Software development data security management method, platform and electronic device

By extracting the spatiotemporal characteristics of user access behavior and quantifying code acquisition intensity, combined with core file hit rate and sensitive information fingerprint matching, the problem of real-time detection of abnormal user behavior in enterprise code hosting platforms has been solved, achieving efficient security management and automated response.

CN122372610APending Publication Date: 2026-07-10XIAN VIBRANT BEAR TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610460627.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-04-09
Publication Date
2026-07-10

AI Technical Summary

Technical Problem

Existing enterprise code hosting platforms lack real-time detection of abnormal user behavior, and traditional security auditing methods cannot effectively identify sensitive file downloads and permission abuse, resulting in a high false negative rate.

Method used

By extracting the spatiotemporal characteristics of user access behavior, quantifying the intensity of code acquisition and the proportion of non-routine access, and combining the core file hit rate and sensitive information fingerprint matching, behavioral risk scoring is achieved, and a graded automated response strategy is executed.

Benefits of technology

It enables real-time security auditing of enterprise internal code hosting platforms, accurately identifies high-risk behaviors, prevents code leaks and privilege abuse, requires no manual intervention, and is suitable for large-scale enterprise code hosting platforms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122372610A_ABST
    Figure CN122372610A_ABST
Patent Text Reader

Abstract

This invention relates to the field of software development technology, and more particularly to a software development data security management method, platform, and electronic device. The method includes: extracting spatiotemporal characteristics of user access behavior and determining the first appearance of an IP address; quantifying the intensity of code acquisition by users based on their code download volume and determining a high-intensity acquisition indicator; determining the proportion of non-routine access based on the spatiotemporal characteristics of user access behavior and the user's permission level for each repository; determining a behavioral risk score based on the spatiotemporal characteristics of user access behavior, the first appearance of an IP address, the high-intensity acquisition indicator, and the proportion of non-routine access; extracting session characteristics of users within an analysis window and determining high-risk behavior indicators; and then executing a tiered automated response strategy based on the behavioral risk score and high-risk behavior indicators. This method achieves real-time, accurate identification and differentiated handling of abnormal user acquisition behavior within a code hosting platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of software development technology, and in particular to a software development data security management method, platform, and electronic device. Background Technology

[0002] Enterprise internal code hosting platforms store a large amount of core code, algorithms, and sensitive configuration information, making them a key target for security protection. Traditional security auditing methods mostly rely on static access control and post-event log analysis, which makes it difficult to detect abnormal user behavior in real time, such as bulk code fetching before leaving the company, unauthorized access to repositories not belonging to the user, and downloading sensitive files through new IP addresses.

[0003] Existing intrusion detection systems typically focus on network layer attacks and lack an understanding of Git protocol semantics; while the auditing functions built into code hosting platforms often fail to correlate multi-dimensional data, resulting in a high false negative rate.

[0004] Therefore, there is an urgent need for a security management method that can analyze user behavior characteristics in real time, quantify risks, and automatically execute differentiated responses to make up for the shortcomings of existing solutions. Summary of the Invention

[0005] The purpose of this invention is to provide a software development data security management method, platform, and electronic device to solve at least one of the problems existing in the prior art.

[0006] To achieve the above objectives, the present invention adopts the following technical solution:

[0007] A software development data security management method, comprising:

[0008] Extract the spatiotemporal features of user access behavior and determine the first appearance marker of the IP address;

[0009] The intensity of a user's code acquisition is quantified based on the amount of code downloaded, and indicators of high-intensity acquisition are identified.

[0010] The proportion of non-routine access is determined based on the spatiotemporal characteristics of user access behavior and the user's permission level for each repository.

[0011] Behavioral risk scores are determined based on the spatiotemporal characteristics of user access behavior, the first appearance of an IP address, high-intensity acquisition indicators, and the proportion of non-routine access.

[0012] Extract user session characteristics within the analysis window and identify high-risk behavior indicators, then execute a graded automated response strategy based on the behavioral risk score and high-risk behavior indicators.

