Network security data privacy protection management system and method
By employing a data asset and lineage analysis module, a multi-dimensional contextual information acquisition module, a dynamic privacy risk assessment engine, and an adaptive policy execution module, this technology addresses the problems of static policies, isolated decision-making, passive responses, and complex management found in existing technologies. It achieves dynamic and contextualized data privacy protection, improves the accuracy and foresight of protection, and reduces manual maintenance costs.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NAT COMPUTER NETWORK & INFORMATION SECURITY MANAGEMENT CENT GANSU BRANCH
- Filing Date
- 2026-02-04
- Publication Date
- 2026-05-15
AI Technical Summary
Existing data privacy protection technologies suffer from static strategies, isolated decision-making, passive responses, and complex management, making them unsuitable for complex business scenarios and lacking proactive risk warnings.
It employs a data asset and lineage analysis module, a multi-dimensional contextual information collection module, a dynamic privacy risk assessment engine, an adaptive strategy execution module, and a closed-loop feedback and model optimization module to achieve dynamic and contextualized privacy protection management. By collecting multi-dimensional contextual information in real time, it dynamically calculates risk scores and adaptively executes protection strategies, possessing self-learning and optimization capabilities.
It achieves a leap from static rules to dynamic intelligent protection, improving the accuracy and effectiveness of protection, reducing the impact on normal business, providing forward-looking risk warning capabilities, and reducing manual maintenance costs.
Smart Images

Figure CN122053147A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a network security data privacy protection management system and method. Background Technology
[0002] With the rapid development of big data, cloud computing, and artificial intelligence technologies, data has become a core asset for enterprises and organizations. However, data faces unprecedented privacy risks during its flow, sharing, and use. Global data protection regulations such as GDPR and CCPA have been introduced, imposing extremely high requirements on the compliance of data processing.
[0003] Existing data privacy protection technologies or systems typically have the following drawbacks:
[0004] 1. Static strategies, lacking flexibility: Most adopt rule-based static strategy engines. For example, fixed de-identification rules are applied to all fields identified as "phone numbers". This one-size-fits-all approach cannot adapt to complex business scenarios, and may affect business efficiency due to over-protection, or lead to data leakage due to insufficient protection.
[0005] 2. Isolated decision-making, ignoring context: Traditional access control or data loss prevention (DLP) systems typically only consider isolated factors such as user identity and data tags when making decisions, ignoring access time, location, access frequency, device used, request purpose, and the "aggregation risk" that arises when multiple data are accessed simultaneously.
[0006] 3. Passive response and lack of predictability: Most existing systems passively execute preset rules. When new attacks or abnormal access patterns by internal personnel occur, the system cannot proactively identify potential risks and adjust protection strategies.
[0007] 4. Complex management and reliance on manual intervention: The formulation, updating, and optimization of policies heavily depend on the experience of security administrators. As the types of data and business scenarios increase, policy management becomes extremely complex and prone to errors.
[0008] Therefore, there is an urgent need for a data privacy protection management system and method that can overcome the above-mentioned defects and achieve intelligent, contextualized, dynamic and adaptive data privacy protection. Summary of the Invention
[0009] Purpose of the invention: To provide a network security data privacy protection management system, and further to provide a management method based on the above-mentioned network security data privacy protection management system, so as to solve the above-mentioned problems existing in the prior art.
[0010] Technical solution: A network security data privacy protection and management system, comprising seven components: processor, memory, data asset and lineage analysis module, multi-dimensional contextual information acquisition module, dynamic privacy risk assessment engine, adaptive policy execution module, and closed-loop feedback and model optimization module.
[0011] The processor may be one or more;
[0012] The memory stores instructions that can be executed by the processor, and when the instructions are executed, they cause the processor to perform the following:
[0013] The data asset and lineage analysis module is used to identify data assets, determine their sensitivity levels, and construct data lineage maps.
[0014] The multi-dimensional contextual information acquisition module is used to collect multi-dimensional contextual information related to data access requests in real time.
[0015] The dynamic privacy risk assessment engine is used to calculate a quantitative privacy exposure risk score in real time based on the multi-dimensional contextual information.
[0016] The adaptive policy execution module is used to select and execute a privacy protection policy that matches the risk level from a preset policy library based on the risk score.
[0017] The closed-loop feedback and model optimization module is used to record the processing and use historical data to perform machine learning-driven optimization of the dynamic privacy risk assessment engine.
