Risk identification method and device, electronic equipment, storage medium and program product
By acquiring security policies and logs, determining user behavior sequences, and performing risk detection to generate risk reports, this solves the problem of security policy updates relying on experience in existing technologies and improves the protective effect of security policies.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-23
- Publication Date
- 2026-04-10
AI Technical Summary
The formulation and updating of existing security policies rely heavily on the experience of administrators and lack a data-driven continuous optimization loop. Administrators are unable to know whether there are unknown bypass risks in the policies.
By acquiring multiple stored security policies and logs, the user behavior sequence is determined, business nodes are added according to the access path of the event, risk detection is performed, and a risk report is generated.
It enables automatic identification of risks in security policies, improves the protective effect of security policies, and facilitates administrators in making repairs.
Smart Images

Figure CN121841809A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, and in particular to risk identification methods, devices, electronic devices, storage media, and program products. Background Technology
[0002] With the deepening of digital transformation, cyberspace has become a core carrier of social production and life. The coupling between various business systems, data resources, and the network environment continues to increase. Consequently, security threats are becoming more diversified, complex, and large-scale. From traditional network attacks (such as port scanning, malicious IP intrusion, and virus propagation) to new types of data breaches, unauthorized access, and supply chain attacks, security risks have permeated the entire business chain, including the network layer, application layer, data layer, and terminal layer. This poses a serious threat to core enterprise assets, user privacy, and business continuity. Against this backdrop, security strategies, as a core means of resisting security threats, regulating access behavior, and ensuring system security, are becoming increasingly important.
[0003] A security policy is a set of rules based on security protection objectives. It defines rules, assigns permissions, and configures controls for various access and operational behaviors to identify, block, and audit unauthorized activities. Depending on the protection scenario, security policies can be categorized into network security policies (such as firewall access control rules and IDS / IPS detection rules), data security policies (such as sensitive data access permission rules and data export control rules), endpoint security policies (such as malware blocking rules and external device control rules), and application security policies (such as interface access permission rules and operational behavior auditing rules).
[0004] Current security policy formulation and updates heavily rely on administrator experience and unforeseen events. There is a lack of a data-driven, continuous optimization loop based on actual protection effectiveness. Once deployed, the actual effectiveness of a security policy is like a "black box," as administrators cannot know if the policy has been bypassed by users through unknown means. Therefore, a method for identifying risks in security policies is urgently needed. Summary of the Invention
[0005] This invention provides a risk identification method, apparatus, electronic device, storage medium, and program product for automatically identifying risks in security protection strategies to improve the effectiveness of these strategies.
[0006] According to one aspect of the present invention, a risk identification method is provided, the method comprising: Retrieve multiple stored security policies and multiple logs within a first specified time period; Based on the multiple logs, a sequence of behaviors for multiple users is determined, wherein the sequence of behaviors includes the order of events being invoked, the time of invocation, and the result of invocation. For any event in any behavior sequence, the business node corresponding to the event is determined according to the access path of the event, and the business node is added to the behavior sequence to obtain the user's target behavior sequence, wherein the target behavior sequence includes the calling order, calling time and calling result of multiple business nodes; Based on the target behavior sequences of the multiple users, risk detection is performed on the multiple security policies to obtain detection results; For any given security policy, a risk report for that security policy is generated based on the detection results of that security policy.
[0007] According to another aspect of the present invention, a risk identification device is provided, the device comprising: The acquisition module is used to acquire multiple stored security policies and multiple logs within a first specified time period; The behavior sequence determination module is used to determine the behavior sequence of multiple users based on the multiple logs, wherein the behavior sequence includes the calling order, calling time and calling result of multiple events; The business node determination module is used to determine the business node corresponding to any event in any behavior sequence based on the access path of the event, and add the business node to the behavior sequence to obtain the user's target behavior sequence. The target behavior sequence includes the calling order, calling time and calling result of multiple business nodes. The detection module is used to perform risk detection on the multiple security policies based on the target behavior sequences of the multiple users, and obtain the detection results; The risk report determination module is used to generate a risk report for any given security policy based on the detection results of the security policy.
