Data processing method and device, processor and electronic equipment
By determining the data type and selecting the matching interface in the data processing system for asset data access and transformation, the problem of low data processing security in terminal device security management is solved, achieving higher security and compatibility.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHINA FAW CO LTD
- Filing Date
- 2026-03-03
- Publication Date
- 2026-05-01
AI Technical Summary
In existing technologies, the security management of terminal devices adopts a centralized architecture, which results in low data processing security and a lack of effective solutions.
By determining the data type of asset data in the data processing system, selecting a matching target interface, accessing the asset data of the service platform, and transforming it, such as through encryption, data security can be improved.
This system enables the selection of specific interfaces to collect specific data based on different data types, improving the security and compatibility of data processing, avoiding excessive consumption of computing resources, and stabilizing system operation.
Smart Images

Figure CN121967064A_ABST
Abstract
Description
Data processing methods, apparatus, processors and electronic devices Technical Field
[0001] This application relates to the field of information, and more specifically, to a data processing method, apparatus, processor, and electronic device. Background Technology
[0002] Currently, with the improvement of informatization, terminal devices, as the front-end entry point of the network, have become a key link in the network security protection system.
[0003] However, the security management of terminal devices in related technologies often adopts a centralized architecture, which uniformly manages the security policies and data collection of all terminal devices, resulting in technical problems of low data processing security.
[0004] There is currently no effective solution to the technical problem of low security in the aforementioned data processing. Summary of the Invention
[0005] This application provides a data processing method, apparatus, processor, and electronic device to at least address the technical problem of low data processing security.
[0006] According to one aspect of the embodiments of this application, a data processing method is provided, which is applied to a data processing system that communicates with a service platform and a processing platform. The method may include: determining the data type of asset data to be collected from the service platform; based on the data type, determining a target interface matching the data type from a set of interfaces of the data processing system, wherein different interfaces in the interface set are matched with different data types; accessing the asset data of the data type on the service platform through the target interface; transforming the asset data to obtain transformed asset data, wherein the security level of the transformed asset data is higher than that of the asset data before transformation, and the transformed asset data is used to transmit to the processing platform, which performs various types of processing operations on the transformed asset data.
[0007] Optionally, the data types include: single data types and mixed data types, wherein, based on the data type, the target interface matching the data type is determined from the interface set of the data processing system, including: determining the target interface matching the single data type from the interface set; and determining the target interface matching the mixed data type from the interface set.
[0008] Optionally, based on a single data type, a target interface matching the single data type is determined from the interface set, including: in response to the single data type being a disk data type, a target interface matching the disk data type is determined from the interface set; in response to the single data type being a network data type, a target interface matching the network data type is determined from the interface set; in response to the single data type being a system data type, a target interface matching the system data type is determined from the interface set.
[0009] Optionally, based on the mixed data type, from the interface set, determine the target interface matching the mixed data type, including: in response to the mixed data type including disk data type and network data type, determining the target interface matching the disk data type and the target interface matching the network data type from the interface set; in response to the mixed data type including network data type and system data type, determining the target interface matching the network data type and the target interface matching the system data type from the interface set; in response to the mixed data type including disk data type and system data type, determining the target interface matching the disk data type and the target interface matching the system data type from the interface set; in response to the mixed data type including disk data type, network data type and system data type, determining the target interface matching the disk data type, the target interface matching the network data type, and the target interface matching the system data type from the interface set.
[0010] Optionally, the asset data is transformed to obtain transformed asset data, including: encrypting the asset data to obtain encrypted asset data; and identifying the encrypted asset data as the transformed asset data.
[0011] Optionally, the method further includes: determining computing resource data of the data processing system, wherein the computing resource data is used to represent the proportion of computing resources occupied by the data processing system in the total computing resources during operation; and controlling the data processing system based on the computing resource data.
[0012] Optionally, based on computing resource data, the data processing system is controlled, including: pausing the data processing system's data transmission operation on the converted asset data in response to the proportion corresponding to the computing resource data being greater than or equal to a proportion threshold; controlling the data processing system to perform data transmission operation on the converted asset data in response to the proportion corresponding to the computing resource data being less than a proportion threshold; and determining the next asset data as asset data in response to the completion of the data transmission operation and the existence of the next asset data, and returning to execute the following steps: determining the data type of the asset data to be collected from the service platform.
[0013] According to one aspect of the embodiments of this application, a data processing apparatus is provided, which is applied to a data processing system that communicates with a service platform and a processing platform. The apparatus may include: a first determining unit for determining the data type of asset data to be collected from the service platform; a second determining unit for determining, based on the data type, a target interface matching the data type from a set of interfaces of the data processing system, wherein different interfaces in the interface set are matched with different data types; an access unit for accessing asset data of the same data type on the service platform through the target interface; and a transmission unit for converting the asset data to obtain converted asset data, wherein the security level of the converted asset data is higher than that of the asset data before conversion, and the converted asset data is transmitted to the processing platform, which performs various types of processing operations on the converted asset data.
[0014] According to another aspect of the embodiments of this application, a processor is also provided. The processor is used to run a program, wherein the program, when run by the processor, performs the data processing method described in the embodiments of this application.
[0015] According to another aspect of the embodiments of this application, an electronic device is also provided, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the data processing methods of various embodiments of this application when it runs.
[0016] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided. This computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device where the computer-readable storage medium is located to perform the data processing method of the embodiments of this application.
