A method for auditing classification hierarchy compliance in data flow transformation processes
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHEJIANG TIANHANG CONSULTING & SUPERVISION CO LTD
- Filing Date
- 2026-07-09
- Publication Date
- 2026-08-07
AI Technical Summary
1.本发明通过对分级要素向量集开展置信度校验与标记处理,结合动态分级评估空间及时空衰减因子计算合规基准安全级别,能够精准匹配数据流转的业务场景与时空变化特征,摒弃传统静态分级判定的局限性,显著提升数据分类分级合规判定的精准度与场景适配性,确保合规基准安全级别贴合数据单元的实际流转状态。
Smart Images

Figure CN122529918A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of compliance auditing technology, and in particular to a classification and grading compliance auditing method for data flow processes. Background Technology
[0002] With the widespread adoption of digital applications and the continued advancement of the market-based circulation of data elements, data is increasingly flowing across departments, organizations, and fields in diverse scenarios. The dynamic attributes of the entire process of data transmission, sharing, and use are becoming more prominent, significantly increasing the difficulty of managing data classification, grading, compliance auditing. Most existing data classification, grading, compliance auditing technologies rely on pre-set static data labels and fixed judgment rules to conduct compliance checks. They can only verify the fixed attributes of data and cannot adapt to the real-time changes in dynamic attributes such as timeliness, scenario, and scope during data flow. They also struggle to adaptively adjust grading assessments based on the spatiotemporal characteristics of data flow and actual business scenarios, leading to a disconnect between compliance auditing and the actual data flow status, making it difficult to guarantee effective management.
[0003] Existing data flow compliance audit processes can only perform simple surface-level comparisons of data security levels, lacking the ability to verify the confidence level of hierarchical elements, mark anomalies, and accurately trace the source. When compliance deviations occur, it is impossible to pinpoint the specific hierarchical element and rule matching issues that caused the deviation, and the audit results lack traceability support. Furthermore, existing technologies lack the ability to automatically optimize and iterate the classification and hierarchical rule base. After handling violations, it is impossible to update and improve the rule system in reverse, making it difficult to build a closed-loop handling mechanism for audit identification, risk alerts, flow control, and rule optimization. This significantly reduces the efficiency and accuracy of data flow compliance audits, failing to meet the full-process compliance control needs in dynamic data flow scenarios. Summary of the Invention
[0004] This invention provides a method for classifying and grading compliance auditing during data flow to solve the problems mentioned in the background art.
[0005] To achieve the above objectives, this invention provides a method for classification and hierarchical compliance auditing during data flow, comprising: B1: Extract the metadata information corresponding to the data unit in the data flow event, generate a hierarchical element vector set of the data flow event, calculate the confidence weight of each hierarchical element in the hierarchical element vector set, and perform confidence verification and labeling operations on the hierarchical element vector set. B2: Construct a dynamic hierarchical evaluation space, introduce a spatiotemporal decay factor, map the hierarchical element vector set to the dynamic hierarchical evaluation space, and calculate the compliance benchmark security level of the data unit in the current state based on a preset classification and hierarchical rule base. B3: Perform a fuzzy matching comparison between the compliance benchmark security level and the actual security level of the data unit, and generate a compliance audit record based on the fuzzy matching comparison result; B4: If the fuzzy matching comparison result deviates from compliance, an alarm event is triggered at each level, the classification and grading rule base is automatically optimized and iterated, and the data flow event is blocked or marked.
[0006] In a preferred embodiment, the step of extracting elements from the metadata information corresponding to the data units in the data flow event, generating a hierarchical element vector set for the data flow event, calculating the confidence weight of each hierarchical element in the hierarchical element vector set, and performing confidence verification and labeling operations on the hierarchical element vector set includes: Based on the business attributes of data flow events, effective feature items in metadata information are filtered, and the effective feature items are decomposed and combined in a hierarchical manner to obtain the hierarchical feature vector set corresponding to the data flow event. Based on the degree of correlation between the grading elements and the preset security classification grading standards, each grading element in the grading element vector set is assigned a corresponding confidence weight. Perform an overall confidence check on the hierarchical element vector set, identify the hierarchical element vectors that fail the check, and mark the hierarchical element vectors as anomalies. The hierarchical element vectors marked with anomalies are traced, located, and isolated, and anomaly element traceability records associated with corresponding data flow events are generated.
