Data breach source detection methods, devices, servers, and storage media

By generating session watermark binary sequences and adjusting data packet delays on internal network terminals, and embedding watermark encoding, the problem of tracing the source of data leakage is solved, enabling accurate source identification and accountability in complex network environments.

CN121603309BActive Publication Date: 2026-07-17TIANJIN POLYTECHNIC UNIV

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TIANJIN POLYTECHNIC UNIV
Filing Date
2026-01-29
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

Existing technologies cannot accurately trace the source of data leaks during transmission between internal and external networks, especially after data has been forwarded, repackaged, or encrypted multiple times after legitimate transmission, making it difficult to trace the leak path and identify the responsible party.

Method used

When a transmission is initiated from an internal network terminal, a session watermark binary sequence is generated, the data stream is divided into multiple watermark binary encoding windows, the data packet delay is adjusted to embed the watermark encoding, and the centroid is extracted from the outflow traffic for similarity matching to determine the source of data leakage.

Benefits of technology

It enables tracking whether data has been leaked to the external network and the responsible party without intruding on the data itself, reducing the impact on business latency and bandwidth, and accurately determining the source of the leak even after multiple forwardings.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121603309B_ABST
    Figure CN121603309B_ABST
Patent Text Reader

Abstract

This invention discloses a method, apparatus, server, and storage medium for detecting data leakage sources, belonging to the field of network security. The method includes: when a terminal on an internal network initiates an outward transmission service request, generating a session watermark binary sequence based on the service request information; dividing the data stream into multiple encoding windows according to a preset duration window; assigning corresponding codes to the encoding windows according to the order relationship between the watermark and the encoding windows; adjusting the delay of the data packets in the encoding windows according to the codes, and adjusting the center of gravity of the data packets in the encoding windows to express the watermark binary code using the center of gravity; acquiring the outflow traffic, extracting the center of gravity from the traffic packets of the outflow traffic, obtaining a verification session watermark using the center of gravity, performing similarity matching between the verification session watermark and the session watermark, and determining the source of data leakage using the decrypted session watermark binary sequence. This method achieves data leakage detection and accountability without data intrusion.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method, apparatus, server, and storage medium for detecting the source of data leakage. Background Technology

[0002] With the development of digital business, a large amount of sensitive information is generated, and sensitive data is continuously transmitted between the system and the outside world through the network. Once intercepted or copied in the transmission path, or disseminated through unauthorized terminals and channels, it will bring serious data risks.

[0003] To mitigate data breach risks, technologies such as access control and authentication, encryption and secure channels, content-based data breach protection, and traffic-based intrusion detection and anomaly analysis can be employed. However, access control, log auditing, and content-based data breach protection primarily function within business systems or at the first-hop network exit. Once sensitive data is legally accessed or exported, it may be repeatedly forwarded, repackaged, or re-encrypted by users through personal terminals, third-party platforms, cloud storage, and other channels. Along these subsequent propagation paths, the original access control and content detection often fail to provide sustained effectiveness, making it impossible to definitively determine whether data has been leaked and accurately trace the source of the leak. Encryption and secure channels primarily ensure the confidentiality and integrity of data during transmission but do not directly provide granular tracing capabilities regarding "who transmitted what data in what session and to what location." Therefore, these methods cannot accurately trace the source of a data breach. Summary of the Invention

[0004] This invention provides a method, apparatus, server, and storage medium for detecting the source of data leakage, thereby solving the technical problem in the prior art that internal networks cannot accurately trace the source of data leakage when connected to external networks.

[0005] In a first aspect, embodiments of the present invention provide a method for detecting the source of data leakage, including:

[0006] When a terminal on the internal network initiates an external transmission service request, a session watermark binary sequence is generated based on the service request information;

[0007] The data stream corresponding to this session is divided into multiple watermark binary encoding windows according to the preset duration window;

[0008] Assign corresponding binary codes to the watermark binary encoding windows according to the order of the session watermark binary sequence and the watermark binary encoding window;

[0009] The delay of the data packets in the watermark binary encoding window is adjusted according to the binary encoding, and the center of gravity of the data packets in the watermark binary encoding window is adjusted so as to express the watermark binary encoding using the center of gravity of the data packets.

[0010] The outflow traffic is obtained, the centroid is extracted from the outflow traffic packets, and the verification session watermark binary sequence is obtained using the centroid. The verification session watermark binary sequence is matched with the session watermark binary sequence for similarity. When the similarity exceeds a preset threshold, the source of data leakage is determined using the decrypted session watermark binary sequence.