[0013] Optionally, the user access logs collected within a 5-minute analysis window are aggregated. For each user, the total number of accesses Na and the number of different repositories accessed Nr within the analysis window are counted. At the same time, the client IP address of the user's current access is recorded and compared with the user's historical IP address database (which stores IP addresses that have appeared in the last 30 days). If the current IP address does not exist in the historical IP address database, the first appearance of the IP is marked as Pz = 1, otherwise it is 0.

[0014] Optionally, for each user's access record, the code download volume data obtained from the deep packet inspection device is associated to calculate the total code download volume Dtotal for each user in the analysis window; if the user's Dtotal > 3 × Dbase, the high-intensity acquisition flag Qz is triggered to be 1, otherwise it is 0, and Dbase is the department download volume benchmark.

[0015] Optionally, for each repository accessed by each user, query the user's permission level Plevel for that repository. The permission level Plevel is defined as: read-only = 1, read-write = 2, administrator = 3.

[0016] Meanwhile, "non-routine access warehouses" are defined as warehouses that users have accessed less than twice in the past 30 days. The number of non-routine warehouses accessed by users within this window is counted as Nu; the non-routine access ratio Ru = Nu / (Nr+1) is calculated.

[0017] Optionally, the expression for the behavioral risk score Rs is: Rs=w1×Pz+w2×Qz+w3×Ru+w4×min(1,Na / N0);

[0018] Among them, w1, w2, w3 and w4 are preset weight coefficients, and w1+w2+w3+w4=1, and N0 is the preset number of visits.

[0019] Optionally, extract all code file paths accessed by the user within the analysis window, compare them with a predefined list of core code files for the project, and calculate the core file hit rate Hc, where Hc = Nhit / Nf, and Nhit is the number of hit core files, and Nf is the total number of code files accessed by the user within this analysis window. If Nf = 0, then Hc = 0.

[0020] Optionally, a pre-computed sensitive information fingerprint database is used to perform fingerprint matching on the content of the code package downloaded by the user. During matching, the system extracts continuous string segments from the code package content cached by the deep packet inspection device according to natural delimiters such as newline characters, spaces, and commas. The SHA-256 hash value of each segment is calculated and compared with the hash value in the fingerprint database. If Hc is greater than 0.5 or the sensitive information fingerprint matches, that is, the code package contains any sensitive string, the high-risk behavior flag is determined to be 1; otherwise, it is 0.

[0021] Optionally, if the high-risk behavior flag is 1, the priority is determined as the first priority. The system will immediately terminate all current active sessions of the user and temporarily freeze the user's account for 24 hours. At the same time, an emergency alarm message will be sent to the security administrator, which includes the user account, timestamp, list of accessed core files and fingerprint matching results of sensitive information.

[0022] If the high-risk behavior flag is 0 and Rs is greater than the first preset risk value, the priority is determined to be the second priority. The system sends a risk warning email to the user, requiring them to click a link within 15 minutes to confirm whether it was their own operation. At the same time, the user's subsequent operations are placed in "observation mode", and all code download operations are delayed by 5 minutes until the security administrator confirms and allows them to proceed.

[0023] If the high-risk behavior flag is 0 and Rs is greater than the second preset risk value and less than or equal to the first preset risk value, the priority is determined to be the third priority. The system only records this abnormal event in the audit log for the security administrator to review afterward.

[0024] If the high-risk behavior flag is 0 and Rs is less than or equal to the second preset risk value, the priority is set to the fourth priority. The system then determines that the user behavior in this analysis window is normal and does not perform any blocking or alarm operations.

[0025] According to another aspect of this application, a software development data security management platform is provided, comprising:

[0026] Spatiotemporal feature unit, used to extract spatiotemporal features of user access behavior and determine the first appearance of IP address;

[0027] The strength unit is used to quantify the strength of a user's code acquisition based on the amount of code downloaded, and to identify high-intensity acquisition indicators.