[0018] In a further embodiment, the dynamic privacy risk assessment engine further includes an aggregation risk calculation unit. The aggregation risk calculation unit is configured to analyze the correlation between multiple data items in the same request based on the data lineage graph, and calculate the incremental information leakage risk resulting from their aggregation, in order to adjust the risk score.
[0019] In a further embodiment, the dynamic privacy risk assessment engine further includes a behavioral baseline analysis unit. The behavioral baseline analysis unit is configured to establish a historical access behavior baseline model for each user and adjust the risk score by comparing the deviation of the current access behavior from this baseline.
[0020] In a further embodiment, the privacy protection policy executed by the adaptive policy execution module is hierarchical, including at least: logging, dynamic data anonymization, access blocking, and multi-factor authentication or manual approval requests.
[0021] In a further embodiment, the closed-loop feedback and model optimization module trains the risk assessment model using manually labeled access events through a supervised learning algorithm, and discovers new abnormal behavior patterns from massive access logs through an unsupervised learning algorithm.
[0022] A management method for a network security data privacy protection management system includes the following steps:
[0023] S1. Identify and classify data assets, and construct a data lineage map;
[0024] S2. When a data access request is received, collect multi-dimensional contextual information related to the request in real time.
[0025] S3. Based on the aforementioned contextual information, calculate a quantified privacy exposure risk score using a dynamic risk model;
[0026] S4. Based on the risk score, match and execute a graded, adaptive privacy protection strategy;
[0027] S5. Record the complete access and decision-making process, and use the recorded data to continuously optimize the dynamic risk model through machine learning.
[0028] In a further embodiment, the step of calculating the privacy exposure risk score further includes analyzing whether there is aggregated access of multiple related data items in the request. If so, the risk score is increased based on the information entropy increment of the aggregated data.
[0029] In a further embodiment, the step of calculating the privacy exposure risk score further includes comparing the current user's access behavior with its historical behavior baseline, and if a significant deviation is detected, increasing the risk score.
[0030] In a further embodiment, the step of implementing the privacy protection policy includes taking differentiated measures, including logging, dynamic data anonymization, access blocking, and requiring additional verification, based on the different ranges in which the risk score falls.
[0031] In a further embodiment, the step of optimizing the dynamic risk model includes periodically retraining the risk model using historical data containing the results of human intervention, in order to improve its decision-making accuracy.
[0032] Beneficial effects: This invention relates to a network security data privacy protection management system and method, which has the following significant advantages:
[0033] 1. From "static rules" to "dynamic intelligence": It has achieved a leap from passive protection based on fixed rules to dynamic intelligent protection based on real-time scenarios, which greatly improves the accuracy and effectiveness of protection.
[0034] 2. Refined and differentiated protection: Through an adaptive hierarchical strategy, the impact on normal business operations is minimized while ensuring security, achieving a balance between security and efficiency.
[0035] 3. Proactive risk warning: Through behavioral baseline analysis and aggregated risk calculation, it can identify potential and unknown internal threats and data misuse risks, transforming passive defense into proactive warning.
[0036] 4. Automation and self-evolution: The closed-loop learning mechanism enables the system to self-optimize over time, continuously adapting to new business scenarios and attack methods, significantly reducing manual maintenance costs and error rates.
[0037] 5. Enhanced compliance audit capabilities: The risk assessment process and decision-making basis for each access are recorded in detail, providing strong technical support for meeting the audit requirements of data protection regulations. Attached Figure Description
[0038] Figure 1 This is a schematic diagram of the composition framework of the network security data privacy protection management system described in this invention.
[0039] Figure 2 This is a flowchart illustrating the management method of the network security data privacy protection management system of the present invention. Detailed Implementation
[0040] In the following description, numerous specific details are set forth in order to provide a more thorough understanding of the invention. However, it will be apparent to those skilled in the art that the invention can be practiced without one or more of these details. In other instances, certain technical features well-known in the art have not been described in order to avoid obscuring the invention.
[0041] The network security data privacy protection management system involved in this invention mainly comprises seven components: a processor, a memory, a data asset and lineage analysis module, a multi-dimensional contextual information acquisition module, a dynamic privacy risk assessment engine, an adaptive policy execution module, and a closed-loop feedback and model optimization module.
[0042] The processor may be one or more;
[0043] The memory stores instructions that can be executed by the processor, and when the instructions are executed, they cause the processor to perform the following:
[0044] The data asset and lineage analysis module is used to identify data assets, determine their sensitivity levels, and construct data lineage maps.