[0011] Secondly, embodiments of the present invention also provide a data leakage source detection device, comprising:

[0012] The generation module is used to generate a session watermark binary sequence based on the service request information when a terminal on the internal network initiates an external transmission service request.

[0013] The segmentation module is used to divide the data stream corresponding to this session into multiple watermark binary encoding windows according to a preset duration window;

[0014] The allocation module is used to allocate the corresponding binary code to the watermark binary encoding window according to the order of the session watermark binary sequence and the watermark binary encoding window;

[0015] The adjustment module is used to adjust the delay of the data packets in the watermark binary encoding window according to the binary encoding, and to adjust the center of gravity of the data packets in the watermark binary encoding window so as to express the watermark binary encoding using the center of gravity of the data packets.

[0016] The determination module is used to acquire outflow traffic, extract the centroid from the outflow traffic packets, obtain the verification session watermark binary sequence using the centroid, perform similarity matching between the verification session watermark binary sequence and the session watermark binary sequence, and determine the source of data leakage using the decrypted session watermark binary sequence when the similarity exceeds a preset threshold.

[0017] Thirdly, embodiments of the present invention also provide a server, comprising:

[0018] One or more processors;

[0019] Storage device for storing one or more programs.

[0020] When the one or more programs are executed by the one or more processors, the one or more processors implement the data leakage source detection method provided in the above embodiments.

[0021] Fourthly, embodiments of the present invention also provide a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform the data leakage source detection method provided in the above embodiments.

[0022] The data leakage source detection method, apparatus, server, and storage medium provided in this invention generate a session watermark binary sequence based on the service request information when a terminal on an internal network initiates an outward transmission service request. The data stream corresponding to this session is divided into multiple watermark binary encoding windows according to a preset duration window. Binary codes are assigned to the watermark binary encoding windows according to the order of the session watermark binary sequence and the watermark binary encoding windows. The delay of the data packets in the watermark binary encoding window is adjusted according to the binary codes, and the center of gravity of the data packets in the watermark binary encoding window is adjusted to express the watermark binary code using the center of gravity. Outward traffic is acquired, and the center of gravity is extracted from the outward traffic packets. A verification session watermark binary sequence is obtained using the center of gravity. The verification session watermark binary sequence is matched with the session watermark binary sequence for similarity. When the similarity exceeds a preset threshold, the decrypted session watermark binary sequence is used to determine the source of the data leakage. A watermark bound to the user / session can be embedded in the packet time domain, enabling detection of whether system data has been leaked to the external network and tracing of the responsible party without data intrusion, while minimizing the impact on service latency and bandwidth. Even after multiple forwardings, the embedded watermark can still be retained, thus determining whether there is a data leak and the corresponding internal entity. Attached Figure Description

[0023] Other features, objects, and advantages of the invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings:

[0024] Figure 1 This is a flowchart illustrating the data leakage source detection method provided in Embodiment 1 of the present invention;

[0025] Figure 2 This is a flowchart illustrating the data leakage source detection method provided in Embodiment 2 of the present invention;

[0026] Figure 3 This is a schematic diagram of the data leakage source detection device provided in Embodiment 3 of the present invention;

[0027] Figure 4 This is a schematic diagram of the server structure provided in Embodiment 4 of the present invention. Detailed Implementation

[0028] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present invention, and not all of the structures.

[0029] Example 1

[0030] Figure 1 This is a flowchart illustrating the data leakage source detection method provided in Embodiment 1 of the present invention. This embodiment is applicable to the detection of data leakage sources when data is transmitted from an internal network to an external network. The method can be executed by a data leakage source detection device and specifically includes the following steps:

[0031] Step 110: When a terminal on the internal network initiates an external transmission service request, a session watermark binary sequence is generated based on the service request information.

[0032] In this embodiment, a hospital internal network system is used as an example. However, the method provided in this embodiment is not limited to hospital internal network systems. It can also be applied to internal networks of schools, government departments, industrial and mining enterprises, etc., and the implementation method is the same.

[0033] With the widespread adoption of digital health, telemedicine, and electronic medical records, medical institutions have extensively deployed various business systems, including Hospital Information Systems (HIS), Electronic Medical Record Systems (EMR), Picture Archiving and Communication Systems (PACS), mobile ward round systems, and internet hospitals. These systems provide services externally via intranets, dedicated networks, and the internet, carrying a large amount of sensitive patient-related information, including basic identity information, medical records, imaging data, and laboratory reports. This sensitive data is continuously transmitted between the internal and external systems via the network. If this data is intercepted or copied during transmission, or disseminated outside the hospital through unauthorized terminals and channels, it poses serious risks to patient privacy protection, medical institution compliance, and regulatory auditing.