[0028] The abnormal ratio unit is used to determine the proportion of non-routine accesses based on the spatiotemporal characteristics of user access behavior and the user's permission level for each repository.

[0029] The graded response unit is used by the risk scoring unit to determine behavioral risk scores based on the spatiotemporal characteristics of user access behavior, the first appearance of IP address, high-intensity acquisition, and the proportion of non-routine access.

[0030] The strategy execution unit is used to extract user session characteristics within the analysis window, identify high-risk behavior indicators, and then execute a graded automated response strategy based on the behavior risk score and high-risk behavior indicators.

[0031] According to another aspect of this application, an electronic device is provided, comprising:

[0032] One or more processors;

[0033] Storage device for storing one or more programs;

[0034] When the one or more programs are executed by the one or more processors, the one or more processors implement the software development data security management method.

[0035] The beneficial effects of this invention are as follows: The software development data security management method provided in this embodiment constructs a complete security audit chain from feature extraction and risk scoring to tiered response by integrating multi-source data such as audit logs, permission lists, network traffic, and human resource systems. This method dynamically extracts behavioral characteristics such as the first appearance of a user's IP address, code acquisition intensity, and proportion of non-routine accesses within a time window to form a comprehensive risk score. Simultaneously, it accurately identifies high-risk behaviors by combining core file hit rates and sensitive information fingerprint matching. Based on this, a four-level automated response strategy is implemented, covering account freezing, delayed execution, log recording, and normal access. This method can effectively detect abnormal code acquisition behavior by internal personnel, prevent code leakage and permission abuse, and requires no manual intervention, making it suitable for real-time security audit scenarios of large-scale enterprise code hosting platforms. Attached Figure Description

[0036] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0037] Figure 1 This is a flowchart illustrating the software development data security management method of this embodiment.

[0038] Figure 2 This is a flowchart illustrating the automated policy response method in this embodiment.

[0039] Figure 3This is a schematic diagram of the structure of the software development data security management platform in this embodiment.

[0040] Figure 4 This is a schematic diagram of the electronic device in this embodiment. Detailed Implementation

[0041] To more clearly illustrate the present invention, the following description, in conjunction with preferred embodiments and accompanying drawings, further clarifies the invention. Similar components in the drawings are indicated by the same reference numerals. Those skilled in the art should understand that the specific description below is illustrative rather than restrictive and should not be construed as limiting the scope of protection of the present invention.

[0042] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate for the embodiments of this application described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0043] Specifically, this embodiment is applied to the daily security audit scenario of an enterprise's internal code hosting platform.

[0044] Please see Figure 1 As shown, this is a flowchart illustrating the software development data security management method of this embodiment. Before the method is executed, the system synchronously collects data through monitoring agents deployed on the code hosting platform server and network egress, including:

[0045] Through the platform's audit log interface, all users' access records can be obtained in real time, including user account, operation time, accessed repository path, operation type (clone, pull, push, browse), client IP address, and session identifier.

[0046] By using the platform's permission management interface, the access control list of each project repository can be obtained, and the permission level of each user for each repository can be recorded (e.g., read-only, read-write, administrator).

[0047] By deploying deep packet inspection equipment at the network egress point, the system identifies and extracts code transmission traffic from Git / HTTPS protocol payloads. For HTTPS encrypted traffic, the system employs a pre-installed enterprise root certificate for SSL man-in-the-middle decryption: an enterprise CA certificate is installed on each employee terminal, and the deep packet inspection equipment acts as a proxy, intercepting the TLS handshake process, decrypting it to restore the plaintext HTTP payload, and then extracting Git protocol commands and transmitted code data from it. The total number of bytes of code actually transmitted by the user in each session is recorded as the code download volume. Simultaneously, for scenarios requiring sensitive information fingerprint matching, the deep packet inspection equipment performs streaming reassembly and temporary caching of the complete code package content downloaded by the user (such as the packaged object returned by gitclone or gitpull), releasing it immediately after scanning without retaining a plaintext copy.