[0045] The multi-dimensional contextual information acquisition module is used to collect multi-dimensional contextual information related to data access requests in real time.
[0046] The dynamic privacy risk assessment engine is used to calculate a quantitative privacy exposure risk score in real time based on the multi-dimensional contextual information.
[0047] The adaptive policy execution module is used to select and execute a privacy protection policy that matches the risk level from a preset policy library based on the risk score.
[0048] The closed-loop feedback and model optimization module is used to record the processing and use historical data to perform machine learning-driven optimization of the dynamic privacy risk assessment engine.
[0049] The dynamic privacy risk assessment engine further includes an aggregation risk calculation unit. This aggregation risk calculation unit is configured to analyze the correlation between multiple data items in the same request based on the data lineage graph, and calculate the incremental information leakage risk resulting from their aggregation, in order to adjust the risk score.
[0050] The dynamic privacy risk assessment engine further includes a behavioral baseline analysis unit. This behavioral baseline analysis unit is configured to build a historical access behavior baseline model for each user and adjust the risk score by comparing the deviation of the current access behavior from this baseline.
[0051] The privacy protection policies executed by the adaptive policy execution module are hierarchical, including at least: logging, dynamic data anonymization, access blocking, and multi-factor authentication or manual approval requests.
[0052] The closed-loop feedback and model optimization module trains the risk assessment model using manually labeled access events through supervised learning algorithms, and discovers new abnormal behavior patterns from massive access logs through unsupervised learning algorithms.
[0053] Based on the aforementioned depalletizing system, this invention proposes a management method for a network security data privacy protection management system, the specific steps of which are as follows:
[0054] First, identify and classify data assets, and construct a data lineage map;
[0055] Next, when a data access request is received, multi-dimensional contextual information related to the request is collected in real time;
[0056] Then, based on the aforementioned contextual information, a quantified privacy exposure risk score is calculated using a dynamic risk model;
[0057] At the same time, based on the risk score, a tiered and adaptive privacy protection strategy is matched and executed;
[0058] Finally, the complete access and decision-making process is recorded, and the recorded data is used to continuously optimize the dynamic risk model through machine learning.
[0059] The step of calculating the privacy exposure risk score further includes analyzing whether there is an aggregated access of multiple related data items in the request. If so, the risk score is increased based on the information entropy increment after aggregation.
[0060] The step of calculating the privacy exposure risk score further includes comparing the current user's access behavior with its historical behavior baseline, and if a significant deviation is detected, increasing the risk score.
[0061] The steps for implementing the privacy protection strategy include taking differentiated measures, such as logging, dynamic data anonymization, access blocking, and requiring additional verification, based on the different ranges in which the risk score falls.
[0062] The steps for optimizing the dynamic risk model include periodically retraining the risk model using historical data containing the results of human intervention, in order to improve its decision-making accuracy.
[0063] This invention aims to address the problems of static strategies, isolated decision-making, passive response, and complex management in existing data privacy protection technologies. It provides an intelligent data privacy protection management system and method that can dynamically assess risks based on multi-dimensional scenarios, adaptively execute protection strategies, and has self-learning and optimization capabilities.
[0064] To achieve the above objectives, the present invention provides a network security data privacy protection management system, characterized in that it includes:
[0065] Data Assets and Lineage Analysis Module: Configured for automatic discovery of data assets in the network, using Natural Language Processing (NLP) and Machine Learning (ML) technologies to perform content recognition and sensitivity classification of data, and constructing a data lineage map to track the source, flow and processing history of data.
[0066] Multi-dimensional contextual information acquisition module: Configured for real-time acquisition of multi-dimensional contextual information associated with data access requests. The contextual information includes at least: user context (identity, role, historical behavior), request context (access purpose, application used, operation type), data context (data sensitivity level, data lineage, associated data), and environmental context (access IP, device status, current network threat intelligence).
[0067] Dynamic Privacy Risk Assessment Engine: The core of this invention. It is configured to receive the multi-dimensional contextual information and calculate a quantified "privacy exposure risk score" in real time based on a preset risk model. This engine further includes:
[0068] An aggregation risk calculation unit is introduced: Based on the data lineage graph, when multiple data fields are detected to be accessed by the same request, this unit calculates the "information entropy increment" of these aggregated data. If the increment exceeds a threshold, the risk score is significantly increased. For example, accessing "name" and "address" individually has low risk, but accessing them simultaneously greatly increases the risk.
