Data file security assessment method and device, equipment, storage medium and product

By employing dynamic field configuration technology and cross-file, cross-level association models, the accuracy issue of multi-source evaluation files for financial institutions' data files has been resolved, achieving more efficient and accurate security assessments.

CN121833795APending Publication Date: 2026-04-10CHINA CONSTRUCTION BANK +1
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-23
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

In existing technologies, when retrieving assessment files using fixed fields, it is difficult to accurately process multi-source assessment files from financial institutions, resulting in poor accuracy in security assessments.

Method used

By employing dynamic field configuration technology, cross-file and cross-level associations are established. Through a bidirectional association model at the file name level and content level, field information associated with security assessment use cases is filtered out to generate security assessment results.

Benefits of technology

It improved the accuracy and efficiency of security assessments, reduced assessment omissions, and enhanced the automation level and consistency of compliance assessment results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121833795A_ABST
    Figure CN121833795A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a data file security assessment method and device, equipment, a storage medium and a product. The method comprises the following steps: in response to a security evaluation request of a data file, obtaining a security evaluation case corresponding to the security evaluation request; according to the security assessment case, determining at least one piece of first field information associated with the security assessment case from an association relationship between the security assessment case and the field content information; for each piece of first field information, screening out at least one piece of second field information associated with the first field information from the plurality of evaluation files according to a first field identifier and first field content of the first field information; and generating a security evaluation result of the data file according to the at least one piece of first field information and the at least one piece of second field information associated with each piece of first field information. According to the method, the accuracy of safety assessment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of finance, and in particular to a data file security evaluation method and device, equipment, storage medium and product. BACKGROUND

[0002] In the financial industry, with the increasingly stringent regulatory policies and the continuous upgrading of data security requirements, the data files of financial institutions need to meet the requirements of multi-source evaluation files such as external regulations, internal systems, and industry standards.

[0003] In the prior art, the evaluation files are stored in a structured manner through fixed fields. When evaluating the data files, the evaluation files are retrieved through the fixed fields, and the data files are evaluated through the retrieved evaluation files.

[0004] However, in actual business, the hierarchical structure of the evaluation files is significantly different, and there are complex reference, dependence and coverage relationships between the files. Retrieving the evaluation files through fixed fields is easy to miss the evaluation files, resulting in poor accuracy of the security evaluation of the data files. SUMMARY

[0005] The embodiments of the present application provide a data file security evaluation method, device, equipment, storage medium and product to improve the efficiency of processing multi-source evaluation files.

[0006] In a first aspect, the embodiments of the present application provide a data file security evaluation method, comprising:

[0007] In response to a security evaluation request of a data file, obtaining a security evaluation use case corresponding to the security evaluation request;

[0008] According to the security evaluation use case, determining at least one first field information associated with the security evaluation use case from the association relationship between the security evaluation use case and the field content information;

[0009] For each first field information, according to the first field identifier and the first field content of the first field information, filtering at least one second field information associated with the first field information from a plurality of evaluation files;

[0010] According to at least one first field information and at least one second field information associated with each first field information, generating a security evaluation result of the data file.

[0011] In one possible implementation, selecting at least one second field information associated with the first field information from multiple evaluation files based on the first field identifier and the first field content of the first field information includes: determining at least one second field identifier referenced by the first field identifier from the reference relationships between multiple field identifiers based on the first field identifier of the first field information; selecting at least one second field information associated with the first field information from multiple evaluation files based on the at least one second field identifier; determining at least one second field content associated with the first field content from the association relationships between multiple field contents based on the first field content of the first field information; and selecting at least one second field information associated with the first field information from multiple evaluation files based on the at least one second field content.

[0012] In one possible implementation, the method further includes:

[0013] Obtain the field attribute information corresponding to each field in multiple evaluation files. The field attribute information includes field identifier, field content information, and field association information. Based on the field identifier and field association information corresponding to each field in each evaluation file, create reference relationships between multiple field identifiers. Based on the field content information corresponding to each field in each evaluation file, create association relationships between multiple field contents and association relationships between security evaluation use cases and field content information.

[0014] In one possible implementation, obtaining the field attribute information corresponding to each field in multiple evaluation files includes: obtaining the file type information corresponding to each of the multiple evaluation files; for each evaluation file, determining the field configuration information corresponding to the file type information based on the file type information of the evaluation file; and generating the field attribute information corresponding to each field in the evaluation file based on the field configuration information.