[0048] Obtain the user's employment status and department information from the company's human resources system.

[0049] This embodiment does not impose specific limitations on the data collection method described above; those skilled in the art can freely set it according to their needs.

[0050] The method includes:

[0051] Step S1: Extract the spatiotemporal features of user access behavior and determine the first appearance marker of the IP address.

[0052] Specifically, the analysis window is divided into 5-minute intervals. The user access logs collected within the window are aggregated. For each user, the total number of accesses Na and the number of different repositories accessed Nr within the analysis window are counted. At the same time, the client IP address of the user's current access is recorded and compared with the user's historical IP address database (which stores IP addresses that have appeared in the last 30 days). If the current IP address does not exist in the historical IP address database, it is marked as the first appearance of the IP with a flag of 1; otherwise, it is 0.

[0053] Specifically, by extracting the spatiotemporal characteristics of user access behavior and identifying the first appearance of an IP address, access behavior originating from abnormal geographical locations can be effectively detected. By comparing this with a historical IP address database, new IP sources that have never been used before can be quickly identified, helping to identify abnormal access by attackers through jump servers or proxy servers, providing fundamental characteristics for subsequent risk scoring.

[0054] Please continue reading. Figure 1 As shown, the software development data security management method further includes:

[0055] Step S2: Quantify the intensity of a user's code acquisition based on the amount of code downloaded, and identify high-intensity acquisition indicators.

[0056] Specifically, for each user's access records, the code download volume data obtained from the deep packet inspection device is correlated, and the total code download volume Dtotal for each user in the analysis window is calculated. If the user's Dtotal > 3 × Dbase, the high-intensity acquisition flag Qz is triggered to be 1, otherwise it is 0. Dbase is the department's download volume benchmark.

[0057] Preferably, the departmental download volume benchmark Dbase is calculated as follows: the code download volume of all users in the department within the same analysis window in the past 7 days is counted, the median of the daily download volume of each window is taken, and then the average is obtained by window, finally obtaining a benchmark value Dbase with a granularity of 5 minutes.

[0058] Specifically, the intensity of code retrieval by users is quantified based on code download volume and compared with the department's download benchmark for the same period. By setting reasonable high-intensity trigger conditions, it is possible to effectively distinguish between normal development activities and abnormal batch code retrieval behavior, avoid misjudgments caused by differences in individual development habits, and eliminate the impact of differences in business characteristics between different departments on the judgment results.

[0059] Please continue reading. Figure 1 As shown, the software development data security management method further includes:

[0060] Step S3: Determine the proportion of non-routine accesses based on the spatiotemporal characteristics of user access behavior and the user's permission level for each repository.

[0061] Specifically, for each repository accessed by each user, query the user's permission level Plevel for that repository. The permission level Plevel is defined as: read-only = 1, read-write = 2, administrator = 3.

[0062] Meanwhile, "non-routine access warehouses" are defined as warehouses that users have accessed less than twice in the past 30 days. The number of non-routine warehouses accessed by users within this window is counted as Nu; the non-routine access ratio Ru = Nu / (Nr+1) is calculated.

[0063] It is worth noting that when Nr=0, meaning the user has no repository access records in the current analysis window, the user has not performed any code acquisition behavior, and therefore there is no security risk. In this case, the system does not need to perform the risk calculation and in-depth analysis in steps S3 to S5, but directly assigns the behavior risk score Rs of the window to 0, and jumps to step S52 to determine it as the fourth priority, only recording the absence of access event and ending the analysis process.

[0064] Specifically, by statistically analyzing the proportion of users accessing non-routine repositories and combining this with user permission levels for those repositories, we can accurately identify users attempting to access code outside their job responsibilities across projects and with different access levels. The definition of non-routine repositories is based on historical access frequency, effectively filtering out normal periodic access and highlighting abnormal interest diffusion behavior, providing quantitative evidence for detecting permission abuse or lateral movement.