[0069] Integrated Behavioral Baseline Analysis Unit: Establishes a baseline model of normal access behavior for each user. When real-time access behavior deviates from the baseline (such as late-night access or a large number of queries in a short period of time), the risk score is increased.
[0070] Adaptive policy execution module: Configured to dynamically match and execute the optimal privacy protection policy from the policy library based on the risk score output by the dynamic privacy risk assessment engine. The policy library contains multi-level protection measures corresponding to different risk score ranges, for example:
[0071] Low-risk range (0-30 points): Access is allowed, but only audit logs are recorded.
[0072] Medium risk range (31-60 points): Access is allowed, but sensitive fields are dynamically desensitized (e.g., partially masked).
[0073] High-risk range (61-90 points): Access blocked, requiring secondary identity verification or higher-level approval process.
[0074] Extremely high risk range (91-100 points): Immediately block access, trigger a security alert, and temporarily freeze the relevant account. Closed-loop feedback and model optimization module: Configured to record all data access requests, contextual information, risk scores, implemented strategies, and final results (such as administrator intervention comments). This module utilizes this data:
[0075] Supervised learning: The risk assessment model is retrained periodically using data labeled by administrators (such as "false alarm" or "confirmed violation") to improve its accuracy.
[0076] Unsupervised learning: Discover new and unknown abnormal access patterns through clustering algorithms and suggest the generation of new risk rules to the administrator.
[0077] This invention also provides a corresponding network security data privacy protection and management method, characterized by the following steps: S1: Classifying and grading data assets and constructing a data lineage map through a data asset and lineage analysis module. S2: When the system receives a data access request, the multi-dimensional contextual information acquisition module captures user, request, data, and environmental contextual information related to the request.
[0078] S3: The collected contextual information is transmitted to the dynamic privacy risk assessment engine, which comprehensively evaluates the data, especially analyzing aggregated risks and deviations from behavioral baselines, to calculate a real-time privacy exposure risk score. S4: The adaptive policy execution module matches and executes corresponding tiered protection policies based on the risk score. S5: The closed-loop feedback and model optimization module records the entire processing and uses historical data to continuously and automatically learn and optimize the risk assessment model and policy library.
[0079] Furthermore, specific embodiments of the present invention are described in detail below.
[0080] The network security data privacy protection and management system of the present invention can be deployed in an enterprise intranet or cloud environment as a gateway or proxy for data access. The system includes:
[0081] The Data Asset and Lineage Analysis module scans databases, file servers, and API interfaces, using regular expressions, keyword matching, and pre-trained NLP models (such as BERT) to identify sensitive information such as Personal Information (PI) and financial data, automatically labeling them with tags like "Name," "ID Card Number," and "Confidential." Simultaneously, it analyzes ETL tasks and SQL query logs to construct dependencies and flow relationships between data, forming a visualized data lineage graph G1.
[0082] Multidimensional Contextual Information Acquisition Module: It is an information collector that integrates with identity authentication systems (such as LDAP), application log systems, network traffic analysis devices (NTA), and threat intelligence platforms to acquire contextual data in real time.
[0083] Dynamic privacy risk assessment engine: This engine receives a context vector V from the module.
[0084] First, the basic risk calculation unit 131 provides a basic score based on the sensitivity level of the data itself and the user's static permissions. .
[0085] Then, the behavior baseline analysis unit compares the current user's behavior (access time, frequency, etc.) with the baseline stored in their historical behavior model to calculate the degree of abnormal deviation. Generate risk adjustment coefficient .
[0086] Simultaneously, the aggregation risk calculation unit checks whether the request contains multiple related data items (based on the lineage graph G1). If so, it calculates the difference between the sum of the information entropies of these data items and their aggregated joint information entropy, i.e., the "aggregation entropy increment" ΔH. If ΔH is greater than a preset threshold... This generates a higher risk adjustment coefficient. .
[0087] Final risk score ,in It is an environmental risk score given based on environmental threat intelligence.
[0088] Closed-loop feedback and model optimization module: For example, in the event of a high-risk operation... After being blocked, the user appeals, and their supervisor approves the appeal. The module records this "human intervention" event. During the next model training, this sample (containing its complete context vector V and the "allowed" label) will be used to fine-tune the risk model, so that in similar situations in the future, it may give a slightly lower score but still within the warning zone, or indicate that supervisor approval is required.
[0089] The method flow of the present invention is as follows:
[0090] A specific scenario example:
[0091] An analyst typically accesses a client database via their office computer at a fixed time during the workday to perform report analysis.