[0017] According to another aspect of the embodiments of this application, a computer program product is also provided. This computer program product includes a computer program, wherein, when executed by a processor, the computer program implements the data processing method of the embodiments of this application.
[0018] According to another aspect of the embodiments of this application, a computer program product is also provided, including a non-volatile computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the data processing method of the embodiments of this application.
[0019] According to another aspect of the embodiments of this application, an embodiment of this application also provides a computer program. When executed by a processor, this computer program implements the data processing method described in the embodiments of this application.
[0020] In this embodiment, during data processing, the data type of the asset data to be collected from the service platform is determined; based on the data type, a target interface matching the data type is determined from the interface set of the data processing system; the asset data of the aforementioned data type is accessed through the target interface; and the asset data is converted to obtain the converted asset data. In other words, in this embodiment, based on determining the data type of the asset data to be collected, a target interface matching the data type can be determined from the interface set of the data processing system. Through the target interface, asset data of the aforementioned data type in the service platform can be accessed. Finally, by converting the asset data, the converted asset data can be obtained. Since this embodiment can determine different target interfaces based on different data types, it achieves the goal of collecting asset data of specific data types using specific interfaces, thereby solving the technical problem of low data processing security and achieving the technical effect of improving data processing security. Attached Figure Description
[0021] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0022] Figure 1 is a flowchart of a data processing method according to an embodiment of this application;
[0023] Figure 2 is a flowchart of the operation of a Windows-based terminal security protection system according to an embodiment of this application;
[0024] Figure 3 is a schematic diagram of a data processing apparatus according to an embodiment of this application. Detailed Implementation
[0025] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present application.
[0026] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0027] According to an embodiment of this application, a data processing method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0028] This application provides a data processing method that can be applied to a data processing system. Optionally, the data processing system can communicate with both a service platform and a processing platform. Specifically, the data processing system can collect data on the service platform and transmit the collected data to the processing platform. For example, the data processing system can be a terminal security system.
[0029] Figure 1 is a flowchart of a data processing method according to an embodiment of this application. As shown in Figure 1, the method may include the following steps.
[0030] Step S101: Determine the data type of the asset data to be collected from the service platform.
[0031] In the technical solution provided by step S101 of this application, the service platform can be used to provide the aforementioned asset data. Optionally, the service platform can be an operating system platform. For example, the operating system platform can be a Windows system platform.
[0032] In this embodiment, the aforementioned asset data can be used to describe the parameter information of the terminal device. For example, the parameter information may include, but is not limited to: device information, disk information, network information, operating system information, performance information, process information, service information, and session information. The terminal device is connected to the service platform, allowing the parameter information of the terminal device to be transmitted to the service platform.
[0033] Optionally, the aforementioned device information may include, but is not limited to: motherboard serial number, Universally Unique Identifier (UUID), Basic Input / Output System (BIOS) serial number, and chassis serial number.
[0034] Optionally, the disk information mentioned above may include, but is not limited to: disk capacity, disk usage, file system type, disk partition table, and physical disk model.
[0035] Optionally, the aforementioned network information may include, but is not limited to: Media Access Control (MAC) address, Internet Protocol (IP) address, subnet mask, and network 5-tuple (source IP address, source port, destination IP address, destination port, and transport layer protocol).
[0036] Optionally, the above operating system information may include, but is not limited to: Windows version, user list, Certificate Authority Certificate (CA) certificate list, and system language.
[0037] Optionally, the above performance information may include, but is not limited to: Central Processing Unit (CPU) utilization, total memory, memory usage, memory availability, system load, and disk I / O.
[0038] Optionally, the above process information may include, but is not limited to: process identifier (ID), process name, parent process ID, command-line arguments, CPU usage, and memory usage.
[0039] Optionally, the above service information may include, but is not limited to: service name, display name, service status, startup type, and service description.
[0040] Optionally, the above session information may include, but is not limited to: logged-in user, session ID, session status, client IP, and login time.
[0041] In this embodiment, the aforementioned data type can be used to represent the type of the asset data. Optionally, the aforementioned data type may include: hard disk data type, network data type, and system data type. Specifically, the asset data indicated by the aforementioned hard disk data type may include: the aforementioned device information and the aforementioned disk information; the asset data indicated by the aforementioned network data type may include: the aforementioned network information; and the asset data indicated by the aforementioned system data type may include: the aforementioned operating system information, the aforementioned performance information, the aforementioned process information, the aforementioned service information, and the aforementioned session information.
[0042] In this embodiment, the data type of the asset data to be collected from the service platform is determined. Optionally, type detection or type identification can be performed on the asset data provided by the service platform to obtain the data type of the asset data, which may be a hard disk data type, a network data type, or a system data type.
[0043] Step S102: Based on the data type, determine the target interface that matches the data type from the interface set of the data processing system.
[0044] In the technical solution provided by step S102 of this application, the interface set may include multiple different interfaces.
[0045] In this embodiment, different interfaces in the above interface set are matched with different data types.
[0046] In this embodiment, after determining the data type, a target interface matching the data type can be determined from the interface set of the data processing system based on the data type. Optionally, if the determined data type is the aforementioned hard disk data type, then the first interface in the interface set that matches the hard disk data type is determined as the target interface; if the determined data type is the aforementioned network data type, then the second interface in the interface set that matches the network data type is determined as the target interface; if the determined data type is the aforementioned system data type, then the third interface in the interface set that matches the system data type is determined as the target interface.