[0015] In one possible implementation, multiple reference relationships between field identifiers are created based on the field identifiers and field association information corresponding to each field in each evaluation file. This includes: creating field identifier reference relationships between external and internal evaluation files, between external evaluation files, and between internal evaluation files based on a field identifier association model. The field identifier reference relationship includes a field identifier at the first field level referencing a field identifier at the second field level or a field identifier in an external evaluation file, where the second field level is the parent field level of the first field level.

[0016] In one possible implementation, based on the field content information corresponding to each field in each evaluation file, multiple relationships between field contents and relationships between security evaluation use cases and field content information are created. This includes: creating relationships between external evaluation file content and internal evaluation file content, between external evaluation file content and external evaluation file content, and between internal evaluation file content and internal evaluation file content based on the file content relationship model; and creating relationships between security evaluation use cases and field content information based on the file content relationship model.

[0017] Secondly, embodiments of this application provide a data file security assessment apparatus, comprising:

[0018] The acquisition module is used to retrieve the security assessment test cases corresponding to the security assessment request in response to the security assessment request of the data file.

[0019] The determination module is used to determine at least one first field information associated with the security assessment use case from the association relationship between the security assessment use case and the field content information, based on the security assessment use case.

[0020] The filtering module is used to filter out at least one second field information associated with the first field information from multiple evaluation files for each first field information, based on the first field identifier and the first field content of the first field information;

[0021] The security assessment module is used to generate a security assessment result for a data file based on at least one first field of information and at least one second field of information associated with each first field of information.

[0022] Thirdly, embodiments of this application provide an electronic device, including: a memory and a processor;

[0023] The memory stores the instructions that the computer executes;

[0024] The processor executes computer execution instructions stored in memory, causing the processor to perform the first aspect and / or various possible implementations of the first aspect as described above.

[0025] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the first aspect and / or various possible implementations of the first aspect.

[0026] Fifthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the first aspect and / or various possible implementations of the first aspect.

[0027] This application provides a data file security assessment method, apparatus, device, storage medium, and product. The method includes: responding to a data file security assessment request, obtaining a security assessment use case corresponding to the security assessment request; determining at least one first field information associated with the security assessment use case from the association relationship between the security assessment use case and field content information; for each first field information, filtering at least one second field information associated with the first field information from multiple assessment files based on the first field identifier and the first field content of the first field information; and generating a data file security assessment result based on the at least one first field information and the at least one second field information associated with each first field information. In this embodiment, because at least one second field information associated with the first field information is filtered from multiple assessment files based on the first field identifier and the first field content of the first field information, a bidirectional association model at the file name level and content level is used to achieve cross-file and cross-level compliance requirement association analysis, thus improving the accuracy of the security assessment. Attached Figure Description

[0028] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0029] Figure 1 A schematic diagram illustrating a scenario for the security assessment method of the data files provided in this application;

[0030] Figure 2 A flowchart illustrating the security assessment method for data files provided in this application embodiment;

[0031] Figure 3 A schematic diagram of the structure of the data file security assessment device provided in the embodiments of this application;

[0032] Figure 4 A schematic diagram of the structure of the electronic device provided in this application.

[0033] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0034] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0035] In the financial industry, with increasingly stringent regulatory policies and continuously escalating data security requirements, financial institutions' data files need to simultaneously meet the requirements of multi-source evaluation documents, including external regulations, internal policies, and industry standards. Current technologies use fixed fields (such as file name, number, issuing authority, and effective date) for structured storage of evaluation documents. When evaluating data files, these fixed fields are used to retrieve the evaluation documents, and the retrieved documents are then used to conduct a security assessment of the data files.

[0036] In actual business operations, security assessment documents are of various types and have different content levels. Furthermore, the relationships and references between security assessment documents are complex. Searching for assessment documents using fixed fields can easily lead to omissions, resulting in poor accuracy in security assessment of data files using the aforementioned existing technologies.

[0037] To address the aforementioned technical problems, the inventors propose the following technical concept: For multi-source assessment documents, flexible field modeling is achieved through dynamic field configuration technology, and highly complex and intersecting relationships of compliance requirements are established. At the same time, security inspection metadata is used as a base point to link different security compliance requirements together, thereby improving the accuracy of security assessment.