[0034] Within the hospital system, the terminal devices include, but are not limited to, doctor workstations, mobile terminals, and department servers. When a terminal device initiates a business request that requires the external transmission of medical data, such as pushing examination results to an external service, a session watermark binary sequence is generated based on the business request information. For example, a watermark is first generated and then converted into binary information to form a session watermark binary sequence.

[0035] Optionally, the service request information includes: user ID and session SID; correspondingly, generating the session watermark binary sequence based on the service request information includes: using a preset key, user ID, and session SID, and employing a pseudo-random sequence generation algorithm to generate the session watermark binary sequence.

[0036] In the hospital system, unique user identifiers (IDs) are assigned to users with access or external sharing permissions, such as doctor accounts, department accounts, and system accounts. The business system generates a session identifier (SID) for this interaction. Using a pre-defined key, such as the system public key, a pseudo-random sequence generation algorithm is employed to generate a watermark sequence bound to this session.

[0037] Step 120: Divide the data stream corresponding to this session into multiple watermark binary encoding windows according to the preset duration window.

[0038] For example, medical service flows originating from terminal devices and destined for external or cross-network segments can be identified based on source / destination IP addresses, port numbers, protocol types, and application layer characteristics. These flows are then divided into multiple flow windows according to preset rules. Flow windows can be divided by the number of data packets (e.g., one window for every N data packets), or by time (e.g., one window for every T milliseconds), or a combination of both can be used to determine the window size, thus dividing the data flow into multiple watermarked binary encoded windows.

[0039] Step 130: Assign the corresponding binary code to the watermark binary encoding window according to the order of the session watermark binary sequence and the watermark binary encoding window.

[0040] In this embodiment, the session watermark needs to be embedded into the data stream. For example, the data stream can be embedded into multiple watermark binary encoding windows. During the embedding process, it is necessary to establish a matching relationship between elements in the session watermark binary sequence, i.e., one bit of the binary code, and the watermark binary encoding window. For example, one bit of the binary code can be matched with one watermark binary encoding window, or one bit of the binary code can be matched with multiple watermark binary encoding windows, thereby assigning a corresponding binary code to each watermark binary encoding window.

[0041] Step 140: Adjust the delay of the data packets in the watermark binary encoding window according to the binary encoding, and adjust the center of gravity of the data packets in the watermark binary encoding window so as to express the watermark binary encoding using the center of gravity of the data packets.

[0042] Optionally, the embedding of binary codes can be achieved by utilizing the transmission time interval of data packets within the watermark binary encoding window. For example, the transmission time of the entire data packet can be delayed, or the transmission time of a portion of the data packets can be delayed. During normal transmission, the data packets within the watermark binary encoding window are evenly distributed, with the center of gravity of the entire data packet located in the middle of the watermark binary encoding window. Through the aforementioned adjustment, "1" or "0" from the binary code can be embedded into this watermark binary encoding window, while the normal watermark binary encoding window, without delay, is set to a different binary code. Furthermore, the center of gravity of the entire data packet within a preset number of consecutive watermark binary encoding windows can be adjusted to sequentially embed consecutive watermark binary codes into multiple consecutive watermark binary encoding windows, facilitating subsequent detection.

[0043] While the above method can achieve the embedding of binary codes, it is prone to errors during detection when there is network jitter. Therefore, in this embodiment, the method of adjusting the delay of data packets in the watermark binary encoding window and adjusting the center of gravity of data packets in the watermark binary encoding window can be optimized as follows: When performing the first binary encoding, two consecutive watermark binary encoding windows are selected, and the data packets in the first watermark binary encoding window are delayed according to a first delay rate, while the data in the second watermark binary encoding window is delayed according to a second delay rate; when performing the second binary encoding, two consecutive watermark binary encoding windows are selected, and a preset number of data packets from the end of the first watermark binary encoding window are delayed according to the second delay rate, so that some delayed data packets are placed into the second watermark binary encoding window.

[0044] For example, the modulation scheme for bit "1" is as follows: Two consecutive time windows, denoted as P and Q, are selected, each with a duration of T / 2. Within window P, a slight delay is applied to the data packets, causing most packets to concentrate at the time offset position T / 2-ta within window P. If the delay is larger, some packets will be pushed into window Q. Simultaneously, the data packets within window Q are also adjusted to the vicinity of T / 2-ta within window Q. Because the packet distribution in both windows shifts simultaneously, the centroids of both windows move to the right, allowing the receiver to recognize this structure as bit "1".