[0047] Step S103: Access asset data of data type on the service platform through the target interface.
[0048] In the technical solution provided in step S103 of this application, after determining the target interface, asset data of data type on the service platform can be accessed through the target interface. Optionally, if the target interface is the first interface, asset data of hard disk data type on the service platform can be accessed through the first interface; if the target interface is the second interface, asset data of network data type on the service platform can be accessed through the second interface; if the target interface is the third interface, asset data of system data type on the service platform can be accessed through the third interface.
[0049] Step S104: Convert the asset data to obtain the converted asset data.
[0050] In the technical solution provided by step S104 of this application, the security level of the converted asset data is higher than that of the asset data before conversion. Optionally, the conversion operation can be used to improve the security level of the asset data. For example, the conversion operation can be an encryption operation on the asset data.
[0051] In this embodiment, the converted asset data can be transmitted to a processing platform. This processing platform can be a backend server.
[0052] In this embodiment, the processing platform described above can be used to perform various types of processing operations on the converted asset data. For example, these various types of processing operations may include: establishing digital asset profiles for terminal devices, performing security and compliance checks on terminal devices, and monitoring the operational status of terminal devices.
[0053] In this embodiment, after obtaining the asset data, the asset data is transformed to obtain transformed asset data. Optionally, the asset data is encrypted according to a preset encryption algorithm to obtain encrypted asset data. The encrypted asset data is then identified as the transformed asset data. The preset encryption algorithm can be a cipher block cipher (BCP) encryption algorithm. Subsequently, the transformed asset data is transmitted to a processing platform, for example, to a backend server.
[0054] In steps S101 to S104 of this embodiment, during data processing, the data type of the asset data to be collected from the service platform is determined; based on the data type, a target interface matching the data type is determined from the interface set of the data processing system; the asset data of the aforementioned data type is accessed through the target interface; and the asset data is converted to obtain the converted asset data. In other words, in this embodiment, based on determining the data type of the asset data to be collected, a target interface matching the data type can be determined from the interface set of the data processing system. Through the target interface, asset data of the aforementioned data type can be accessed on the service platform. Finally, by converting the asset data, the converted asset data can be obtained. Since this embodiment can determine different target interfaces based on different data types, it achieves the goal of collecting asset data of specific data types using specific interfaces, thereby solving the technical problem of low data processing security and achieving the technical effect of improving data processing security.
[0055] The method described in this embodiment will be further described below.
[0056] As an optional implementation method, the data type includes: a single data type and a mixed data type, wherein step S102, based on the data type, determines the target interface matching the data type from the interface set of the data processing system, including: determining the target interface matching the single data type from the interface set; and determining the target interface matching the mixed data type from the interface set.
[0057] In this embodiment, the single data type can be used to represent any one of the following data types: hard disk data type, network data type, and system data type; the mixed data type can be used to represent any two or three of the following data types: hard disk data type, network data type, and system data type.
[0058] In this embodiment, after determining the data type, a target interface matching the single data type can be determined from the interface set. Optionally, when the data type is a single data type, a target interface matching the single data type can be determined from the interface set.
[0059] In this embodiment, after determining the data type, target interfaces matching the mixed data type can be identified from the interface set. Optionally, when the data type is a mixed data type, multiple target interfaces matching the mixed data type can be identified from the interface set.
[0060] In this embodiment, based on the determination of the data type, different target interfaces can be determined according to different data types. This achieves the goal of using different interfaces to access asset data of different data types, thereby realizing the technical effect of improving the data compatibility of the data processing system.
[0061] As an optional implementation method, based on a single data type, determining a target interface matching the single data type from an interface set includes: in response to the single data type being a disk data type, determining a target interface matching the disk data type from an interface set; in response to the single data type being a network data type, determining a target interface matching the network data type from an interface set; and in response to the single data type being a system data type, determining a target interface matching the system data type from an interface set.
[0062] In this embodiment, after determining the data type, in response to the single data type being a hard disk data type, a target interface matching the hard disk data type is determined from the interface set. Optionally, when the determined interface type is the aforementioned hard disk data type, the first interface matching the hard disk data type in the aforementioned interface set can be determined as the aforementioned target interface.
[0063] In this embodiment, after determining the data type, in response to the single data type being a network data type, a target interface matching the network data type is determined from the interface set. Optionally, when the determined interface type is the aforementioned network data type, the second interface matching the network data type in the aforementioned interface set can be determined as the aforementioned target interface.
[0064] In this embodiment, after determining the data type, in response to the single data type being a system data type, a target interface matching the system data type is determined from the interface set. Optionally, when the determined interface type is the aforementioned system data type, the third interface matching the system data type in the aforementioned interface set can be determined as the aforementioned target interface.
[0065] In this embodiment, based on the determination of the data type, different target interfaces can be determined according to different data types. This achieves the goal of using different interfaces to access asset data of different data types, thereby realizing the technical effect of improving the data compatibility of the data processing system.