[0038] The specific steps may include: in response to a security assessment request for a data file, obtaining a security assessment use case corresponding to the security assessment request; based on the security assessment use case, determining at least one first field information associated with the security assessment use case from the association relationship between the security assessment use case and field content information; for each first field information, filtering at least one second field information associated with the first field information from multiple assessment files based on the first field identifier and the first field content of the first field information; and generating a security assessment result for the data file based on at least one first field information and at least one second field information associated with each first field information.

[0039] In this embodiment of the disclosure, since at least one second field information associated with the first field information is selected from multiple evaluation files based on the first field identifier and the first field content of the first field information, and a bidirectional association model at the file name level and content level is used to realize cross-file and cross-level compliance requirement association analysis, the accuracy of security assessment is improved.

[0040] The collection, storage, use, processing, transmission, provision, and disclosure of financial data or user data involved in the technical solution of this application all comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0041] It should be noted that in the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the solution.

[0042] Figure 1 A schematic diagram illustrating a scenario for the security assessment method of the data files provided in this application. For example... Figure 1 In this scenario, the components include: server 102 and terminal 101.

[0043] In the specific implementation process, server 102 and terminal 101 can be implemented using a cluster of one or more servers with more powerful processing capabilities and higher security. Where possible, computers or laptops with strong computing power can also be used as alternatives.

[0044] The connection between server 102 and terminal 101 can be either wired or wireless. The user can send a data file security assessment request to server 102 via terminal 101. Server 102 receives the security assessment request and generates a data file security assessment result using the data file security assessment method provided in this application. Server 102 then returns the generated security assessment result to terminal 101.

[0045] It is understood that the scenarios illustrated in the embodiments of this application do not constitute a specific limitation on the security assessment method for data files. In other feasible embodiments of this application, the above scenarios may include more or fewer components than illustrated, or combine some components, or split some components, or arrange different components, which can be determined according to the actual application scenario and are not limited here. Figure 1 The scenario shown can be implemented by hardware, software, or a combination of both.

[0046] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0047] Figure 2This is a flowchart illustrating the data file security assessment method provided in this application embodiment. The executing entity of this application embodiment may be... Figure 1 The server 102 in this embodiment can also be a computer and / or a mobile phone, etc., and this embodiment does not impose any special restrictions on it. Figure 2 As shown, the method includes:

[0048] S201. In response to the security assessment request for the data file, obtain the security assessment use case corresponding to the security assessment request.

[0049] In this embodiment of the disclosure, security assessments of data files can be performed using security assessment use cases. Different security assessment requests correspond to different security assessment use cases. For example, a security assessment request may include a data encryption security assessment request, and the corresponding security assessment use case for this request is a data encryption check use case.

[0050] S202. Based on the security assessment use case, determine at least one first field information associated with the security assessment use case from the association relationship between the security assessment use case and the field content information.

[0051] In this embodiment of the disclosure, each security assessment use case is associated with field content information in multiple assessment files. These multiple assessment files include assessment files corresponding to multiple data sources.

[0052] For example, the data encryption inspection use case is associated with Section 25 of the assessment document, the Data Security Act.

[0053] S203. For each first field information, based on the first field identifier and the first field content of the first field information, filter out at least one second field information associated with the first field information from multiple evaluation files.

[0054] In one possible implementation, selecting at least one second field information associated with the first field information from multiple evaluation files based on the first field identifier and the first field content of the first field information includes: determining at least one second field identifier referenced by the first field identifier from the reference relationships between multiple field identifiers based on the first field identifier of the first field information; selecting at least one second field information associated with the first field information from multiple evaluation files based on the at least one second field identifier; determining at least one second field content associated with the first field content from the association relationships between multiple field contents based on the first field content of the first field information; and selecting at least one second field information associated with the first field information from multiple evaluation files based on the at least one second field content.

[0055] Optionally, the first field identifier of the first field information includes the file name and the field name.

[0056] For example, the first field identifier includes the file name "Data Security Law" and the field name "Article 25". The second field identifier includes the file name "Financial Industry Standard" and the field name "Standard 3.2.1". In this case, the content of the field "Standard 3.2.1" is determined as the second field information.

[0057] For example, the first field content includes the field content of "Article 25 of the Data Security Law". The second field content associated with the field content of "Article 25 of the Data Security Law" includes the field content of "Article 26 of the Data Security Law". In this case, the field content of "Article 26 of the Data Security Law" is determined as the second field information.