[0045] Modulation of bit "0": For bit 0, adjacent windows P' and Q' are selected. In P', only the latter half of the data packet is delayed, pushing a portion of the packet into Q'. This shifts the time centroid of P' forward, while the centroid of Q' shifts forward accordingly due to the received data packets moving across the window, resulting in a centroid state significantly different from that of bit 1. More importantly, this strategy completes encoding without additional adjustments to Q'. The first and second delay rates can be the same or different, with the primary consideration being whether they do not affect normal communication.

[0046] Using the above method, a stable and detectable centroid shift pattern can be constructed in the time domain, while having minimal impact on the distribution of normal traffic. This method is suitable for watermark embedding under complex network conditions such as multi-hop, jitter, and high noise, thereby improving the accuracy of binary code embedding.

[0047] Step 150: Obtain outflow traffic, extract centroids from the outflow traffic packets, use the centroids to obtain the verification session watermark binary sequence, perform similarity matching between the verification session watermark binary sequence and the session watermark binary sequence, and when the similarity exceeds a preset threshold, use the decrypted session watermark binary sequence to determine the source of data leakage.

[0048] In this embodiment, the watermark embedding node forwards the medical service flow after watermark embedding to the hospital's core network and external network; the device leading to the external network can be equipped with a mirror port to continuously receive outbound traffic, and the corresponding outbound traffic can be determined by the five-tuple of the service flow (source address, destination address, source port, destination port, protocol type).

[0049] In addition, relevant information about the watermark embedding can be recorded. For example, this may include the user ID, session ID (SID), watermark sequence W, the five-tuple of the service flow (source address, destination address, source port, destination port, protocol type), flow window parameters, and embedding strategy, for subsequent comparison. When it is necessary to detect whether there is system data leakage within a certain period, target connections are filtered according to the condition that the source address is an internal hospital address and the destination address is an external server. The flow window for each connection is divided according to the same rules as in the embedding stage.

[0050] For example, this may include: dividing outgoing traffic into verification windows according to a preset duration window, obtaining the corresponding arrival time of data packets in the verification window, determining the distribution of traffic packets based on the arrival time to obtain the center of gravity of the verification window, and obtaining a verification session watermark binary sequence based on the centers of gravity of multiple verification windows. Specifically, each connection is divided into flow windows according to the same rules as in the embedding phase.

[0051] Alternatively, the centroid can be calculated in the following way:

[0052] The centroid of the verification window is calculated using the following method:

[0053] ;

[0054] Let I be the centroid of the current verification window, and let I be the arrival time series within each window interval of duration I. s is the start time of the current window interval, and m is the number of data packets in the current interval I.

[0055] The above method can be used not only for the centroid of a single verification window, but also for multiple consecutive windows, especially the centroids of two consecutive windows. Using this method, the centroid can be accurately calculated, and the verification session watermark binary sequence can be obtained from the centroid, thus revealing the source of the data.

[0056] This embodiment generates a session watermark binary sequence based on the service request information when a terminal on the internal network initiates an outward transmission service request. The data stream corresponding to this session is divided into multiple watermark binary encoding windows according to a preset duration window. Binary codes are assigned to the watermark binary encoding windows according to the order of the session watermark binary sequence and the watermark binary encoding windows. The delay of the data packets in the watermark binary encoding window is adjusted based on the binary codes, and the center of gravity of the data packets in the watermark binary encoding window is adjusted to express the watermark binary code using the center of gravity. Outward traffic is acquired, and the center of gravity is extracted from the outward traffic packets. The session watermark binary sequence is then used to obtain a verification session watermark binary sequence. The verification session watermark binary sequence is matched with the session watermark binary sequence for similarity. When the similarity exceeds a preset threshold, the source of data leakage is determined using the decrypted session watermark binary sequence. A watermark bound to the user / session can be embedded in the packet time domain, enabling detection of system data leakage to the external network and tracing of responsible parties without data intrusion, while minimizing the impact on service latency and bandwidth. Even after multiple forwardings, the embedded watermark can still be retained, thus determining whether there is a data leak and the corresponding internal entity.

[0057] Example 2

[0058] Figure 2This is a flowchart illustrating the data leakage source detection method provided in Embodiment 2 of the present invention. Based on the above embodiment, before dividing the data stream corresponding to the current session into multiple watermark binary encoding windows according to a preset duration window, the method may further include the following steps: selecting a second preset number of consecutive data packets, generating an auto-incrementing data packet sequence, and adjusting the order of the data packets in the auto-incrementing data packet sequence; and specifically optimizing the division of the data stream corresponding to the current session into multiple watermark binary encoding windows according to a preset duration window as follows: dividing the data stream after the adjusted auto-incrementing data packet sequence into multiple watermark binary encoding windows according to a preset duration window.