[0092] 1. Normal Access: On a specific workday, an analyst queries the "City" field for 10 clients. System Assessment: User identities are normal, time is normal, data sensitivity is low, and there is no aggregation risk. Risk Score = 15. Execution Strategy: Allow access, log the query.
[0093] 2. Unauthorized Access: An analyst attempted to access the site from an unknown IP address during the early morning hours on a non-working day. Figure 1 Export the "name," "mobile phone number," and "bank card number" of 1000 customers at once. System evaluation:
[0094] User scenario: Access time and IP address deviate significantly from the behavioral baseline. Very high.
[0095] Data Context: "Name + Mobile Number + Card Number" constitutes a high-risk information aggregation. great, Very high.
[0096] The calculated risk score is as high as 95.
[0097] Execution Strategy: Immediately block the database connection, send a critical alert to the security operations center, and temporarily lock analyst Zhang's database account. Simultaneously, the module will use this incident as a high-value sample for subsequent training.
[0098] As described above, although the invention has been shown and described with reference to specific preferred embodiments, it should not be construed as limiting the invention itself. Various changes in form and detail may be made without departing from the spirit and scope of the invention as defined in the appended claims.
Claims
1. A network security data privacy protection management system, characterized in that: include: One or more processors; A memory storing instructions that can be executed by the processor, which, when executed, cause the processor to perform [the task]. The data asset and lineage analysis module is used to identify data assets, determine their sensitivity levels, and construct data lineage maps. The multi-dimensional contextual information acquisition module is used to collect multi-dimensional contextual information related to data access requests in real time. A dynamic privacy risk assessment engine is used to calculate a quantitative privacy exposure risk score in real time based on the multi-dimensional contextual information. An adaptive policy execution module is used to select and execute a privacy protection policy that matches the risk level from a preset policy library based on the risk score. The closed-loop feedback and model optimization module is used to record the processing and use historical data to perform machine learning-driven optimization of the dynamic privacy risk assessment engine.
2. The network security data privacy protection management system according to claim 1, characterized in that, The dynamic privacy risk assessment engine further includes: The aggregation risk calculation unit is configured to analyze the correlation of multiple data items in the same request based on the data lineage map, and calculate the information leakage risk increment caused by their aggregation, so as to adjust the risk score.
3. A network security data privacy protection management system according to claim 1 or 2, characterized in that, The dynamic privacy risk assessment engine further includes: The behavior baseline analysis unit is configured to establish a historical access behavior baseline model for each user and adjust the risk score by comparing the deviation of the current access behavior from the baseline.
4. The network security data privacy protection management system according to claim 3, characterized in that: The privacy protection policies executed by the adaptive policy execution module are hierarchical, including at least: logging, dynamic data anonymization, access blocking, and multi-factor authentication or manual approval requests.
5. The network security data privacy protection management system according to claim 3, characterized in that: The closed-loop feedback and model optimization module trains the risk assessment model using manually labeled access events through supervised learning algorithms, and discovers new abnormal behavior patterns from massive access logs through unsupervised learning algorithms.
6. A management method for a network security data privacy protection management system according to any one of claims 1 to 8, characterized in that... Includes the following steps: S1. Identify and classify data assets, and construct a data lineage map; S2. When a data access request is received, collect multi-dimensional contextual information related to the request in real time. S3. Based on the aforementioned contextual information, calculate a quantified privacy exposure risk score using a dynamic risk model; S4. Based on the risk score, match and execute a graded, adaptive privacy protection strategy; S5. Record the complete access and decision-making process, and use the recorded data to continuously optimize the dynamic risk model through machine learning.
7. The management method of a network security data privacy protection management system according to claim 6, characterized in that, The step of calculating the privacy exposure risk score further includes: If the analysis request contains aggregated access to multiple related data items, the risk score is increased based on the increase in information entropy after aggregation.
8. The management method of a network security data privacy protection management system according to claim 6 or 7, characterized in that... The step of calculating the privacy exposure risk score further includes: The current user's access behavior is compared with its historical baseline behavior. If a significant deviation is detected, the risk score is increased.
9. The management method of a network security data privacy protection management system according to claim 6, characterized in that, The steps for implementing the privacy protection policy include: Depending on the different risk score ranges, differentiated measures will be taken, including logging, dynamic data anonymization, access blocking, and requiring additional verification.
10. The management method of a network security data privacy protection management system according to claim 6, characterized in that, The steps for optimizing the dynamic risk model include: The risk model is periodically retrained using historical data that includes the results of human intervention to improve its decision-making accuracy.