[0066] As an optional implementation, based on a mixed data type, determining a target interface matching the mixed data type from an interface set includes: in response to the mixed data type including disk data type and network data type, determining a target interface matching the disk data type and a target interface matching the network data type from the interface set; in response to the mixed data type including network data type and system data type, determining a target interface matching the network data type and a target interface matching the system data type from the interface set; in response to the mixed data type including disk data type and system data type, determining a target interface matching the disk data type and a target interface matching the system data type from the interface set; in response to the mixed data type including disk data type, network data type and system data type, determining a target interface matching the disk data type, a target interface matching the network data type, and a target interface matching the system data type from the interface set.
[0067] In this embodiment, after determining the data type, in response to the mixed data type including disk data type and network data type, target interfaces matching the disk data type and target interfaces matching the network data type are determined from the interface set. Optionally, when the determined data type includes the aforementioned disk data type and the aforementioned network data type, the first interface matching the disk data type and the second interface matching the network data type in the aforementioned interface set can be determined as the aforementioned target interfaces.
[0068] In this embodiment, after determining the data type, in response to the mixed data type including network data type and system data type, target interfaces matching the network data type and target interfaces matching the system data type are determined from the interface set. Optionally, when the determined data type includes the aforementioned network data type and the aforementioned system data type, the aforementioned second interface matching the network data type and the aforementioned third interface matching the system data type in the aforementioned interface set can be determined as the aforementioned target interfaces.
[0069] In this embodiment, after determining the data type, in response to the mixed data type including hard disk data type and system data type, a target interface matching the hard disk data type and a target interface matching the system data type are determined from the interface set. Optionally, when the determined data type includes the above-mentioned hard disk data type and the above-mentioned system data type, the above-mentioned first interface matching the hard disk data type and the above-mentioned third interface matching the system data type in the above-mentioned interface set can be determined as the above-mentioned target interface.
[0070] In this embodiment, after determining the data type, in response to the mixed data type including disk data type, network data type, and system data type, target interfaces matching the disk data type, the network data type, and the system data type are determined from the interface set. Optionally, when the determined data type includes the aforementioned disk data type, network data type, and system data type, the first interface matching the disk data type, the second interface matching the network data type, and the third interface matching the system data type from the interface set can be determined as the target interfaces.
[0071] In this embodiment, based on the determination of the data type, different target interfaces can be determined according to different data types. This achieves the goal of using different interfaces to access asset data of different data types, thereby realizing the technical effect of improving the data compatibility of the data processing system.
[0072] As an optional embodiment, step S104, converting the asset data to obtain converted asset data, includes: encrypting the asset data to obtain encrypted asset data; and identifying the encrypted asset data as the converted asset data.
[0073] In this embodiment, after accessing and obtaining asset data, the asset data is encrypted to obtain encrypted asset data. Optionally, at least the following parameter information can be encrypted according to a preset encryption algorithm to obtain encrypted parameter information: device information, disk information, network information, operating system information, performance information, process information, service information, and session information.
[0074] For example, by using the Advanced Encryption Standard with 256-bit key in Cipher Block Chaining mode (AES-256-CBC) encryption algorithm to locally encrypt the parameter information, the above-mentioned encrypted parameter information can be obtained.
[0075] In this embodiment, after obtaining the encrypted asset data, the encrypted asset data can be identified as the converted asset data. Optionally, after obtaining the encrypted parameter information described above, the encrypted parameter information can be identified as the converted parameter information.
[0076] In this embodiment, the accessed asset data is encrypted to obtain encrypted asset data, and the encrypted asset data is identified as the converted asset data. This achieves the purpose of encrypting asset data and thus realizes the technical effect of improving the security of asset data.
[0077] As an optional embodiment, the method further includes: determining computing resource data of the data processing system, wherein the computing resource data is used to represent the proportion of computing resources occupied by the data processing system in the total computing resources during operation; and controlling the data processing system based on the computing resource data.
[0078] In this embodiment, the aforementioned computing resource data can be used to represent the proportion of computing resources occupied by the data processing system during operation within the total computing resources. Optionally, the aforementioned computing resource data can be CPU utilization.
[0079] In this embodiment, the computing resource data of the data processing system is determined. Optionally, the CPU utilization rate included in the performance information of the aforementioned asset data can be used to determine the aforementioned computing resource data.
[0080] In this embodiment, after determining the aforementioned computing resource data, the data processing system can be controlled based on the computing resource data. Optionally, based on the ratio and ratio threshold corresponding to the aforementioned computing resource data, the data processing system can be controlled to perform data transmission operations, or the data processing system can be controlled to pause the execution of data transmission operations.
[0081] In this embodiment, by determining the computing resource data of the data processing system, the working state of the data processing system can be controlled according to the computing resource data, thereby achieving the goal of avoiding the data processing system from occupying too many computing resources, and thus realizing the technical effect of improving the operational stability of the data processing system.
[0082] As an optional embodiment, based on computing resource data, the control of the data processing system includes: pausing the data processing system's data transmission operation on the converted asset data in response to the proportion corresponding to the computing resource data being greater than or equal to a proportion threshold; controlling the data processing system to perform data transmission operation on the converted asset data in response to the proportion corresponding to the computing resource data being less than a proportion threshold; and, in response to the completion of the data transmission operation and the existence of the next asset data, determining the next asset data as asset data and returning to execute the following steps: determining the data type of the asset data to be collected from the service platform.
[0083] In this embodiment, the aforementioned percentage threshold can be a preset CPU utilization rate. For example, the preset CPU utilization rate can be 50%. This value is only for illustrative purposes and is not intended to be specific.