[0065] Please continue reading. Figure 1 As shown, the software development data security management method further includes:

[0066] Step S4: Determine the behavioral risk score based on the spatiotemporal characteristics of user access behavior, the first appearance of IP address, the high-intensity acquisition indicator, and the proportion of non-routine access.

[0067] Specifically, the expression for the behavioral risk score Rs is: Rs = w1 × Pz + w2 × Qz + w3 × Ru + w4 × min(1, Na / N0);

[0068] Among them, w1, w2, w3 and w4 are preset weight coefficients, and w1+w2+w3+w4=1, and N0 is the preset number of visits.

[0069] Preferably, in this embodiment, w1 is 0.3, w2 is 0.2, w3 is 0.2, w4 is 0.3, and the preset number of accesses is 100.

[0070] Specifically, multiple dimensions of characteristics, such as abnormal IP addresses, abnormal download intensity, proportion of non-routine visits, and access frequency, are weighted and integrated to form a comprehensive behavioral risk score. This score can comprehensively reflect the user's overall risk level within the current time window, avoiding biased judgments caused by a single indicator, and providing a reliable decision-making basis for subsequent tiered response.

[0071] Please continue reading. Figure 1 As shown, the software development data security management method further includes:

[0072] Step S5: Extract the user's session characteristics within the analysis window and identify high-risk behavior indicators. Then, execute a graded automated response strategy based on the behavior risk score and high-risk behavior indicators.

[0073] Please see Figure 2 As shown, the automated policy response method includes:

[0074] Step S51: Extract the user's session features within the analysis window and identify high-risk behavior indicators.

[0075] Specifically, extract all code file paths accessed by the user within the analysis window, compare them with a predefined list of core code files for the project, and calculate the core file hit rate Hc, where Hc = Nhit / Nf, and Nhit is the number of core files hit, and Nf is the total number of code files accessed by the user within this analysis window. If Nf = 0, then Hc = 0.

[0076] Simultaneously, a pre-calculated sensitive information fingerprint database is used to perform fingerprint matching on the content of the code package downloaded by the user. The sensitive information fingerprint database is a fixed-length hexadecimal string set obtained by hashing sensitive strings such as database connection strings, API keys, and encryption certificates using SHA-256. During matching, the system extracts continuous string segments from the code package content cached by the deep packet inspection device, using natural delimiters such as newlines, spaces, and commas. The SHA-256 hash value of each segment is calculated and compared with the hash values ​​in the fingerprint database. If Hc is greater than 0.5 or a sensitive information fingerprint match is found (i.e., the code package contains any sensitive string), the high-risk behavior flag is set to 1; otherwise, it is set to 0.

[0077] Preferably, the predefined list of core code files for the project is maintained weekly by the project leader and stored in JSON format. It includes path matching rules for the project's core algorithm modules, configuration files, key files, etc. An example format is: [{"path":" / src / core / ","type":"prefix"},{"path":" / config / db.yml","type":"exact"},{"path":"*.pem","type":"wildcard"}).

[0078] Preferably, the core file hit count Nhit is obtained as follows: the system compares each code file path accessed by the user in the analysis window with the path matching rules in the predefined project core code file list one by one. The matching rules support exact matching (e.g., complete paths are equal), prefix matching (e.g., the path starts with a certain directory) and wildcard matching (e.g., *.key). For each successful file match, the Nhit count is incremented by 1. The predefined project core code file list is maintained weekly by the project manager and stored in JSON format. An example format is: [{"path":" / src / core / ","type":"prefix"},{"path":" / config / db.yml","type":"exact"},{"path":"*.pem","type":"wildcard"}].