[0058] S204. Generate a security assessment result for the data file based on at least one first field information and at least one second field information associated with each first field information.

[0059] The data file security assessment method provided in this application embodiment includes: responding to a data file security assessment request, obtaining a security assessment use case corresponding to the security assessment request; determining at least one first field information associated with the security assessment use case from the association relationship between the security assessment use case and field content information; for each first field information, filtering at least one second field information associated with the first field information from multiple assessment files based on the first field identifier and the first field content of the first field information; and generating a data file security assessment result based on the at least one first field information and the at least one second field information associated with each first field information. In this embodiment, because at least one second field information associated with the first field information is filtered from multiple assessment files based on the first field identifier and the first field content of the first field information, a bidirectional association model at the file name level and content level is used to achieve cross-file and cross-level compliance requirement association analysis, thus improving the accuracy of the security assessment.

[0060] It should be noted that, before step S201, in response to the security assessment request of the data file and obtaining the security assessment use case corresponding to the security assessment request, the method may further include:

[0061] (1) Obtain the field attribute information corresponding to each field in multiple evaluation files. The field attribute information includes field identifier, field content information and field association information.

[0062] In some embodiments, dynamic field configuration technology is adopted, based on a general model framework (field basic information, field content information, field association information) and a dynamic field configuration mechanism, to generate field attribute information corresponding to each field according to the hierarchical structure and attribute requirements of the target file.

[0063] Optionally, the field attribute information corresponding to each field in multiple evaluation files is obtained, including: obtaining the file type information corresponding to each of the multiple evaluation files; for each evaluation file, determining the field configuration information corresponding to the file type information based on the file type information of the evaluation file; and generating the field attribute information corresponding to each field in the evaluation file based on the field configuration information.

[0064] For example, the "Chapter-Clause-Sub-Clause" field can be dynamically configured for legal documents, and the "Standard-Requirement-Sub-Requirement" field can be dynamically configured for standard documents, with custom fields added according to attribute requirements (such as the priority of compliance requirements and implementation stage).

[0065] In this embodiment of the disclosure, since the general model framework provides standardized field classification (such as basic information, content information, etc.), the dynamic configuration mechanism generates an adapted field structure according to the hierarchical differences of file types (such as laws, standards) and attribute requirements (such as priority, implementation stage), which solves the problem of insufficient flexibility in field modeling in the prior art.

[0066] (2) Create reference relationships between multiple field identifiers based on the field identifiers and field association information corresponding to each field in each evaluation file.

[0067] In some embodiments, a reference relationship between multiple field identifiers is created based on the field identifiers and field association information corresponding to each field in each evaluation file, including: creating field identifier reference relationships between external evaluation files and internal evaluation files, between external evaluation files, and between internal evaluation files based on the field identifier association model; wherein, the field identifier reference relationship includes a field identifier at the first field level referencing a field identifier at the second field level or a field identifier of an external evaluation file, and the second field level is the parent field level of the first field level.

[0068] In this embodiment, by introducing a security check case metadata-driven evaluation mechanism, using check cases as the metadata base, evaluation tasks are generated and evaluation results are reused by automatically associating evaluation files with check cases. For example, after evaluating the "data encryption" check case, all evaluation file clauses involving data encryption are automatically associated, reducing redundant evaluations.

[0069] (3) Based on the field content information corresponding to each field in each assessment file, create the association between multiple field contents and the association between security assessment use cases and field content information.

[0070] In some embodiments, based on the field content information corresponding to each field in each evaluation file, multiple relationships between field contents and relationships between security evaluation use cases and field content information are created, including: creating relationships between external evaluation file content and internal evaluation file content, between external evaluation file content and external evaluation file content, and between internal evaluation file content and internal evaluation file content based on the file content association model; and creating relationships between security evaluation use cases and field content information based on the file content association model.

[0071] In this embodiment, a metadata-driven evaluation mechanism for security check cases is introduced. Using check cases as the metadata base, evaluation tasks are generated and evaluation results are reused by automatically associating evaluation documents with check cases. For example, after evaluating the "data encryption" check case, all evaluation document clauses involving data encryption are automatically associated, reducing redundant evaluations. This technique significantly improves the automation level of compliance evaluation, reduces manual intervention, and supports the dynamic management needs of large-scale evaluation documents. Furthermore, the ability to reuse evaluation results reduces compliance management costs and improves the uniformity and consistency of evaluation results.