[0059] See Figure 2 The data leakage source detection method includes:

[0060] Step 210: When a terminal on the internal network initiates an external transmission service request, a session watermark binary sequence is generated based on the service request information.

[0061] Step 220: Select a second preset number of consecutive data packets, generate an auto-incrementing data packet sequence, and adjust the order of the data packets in the auto-incrementing data packet sequence.

[0062] Because network fluctuations can cause disturbances, to ensure the accuracy of synchronization between watermark embedding and detection, it is necessary to provide an indication for the portion of the data stream where the watermark is embedded. This allows for the determination of the starting point of the watermark's binary encoding window during subsequent detection. In this embodiment, a similar interference-like marking method is used to accurately capture the starting point of the embedded watermark during detection.

[0063] For example, it can be implemented in the following way:

[0064] By utilizing the auto-incrementing property of the IP-ID field in data packets, four consecutive packets are encoded into a synchronization vector. Let the sequence of data packets in the target flow be... By setting the embedding probability through pseudo-random operations, four consecutive packets are randomly selected. And define the ID field value in the IP header of these four consecutive packets as... It is encoded as a synchronization vector according to the following rules:

[0065] Based on the characteristics of packet IP-ID, the following should be met under normal circumstances:

[0066] ,

[0067] ,

[0068] .

[0069] The sequence is adjusted to the following form to complete the encoding of the synchronization vector:

[0070] ,

[0071] ,

[0072] .

[0073] Step 230: Divide the data stream after the adjusted auto-incrementing data packet sequence into multiple watermark binary encoding windows according to a preset duration window.

[0074] Step 240: Assign the corresponding binary code to the watermark binary encoding window according to the order of the session watermark binary sequence and the watermark binary encoding window.

[0075] Step 250: Adjust the delay of the data packets in the watermark binary encoding window according to the binary encoding, and adjust the center of gravity of the data packets in the watermark binary encoding window so as to express the watermark binary encoding using the center of gravity of the data packets.

[0076] Step 260: Obtain outflow traffic. Based on the order of the data packets, determine whether it is an adjusted auto-incrementing data packet sequence. If it is an adjusted auto-incrementing data packet sequence, extract the centroid from the outflow traffic packets. Use the centroid to obtain the verification session watermark binary sequence. Perform similarity matching between the verification session watermark binary sequence and the session watermark binary sequence. When the similarity exceeds a preset threshold, use the decrypted session watermark binary sequence to determine the source of data leakage.

[0077] For example, the order of data packets can be used to determine whether it is an adjusted auto-incrementing data packet sequence during the watermark embedding process. After determining that it is an auto-incrementing data packet sequence, it can be used as a starting point marker to extract the centroid from subsequent traffic packets, thereby extracting the session watermark binary sequence, matching it with the watermark recorded during the embedding process, determining the corresponding approximation, and thus determining the source of data leakage.

[0078] This embodiment adds the following steps: selecting a second preset number of consecutive data packets, generating an auto-incrementing data packet sequence, and adjusting the order of the data packets in the auto-incrementing data packet sequence; specifically, the data stream corresponding to this session is divided into multiple watermark binary encoding windows according to a preset duration window. This is further optimized by dividing the data stream after the adjusted auto-incrementing data packet sequence into multiple watermark binary encoding windows according to a preset duration window. Using this method, an accurate starting point can be set for the watermark binary encoding window, facilitating accurate identification of the watermark binary encoding window during subsequent detection, and further improving the accuracy of determining the source of leaked data.

[0079] Example 3

[0080] Figure 3 This is a schematic diagram of the data leakage source detection device provided in Embodiment 3 of the present invention. See also... Figure 3 The data leakage source detection device includes:

[0081] The generation module 310 is used to generate a session watermark binary sequence based on the service request information when a terminal on the internal network initiates an external transmission service request.

[0082] The segmentation module 320 is used to divide the data stream corresponding to this session into multiple watermark binary encoding windows according to a preset duration window;

[0083] The allocation module 330 is used to allocate the corresponding binary code to the watermark binary encoding window according to the order relationship between the session watermark binary sequence and the watermark binary encoding window;

[0084] The adjustment module 340 is used to adjust the delay of the data packets in the watermark binary encoding window according to the binary encoding, and adjust the center of gravity of the data packets in the watermark binary encoding window so as to express the watermark binary encoding using the center of gravity of the data packets.