[0008] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, which enables the at least one processor to perform the risk identification method described in any embodiment of the present invention.
[0009] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the risk identification method described in any embodiment of the present invention.
[0010] According to another aspect of the present invention, a computer program product is also provided, including a computer program that, when executed by a processor, implements the steps of the risk identification method as described in any embodiment of the present invention.
[0011] The technical solution of this invention involves acquiring multiple stored security policies and multiple logs within a first specified time period; based on the multiple logs, determining the behavior sequences of multiple users. For any event in any behavior sequence, the business node corresponding to the event is determined according to the event's access path, and the business node is added to the behavior sequence to obtain the user's target behavior sequence. Then, based on the target behavior sequences of multiple users, risk detection is performed on multiple security policies to obtain detection results; for any security policy, a risk report for the security policy is obtained based on the detection results. Therefore, this embodiment can automatically identify the risks existing in security policies, facilitating administrators to remediate the security policies and further improving the protective effect of the security policies.
[0012] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0013] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0014] Figure 1 This is a schematic diagram of an application scenario provided by an embodiment of the present invention; Figure 2 This is a flowchart illustrating a risk identification method provided according to an embodiment of the present invention; Figure 3 This is a flowchart illustrating a risk detection method provided according to an embodiment of the present invention; Figure 4 This is another schematic diagram of a risk detection method provided according to an embodiment of the present invention; Figure 5This is another schematic diagram of a risk detection method provided according to an embodiment of the present invention; Figure 6 This is a schematic diagram of a risk detection device according to an embodiment of the present invention; Figure 7 This is a schematic diagram of the structure of an electronic device that implements the risk detection method of this invention. Detailed Implementation
[0015] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0016] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0017] Before introducing the intelligent customer service method provided in the embodiments of this application, for ease of understanding, the technical background of the embodiments of this application will be described in detail below.
[0018] In existing technologies, the formulation and updating of security policies heavily rely on the administrator's experience and occasional events. There is a lack of a data-driven, continuous optimization loop based on actual protection effectiveness. Once a security policy is deployed, its actual effectiveness is like a "black box," as administrators cannot know whether the policy has been bypassed by users through unknown means. Therefore, there is an urgent need for a method for identifying risks in security policies.
[0019] In view of this, this application provides a risk identification method, which acquires multiple stored security policies and multiple logs within a first specified time period; based on the multiple logs, it determines the behavior sequences of multiple users. For any event in any behavior sequence, based on the access path of the event, it determines the business node corresponding to the event and adds the business node to the behavior sequence to obtain the user's target behavior sequence. Then, based on the target behavior sequences of multiple users, it performs risk detection on multiple security policies to obtain detection results; for any security policy, based on the detection results of the security policy, it obtains a risk report of the security policy. Thus, in the embodiments of this application, the risks existing in the security policy can be automatically identified, so that the administrator can repair the security policy and further improve the protection effect of the security policy.
[0020] Before introducing the risk identification method in this application, we will first introduce the application scenarios of the risk identification method in this application. Figure 1 This is a schematic diagram of an application scenario, from Figure 1 As can be seen from this, the application scenario includes server 110 and terminal device 120. In the implementation embodiment of this application, server 110 can be implemented by a physical server or by a virtual server.
[0021] In one possible application scenario, server 110 acquires multiple stored security policies and multiple logs within a first specified time period. Then, based on the logs, server 110 determines multiple user behavior sequences, where each behavior sequence includes the call order, call time, and call result of multiple events. For any event in any behavior sequence, server 110 determines the corresponding business node based on the event's access path and adds the business node to the behavior sequence to obtain the user's target behavior sequence, where the target behavior sequence includes the call order, call time, and call result of multiple business nodes. Then, server 110 performs risk detection on the multiple security policies based on the target behavior sequences of the multiple users, obtaining detection results. For any security policy, server 110 obtains a risk report based on the detection results. Finally, server 110 sends the risk report to terminal device 120 for display.
