the time window t; the mean μ and variance of the packet size distribution are statistically analyzed. The formulas are as follows: , ;in, Let be the size of the i-th data packet.
[0094] Anomaly detection is performed using an isolation forest, and a traffic anomaly score s(x) is calculated to reflect the degree of isolation between a sample and other samples. A higher score indicates a higher likelihood of an anomaly. The anomaly score calculation formula for sample x in the isolation forest is based on the average path length E(h(x)) of the sample in the tree structure, obtained through normalization:
[0095]
[0096] Wherein, c(n) is a normalization constant, which is related to the sample size n. In other embodiments, the traffic anomaly score can also be calculated using other formulas, which are not limited herein.
[0097] A judgment matrix is constructed based on traffic anomaly score, sensitive data information density, intelligence relevance, and the corresponding weight values of traffic anomaly score, sensitive data information density, and intelligence relevance; intelligence relevance is the degree of matching between current traffic characteristics and known threat intelligence.
[0098] Security situation assessment results are obtained through a judgment matrix.
[0099] Specifically, a hierarchical analysis model is constructed to determine the weights of indicators such as traffic anomaly degree, sensitive data density, and intelligence relevance. By constructing a judgment matrix and calculating eigenvectors to obtain the weights of each indicator, the security situation value S is generated by fusing the values of each indicator.
[0100]
[0101] in, This represents the normalized value of the i-th indicator. For data breach scenarios in the financial industry, compliance risk weights can be introduced. For example, when sensitive data such as customer bank card numbers or transaction records are leaked, the corresponding indicator weights can be increased to more accurately reflect the security situation of financial operations.
[0102] In one embodiment, step S104 specifically includes the following steps:
[0103] Based on sensitive data and security situation assessment results, threat events and asset information are obtained.
[0104] Specifically, threat weights and asset value weights are introduced. For event items in a transaction cluster (such as access to sensitive databases, outbound traffic, etc.), different weights are assigned based on the threat level of the event (e.g., malicious IP access has a high threat level) and the asset value involved (e.g., financial customer information assets have high asset value). When an anomaly is detected by situational awareness, the asset value and business functions of the corresponding network node are queried in the asset database. Combined with the characteristics of historical attack events, such as attack methods and vulnerability exploits, it is determined whether the current anomaly is a new attack or a continuation of a historical attack. The correlation between the anomaly event and past security risks is traced to assist in the analysis of attack intent and the possible scope of impact.
[0105] Using association rules and time series analysis models, prediction results for sensitive data information are generated; these prediction results are used to predict the development trend of sensitive data information.
[0106] Based on the prediction results, correlation analysis results are generated.
[0107] Specifically, a Long Short-Term Memory (LSTM) network is used to capture the temporal dependencies of security events, and the event sequence is analyzed. (Each event) (Represented by vectors), the hidden state is updated through LSTM units. :
[0108]
[0109] By leveraging attention mechanisms to highlight the temporal impact of key events, the importance weights of each event are calculated. :
[0110] ,
[0111] Where u is the attention vector and c is the context representation. Combining a causal graph model, the causal relationships between events are analyzed, spurious associations are eliminated, and genuine attack causal chains such as "vulnerability exploitation - sensitive data theft - data leakage" are identified.
[0112] In one embodiment, association rules and time series analysis models are used to generate prediction results for sensitive data information, specifically including the following steps:
[0113] Construct a graph model of the attack path for sensitive data information, and identify the key nodes in the attack path based on the graph model.
[0114] Based on key nodes, predictive results for sensitive data information are generated.
[0115] Specifically, if an attack-related anomaly is detected, time-series data of traffic rates is analyzed, and the ARIMA model is used to predict traffic trends and calculate prediction residuals. Source IPs are clustered using the K-Means clustering algorithm, and attack source clusters are identified based on the clustering results (such as cluster centers and intra-cluster distances). For example, source IPs that are close to each other and exhibit similar attack behaviors are grouped together to locate the IP range and network area of the attack initiator and trace the attack source. For anomalies in sensitive data propagation, the transmission frequency of sensitive data across different IPs and ports is statistically analyzed, and propagation heatmaps and propagation graphs are constructed (nodes represent network entities, and edges represent data transmission relationships). The PageRank algorithm is used to calculate the importance of nodes, identifying key nodes such as high-frequency forwarding IPs and data leakage exit nodes, thus clarifying the critical paths and main leakage points of sensitive data propagation.