[0084] In this embodiment, after determining the computing resource data, in response to the proportion corresponding to the computing resource data being greater than or equal to a proportion threshold, the data processing system suspends the data transmission operation on the converted asset data. Optionally, when the CPU utilization rate is greater than or equal to the aforementioned preset CPU utilization rate, the data processing system can suspend the data transmission operation on the converted asset data.
[0085] In this embodiment, after determining the computing resource data, in response to the proportion corresponding to the computing resource data being less than a proportion threshold, the data processing system is controlled to perform a data transmission operation on the converted asset data. Optionally, when the CPU utilization rate is less than the aforementioned preset CPU utilization rate, the data processing system can be controlled to perform a data transmission operation on the converted asset data.
[0086] In this embodiment, in response to the completion of the data transmission operation and the existence of next asset data, the next asset data is identified as asset data, and the process returns to execute the following steps: determining the data type of the asset data to be collected from the service platform. Optionally, when the data transmission operation is completed, if the next asset data exists in the service platform, the next asset data is identified as asset data, and the process returns to execute the step of determining the data type of the asset data to be collected from the service platform.
[0087] In this embodiment, by determining the computing resource data of the data processing system, the working state of the data processing system can be controlled according to the computing resource data, thereby achieving the goal of avoiding the data processing system from occupying too many computing resources, and thus realizing the technical effect of improving the operational stability of the data processing system.
[0088] In this embodiment, during data processing, the data type of the asset data to be collected from the service platform is determined; based on the data type, a target interface matching the data type is determined from the interface set of the data processing system; the asset data of the aforementioned data type is accessed through the target interface; and the asset data is converted to obtain the converted asset data. In other words, in this embodiment, based on determining the data type of the asset data to be collected, a target interface matching the data type can be determined from the interface set of the data processing system. Through the target interface, asset data of the aforementioned data type can be accessed on the service platform. Finally, by converting the asset data, the converted asset data can be obtained. Since this embodiment can determine different target interfaces based on different data types, it achieves the goal of collecting asset data of specific data types using specific interfaces, thereby solving the technical problem of low data processing security and achieving the technical effect of improving data processing security.
[0089] The technical solutions of the embodiments of this application will be illustrated below with reference to preferred embodiments.
[0090] Currently, with the improvement of informatization, terminal devices, as the front-end entry point of the network, have become a key link in the network security protection system. However, the existing security management of terminal devices often adopts a centralized architecture, uniformly managing the security policies and data collection of all terminal devices, which leads to technical problems such as low data processing security.
[0091] To address the aforementioned technical problems, this application proposes a data processing method. During data processing, the data type of the asset data to be collected from the service platform is determined. Based on the data type, a target interface matching the data type is determined from the interface set of the data processing system. The asset data of the aforementioned data type is accessed through the target interface. Finally, the asset data is converted to obtain the converted asset data. In other words, in this application embodiment, based on determining the data type of the asset data to be collected, a target interface matching the data type can be determined from the interface set of the data processing system. Through the target interface, asset data of the aforementioned data type can be accessed on the service platform. Finally, the converted asset data is obtained by converting the asset data. Since this application embodiment can determine different target interfaces based on different data types, it achieves the goal of collecting asset data of specific data types using specific interfaces, thereby solving the technical problem of low data processing security and achieving the technical effect of improving data processing security.
[0092] Figure 2 is a flowchart illustrating the operation of a Windows-based endpoint security protection system according to an embodiment of this application. As shown in Figure 2, the process may include the following steps.
[0093] Step S201: The daemon process starts automatically.
[0094] In step S201 above, the daemon process starts automatically when the Windows service starts. At this point, step S202 can be executed.
[0095] Step S202: Initialize resource limits and configuration.
[0096] In step S202 above, after the daemon process starts, it automatically performs initialization of resource limits and configurations. This initialization may include, but is not limited to: configuring CPU utilization limits (default 50%) to ensure the terminal security protection system does not overload CPU resources; creating a process lock file to ensure only one instance runs; and loading global configurations. These global configurations may include, but are not limited to: log configurations, scheduler configurations, Remote Procedure Call (RPC) configurations, and event sender configurations. After initializing resource limits and configurations, step S203 can be executed.
[0097] Step S203: Start the scheduled task scheduler.
[0098] In step S203 above, after initializing resource limits and configuration, the scheduled task scheduler can be started. The scheduled task scheduler can execute heartbeat tasks at the 10th second of every hour to collect current system status information and send heartbeat data to the heartbeat server. Simultaneously, the scheduled task scheduler can also set the execution frequency for asset data collection. After starting the scheduled task scheduler, step S204 can be executed.
[0099] Step S204: Start the RPC server.
[0100] In step S204 above, after starting the scheduled task, the RPC server can be started. The RPC server can provide asset query services, baseline check services, configuration management services, and upgrade control services, etc. After starting the RPC server, step S205 can be executed.
[0101] Step S205: Perform various asset collection tasks as planned.
[0102] In step S205 above, after starting the RPC server, various asset collection tasks can be executed as planned.
[0103] Optionally, the scheduled task can execute device information collection tasks every 12 hours. Simultaneously, the collected device information is accessed via a device information interface. Finally, a device asset report is generated using the device information and sent to the distributed event streaming platform (Kafka) message queue.
[0104] Optionally, the scheduled task can execute disk information collection tasks every 12 hours. Simultaneously, the collected disk information is accessed via a disk information interface. Finally, a disk asset report is generated using the disk information and sent to the Kafka message queue.