[0022] in, Figure 1 The server 110 and the terminal device 120 can exchange information through a communication network. The communication network can be either wireless or wired.
[0023] For example, server 110 can access the network via cellular mobile communication technology and communicate with terminal device 120, wherein the cellular mobile communication technology includes, for example, 5th generation mobile networks (5G) technology.
[0024] Optionally, server 110 can access the network and communicate with terminal device 120 via short-range wireless communication, wherein the short-range wireless communication method includes, for example, Wireless Fidelity (Wi-Fi) technology.
[0025] Furthermore, the description in this application focuses only on a single server 110 and a single terminal device 120. However, those skilled in the art should understand that the illustrated server 110 and terminal device 120 are intended to illustrate the operation of the server 110 and terminal device 120 involved in the technical solutions of this application, and are not intended to imply any limitation on the number, type, or location of the server 110 and terminal device 120. It should be noted that adding additional modules to or removing individual modules from the illustrated environment will not change the underlying concept of the exemplary embodiments of this application.
[0026] It should be noted that the risk identification method proposed in this application is not only applicable to... Figure 1 The application scenarios shown are also applicable to any risk identification device.
[0027] For example, terminal device 120 includes, but is not limited to: large visual screens, tablet computers, laptops, handheld computers, mobile internet devices (MID), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminal devices in industrial control, wireless terminal devices in autonomous driving, wireless terminal devices in smart grids, wireless terminal devices in transportation safety, wireless terminal devices in smart cities, or wireless terminal devices in smart homes, etc.; the terminal device may have a related client installed, which may be software (e.g., browsers, short video software, etc.), or web pages, mini-programs, etc.
[0028] The risk identification method of this application, in conjunction with the application scenarios described above and with reference to the accompanying drawings, is described below as an exemplary embodiment. It should be noted that the above application scenarios are only shown to facilitate understanding of the methods and principles of this application, and the implementation of this application is not limited in any way in this respect.
[0029] The risk identification method in the embodiments of this application will be described in detail below. Figure 2 A flowchart of a risk identification method provided in an embodiment of the present invention, the method comprising: S210: Retrieve multiple stored security policies and multiple logs within a first specified time period; In this embodiment, full operation logs from devices such as DLP (Data Leakage Prevention) systems, firewalls, Web (World Wide Web) gateways, and terminal agents are collected through methods such as Agent, Syslog, and API (Application Programming Interface). The logs in this embodiment include fields such as: [timestamp, subject (user / host), operation type, target object (file hash / URL / application), action (Allow / Deny / Alert), matching policy ID, etc.].
[0030] In this embodiment, the currently effective security policy set of devices such as DLP system, firewall, web gateway, and terminal agent is collected synchronously through device management API or configuration repository. The security policy in this embodiment is stored as [policy ID, policy description, matching condition (logical expression), execution action, target (user group / IP segment / application)].
[0031] In this embodiment, a pre-defined mapping relationship between security policies and business tags is established. When user behavior is detected, the system not only checks whether the security policy matches, but also records the business tags that the behavior may involve. By analyzing the set of behaviors blocked / allowed by the same security policy, the actual scope of services protected by the security policy can be automatically inferred based on the business tags.
[0032] It should be noted that the first specified time period in this application embodiment can be set according to the specific actual situation, and this application embodiment does not limit the first specified time period.
[0033] S220: Based on the multiple logs, determine the behavior sequence of multiple users, wherein the behavior sequence includes the calling order, calling time and calling result of multiple events; In this embodiment, events in multiple logs can be classified by user identifier, events belonging to the same user identifier are placed in the same sequence, and then the events in the same sequence are arranged in chronological order to obtain a behavior sequence.
[0034] In this embodiment, the invocation time and invocation result of each event are obtained directly from the log.