[0007] In a preferred embodiment, assigning a corresponding confidence weight to each grading element in the grading element vector set based on the correlation between the grading element and the preset security classification grading standard includes: The classification elements are matched with the classification element dimensions in the preset security classification standard to obtain the initial association result of the classification elements. Based on the affected objects and the criteria for determining the degree of impact in the aforementioned safety classification standard, the initial association results are weighted and hierarchically labeled. Based on the weight hierarchy calibration results, initial confidence weights are assigned to the hierarchical elements, and the initial confidence weights are calibrated and normalized to obtain the confidence weights of the hierarchical elements.
[0008] In a preferred embodiment, the construction of a dynamic hierarchical evaluation space, the introduction of a spatiotemporal decay factor, mapping the hierarchical element vector set to the dynamic hierarchical evaluation space, and the calculation of the compliance benchmark security level of the data unit in its current state based on a preset classification and hierarchical rule base, includes: Based on the business scenarios and lifecycle stages of the data flow events, a dynamic hierarchical evaluation space is constructed. The spatiotemporal decay factor is adapted and bound to the dynamic hierarchical evaluation space to obtain the evaluation carrier of the dynamic hierarchical evaluation space. Align and match the hierarchical element vector set with the dimensional features of the evaluation carrier to obtain the mapping result of the hierarchical element vector set; Based on the level determination criteria of the preset classification and grading rule base, the mapping result is subjected to compliance analysis, and the compliance baseline security level of the data unit in the current state is determined based on the compliance analysis result.
[0009] In a preferred embodiment, the step of adapting and binding the spatiotemporal decay factor with the dynamic hierarchical evaluation space to obtain the evaluation carrier of the dynamic hierarchical evaluation space includes: Based on the dimensional attribute characteristics of the dynamic hierarchical evaluation space, the associated dimensions used to adapt the spatiotemporal decay factor are determined. Based on the timeliness characteristics and scenario attributes of the data flow events, the spatiotemporal decay factor is decomposed into features, and the feature decomposition results are matched and fused with the associated dimensions to obtain the fusion dimension combination of the dynamic hierarchical evaluation space. A consistency check is performed on the fusion dimension combination, and an evaluation carrier for the dynamic hierarchical evaluation space is generated based on the check result.
[0010] In a preferred embodiment, the step of performing compliance analysis on the mapping result based on the level determination criteria of a preset classification and grading rule base, and determining the compliance baseline security level of the data unit in its current state based on the compliance analysis result, includes: Extract the level determination dimensions and impact assessment criteria from the classification and grading rule base, and perform correlation matching between the mapping result and the level determination dimensions to generate dimension matching features of the mapping result; Based on the aforementioned impact assessment criteria, compliance verification is performed on the dimension matching features to obtain the security impact attributes corresponding to the data unit, and the compliance baseline security level of the data unit in its current state is calculated.
[0011] In a preferred embodiment, the formula for calculating the compliance baseline security level is: ; In the formula, This indicates the compliance baseline security level of the data unit in its current state. This represents the fit coefficient of the dynamic hierarchical evaluation space. This represents the total number of valid hierarchical elements in the hierarchical element vector set. Indicates the first The confidence weights of each hierarchical element. Indicates the first The hierarchical element vector mapping value of each hierarchical element. Indicates the first Time decay characteristic values of each hierarchical element Indicates the first Spatial attenuation characteristic values of each hierarchical element This is the spatiotemporal decay adjustment coefficient. This represents the matching coefficient of the classification and grading rule base. This is the normalization factor.