[0116] This embodiment integrates sensitive data identification results, situational awareness analysis results, and external threat intelligence, utilizing improved association rule mining and time-series analysis to construct attack paths. For example, it mines association rules and time-series relationships for the sequence: phishing email inducement (Event A) → credential theft (Event B) → sensitive database access (Event C) → data outflow (Event D). Combining these with timestamps from traffic logs and system logs, and the network entities involved (IPs, accounts, etc.), the attack steps are reconstructed. By querying the specific operations corresponding to each event (such as the content of the phishing email, the type of stolen credentials, the database tables accessed, etc.), the attack source and intermediate links are accurately traced.
[0117] like Figure 2 As shown, Figure 2 This is a schematic diagram of the structure of a data security protection device provided in an embodiment of this application. The data security protection device 200 includes: a data acquisition module 201, used to acquire network traffic data; the network traffic data includes plaintext traffic data and encrypted traffic data; a sensitive data identification module 202, used to identify sensitive data information in the network traffic data based on the network traffic data, and construct associated data of the sensitive data information; the associated data includes transmission information, port information and protocol of the sensitive data information; a situational awareness analysis module 203, used to obtain security situation assessment results based on sensitive data information, associated data, and traffic characteristics; the traffic characteristics include the distribution of traffic rate and data packet size; an association analysis module 204, used to perform association analysis based on sensitive data signals and security situation assessment results, and obtain association analysis results; the association analysis results are used to identify attack paths associated with sensitive data information; and a processing module 205, used to perform data security protection based on the association analysis results.
[0118] like Figure 3 As shown, Figure 3 A flowchart of a data security protection device provided in another embodiment of this application. (In conjunction with...)Figure 1 , Figure 3 This study comprehensively analyzes and understands the data security protection of this application, integrates sensitive data identification results, situational awareness analysis results and external threat intelligence, and constructs attack paths by utilizing improved association rule mining and time series analysis.
[0119] In one embodiment, the sensitive data identification module 202 is used to extract features from plaintext traffic data to generate a plaintext feature vector sequence; extract ciphertext statistical features from encrypted traffic data; and perform logistic regression fusion on the plaintext feature vector sequence and the ciphertext statistical features to generate sensitive data information.
[0120] In one embodiment, the sensitive data identification module 202 is used to obtain text features from plaintext traffic data by using regular expression matching and dictionary matching; and to generate a plaintext feature vector sequence by using a multi-head attention mechanism to process the text features.
[0121] In one embodiment, the situational awareness analysis module 203 is used to calculate a traffic anomaly score based on sensitive data information, related data, and traffic characteristics; construct a judgment matrix based on the traffic anomaly score, sensitive data information density, intelligence relevance, and the corresponding weight values of the traffic anomaly score, sensitive data information density, and intelligence relevance; the intelligence relevance is the degree of matching between the current traffic characteristics and known threat intelligence; and obtain the security situation assessment result through the judgment matrix.
[0122] In one embodiment, the correlation analysis module 204 is used to obtain threat events and asset information based on sensitive data information and security situation assessment results; generate prediction results of sensitive data information by using correlation rules and time series analysis models; the prediction results are used to predict the development trend of sensitive data information; and generate correlation analysis results based on the prediction results.
[0123] In one embodiment, the correlation analysis module 204 is used to construct a graph model of the attack path of sensitive data information, and determine the key nodes in the attack path based on the graph model; based on the key nodes, it generates the prediction result of sensitive data information.
[0124] In one embodiment, the sensitive data identification module 202 is used to directly map network traffic data into memory using zero-copy technology and to perform structured parsing of traffic features using columnar storage format.
[0125] The data security protection device 200 provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.
[0126] This application provides an electronic device, including: a processor, and a memory communicatively connected to the processor;
[0127] The memory stores instructions that the computer executes;
[0128] The processor executes computer-executable instructions stored in memory to implement any of the methods described above.
[0129] Figure 4 A schematic diagram of the structure of the electronic device provided in this application. Figure 4 As shown, the electronic device 400 provided in this embodiment includes at least one processor 401 and a memory 402. Optionally, the electronic device 400 further includes a communication component 403. The processor 401, memory 402, and communication component 403 are connected via a bus 404.
[0130] In a specific implementation, at least one processor 401 executes computer execution instructions stored in memory 402, causing at least one processor 401 to perform the above-described method.
[0131] The specific implementation process of processor 401 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0132] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.
[0133] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.
[0134] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.
[0135] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0136] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.
[0137] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.