[0035] S230: For any event in any behavior sequence, determine the business node corresponding to the event according to the access path of the event, and add the business node to the behavior sequence to obtain the user's target behavior sequence, wherein the target behavior sequence includes the calling order, calling time and calling result of multiple business nodes; In one possible embodiment, S230 can be specifically implemented as follows: using a pre-set correspondence between each access path and each service node, determine the service node corresponding to the access path of the event. If, using the pre-set correspondence between each access path and each service node, it is determined that the access path of the event does not have a corresponding service node, then in response to a service node setting instruction sent by the user, determine the service node corresponding to the access path of the event.
[0036] In one possible embodiment, the correspondence between each access path and each service node is determined as follows: the historical access paths are clustered using the DBSCAN clustering algorithm to obtain each cluster, wherein any cluster includes at least one historical access path; in response to a service node setting instruction sent by the user, the service nodes corresponding to each cluster are determined; for any cluster, the service node corresponding to the cluster is determined as the service node corresponding to the access path included in the cluster.
[0037] S240: Based on the target behavior sequence of the multiple users, perform risk detection on the multiple security policies to obtain the detection results; The following describes the risk detection method in S240. In this embodiment, three risk detection methods may be included. Figure 3 This is one of the flowcharts for a risk detection method, which may include the following steps: S310: For any user's target behavior sequence, obtain the first target business node in the target behavior sequence whose call result is failed; S320: For any first target business node, if there is a second target business node with a successful call result within a second specified time period after the call time of the first target business node, then determine the similarity between the first target business node and the second target business node, and determine whether the second target business node is covered by the target security policy corresponding to the first target business node, and obtain the verification result, wherein the second specified time period is not greater than the first specified time period; In one possible embodiment, the similarity between the first target service node and the second target service node is determined by inputting the parameters corresponding to the first target service node and the second target service node into a similarity determination algorithm to obtain the similarity between the first target service node and the second target service node. The parameters in this embodiment include filename, file type, keywords, etc. These parameters can be obtained from the logs corresponding to each target service node, and will not be elaborated further in this embodiment.
[0038] For example, the similarity determination algorithm in this application embodiment may be the SimHash algorithm or the MinHash algorithm. However, this application embodiment does not limit the similarity algorithm, and the similarity algorithm can be set according to the specific actual situation.
[0039] In one possible embodiment, the verification result is obtained by determining whether the second target service node is covered by the target security policy corresponding to the first target service node in the following manner: In this embodiment, a lightweight policy execution simulator is pre-configured. The security policy of the first target service node and the second target service node are input into the policy execution simulator. It is determined whether the security policy and the second target service node match. If they do, it is determined that the second target service node is covered by the corresponding target security policy of the first target service; if not, it is determined that the second target service node is not covered by the corresponding target security policy of the first target service.
[0040] S330: Determine the detection result based on the similarity and the verification result.
[0041] In one possible embodiment, S330 can be specifically implemented as follows: if the similarity is greater than a first specified threshold and the second target service node is not covered by the target security policy of the first target service node, then the detection result is determined to be that the security policy is bypassed, and the user, the target security policy, the first target service node and the second target service node are added to the detection result; otherwise, the detection result is determined to be that the security policy is not bypassed.
[0042] It should be noted that the first specified threshold in this application embodiment can be set according to the specific actual situation, and the specific value of the first specified threshold is not limited in this application embodiment.
[0043] Figure 4 Here is another flowchart illustrating a risk detection method, which may include the following steps: S410: Determine the third target object node based on the target object detection command sent by the user; The target object detection instruction in this embodiment includes a third target object node.
[0044] S420: Based on the target behavior sequence of the multiple users, determine the multiple target users who will call the third target service node; S430: Based on the call results of the third target business node, classify the multiple target users to obtain a set of successful users and a set of failed users; In this embodiment, users whose call to the third target business node is successful are added to the successful user set, and users whose call to the third target business node fails are added to the failed user set.
[0045] S440: Determine the detection result of the security policy corresponding to the third target service node based on the tags of the users in the successful user set and the failed user set.
[0046] In one possible embodiment, S440 is specifically implemented as follows: if there are users with the same user tag in the successful user set and the failed user set, then the detection result of the security policy is determined to be that the security policy has been bypassed; if there are no users with the same user tag in the successful user set and the failed user set, then the detection result of the security policy is determined to be that the security policy has not been bypassed.