[0079] Preferably, the method for constructing the pre-calculated sensitive information fingerprint database is as follows: The system administrator pre-collects a set of sensitive strings that need to be protected, such as the database connection string "jdbc:mysql: / / 192.168.1.1:3306 / prod", the API key "sk-abc123def456", and specific fragments of the encryption certificate private key; for each sensitive string, a fixed-length hexadecimal hash value is calculated using the SHA-256 hash algorithm (e.g., sha256("jdbc:mysql: / / ...")="e3b0c442..."), and all hash values ​​are stored in the fingerprint database. During matching, the system performs a streaming scan on the content of the code package downloaded by the user, extracts continuous string fragments according to natural delimiters such as newlines, spaces, and commas, calculates the SHA-256 hash value of each fragment, and compares it with the hash values ​​in the fingerprint database. If any hash value matches, it is determined that "sensitive information fingerprint matching hit", that is, the code package contains a sensitive string.

[0080] Specifically, by extracting the code file paths accessed by users within the analysis window and matching them with a predefined list of core files, the system calculates the core file hit rate, accurately identifying high-frequency access behaviors of users to the project's core algorithms, critical configurations, or key files. Simultaneously, by utilizing a pre-calculated sensitive information fingerprint database, hash matching of the code package content effectively detects the risk of leakage of sensitive strings such as database connection strings, API keys, and encryption certificates. These two detection methods complement each other; the former focuses on access patterns, while the latter focuses on the substance of the content, together forming a dual-judgment mechanism for high-risk behavior, avoiding false negatives or missed detections due to a single dimension.

[0081] Please continue reading. Figure 1 As shown, the automated policy response method further includes:

[0082] Step S52: Implement a graded automated response strategy based on behavioral risk scores and high-risk behavioral indicators.

[0083] Specifically, if the high-risk behavior flag is 1, the priority is determined to be the first priority. The system will immediately terminate all active sessions of the user and temporarily freeze the account for 24 hours. At the same time, an emergency alarm message will be sent to the security administrator, which includes the user account, timestamp, list of accessed core files, and fingerprint matching results of sensitive information.

[0084] If the high-risk behavior flag is 0 and Rs is greater than the first preset risk value, the priority is determined to be the second priority. The system sends a risk warning email to the user, requiring them to click a link within 15 minutes to confirm whether it was their own operation. At the same time, the user's subsequent operations are placed in "observation mode", and all code download operations are delayed by 5 minutes until the security administrator confirms and allows them to proceed.

[0085] If the high-risk behavior flag is 0 and Rs is greater than the second preset risk value and less than or equal to the first preset risk value, the priority is determined to be the third priority. The system only records this abnormal event in the audit log for the security administrator to review afterward.

[0086] If the high-risk behavior flag is 0 and Rs is less than or equal to the second preset risk value, the priority is set to the fourth priority. The system then determines that the user behavior in this analysis window is normal and does not perform any blocking or alarm operations.

[0087] Preferably, in this embodiment, the first preset risk value is 0.85 and the second preset risk value is 0.5.

[0088] Preferably, the delayed execution is implemented through a code hosting platform plugin mechanism: the system registers a Git transfer hook (such as a pre-receive or pre-download hook). When a target user initiates a clone or pull operation, the hook script intercepts the request, stores the request information in a delay queue, sets a 5-minute timer, and allows the request to proceed only after the timer expires and no blocking instruction is received.

[0089] Specifically, based on behavioral risk scores and high-risk behavior indicators, a four-tiered differentiated automated response strategy is implemented. For confirmed high-risk behaviors, the account is immediately frozen and an emergency alert is sent, achieving second-level blocking; for relatively high-risk behaviors, a delayed execution combined with a user confirmation mechanism is used to prevent code leakage while providing an opportunity to correct errors; for medium-risk behaviors, only logs are recorded for post-event review to avoid excessive interference; for normal behaviors, they are allowed directly to ensure development efficiency. This tiered strategy balances security and availability, achieving refined management of risk handling.