[0085] The determination module 350 is used to acquire outflow traffic, extract the centroid from the outflow traffic packets, obtain the verification session watermark binary sequence using the centroid, perform similarity matching between the verification session watermark binary sequence and the session watermark binary sequence, and determine the source of data leakage using the decrypted session watermark binary sequence when the similarity exceeds a preset threshold.

[0086] The data leakage source detection device provided in this embodiment generates a session watermark binary sequence based on the service request information when a terminal on the internal network initiates an outward transmission service request. It divides the data stream corresponding to this session into multiple watermark binary encoding windows according to a preset duration window. It assigns corresponding binary codes to the watermark binary encoding windows according to the order of the session watermark binary sequence and the watermark binary encoding windows. It adjusts the delay of the data packets in the watermark binary encoding windows based on the binary codes, and adjusts the center of gravity of the data packets in the watermark binary encoding windows to express the watermark binary code using the center of gravity. It acquires the outflow traffic, extracts the center of gravity from the outflow traffic packets, and uses the center of gravity to obtain the verification session watermark binary sequence. It performs similarity matching between the verification session watermark binary sequence and the session watermark binary sequence. When the similarity exceeds a preset threshold, it uses the decrypted session watermark binary sequence to determine the source of the data leakage. A watermark bound to the user / session can be embedded in the packet time domain, enabling detection of whether system data has been leaked to the external network and tracing of the responsible party without data intrusion, while minimizing the impact on service latency and bandwidth. Even after multiple forwardings, the embedded watermark can still be retained, thus determining whether there is a data leak and the corresponding internal entity.

[0087] Based on the above embodiments, the adjustment module includes:

[0088] The adjustment unit is used to adjust the center of gravity of the entire data packet of a preset number of continuous watermark binary encoded windows.

[0089] Based on the above embodiments, the adjustment module includes:

[0090] The first delay unit is used to select two consecutive watermark binary encoding windows when encoding the first binary data, delay the data packets of the first watermark binary encoding window according to the first delay rate, and delay the data of the second watermark binary encoding window according to the second delay rate.

[0091] The second delay unit is used to select two consecutive watermark binary encoding windows when encoding the second binary data, and delay a preset number of data packets from the first watermark binary encoding window according to the second delay rate, so as to place some of the delayed data packets into the second watermark binary encoding window.

[0092] Based on the above embodiments, the device further includes:

[0093] The generation module is used to select a second preset number of consecutive data packets and generate an auto-incrementing data packet sequence.

[0094] The adjustment module is used to adjust the order of data packets in the auto-incrementing data packet sequence;

[0095] Accordingly, the partitioning module includes:

[0096] The partitioning unit is used to divide the data stream after the adjusted auto-incrementing data packet sequence into multiple watermark binary encoding windows according to a preset duration window.

[0097] Based on the above embodiments, the service request information includes: user ID and session SID;

[0098] Accordingly, the generation module includes:

[0099] The generation unit is used to generate a session watermark binary sequence using a pseudo-random sequence generation algorithm with a preset key, user ID, and session ID.

[0100] Based on the above embodiments, the determining module includes:

[0101] The verification unit is used to divide the outgoing traffic into verification windows according to a preset duration window, obtain the corresponding arrival time of the data packets in the verification window, determine the distribution of traffic packets based on the arrival time, obtain the center of gravity of the verification window, and obtain the verification session watermark binary sequence based on the center of gravity of multiple verification windows.

[0102] Based on the above embodiments, the verification unit is used for:

[0103] The centroid of the verification window is calculated using the following method:

[0104] ;

[0105] Let I be the centroid of the current verification window, and let I be the arrival time series within each window interval of duration I. s is the start time of the current window interval, and m is the number of data packets in the current interval I.

[0106] The data leakage source detection device provided in this embodiment of the invention can execute the data leakage source detection method provided in any embodiment of the invention, and has the corresponding functional modules and beneficial effects of the method.

[0107] Example 4

[0108] Figure 4 This is a schematic diagram of the structure of a server provided in Embodiment 4 of the present invention. Figure 4 A block diagram of an exemplary server 12 suitable for implementing embodiments of the present invention is shown. Figure 4 The server 12 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.

[0109] like Figure 4 As shown, server 12 is presented in the form of a general-purpose computing server. The components of server 12 may include, but are not limited to: one or more processors or processing units 16, system memory 28, and bus 18 connecting different system components (including system memory 28 and processing unit 16).