[0047] In this embodiment, user tags can be used to represent a user's job title, department, etc. This embodiment does not limit the use of user tags.
[0048] In this embodiment, the access paths, times, and applications used by users in the successful user set can be compared with those used by users in the failed user set. This helps identify policy exceptions (such as allowing access to specific IP ranges or policies not taking effect at specific times) or policy deployment vulnerabilities (such as certain traffic not passing through checkpoints).
[0049] Figure 5 Here is another flowchart illustrating a risk detection method, which may include the following steps: S510: In response to the user's target path determination operation, determine the target path, wherein the target path includes multiple service nodes arranged in chronological order; The target path determination operation in this application embodiment includes a target path. For example, the target path could be: download customer data -> local anonymization -> send via Webmail.
[0050] S520: For any one of the plurality of service nodes, determine whether the service node has a corresponding security policy; if yes, execute S530; otherwise, execute S570. By utilizing the pre-defined correspondence between each business node and each security policy, it can be determined whether the business node has a corresponding security policy.
[0051] S530: Calculate the blocking rate of the security policy, wherein the blocking rate of the security policy is used to characterize the proportion of violations successfully blocked by the security policy; In one possible embodiment, the blocking rate is obtained by dividing the number of violations successfully blocked by the security policy by the total number of violations blocked by the security policy.
[0052] S540: Determine whether the blocking rate is less than a second specified threshold. If yes, proceed to S550; otherwise, proceed to S560. S550: Determine that the detection result of the security policy is that the security policy has been bypassed; S560: Determine that the detection result of the security policy is that the security policy has not been bypassed; S570: The detection result indicates that the business node lacks a security policy.
[0053] It should be noted that the second specified threshold in this application embodiment can be set according to the specific actual situation, and this application embodiment does not limit the second specified threshold.
[0054] S250: For any given security policy, obtain a risk report for the security policy based on the detection results of the security policy.
[0055] In one possible embodiment, if the detection result indicates that the security policy has been bypassed, the following steps are taken: the number of times the security policy has been bypassed, the importance of the user's tag for bypassing the security policy, and the sensitivity of the data accessed by the user are statistically analyzed. The number of times the security policy has been bypassed, the importance of the user's tag for bypassing the security policy, and the sensitivity of the data are then weighted and summed to obtain the vulnerability index of the security policy. The vulnerability instruction of the security policy is used to characterize the vulnerability of the security policy; a larger vulnerability index indicates a less secure security policy. Additionally, the number of times a user bypasses the policy, the importance of the user's tag, and the sensitivity of the data are statistically analyzed. The number of times a user bypasses the policy, the importance of the user's tag, and the sensitivity of the data are then weighted and summed to obtain the user's risk score. The vulnerability instruction of the security policy, the user's risk score, and the detection result are then added to the risk report.
[0056] In this embodiment, a pre-defined correspondence between user tags and importance is used to determine the importance corresponding to the user's tags. Furthermore, the sensitivity of each data point in this embodiment is pre-defined. If a user accesses data with multiple sensitivities, the average sensitivity of the accessed data is used as the final sensitivity of the user's accessed data.
[0057] In one possible embodiment, if the detection result indicates a lack of security policy, the business node and the detection result are added to the risk report.
[0058] For example, a risk report could state that the "Export from Database" node lacks effective monitoring and poses a risk of data leakage.
[0059] Based on the same inventive concept, this application also provides a risk identification device. Figure 6 This is a schematic diagram of the risk identification device. Figure 6 As shown, the device 600 includes: The acquisition module 610 is used to acquire multiple stored security policies and multiple logs within a first specified time period; The behavior sequence determination module 620 is used to determine the behavior sequence of multiple users based on the multiple logs, wherein the behavior sequence includes the calling order, calling time and calling result of multiple events; The business node determination module 630 is used to determine the business node corresponding to any event in any behavior sequence according to the access path of the event, and add the business node to the behavior sequence to obtain the user's target behavior sequence, wherein the target behavior sequence includes the calling order, calling time and calling result of multiple business nodes; The detection module 640 is used to perform risk detection on the multiple security policies based on the target behavior sequence of the multiple users, and obtain the detection results; The risk report determination module 650 is used to obtain a risk report for any security policy based on the detection results of the security policy.