[0090] Please see Figure 3 As shown, the software development data security management platform includes:

[0091] Spatiotemporal feature unit, used to extract spatiotemporal features of user access behavior and determine the first appearance of IP address;

[0092] The strength unit is used to quantify the strength of a user's code acquisition based on the amount of code downloaded, and to identify high-intensity acquisition indicators.

[0093] The abnormal ratio unit is used to determine the proportion of non-routine accesses based on the spatiotemporal characteristics of user access behavior and the user's permission level for each repository.

[0094] The graded response unit is used by the risk scoring unit to determine behavioral risk scores based on the spatiotemporal characteristics of user access behavior, the first appearance of IP address, high-intensity acquisition, and the proportion of non-routine access.

[0095] The strategy execution unit is used to extract user session characteristics within the analysis window, identify high-risk behavior indicators, and then execute a graded automated response strategy based on the behavior risk score and high-risk behavior indicators.

[0096] The software development data security management platform provided in this application embodiment can execute the software development data security management method provided in any embodiment of this application, and has the corresponding functional modules and beneficial effects of the execution method.

[0097] From a hardware perspective, to implement the software development data security management method in a computer, this application also provides an electronic device; please refer to [link to relevant documentation]. Figure 4 As shown, it is a schematic diagram of the structure of the electronic device described in this application, including:

[0098] The system comprises a processor 1, a memory 2, a communication interface 3, and a bus 4; wherein the processor 1 and the memory 2, and the memory 2 and the communication interface 3, transmit data via the bus 4; the processor is used to process data in the memory and generate instructions, the memory is used to store data, the communication interface is used to receive and send data, and the bus is used to realize data transmission between the processor, the memory, and the communication interface.

[0099] In this embodiment, the software development data security management method can be implemented as a runnable computer program. When the computer program is loaded into the processor or into the memory and processed by the processor via the bus, one or more steps of the software development data security management can be executed.

[0100] This embodiment also provides a computer-readable storage medium for storing the computer-executable instructions. The computer-readable storage medium is a tangible physical storage medium that can store the computer program and various types of data used in the program. The physical storage medium includes, but is not limited to, existing physical storage media or combinations thereof, such as random access memory, read-only memory, optical disk, and hard disk.

[0101] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention, and are not intended to limit the implementation of the present invention. For those skilled in the art, other variations or modifications can be made based on the above description. It is impossible to exhaustively list all the implementation methods here. All obvious variations or modifications derived from the technical solutions of the present invention are still within the protection scope of the present invention.

Claims

1. A software development data security management method, characterized in that, include: Extract the spatiotemporal features of user access behavior and determine the first appearance marker of the IP address; The intensity of a user's code acquisition is quantified based on the amount of code downloaded, and indicators of high-intensity acquisition are identified. The proportion of non-routine access is determined based on the spatiotemporal characteristics of user access behavior and the user's permission level for each repository. Behavioral risk scores are determined based on the spatiotemporal characteristics of user access behavior, the first appearance of an IP address, high-intensity acquisition indicators, and the proportion of non-routine access. Extract user session characteristics within the analysis window and identify high-risk behavior indicators, then execute a graded automated response strategy based on the behavioral risk score and high-risk behavior indicators.

2. The software development data security management method according to claim 1, characterized in that, The analysis window is divided into 5-minute intervals. The user access logs collected within the window are aggregated. For each user, the total number of accesses Na and the number of different repositories accessed Nr within the analysis window are counted. At the same time, the client IP address of the user's current access is recorded and compared with the user's historical IP address database. If the current IP address does not exist in the historical IP address database, the first appearance of the IP is marked as Pz and is 1; otherwise, it is 0.

3. The software development data security management method according to claim 2, characterized in that, For each user's access records, the code download volume data obtained from the deep packet inspection device is correlated, and the total code download volume Dtotal for each user in the analysis window is calculated. If the user's Dtotal > 3 × Dbase, the high-intensity acquisition flag Qz is triggered to be 1, otherwise it is 0. Dbase is the department's download volume benchmark.