[0105] Optionally, the scheduled task can execute network information collection tasks every 10 minutes. Simultaneously, the collected network information is accessed via a network information interface. Finally, a network asset report is generated using the network information and sent to a Kafka message queue.
[0106] Optionally, the scheduled task can execute the operating system information collection task every 4 hours. Simultaneously, it accesses the collected operating system information using the operating system information interface. Finally, it uses the operating system information to generate an operating system asset report and sends it to the Kafka message queue.
[0107] Optionally, the scheduled task can execute a performance information collection task every 10 minutes. Simultaneously, the collected performance information can be accessed using a performance information interface. Finally, a performance asset report is generated using the performance information and sent to the Kafka message queue.
[0108] Optionally, the scheduled task can execute a process information collection task every 10 minutes. Simultaneously, the collected process information can be accessed using the process information interface. Finally, a process asset report is generated using the process information and sent to the Kafka message queue.
[0109] Optionally, the scheduled task can execute service information collection tasks every 4 hours. Simultaneously, the collected service information is accessed via a service information interface. Finally, a service asset report is generated using the service information and sent to the Kafka message queue.
[0110] Optionally, the scheduled task can execute session information collection tasks every 2 hours. Simultaneously, the collected session information is accessed via a session information interface. Finally, a session asset report is generated using the session information and sent to the Kafka message queue.
[0111] In this embodiment, after various asset collection tasks are executed as planned, step S206 can be performed.
[0112] Step S206: Report data to the backend server in real time.
[0113] In step S206 above, after executing various asset collection tasks as planned, data can be reported to the backend server in real time. Optionally, the various asset reports in the Kafka message queue are serialized into JavaScript Object Notation (JSON) strings, and data such as timestamps, device IDs, and console IDs are added to the JSON strings. Finally, the JSON strings are uploaded to the backend server.
[0114] Step S207: Perform baseline checks and SBOM collection periodically.
[0115] In step S207 above, baseline checks and software bill of materials (SBOM) collection can be performed periodically.
[0116] Optionally, the scheduled task operator can execute baseline check tasks at a frequency of 2:47 AM every Wednesday. These security baseline checks may include, but are not limited to: Windows version checks, account policy checks, local policy checks, advanced audit policy checks, system service checks, Windows firewall checks, and management template checks. The check results are used to generate a baseline check report, which is then sent to a Kafka message queue.
[0117] Optionally, the scheduled task can execute the SBOM collection task at a frequency of 3:00 AM every Monday, and generate an SBOM asset report using the collected SBOM, which is then sent to the Kafka message queue.
[0118] Step S208: Automatically check and perform system upgrade.
[0119] In step S208 above, a system upgrade can be automatically checked and executed. Optionally, the scheduled task can execute the automatic upgrade task at a frequency of 30 minutes and 50 seconds per hour. Through automatic checking, it can be determined whether the terminal security protection system has a higher version. If a higher version is available, a system upgrade is executed; otherwise, no system upgrade is required.
[0120] In steps S201 to S208 above, by initializing resource limits and configurations, the terminal security protection system can operate according to the configured CPU usage limits. Furthermore, when collecting various asset messages, the system accesses the corresponding asset messages using the corresponding type of interface. This achieves the goal of collecting asset data of specific data types using specific interfaces, thereby solving the technical problem of low data processing security and ultimately improving the technical effect of data processing security.
[0121] According to an embodiment of this application, a data processing apparatus is also provided. It should be noted that this data processing apparatus can be used to execute one of the data processing methods described in the embodiment. This data processing apparatus can be applied to a data processing system, which can communicate with both a service platform and a processing platform.
[0122] Figure 3 is a schematic diagram of a data processing apparatus according to an embodiment of the present application. As shown in Figure 3, the data processing apparatus 300 may include: a first determining unit 301, a second determining unit 302, an access unit 303, and a transmission unit 304.
[0123] The first determining unit 301 is used to determine the data type of the asset data to be collected from the service platform.
[0124] The second determining unit 302 is used to determine, based on the data type, a target interface matching the data type from the interface set of the data processing system, wherein different interfaces in the interface set are matched with different data types.
[0125] Access unit 303 is used to access asset data of data type on the service platform through the target interface.
[0126] The transmission unit 304 is used to convert asset data to obtain converted asset data. The converted asset data has a higher security level than the original asset data. The converted asset data is used to transmit to the processing platform, which performs various types of processing operations on the converted asset data.
[0127] Optionally, the second determining unit 302 may include: a first determining module, used to determine a target interface matching a single data type from the interface set; and a second determining module, used to determine a target interface matching a mixed data type from the interface set.
[0128] Optionally, the first determining module may include: a first determining submodule, used to determine a target interface matching the disk data type from the interface set in response to the single data type being a disk data type; a second determining submodule, used to determine a target interface matching the network data type from the interface set in response to the single data type being a network data type; and a third determining submodule, used to determine a target interface matching the system data type from the interface set in response to the single data type being a system data type.