[0060] In one possible embodiment, the detection module 640 is specifically used for: For any user's target behavior sequence, obtain the first target business node in the target behavior sequence whose call result is failure; For any first target business node, if there is a second target business node with a successful call result within a second specified time period after the call time of the first target business node, then determine the similarity between the first target business node and the second target business node, and determine whether the second target business node is covered by the target security policy corresponding to the first target business node, and obtain the verification result, wherein the second specified time period is not greater than the first specified time period; The detection result is determined based on the similarity and the verification result.
[0061] In one embodiment, the detection module 640 is further configured to: If the similarity is greater than the first specified threshold, and the second target business node is not covered by the target security policy of the first target business node, then the detection result is determined to be that the security policy is bypassed, and the user, the target security policy, the first target business node and the second target business node are added to the detection result; Otherwise, the detection result is determined to indicate that the security strategy has not been bypassed.
[0062] In one possible embodiment, the detection module 640 is further configured to: The third target object node is determined based on the target object detection command sent by the user; Based on the target behavior sequence of the multiple users, multiple target users who call the third target service node are identified; Based on the call results of the third target business node, the multiple target users are classified to obtain a set of successful users and a set of failed users; Based on the tags of users in the successful user set and the failed user set, the detection result of the security policy corresponding to the third target business node is determined.
[0063] In one possible embodiment, the detection module 640 is further configured to: If there are users with the same user tag in the set of successful users and the set of failed users, then the detection result of the security policy is determined to be that the security policy has been bypassed. If there are no users with the same label in the set of successful users and the set of failed users, then the detection result of the security policy is determined to be that the security policy has not been bypassed.
[0064] In one possible embodiment, the detection module 640 is further configured to: In response to the user's target path determination operation, a target path is determined, wherein the target path includes multiple business nodes arranged in chronological order; For any one of the plurality of service nodes, determine whether the service node has a corresponding security policy; If so, the blocking rate of the security policy is calculated. If the blocking rate is less than the second specified threshold, the detection result of the security policy is determined to be that the security policy has been bypassed. If the blocking rate is not less than the second specified threshold, the detection result is determined to be that the security policy has not been bypassed. The blocking rate of the security policy is used to characterize the proportion of the security policy that successfully blocks the violation. If not, then the detection result indicates that the business node lacks a security policy.
[0065] The risk identification device provided in the embodiments of the present invention can execute the risk identification method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the method.
[0066] The collection, storage, use, processing, transmission, provision, and disclosure of user personal information involved in the technical solution disclosed herein comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0067] The information collected is information and data authorized by the user or fully authorized by all parties. The collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data all comply with the relevant laws, regulations and standards of the relevant countries and regions, necessary confidentiality measures have been taken, and they do not violate public order and good morals. Corresponding operation portals are provided for users to choose to authorize or refuse.
[0068] Provide users with a corresponding entry point to choose whether to agree to or reject the automated decision-making result; if the user chooses to reject, the process will proceed to the expert decision-making process. Figure 7 A schematic diagram of an electronic device 10, which can be used to implement embodiments of the present invention, is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0069] like Figure 7As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0070] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0071] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as risk identification methods.
[0072] In some embodiments, the risk identification method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the risk identification method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to perform the risk identification method by any other suitable means (e.g., by means of firmware).