4. The software development data security management method according to claim 3, characterized in that, For each repository accessed by each user, query the user's permission level Plevel for that repository. The permission level Plevel is defined as: read-only = 1, read-write = 2, administrator = 3. Meanwhile, "non-routine access warehouses" are defined as warehouses that users have accessed less than twice in the past 30 days. The number of non-routine warehouses accessed by users within this window is counted as Nu; the non-routine access ratio Ru = Nu / (Nr+1) is calculated.

5. The software development data security management method according to claim 4, characterized in that, The expression for the behavioral risk score Rs is: Rs=w1×Pz+w2×Qz+w3×Ru+w4×min(1,Na / N0); Among them, w1, w2, w3 and w4 are preset weight coefficients, and w1+w2+w3+w4=1, and N0 is the preset number of visits.

6. The software development data security management method according to claim 5, characterized in that, Extract all code file paths accessed by the user within the analysis window, compare them with a predefined list of core code files for the project, and calculate the core file hit rate Hc, where Hc = Nhit / Nf, and Nhit is the number of core files hit, and Nf is the total number of code files accessed by the user within this analysis window. If Nf = 0, then Hc = 0.

7. The software development data security management method according to claim 6, characterized in that, The system uses a pre-computed sensitive information fingerprint database to perform fingerprint matching on the content of the code package downloaded by the user. During matching, the system extracts continuous string segments from the code package content cached by the deep packet inspection device according to natural delimiters such as newline characters, spaces, and commas. It calculates the SHA-256 hash value of each segment and compares it with the hash value in the fingerprint database. If Hc is greater than 0.5 or the sensitive information fingerprint matches, that is, the code package contains any sensitive string, the high-risk behavior flag is set to 1; otherwise, it is set to 0.

8. The software development data security management method according to claim 7, characterized in that, If the high-risk behavior flag is 1, the priority is determined to be the first priority. The system will immediately terminate all active sessions of the user and temporarily freeze the account for 24 hours. At the same time, an emergency alarm message will be sent to the security administrator, which includes the user account, timestamp, list of accessed core files and fingerprint matching results of sensitive information. If the high-risk behavior flag is 0 and Rs is greater than the first preset risk value, the priority is determined to be the second priority. The system sends a risk warning email to the user, requiring them to click a link within 15 minutes to confirm whether it was their own operation. At the same time, the user's subsequent operations are placed in "observation mode", and all code download operations are delayed by 5 minutes until the security administrator confirms and allows them to proceed. If the high-risk behavior flag is 0 and Rs is greater than the second preset risk value and less than or equal to the first preset risk value, the priority is determined to be the third priority. The system only records this abnormal event in the audit log for the security administrator to review afterward. If the high-risk behavior flag is 0 and Rs is less than or equal to the second preset risk value, the priority is set to the fourth priority. The system then determines that the user behavior in this analysis window is normal and does not perform any blocking or alarm operations.

9. A software development data security management platform, applied to the software development data security management method as described in any one of claims 1-8, characterized in that, include: Spatiotemporal feature unit, used to extract spatiotemporal features of user access behavior and determine the first appearance of IP address; The strength unit is used to quantify the strength of a user's code acquisition based on the amount of code downloaded, and to identify high-intensity acquisition indicators. The abnormal ratio unit is used to determine the proportion of non-routine accesses based on the spatiotemporal characteristics of user access behavior and the user's permission level for each repository. The graded response unit is used by the risk scoring unit to determine behavioral risk scores based on the spatiotemporal characteristics of user access behavior, the first appearance of IP address, high-intensity acquisition, and the proportion of non-routine access. The strategy execution unit is used to extract user session characteristics within the analysis window, identify high-risk behavior indicators, and then execute graded automated response strategies based on the behavior risk score and high-risk behavior indicators.

10. An electronic device, characterized in that, The electronic device includes: One or more processors; Storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the software development data security management method according to any one of claims 1-8.