[0012] In a preferred embodiment, the step of performing a fuzzy matching comparison between the compliance benchmark security level and the actual security level of the data unit, and generating a compliance audit record based on the fuzzy matching comparison result, includes: Based on the hierarchical judgment criteria and element characteristics of the compliance benchmark security level, the identification information corresponding to the actual security level of the data unit is associated and aligned. The correlation alignment results are compared by fuzzy matching to obtain the compliance deviation status between the compliance benchmark security level and the actual security level. Based on the compliance deviation status, the corresponding compliance judgment result is determined, and the compliance judgment result is bound to the data flow event, data unit and hierarchical element vector set to generate the compliance audit record of the data flow event.
[0013] In a preferred embodiment, the step of performing fuzzy matching comparison on the correlation alignment results to obtain the compliance deviation status between the compliance benchmark security level and the actual security level includes: The hierarchical element features corresponding to the compliance benchmark security level and the attribute identifier features corresponding to the actual security level in the association alignment results are checked item by item to obtain the feature matching difference items of the two types of features. Based on the attributes and scope of influence of the feature matching difference items, the security level deviation of the feature matching difference items is determined, and the security level deviation is classified and labeled to obtain the compliance deviation status between the compliance benchmark security level and the actual security level.
[0014] In a preferred embodiment, if the fuzzy matching comparison result deviates from compliance, a graded alarm event is triggered, the classification and grading rule base is automatically optimized and iterated, and the data flow event is blocked or marked, including: Based on the fuzzy matching comparison results, the degree of compliance deviation is identified, and the corresponding data security risk level is classified. Based on the data security risk level, a preset alarm handling strategy is matched, and corresponding alarm events are triggered in a graded manner; Based on the hierarchical element characteristics and rule matching anomaly information that cause compliance deviations in the compliance audit records, the classification and hierarchical rule base is corrected and updated according to the rule matching anomaly information; Based on the deviation type between the data security risk level and the data flow event, the data flow event is blocked or marked and written into the compliance audit record.
[0015] Compared with the prior art, the present invention has the following beneficial effects: 1. This invention performs confidence verification and labeling on the hierarchical element vector set, and calculates the compliance benchmark security level by combining dynamic hierarchical evaluation space and spatiotemporal decay factor. It can accurately match the business scenarios and spatiotemporal change characteristics of data flow, abandon the limitations of traditional static hierarchical judgment, significantly improve the accuracy and scenario adaptability of data classification and hierarchical compliance judgment, and ensure that the compliance benchmark security level fits the actual flow status of data units.
[0016] 2. Based on fuzzy matching comparison to identify compliance deviations, this invention simultaneously triggers tiered alarms, automatically optimizes and iterates the classification and tiered rule base, and blocks or marks data flow events. It constructs a closed-loop control mechanism for the entire process of audit identification, risk handling, and rule iteration, which can complete the entire process of compliance audit and risk control without manual intervention. This effectively improves the automation level and processing efficiency of data flow compliance audit, and ensures the compliance and security of the entire data flow process. Attached Figure Description
[0017] Figure 1 This is a flowchart illustrating a classification and grading compliance audit method for data flow, provided as an embodiment of the present invention. The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0018] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.
[0019] This application provides a method for classifying and grading compliance auditing during data flow. The executing entity of this method includes, but is not limited to, at least one of the following electronic devices that can be configured to execute the method provided in this application: a server, a terminal, etc. In other words, this method can be executed by software or hardware installed on a terminal device or a server device. The server includes, but is not limited to, a single server, a server cluster, a cloud server, or a cloud server cluster. The server can be an independent server or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms.
[0020] Reference Figure 1 The diagram shown is a flowchart illustrating a classification and grading compliance audit method for data flow according to an embodiment of the present invention. In this embodiment, the classification and grading compliance audit method for data flow includes: B1: Extract the metadata information corresponding to the data unit in the data flow event, generate a hierarchical element vector set of the data flow event, calculate the confidence weight of each hierarchical element in the hierarchical element vector set, and perform confidence verification and labeling operations on the hierarchical element vector set. In this embodiment of the invention, the step of extracting elements from the metadata information corresponding to the data units in the data flow event, generating a hierarchical element vector set for the data flow event, calculating the confidence weight of each hierarchical element in the hierarchical element vector set, and performing confidence verification and labeling operations on the hierarchical element vector set includes: Based on the business attributes of data flow events, effective feature items in metadata information are filtered, and the effective feature items are decomposed and combined in a hierarchical manner to obtain the hierarchical feature vector set corresponding to the data flow event. Based on the degree of correlation between the grading elements and the preset security classification grading standards, each grading element in the grading element vector set is assigned a corresponding confidence weight. Perform an overall confidence check on the hierarchical element vector set, identify the hierarchical element vectors that fail the check, and mark the hierarchical element vectors as anomalies. The hierarchical element vectors marked with anomalies are traced, located, and isolated, and anomaly element traceability records associated with corresponding data flow events are generated.