[0073] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0074] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0075] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0076] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0077] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0078] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0079] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0080] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A risk identification method, characterized in that, The method includes: Retrieve multiple stored security policies and multiple logs within a first specified time period; Based on the multiple logs, a sequence of behaviors for multiple users is determined, wherein the sequence of behaviors includes the order of events being invoked, the time of invocation, and the result of invocation. For any event in any behavior sequence, the business node corresponding to the event is determined according to the access path of the event, and the business node is added to the behavior sequence to obtain the user's target behavior sequence, wherein the target behavior sequence includes the calling order, calling time and calling result of multiple business nodes; Based on the target behavior sequences of the multiple users, risk detection is performed on the multiple security policies to obtain detection results; For any given security policy, a risk report for that security policy is generated based on the detection results of that security policy.
2. The method according to claim 1, characterized in that, The step of performing risk detection on the multiple security policies based on the target behavior sequences of the multiple users, and obtaining detection results, includes: For any user's target behavior sequence, obtain the first target business node in the target behavior sequence whose call result is failure; For any first target business node, if there is a second target business node with a successful call result within a second specified time period after the call time of the first target business node, then determine the similarity between the first target business node and the second target business node, and determine whether the second target business node is covered by the target security policy corresponding to the first target business node, and obtain the verification result, wherein the second specified time period is not greater than the first specified time period; The detection result is determined based on the similarity and the verification result.
3. The method according to claim 2, characterized in that, Determining the detection result based on the similarity and the verification result includes: If the similarity is greater than the first specified threshold, and the second target business node is not covered by the target security policy of the first target business node, then the detection result is determined to be that the security policy is bypassed, and the user, the target security policy, the first target business node and the second target business node are added to the detection result; Otherwise, the detection result is determined to indicate that the security strategy has not been bypassed.
4. The method according to claim 1, characterized in that, The step of performing risk detection on the multiple security policies based on the target behavior sequences of the multiple users, and obtaining detection results, includes: The third target object node is determined based on the target object detection command sent by the user; Based on the target behavior sequence of the multiple users, multiple target users who call the third target service node are identified; Based on the call results of the third target business node, the multiple target users are classified to obtain a set of successful users and a set of failed users; Based on the tags of users in the successful user set and the failed user set, the detection result of the security policy corresponding to the third target business node is determined.
5. The method according to claim 4, characterized in that, The step of determining the detection result of the security policy corresponding to the third target service node based on the tags of users in the successful user set and the failed user set includes: If there are users with the same user tag in the set of successful users and the set of failed users, then the detection result of the security policy is determined to be that the security policy has been bypassed. If there are no users with the same label in the set of successful users and the set of failed users, then the detection result of the security policy is determined to be that the security policy has not been bypassed.
6. The method according to claim 1, characterized in that, The step of performing risk detection on the multiple security policies based on the target behavior sequences of the multiple users, and obtaining detection results, includes: In response to the user's target path determination operation, a target path is determined, wherein the target path includes multiple business nodes arranged in chronological order; For any one of the plurality of service nodes, determine whether the service node has a corresponding security policy; If so, the blocking rate of the security policy is calculated. If the blocking rate is less than the second specified threshold, the detection result of the security policy is determined to be that the security policy has been bypassed. If the blocking rate is not less than the second specified threshold, the detection result is determined to be that the security policy has not been bypassed. The blocking rate of the security policy is used to characterize the proportion of the security policy that successfully blocks the violation. If not, then the detection result indicates that the business node lacks a security policy.
7. A risk identification device, characterized in that, The device includes: The acquisition module is used to acquire multiple stored security policies and multiple logs within a first specified time period; The behavior sequence determination module is used to determine the behavior sequence of multiple users based on the multiple logs, wherein the behavior sequence includes the calling order, calling time and calling result of multiple events; The business node determination module is used to determine the business node corresponding to any event in any behavior sequence based on the access path of the event, and add the business node to the behavior sequence to obtain the user's target behavior sequence. The target behavior sequence includes the calling order, calling time and calling result of multiple business nodes. The detection module is used to perform risk detection on the multiple security policies based on the target behavior sequences of the multiple users, and obtain the detection results; The risk report determination module is used to generate a risk report for any given security policy based on the detection results of the security policy.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the risk identification method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the risk identification method according to any one of claims 1-6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the risk identification method according to any one of claims 1-6.