[0072] For example, the field identification association model is a file name-level association model, and the file content association model is a content-level association model. The file name-level association model establishes macro-level associations between files through referencing relationships (such as "higher-level regulations referencing lower-level regulations"), while the content-level association model establishes micro-level associations through clause-level and attribute-level matching (such as "semantic association between clauses and inspection cases"). This significantly improves the depth and efficiency of compliance assessments, avoids assessment omissions due to missing association relationships, and thus improves the accuracy of security assessments.

[0073] Figure 3 This is a schematic diagram of the structure of a data file security assessment device provided in an embodiment of this application. Figure 3 As shown, the security assessment device for this data file includes:

[0074] The acquisition module 301 is used to acquire the security assessment test case corresponding to the security assessment request in response to the security assessment request of the data file.

[0075] The determination module 302 is used to determine at least one first field information associated with the security assessment use case from the association relationship between the security assessment use case and the field content information, based on the security assessment use case.

[0076] The filtering module 303 is used to filter out at least one second field information associated with the first field information from multiple evaluation files for each first field information, based on the first field identifier and the first field content of the first field information;

[0077] The security assessment module 304 is used to generate a security assessment result for a data file based on at least one first field information and at least one second field information associated with each first field information.

[0078] In one possible implementation, the filtering module 303 filters at least one second field information associated with the first field information from multiple evaluation files based on the first field identifier and the first field content of the first field information. This includes: determining at least one second field identifier referenced by the first field identifier from the reference relationships between multiple field identifiers based on the first field identifier of the first field information; filtering at least one second field information associated with the first field information from multiple evaluation files based on the at least one second field identifier; determining at least one second field content associated with the first field content from the association relationships between multiple field contents based on the first field content of the first field information; and filtering at least one second field information associated with the first field information from multiple evaluation files based on the at least one second field content.

[0079] In one possible implementation, the apparatus further includes: a creation module; the creation module is used to obtain field attribute information corresponding to each field in multiple evaluation files, the field attribute information including field identifier, field content information and field association information; create a reference relationship between multiple field identifiers based on the field identifier and field association information corresponding to each field in each evaluation file; and create an association relationship between multiple field contents and an association relationship between security evaluation use cases and field content information based on the field content information corresponding to each field in each evaluation file.

[0080] In one possible implementation, the creation module obtains field attribute information corresponding to each field in multiple evaluation files, including: obtaining file type information corresponding to each of the multiple evaluation files; for each evaluation file, determining field configuration information corresponding to the file type information based on the file type information of the evaluation file; and generating field attribute information corresponding to each field in the evaluation file based on the field configuration information.

[0081] In one possible implementation, the creation module creates multiple reference relationships between field identifiers based on the field identifiers and field association information corresponding to each field in each evaluation file. This includes: creating field identifier reference relationships between external and internal evaluation files, between external evaluation files, and between internal evaluation files based on the field identifier association model. The field identifier reference relationship includes a field identifier at the first field level referencing a field identifier at the second field level or a field identifier in an external evaluation file, where the second field level is the parent field level of the first field level.

[0082] In one possible implementation, the creation module creates multiple relationships between field contents and between security assessment use cases and field content information based on the field content information corresponding to each field in each assessment file. This includes: creating relationships between external assessment file content and internal assessment file content, between external assessment file content and external assessment file content, and between internal assessment file content and internal assessment file content based on the file content association model; and creating relationships between security assessment use cases and field content information based on the file content association model.

[0083] The data file security assessment device provided in this application improves the accuracy of security assessment by filtering at least one second field information associated with the first field information from multiple assessment files based on the first field identifier and the first field content of the first field information, and realizing cross-file and cross-level compliance requirement association analysis through a bidirectional association model at the file name level and content level.

[0084] The data file security assessment device provided in this embodiment can execute the method provided in the above method embodiment. Its implementation principle and technical effect are similar, and will not be described in detail here.

[0085] Figure 4 A schematic diagram of the structure of the electronic device provided in this application. Figure 4 As shown, the electronic device 40 provided in this embodiment includes at least one processor 401 and a memory 402. Optionally, the electronic device 40 further includes a communication component 403. The processor 401, memory 402, and communication component 403 are connected via a bus.

[0086] In a specific implementation, at least one processor 401 executes computer execution instructions stored in memory 402, causing at least one processor 401 to perform the above-described method.