[0021] The step of assigning a corresponding confidence weight to each grading element in the grading element vector set based on the correlation between the grading elements and the preset security classification grading standards includes: The classification elements are matched with the classification element dimensions in the preset security classification standard to obtain the initial association result of the classification elements. Based on the affected objects and the criteria for determining the degree of impact in the aforementioned safety classification standard, the initial association results are weighted and hierarchically labeled. Based on the weight hierarchy calibration results, initial confidence weights are assigned to the hierarchical elements, and the initial confidence weights are calibrated and normalized to obtain the confidence weights of the hierarchical elements.
[0022] It needs to be specifically explained that, based on the business attributes corresponding to the data flow event, effective feature items that can reflect the data classification and grading characteristics are selected from the metadata information corresponding to the data unit. The selected effective feature items are then decomposed and combined according to the element specifications for data classification and grading to form a set of grading element vectors that completely correspond to the data flow event.
[0023] Furthermore, the hierarchical element vector set is specifically composed of data classification attribute elements used to characterize the business affiliation of data units, describe the object and data subject category; core data classification elements set according to data security classification and grading standards, including domain attributes, group coverage, regional scope, accuracy level, data scale, processing depth, coverage degree and importance, which are used to directly support data level determination; data flow characteristic elements used to characterize the data unit flow status, including timeliness characteristics, transmission range, usage scenario and life cycle stage; and security association elements used to characterize the security-related attributes of data units, including sensitive categories, authorization scope, leakage impact scope and tampering harm degree. This vector set serves as the basic carrier for subsequent confidence weight calculation, dynamic hierarchical assessment spatial mapping and compliance benchmark security level calculation.
[0024] Each of the disassembled and combined hierarchical elements is matched one by one with the hierarchical element dimensions specified in the preset safety classification standard, and the initial association result corresponding to each hierarchical element is generated based on the degree of matching.
[0025] Furthermore, the preset security classification standard is a pre-configured and solidified unified data classification and grading standard formulated in accordance with relevant national data security laws and regulations and national standards for data classification and grading. It is applicable to all scenarios of data flow and is a unified data classification and grading judgment specification. It clearly defines the dimensions of data classification, the core judgment elements of data grading, the basis for identifying different security impact objects and impact levels, the ownership conditions of data at each security level, and the benchmark requirements for compliance verification. It covers all core contents such as the industry domain of data, data subject type, sensitive attributes, security impact scope, and life cycle management requirements, and provides a unified and authoritative judgment basis and execution criteria for the correlation and matching of grading elements, the assignment of confidence weights, and the calculation of compliance benchmark security levels.
[0026] Based on the criteria for determining the affected objects and the criteria for determining the degree of impact clearly recorded in the preset safety classification standards, the initial correlation results corresponding to each graded element are divided and labeled with weight levels to form the weight level labeling results corresponding to each graded element.
[0027] Based on the weight hierarchy calibration results, each hierarchical element is assigned a corresponding initial confidence weight. Weight values with low correlation to data classification and grading requirements are removed, and the remaining weight values are uniformly calibrated. The calibrated weight values are adjusted to the quantization range that fits the hierarchical element vector set to obtain the final confidence weight of each hierarchical element.
[0028] Based on the preset confidence level judgment conditions, a confidence level verification operation is carried out on the hierarchical element vector set. From the verification results, hierarchical element vectors that do not meet the confidence level requirements are selected, and anomaly labels are added to these hierarchical element vectors using feature labeling to complete the anomaly labeling.