[0129] Optionally, the second determining module may include: a fourth determining submodule, configured to, in response to the mixed data type including disk data type and network data type, determine from the interface set a target interface matching the disk data type and a target interface matching the network data type; a fifth determining submodule, configured to, in response to the mixed data type including network data type and system data type, determine from the interface set a target interface matching the network data type and a target interface matching the system data type; a sixth determining submodule, configured to, in response to the mixed data type including disk data type and system data type, determine from the interface set a target interface matching the disk data type and a target interface matching the system data type; and a seventh determining submodule, configured to, in response to the mixed data type including disk data type, network data type and system data type, determine from the interface set a target interface matching the disk data type, a target interface matching the network data type, and a target interface matching the system data type.
[0130] Optionally, the transmission unit 304 may include: an encryption module for encrypting the asset data to obtain encrypted asset data; and a third determination module for determining the encrypted asset data as the converted asset data.
[0131] Optionally, the device may further include: a third determining unit, configured to determine computing resource data of the data processing system, wherein the computing resource data represents the proportion of computing resources occupied by the data processing system in the total computing resources during operation; and a control unit, configured to control the data processing system based on the computing resource data.
[0132] Optionally, the control unit may include: a pause module, used to pause the data processing system from performing data transmission operations on the converted asset data in response to the proportion corresponding to the computing resource data being greater than or equal to a proportion threshold; a transmission module, used to control the data processing system from performing data transmission operations on the converted asset data in response to the proportion corresponding to the computing resource data being less than a proportion threshold; and a fourth determination module, used to determine the next asset data as asset data in response to the completion of the data transmission operation and the existence of the next asset data, and return to perform the following steps: determining the data type of the asset data to be collected from the service platform.
[0133] In this embodiment, a first determining unit is used to determine the data type of the asset data to be collected from the service platform; a second determining unit is used to determine a target interface matching the data type from the interface set of the data processing system based on the data type; an access unit is used to access the asset data of the aforementioned data type on the service platform through the target interface; and a transmission unit is used to convert the asset data to obtain the converted asset data. In other words, in this embodiment, based on determining the data type of the asset data to be collected, a target interface matching the data type can be determined from the interface set of the data processing system. Through the target interface, asset data of the aforementioned data type can be accessed on the service platform. Finally, by converting the asset data, the converted asset data can be obtained. Since this embodiment can determine different target interfaces based on different data types, it achieves the goal of collecting asset data of specific data types using specific interfaces, thereby solving the technical problem of low data processing security and achieving the technical effect of improving data processing security.
[0134] According to an embodiment of this application, a processor is also provided for running a program, wherein the program is executed by the processor to perform the data processing method in the embodiment.
[0135] According to an embodiment of this application, an electronic device is also provided, including: a memory storing an executable program; and a processor for running the program, wherein the program executes the data processing method described in the embodiment during runtime.
[0136] In this application, "multiple" refers to two or more.
[0137] In this application, unless otherwise expressly defined, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection between two components. Those skilled in the art can understand the specific meaning of the above terms in this application based on the specific circumstances.
[0138] The terms “first,” “second,” “third,” “fourth,” etc., in this application (if present) are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0139] In this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, in this application, the character " / " generally indicates that the preceding and following related objects have an "or" relationship.
[0140] According to another aspect of the embodiments of this application, a computer-readable storage medium is also provided. This computer-readable storage medium includes a stored program, wherein, when the program is executed, it controls the device where the computer-readable storage medium is located to perform the data processing method described in the embodiments.
[0141] Computer-readable storage media, also known as computer storage media, may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. These propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable storage media can transmit, propagate, or transfer programs for use by or in conjunction with an instruction execution system, apparatus, or device.
[0142] The program code contained in a computer-readable storage medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, radio frequency, or any suitable combination thereof.
[0143] According to an embodiment of this application, a computer program product is also provided, which includes a computer program, wherein the computer program, when executed by a processor, implements the data processing method of the embodiment.
[0144] According to an embodiment of this application, a computer program is also provided, which, when executed by a processor, implements the data processing method described in the embodiment.
[0145] According to an embodiment of this application, a computer program product is also provided, including a non-volatile computer-readable storage medium for storing a computer program, which, when executed by a processor, implements the data processing method described in the embodiment.
[0146] Optionally, when the above-mentioned computer program is executed by the processor, the program code implements the following steps: determining the data type of the asset data to be collected from the service platform; based on the data type, determining a target interface matching the data type from the interface set of the data processing system, wherein different interfaces in the interface set are matched with different data types; accessing the asset data of the data type on the service platform through the target interface; converting the asset data to obtain converted asset data, wherein the security level of the converted asset data is higher than that of the asset data before conversion, and the converted asset data is used to transmit to the processing platform, and the processing platform is used to perform various types of processing operations on the converted asset data.
[0147] Optionally, when the above computer program is executed by the processor, the program code implements the following steps: determining a target interface matching a single data type from the interface set; determining a target interface matching a mixed data type from the interface set.
[0148] Optionally, when the above computer program is executed by the processor, the program code implements the following steps: in response to a single data type being a disk data type, determining a target interface matching the disk data type from the interface set; in response to a single data type being a network data type, determining a target interface matching the network data type from the interface set; in response to a single data type being a system data type, determining a target interface matching the system data type from the interface set.
[0149] Optionally, when the above-mentioned computer program is executed by a processor, the program code implements the following steps: in response to mixed data types including disk data types and network data types, determining, from the interface set, a target interface matching the disk data type and a target interface matching the network data type; in response to mixed data types including network data types and system data types, determining, from the interface set, a target interface matching the network data type and a target interface matching the system data type; in response to mixed data types including disk data types and system data types, determining, from the interface set, a target interface matching the disk data type and a target interface matching the system data type; in response to mixed data types including disk data types, network data types, and system data types, determining, from the interface set, a target interface matching the disk data type, a target interface matching the network data type, and a target interface matching the system data type.