[0110] Bus 18 represents one or more of several bus architectures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any of the various bus architectures. For example, these architectures include, but are not limited to, the Industry Standard Architecture (ISA) bus, the Micro Channel Architecture (MAC) bus, the Enhanced ISA bus, the Video Electronics Standards Association (VESA) local bus, and the Peripheral Component Interconnect (PCI) bus.

[0111] Server 12 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by server 12, including volatile and non-volatile media, removable and non-removable media.

[0112] System memory 28 may include computer system readable media in the form of volatile memory, such as RAM 30 and / or cache 32. Server 12 may further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, storage system 34 may be used to read and write non-removable, non-volatile magnetic media ( Figure 4 Not shown; usually referred to as a "hard drive"). Although Figure 4 Not shown, a disk drive for reading and writing to a removable non-volatile disk (e.g., a "floppy disk") and an optical disk drive for reading and writing to a removable non-volatile optical disk (e.g., a CD-ROM, DVD-ROM, or other optical media) may be provided. In these cases, each drive may be connected to bus 18 via one or more data media interfaces. System memory 28 may include at least one program product having a set (e.g., at least one) of program modules configured to perform the functions of the embodiments of the present invention.

[0113] A program / utility 40 having a set (at least one) of program modules 42 may be stored, for example, in system memory 28. Such program modules 42 include, but are not limited to, an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment. Program modules 42 typically perform the functions and / or methods described in the embodiments of the present invention.

[0114] Server 12 can also communicate with one or more external devices 14 (e.g., keyboard, pointing server, display 24, etc.), and with one or more servers that enable users to interact with server 12, and / or with any server (e.g., network card, modem, etc.) that enables server 12 to communicate with one or more other computing servers. This communication can be performed via I / O interface 22. Furthermore, server 12 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 20. As shown, network adapter 20 communicates with other modules of server 12 via bus 18. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with server 12, including but not limited to: microcode, server drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0115] The processing unit 16 executes various functional applications and data processing by running programs stored in the system memory 28, such as implementing the data leakage source detection method provided in the embodiments of the present invention.

[0116] Example 5

[0117] Embodiment 5 of the present invention also provides a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform any of the data leakage source detection methods provided in the above embodiments.

[0118] The computer storage medium of this invention can be any combination of one or more computer-readable media. A computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. For example, a computer-readable storage medium can be, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this document, a computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0119] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, capable of sending, propagating, or transmitting programs for use by or in connection with an instruction execution system, apparatus, or device.

[0120] Program code contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to wireless, wire, optical fiber, RF, etc., or any suitable combination thereof.

[0121] Computer program code for performing the operations of this invention can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0122] Note that the above description is merely a preferred embodiment of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and various obvious changes, readjustments, and substitutions can be made without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments, and may include many other equivalent embodiments without departing from the concept of the present invention, the scope of which is determined by the scope of the appended claims.

Claims

1. A method for detecting the source of data leakage, characterized in that, include: When a terminal on the internal network initiates an external transmission service request, a session watermark binary sequence is generated based on the service request information; Select a second preset number of consecutive data packets to generate an auto-incrementing data packet sequence, including: The embedding probability is set by pseudo-random operation, and a preset number of consecutive data packets are randomly selected from the target stream. The ID field value of the IP header of each preset number of data packets is defined respectively. Adjusting the order of data packets in the auto-incrementing data packet sequence includes: Based on the ID field value in the IP header of each data packet, the order of the data packets is adjusted so that the ID field value of the adjusted data packets does not correspond to the order. The data stream corresponding to this session is divided into multiple watermark binary encoding windows according to the preset duration window; The process of dividing the data stream corresponding to this session into multiple watermark binary encoding windows according to a preset duration window includes: The data stream following the adjusted auto-incrementing data packet sequence is divided into multiple watermark binary encoding windows according to a preset duration window; Assign corresponding binary codes to the watermark binary encoding windows according to the order of the session watermark binary sequence and the watermark binary encoding window; The delay of the data packets in the watermark binary encoding window is adjusted according to the binary encoding, and the center of gravity of the data packets in the watermark binary encoding window is adjusted so as to express the watermark binary encoding using the center of gravity of the data packets. The outflow traffic is obtained, the centroid is extracted from the outflow traffic packets, and the verification session watermark binary sequence is obtained using the centroid. The verification session watermark binary sequence is matched with the session watermark binary sequence for similarity. When the similarity exceeds a preset threshold, the source of data leakage is determined using the decrypted session watermark binary sequence. The step of adjusting the delay of the data packets in the watermark binary encoding window according to the binary encoding, and adjusting the center of gravity of the data packets in the watermark binary encoding window, includes: When encoding the first binary data, two consecutive watermark binary encoding windows are selected. The data packets of the first watermark binary encoding window are delayed according to the first delay rate, and the data of the second watermark binary encoding window are delayed according to the second delay rate. When encoding the second binary data, two consecutive watermark binary encoding windows are selected. A preset number of data packets from the first watermark binary encoding window are delayed according to the second delay rate so that some of the delayed data packets are placed into the second watermark binary encoding window.