[0138] When integrated units / modules are implemented in hardware, the hardware can be digital circuits, analog circuits, etc. The physical implementation of the hardware structure includes, but is not limited to, transistors, memristors, etc. Unless otherwise specified, the processor can be any suitable hardware processor, such as a CPU, GPU, FPGA, DSP, and ASIC, etc. Unless otherwise specified, the storage unit can be any suitable magnetic or magneto-optical storage medium, such as Resistive Random Access Memory (RRAM), Dynamic Random Access Memory (DRAM), Static Random Access Memory (SRAM), Enhanced Dynamic Random Access Memory (EDRAM), High-Bandwidth Memory (HBM), Hybrid Memory Cube (HMC), etc.
[0139] If the integrated unit / module is implemented as a software program module and sold or used as an independent product, it can be stored in a computer-readable storage device (CMD). Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned memory includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0140] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.
[0141] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0142] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A data security protection method, characterized in that, include: Obtain network traffic data; The network traffic data includes plaintext traffic data and encrypted traffic data; Based on the network traffic data, sensitive data information in the network traffic data is identified, and associated data of the sensitive data information is constructed; the associated data includes the transmission information, port information, and protocol of the sensitive data information. Based on the aforementioned sensitive data, related data, and traffic characteristics, a security situation assessment result is obtained; the traffic characteristics include the distribution of traffic rate and data packet size. Based on the sensitive data and the security situation assessment results, a correlation analysis is performed to obtain the correlation analysis results; The correlation analysis results are used to identify attack paths associated with the sensitive data information; Data security protection is carried out based on the results of the correlation analysis.
2. The method according to claim 1, characterized in that, Based on the network traffic data, sensitive data information is identified within the network traffic data, specifically including: Feature extraction is performed on the plaintext traffic data to generate a plaintext feature vector sequence; Extract ciphertext statistical features from the encrypted traffic data; The plaintext feature vector sequence and the ciphertext statistical features are fused by logistic regression to generate sensitive data information.
3. The method according to claim 2, characterized in that, The step of extracting features from the plaintext traffic data to generate a plaintext feature vector sequence specifically includes: The plaintext traffic data is used to obtain text features by regular expression matching and dictionary matching. The text features are used to generate a sequence of plaintext feature vectors through a multi-head attention mechanism.
4. The method according to claim 1, characterized in that, The process of obtaining security situation assessment results based on the sensitive data information, related data, and traffic characteristics specifically includes: Based on the aforementioned sensitive data, related data, and traffic characteristics, a traffic anomaly score is calculated. A judgment matrix is constructed based on the traffic anomaly score, sensitive data information density, intelligence relevance, and the corresponding weight values of the traffic anomaly score, sensitive data information density, and intelligence relevance; the intelligence relevance is the degree of matching between the current traffic characteristics and known threat intelligence. The security situation assessment result is obtained through the judgment matrix.
5. The method according to claim 1, characterized in that, The correlation analysis based on the sensitive data information and the security situation assessment results, to obtain the correlation analysis results, specifically includes: Based on the sensitive data and the security situation assessment results, threat events and asset information are obtained; The association rules and time series analysis model are used to generate prediction results for the sensitive data information; the prediction results are used to predict the development trend of the sensitive data information. Based on the prediction results, the correlation analysis results are generated.
6. The method according to claim 5, characterized in that, The process of generating prediction results for the sensitive data information using association rules and time series analysis models specifically includes: Construct a graph model of the attack path for the sensitive data information, and determine the key nodes in the attack path based on the graph model; Based on the key nodes, prediction results for the sensitive data information are generated.
7. The method according to claim 1, characterized in that, Before acquiring network traffic data, the process also includes: Zero-copy technology is used to directly map the network traffic data into memory, and columnar storage format is used to perform structured parsing of traffic characteristics.
8. A data security protection device, characterized in that, include: The data acquisition module is used to acquire network traffic data; The network traffic data includes plaintext traffic data and encrypted traffic data; A sensitive data identification module is used to identify sensitive data information in the network traffic data based on the network traffic data, and to construct associated data of the sensitive data information; the associated data includes the transmission information, port information and protocol of the sensitive data information; The situational awareness analysis module is also used to obtain security situation assessment results based on the sensitive data information, related data, and traffic characteristics; the traffic characteristics include the distribution of traffic rate and data packet size. The correlation analysis module is used to perform correlation analysis based on the sensitive data signals and the security situation assessment results to obtain the correlation analysis results; The correlation analysis results are used to identify attack paths associated with the sensitive data information; The processing module is used to perform data security protection based on the correlation analysis results.
9. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 7.
11. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1 to 7.