[0150] Optionally, when the above computer program is executed by the processor, the program code implements the following steps: encrypting the asset data to obtain encrypted asset data; and determining the encrypted asset data as the converted asset data.
[0151] Optionally, when the above computer program is executed by the processor, the program code implements the following steps: determining the computing resource data of the data processing system, wherein the computing resource data is used to represent the proportion of computing resources occupied by the data processing system in the total computing resources during operation; and controlling the data processing system based on the computing resource data.
[0152] Optionally, when the above computer program is executed by the processor, the program code implements the following steps: in response to the proportion corresponding to the computing resource data being greater than or equal to the proportion threshold, suspending the data processing system from performing data transmission operations on the converted asset data; in response to the proportion corresponding to the computing resource data being less than the proportion threshold, controlling the data processing system to perform data transmission operations on the converted asset data; in response to the completion of the data transmission operation and the existence of the next asset data, determining the next asset data as the asset data, and returning to execute the following steps: determining the data type of the asset data to be collected from the service platform.
[0153] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0154] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0155] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual couplings, direct couplings, or communication connections may be through some interfaces; indirect couplings or communication connections between units or modules may be electrical or other forms.
[0156] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0157] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0158] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to related technologies, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, read-only memory (ROM), random access memory (RAM), portable hard drive, magnetic disk, or optical disk.
[0159] The above are merely preferred embodiments of this application. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A data processing method, characterized in that, An application is made in a data processing system that communicates with a service platform and a processing platform. The method includes: determining the data type of asset data to be collected from the service platform; based on the data type, determining a target interface matching the data type from a set of interfaces of the data processing system, wherein different interfaces in the interface set are matched with different data types; accessing the asset data of the data type on the service platform through the target interface; converting the asset data to obtain converted asset data, wherein the security level of the converted asset data is higher than that of the asset data before conversion; the converted asset data is used to transmit to the processing platform, and the processing platform is used to perform various types of processing operations on the converted asset data.
2. The method according to claim 1, characterized in that, The data types include: single data types and mixed data types. Based on the data types, determining the target interface matching the data type from the interface set of the data processing system includes: determining the target interface matching the single data type from the interface set; and determining the target interface matching the mixed data type from the interface set.
3. The method according to claim 2, characterized in that, Based on the single data type, determining a target interface matching the single data type from the interface set includes: in response to the single data type being a hard disk data type, determining a target interface matching the hard disk data type from the interface set; in response to the single data type being a network data type, determining a target interface matching the network data type from the interface set; and in response to the single data type being a system data type, determining a target interface matching the system data type from the interface set.
4. The method according to claim 2, characterized in that, Based on the mixed data type, determining a target interface matching the mixed data type from the interface set includes: in response to the mixed data type including a disk data type and a network data type, determining a target interface matching the disk data type and a target interface matching the network data type from the interface set; in response to the mixed data type including the network data type and a system data type, determining a target interface matching the network data type and a target interface matching the system data type from the interface set; in response to the mixed data type including the disk data type and the system data type, determining a target interface matching the disk data type and a target interface matching the system data type from the interface set; in response to the mixed data type including the disk data type, the network data type, and the system data type, determining a target interface matching the disk data type, a target interface matching the network data type, and a target interface matching the system data type from the interface set.
5. The method according to claim 1, characterized in that, The process of converting the asset data to obtain the converted asset data includes: encrypting the asset data to obtain the encrypted asset data; and identifying the encrypted asset data as the converted asset data.
6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: determining computing resource data of the data processing system, wherein the computing resource data represents the proportion of computing resources occupied by the data processing system in the total computing resources during operation; and controlling the data processing system based on the computing resource data.
7. The method according to claim 6, characterized in that, Based on the computing resource data, controlling the data processing system includes: pausing the data processing system's data transmission operation on the converted asset data in response to the proportion corresponding to the computing resource data being greater than or equal to a proportion threshold; controlling the data processing system to perform the data transmission operation on the converted asset data in response to the proportion corresponding to the computing resource data being less than the proportion threshold; and determining the next asset data as the asset data in response to the completion of the data transmission operation and the existence of the next asset data, and returning to execute the following steps: determining the data type of the asset data to be collected from the service platform.
8. A data processing apparatus, characterized in that, An apparatus applied to a data processing system that communicates with a service platform and a processing platform, comprising: a first determining unit for determining the data type of asset data to be collected from the service platform; a second determining unit for determining a target interface matching the data type from a set of interfaces of the data processing system, wherein different interfaces in the interface set are matched with different data types; an access unit for accessing asset data of the data type on the service platform through the target interface; and a transmission unit for converting the asset data to obtain converted asset data, wherein the security level of the converted asset data is higher than that of the asset data before conversion, and the converted asset data is transmitted to the processing platform, which performs various types of processing operations on the converted asset data.
9. A processor, characterized in that, The processor is used to run a program, wherein the program is executed by the processor to perform the method according to any one of claims 1 to 7.
10. An electronic device, characterized in that, include: Memory, which stores executable programs; A processor for running the program, wherein the program, when running, performs the method according to any one of claims 1 to 7.