[0029] Furthermore, the confidence level determination criteria are unified judgment criteria set in advance based on the data security classification and grading specifications and the data flow compliance audit requirements. These criteria are used to verify the validity and usability of the graded element vector set. Specifically, they include the completeness of the extracted graded elements, the degree of fit between the characteristics of the graded elements and the dimensions of the preset security classification standards, the authenticity of the graded elements in reflecting the actual attributes and flow status of the data units, the rationality of the confidence level weight values of the graded elements, and the adaptability of the graded elements to the corresponding data flow event business scenarios. By verifying each of the above contents, it is determined whether the graded element vector set meets the usage requirements for subsequent dynamic evaluation, mapping calculation, and compliance determination.
[0030] For the hierarchical element vectors that have been marked as abnormal, source tracing and location positioning operations are performed. These hierarchical element vectors are separated from normal hierarchical element vectors to achieve isolation processing. After integrating the source tracing and location information with the isolation processing information, an abnormal element source tracing record associated with the corresponding data flow event is generated.
[0031] Furthermore, the anomaly traceability record specifically includes the unique identifier of the corresponding data flow event, the specific content and dimension type of the anomaly-marked hierarchical element vector, the judgment result of the confidence verification of the hierarchical element vector failing, the source of the metadata extraction of the anomaly hierarchical element, the basic information of the associated data unit, the execution node of the anomaly mark, and the isolation and handling status of the hierarchical element vector. The above information is integrated to form a complete, traceable, and verifiable record, providing a complete basis for subsequent compliance audits, rule base optimization and iteration, and data flow risk tracing.
[0032] By accurately extracting metadata information corresponding to data units in data flow events to generate standardized hierarchical element vector sets, and assigning appropriate confidence weights to each hierarchical element in combination with preset security classification standards, the hierarchical element vector sets are subjected to confidence verification, anomaly marking, source tracing and isolation processing, and complete anomaly element source tracing records are generated. This effectively ensures the integrity, authenticity and validity of hierarchical elements, eliminates invalid and abnormal hierarchical elements, and provides accurate and reliable basic data support for the subsequent construction of dynamic hierarchical assessment space and calculation of compliance benchmark security level. At the same time, it improves the source tracing capability and judgment accuracy of data flow compliance audit.
[0033] B2: Construct a dynamic hierarchical evaluation space, introduce a spatiotemporal decay factor, map the hierarchical element vector set to the dynamic hierarchical evaluation space, and calculate the compliance benchmark security level of the data unit in the current state based on a preset classification and hierarchical rule base. In this embodiment of the invention, the construction of a dynamic hierarchical evaluation space, the introduction of a spatiotemporal decay factor, mapping the hierarchical element vector set to the dynamic hierarchical evaluation space, and the calculation of the compliance benchmark security level of the data unit in its current state based on a preset classification and hierarchical rule base, includes: Based on the business scenarios and lifecycle stages of the data flow events, a dynamic hierarchical evaluation space is constructed. The spatiotemporal decay factor is adapted and bound to the dynamic hierarchical evaluation space to obtain the evaluation carrier of the dynamic hierarchical evaluation space. Align and match the hierarchical element vector set with the dimensional features of the evaluation carrier to obtain the mapping result of the hierarchical element vector set; Based on the level determination criteria of the preset classification and grading rule base, the mapping result is subjected to compliance analysis, and the compliance baseline security level of the data unit in the current state is determined based on the compliance analysis result.
[0034] The process of adapting and binding the spatiotemporal decay factor with the dynamic hierarchical evaluation space to obtain the evaluation carrier of the dynamic hierarchical evaluation space includes: Based on the dimensional attribute characteristics of the dynamic hierarchical evaluation space, the associated dimensions used to adapt the spatiotemporal decay factor are determined. Based on the timeliness characteristics and scenario attributes of the data flow events, the spatiotemporal decay factor is decomposed into features, and the feature decomposition results are matched and fused with the associated dimensions to obtain the fusion dimension combination of the dynamic hierarchical evaluation space. A consistency check is performed on the fusion dimension combination, and an evaluation carrier for the dynamic hierarchical evaluation space is generated based on the check result.