[0087] The specific implementation process of processor 401 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0088] In the above embodiments, it should be understood that the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in this invention can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules within the processor.

[0089] The memory may include random access memory (RAM) and may also include non-volatile memory (NVM), such as at least one disk storage device.

[0090] The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, the buses shown in the accompanying drawings are not limited to a single bus or a single type of bus.

[0091] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the above-described method.

[0092] This application also provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the above-described method.

[0093] The aforementioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0094] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an Application Specific Integrated Circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the device.

[0095] The division of units is merely a logical functional division; in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.

[0096] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.

[0097] In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0098] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0099] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0100] Finally, it should be noted that other embodiments of the invention will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This invention is intended to cover any variations, uses, or adaptations of the invention that follow the general principles of the invention and include common knowledge or customary techniques in the art not disclosed herein, and is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of the invention is limited only by the appended claims.

Claims

1. A method for security assessment of data files, characterized in that, include: In response to a security assessment request for a data file, obtain the security assessment use case corresponding to the security assessment request; Based on the security assessment use case, determine at least one first field information associated with the security assessment use case from the association relationship between the security assessment use case and the field content information; For each first field information, at least one second field information associated with the first field information is selected from multiple evaluation files based on the first field identifier and the first field content of the first field information; The security assessment result of the data file is generated based on the at least one first field information and the at least one second field information associated with each first field information.

2. The method according to claim 1, characterized in that, The step of filtering out at least one second field information associated with the first field information from multiple evaluation files based on the first field identifier and the first field content of the first field information includes: Based on the first field identifier of the first field information, at least one second field identifier referenced by the first field identifier is determined from the reference relationship between multiple field identifiers. Based on the at least one second field identifier, at least one second field information associated with the first field information is filtered out from the multiple evaluation files. Based on the first field content of the first field information, at least one second field content associated with the first field content is determined from the association relationship between multiple field contents, and based on the at least one second field content, at least one second field information associated with the first field information is filtered out from the multiple evaluation files.

3. The method according to claim 2, characterized in that, The method further includes: Obtain the field attribute information corresponding to each field in multiple evaluation files. The field attribute information includes field identifier, field content information, and field association information. Based on the field identifiers and field association information corresponding to each field in each evaluation file, create reference relationships between multiple field identifiers; Based on the field content information corresponding to each field in each evaluation file, create the association between multiple field contents and the association between security evaluation use cases and field content information.

4. The method according to claim 3, characterized in that, The step of obtaining the field attribute information corresponding to each field in multiple evaluation files includes: Obtain the file type information corresponding to each of the multiple evaluation files; For each evaluation file, determine the field configuration information corresponding to the file type information based on the file type information of the evaluation file; Based on the field configuration information, generate the field attribute information corresponding to each field in the evaluation file.

5. The method according to claim 3, characterized in that, Based on the field identifiers and field association information corresponding to each field in each evaluation file, a reference relationship is created between multiple field identifiers, including: Based on the field identifier association model, create field identifier reference relationships between external evaluation files and internal evaluation files, between external evaluation files, and between internal evaluation files; The field identifier reference relationship includes a field identifier at the first field level referencing a field identifier at the second field level or a field identifier in an external evaluation file, wherein the second field level is the parent field level of the first field level.

6. The method according to claim 3, characterized in that, The step of creating associations between multiple field contents and between security assessment use cases and field content information based on the field content information corresponding to each field in each assessment file includes: Based on the file content association model, relationships are created between the content of external evaluation files and the content of internal evaluation files, between the content of external evaluation files and the content of external evaluation files, and between the content of internal evaluation files and the content of internal evaluation files. In addition, based on the file content association model, relationships are created between security evaluation use cases and field content information.

7. A data file security assessment device, characterized in that, include: The acquisition module is used to acquire the security assessment test case corresponding to the security assessment request in response to the security assessment request of the data file; The determination module is used to determine at least one first field information associated with the security assessment use case from the association relationship between the security assessment use case and the field content information, based on the security assessment use case. The filtering module is used to filter out at least one second field information associated with the first field information from multiple evaluation files for each first field information, based on the first field identifier and the first field content of the first field information; The security assessment module is used to generate a security assessment result for the data file based on the at least one first field information and at least one second field information associated with each first field information.

8. An electronic device, characterized in that, include: Memory, processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory, causing the processor to perform the method as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 6.

10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1 to 6.