2. The method according to claim 1, characterized in that, The adjustment of the data packet centroid in the watermark binary encoding window includes: Adjust the center of gravity of the overall data packet for a preset number of consecutive watermark binary encoded windows.

3. The method according to claim 1, characterized in that, The service request information includes: User ID and Session SID; Accordingly, generating the session watermark binary sequence based on the service request information includes: Using a preset key, user ID, and session ID, a pseudo-random sequence generation algorithm is employed to generate a session watermark binary sequence.

4. The method according to claim 1, characterized in that, The process of acquiring outgoing traffic, extracting the centroid from the outgoing traffic packets, and using the centroid to obtain the verification session watermark binary sequence includes: The outflow traffic is divided into verification windows according to a preset duration window. The arrival time of the data packets in the verification window is obtained, and the distribution of traffic packets is determined based on the arrival time to obtain the center of gravity of the verification window. The binary sequence of the verification session watermark is obtained based on the center of gravity of multiple verification windows.

5. The method according to claim 4, characterized in that, The process of dividing outgoing traffic into verification windows according to a preset duration window, obtaining the corresponding arrival time of data packets in the verification window, and determining the distribution of traffic packets based on the arrival time to obtain the center of gravity of the verification window includes: The centroid of the verification window is calculated using the following method: ; Let I be the centroid of the current verification window, and let I be the arrival time series within each window interval of duration I. s is the start time of the current window interval, and m is the number of data packets in the current interval I.

6. A data leakage source detection device, characterized in that, include: The generation module is used to generate a session watermark binary sequence based on the service request information when a terminal on the internal network initiates an external transmission service request. The segmentation module is used to divide the data stream corresponding to this session into multiple watermark binary encoding windows according to a preset duration window; The allocation module is used to allocate the corresponding binary code to the watermark binary encoding window according to the order of the session watermark binary sequence and the watermark binary encoding window; The adjustment module is used to adjust the delay of the data packets in the watermark binary encoding window according to the binary encoding, and to adjust the center of gravity of the data packets in the watermark binary encoding window so as to express the watermark binary encoding using the center of gravity of the data packets. The determination module is used to acquire outflow traffic, extract the centroid from the outflow traffic packets, obtain the verification session watermark binary sequence using the centroid, perform similarity matching between the verification session watermark binary sequence and the session watermark binary sequence, and determine the source of data leakage using the decrypted session watermark binary sequence when the similarity exceeds a preset threshold. The adjustment module includes: The first delay unit is used to select two consecutive watermark binary encoding windows when encoding the first binary data, delay the data packets of the first watermark binary encoding window according to the first delay rate, and delay the data of the second watermark binary encoding window according to the second delay rate. The second delay unit is used to select two consecutive watermark binary encoding windows when encoding the second binary code, and delay a preset number of data packets from the first watermark binary encoding window according to the second delay rate, so as to place some of the delayed data packets into the second watermark binary encoding window. The device further includes: The generation module is used to select a second preset number of consecutive data packets and generate an auto-incrementing data packet sequence. The generation module includes: a generation unit, used to set the embedding probability through pseudo-random operation, randomly select a preset number of consecutive data packets from the target stream, and define the ID field value of the IP header of each preset number of data packets respectively. An adjustment module is used to adjust the order of data packets in an auto-incrementing data packet sequence. The adjustment module includes: an adjustment unit, used to adjust the order of a data packet according to the ID field value of the IP header of each data packet, so that the ID field value of the adjusted data packet does not correspond to the order. Accordingly, the partitioning module includes: The partitioning unit is used to divide the data stream after the adjusted auto-incrementing data packet sequence into multiple watermark binary encoding windows according to a preset duration window.

7. A server, characterized in that, include: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the data leakage source detection method as described in any one of claims 1-5.

8. A storage medium containing computer-executable instructions, characterized in that, The computer-executable instructions, when executed by a computer processor, are used to perform the data leakage source detection method as described in any one of claims 1-5.