[0035] The method, based on a preset classification and grading rule base, performs compliance analysis on the mapping results and determines the compliance baseline security level of the data unit in its current state based on the compliance analysis results, including: Extract the level determination dimensions and impact assessment criteria from the classification and grading rule base, and perform correlation matching between the mapping result and the level determination dimensions to generate dimension matching features of the mapping result; Based on the aforementioned impact assessment criteria, compliance verification is performed on the dimension matching features to obtain the security impact attributes corresponding to the data unit, and the compliance baseline security level of the data unit in its current state is calculated.
[0036] The formula for calculating the compliance benchmark security level is as follows: ; In the formula, This indicates the compliance baseline security level of the data unit in its current state. This represents the fit coefficient of the dynamic hierarchical evaluation space. This represents the total number of valid hierarchical elements in the hierarchical element vector set. Indicates the first The confidence weights of each hierarchical element. Indicates the first The hierarchical element vector mapping value of each hierarchical element. Indicates the first Time decay characteristic values of each hierarchical element Indicates the first Spatial attenuation characteristic values of each hierarchical element This is the spatiotemporal decay adjustment coefficient. This represents the matching coefficient of the classification and grading rule base. This is the normalization factor.
[0037] It should be specifically noted that a dynamic hierarchical evaluation space is built based on the business scenario attributes corresponding to the data flow events and the life cycle stage of the data units, which can adapt to different flow scenarios and life cycle stages.
[0038] Furthermore, the business scenario attributes corresponding to data flow events refer to a set of structured features that characterize the business environment, flow links, interaction scenarios, and control conditions of data units during the flow process. Specifically, these include business affiliation scenario attributes that define the industry sector, business line, and application system to which the data belongs; flow link scenario attributes that characterize the subject type, level, and interaction relationship of the data flow initiator, receiver, and transit node; business process scenario attributes that distinguish the different business processing stages of data collection, transmission, storage, computation, sharing, and destruction; and control environment scenario attributes that describe access control, encryption protection level, and transmission channel type during the data flow process. These attributes provide a scenario adaptation basis for the construction of a dynamic hierarchical evaluation space, supporting the adaptive adjustment of the evaluation space to different flow scenarios.
[0039] The lifecycle stage of a data unit refers to the key node stages in the entire process from its creation to its destruction, categorized according to the nature, purpose, and operational status of data processing activities. Specifically, this includes the initial generation stage (when the data unit is first generated or collected), the circulation and distribution stage (transmitted between different entities or nodes), the static storage stage (centralized storage or archiving), the computational use stage (called, analyzed, or processed), the sharing and open stage (shared across entities or provided externally), and the final disposal stage (de-identified, deleted, or destroyed). Different lifecycle stages correspond to different data processing purposes, circulation statuses, and security risk characteristics. For example, the initial generation stage focuses on verifying the authenticity of the data source; the circulation and distribution stage focuses on transmission link security and access control; the computational use stage focuses on data usage permissions and processing impact assessment; the sharing and open stage focuses on cross-entity compliance management; and the final disposal stage focuses on verifying the integrity of data de-identification and destruction. This provides a stage-adaptive basis for constructing a dynamic hierarchical assessment space, enabling targeted adjustments to the hierarchical assessment logic to meet the security requirements of different stages, and supporting improved scenario adaptability and accuracy in calculating compliance benchmark security levels.
[0040] The steps for constructing a dynamic hierarchical evaluation space are as follows: Based on the business scenario attributes corresponding to the data flow events and the life cycle stage of the data units, basic dimension parameters supporting data classification and hierarchical compliance assessment are extracted, and an initial framework for dynamic hierarchical assessment space is built. The dimension settings of the initial framework are adapted to the control requirements of the business scenario and the security characteristics of the life cycle stage, providing a standardized spatial basis for the subsequent mapping of hierarchical element vectors and the calculation of compliance benchmark security levels. Based on the dimensional attribute features of the initial framework, we screen and determine the associated dimensions that can be adapted and bound to the spatiotemporal decay factor, clarify the adaptation rules and boundary conditions of each associated dimension, and ensure that the features of the spatiotemporal decay factor can match the dimensional logic of the evaluation space, thus providing an adaptation entry point for the embedding of the spatiotemporal decay factor. Based on the timeliness characteristics and scenario attributes of data flow events, the spatiotemporal decay factor is decomposed into features. The decomposed time decay features and spatial decay features are matched and fused with the determined correlation dimensions to generate a combination of fused dimensions for dynamic hierarchical evaluation space, thereby achieving deep adaptation and binding between the spatiotemporal decay factor and the evaluation space. According to the preset dimensional consistency verification rules, the generated fusion dimension combinations are verified item by item to confirm the matching degree of each dimension feature, the execution of the adaptation rules, and the adaptability to business scenarios and life cycle stages. Dimension combinations that do not meet the verification conditions are eliminated. Based on the verified fusion dimension combinations, the final evaluation carrier of the dynamic hierarchical evaluation space is generated, and the construction of the dynamic hierarchical evaluation space is completed.
[0041] Based on the dimensional attributes of the completed dynamic hierarchical evaluation space, we screened and determined the associated dimensions that can be adapted to the spatiotemporal decay factor.
[0042] Furthermore, the dimensional attribute features specifically include adaptable object attributes that characterize the type of object carried by each dimension, association adaptable attributes that characterize the compatibility of each dimension with external features, quantitative representation attributes that characterize the value taking method and quantification rules of each dimension, rule adaptable attributes that characterize the correspondence between each dimension and the judgment dimensions of the preset classification and grading rule base, and dynamic adaptable attributes that characterize the dynamic adjustment capability of each dimension. Among them, the adaptable object attributes clarify the positioning of the classification attributes, core elements, flow feature elements or security-related elements used by the dimension to carry the grading element vector; the association adaptable attributes define whether the dimension supports temporal feature binding, scenario feature mapping and the corresponding feature fusion method; the quantitative representation attributes include the data type definition, value range and precision requirements of the dimension; the rule adaptable attributes define the correspondence between the dimension and the judgment dimensions of the rule base; and the dynamic adaptable attributes characterize whether the dimension supports parameter adjustment according to business scenarios and life cycle stages. These features provide the dimensional level judgment basis and adaptability foundation for the adaptation and binding of spatiotemporal decay factors, the mapping and matching of grading element vectors and subsequent compliance analysis.
[0043] The spatiotemporal decay factor is composed of a time decay component and a spatial decay component. The time decay component is generated based on the timeliness characteristics of the data unit, such as the data transfer timestamp, data freshness, and life cycle stage duration. It reflects the decay characteristics of the data's security sensitivity or compliance judgment weight over time. The spatial decay component is generated based on the spatial characteristics of the data unit, such as the transfer subject, transmission link, access permission scope, and usage scenario. It reflects the decay characteristics of the data's security impact as the transfer spatial scenario changes. This factor can be adapted and bound to the correlation dimension of the dynamic hierarchical assessment space, participate in the spatial mapping of the hierarchical element vector set and the calculation of the compliance benchmark security level, correct the assessment bias in the traditional static hierarchical judgment that does not consider the dynamic changes in data transfer, and achieve accurate matching between the hierarchical assessment results and the actual transfer status of the data unit.
[0044] Based on the timeliness and scenario attributes reflected in the data flow events, the spatiotemporal decay factor is decomposed and processed. The decomposed spatiotemporal decay features are matched and fused with the determined correlation dimensions one by one to form a combination of fused dimensions corresponding to the dynamic hierarchical evaluation space.
[0045] Furthermore, the fusion dimension combination specifically includes a time-adaptive fusion dimension that carries the capability of time-series correction and a spatial-adaptive fusion dimension that carries the capability of scenario correction. The time-adaptive fusion dimension is formed by fusing the correlation dimension of the corresponding time-series characteristics in the dynamic hierarchical assessment space with the time decay component. It is used to quantify the impact of the timeliness characteristics of data flow on hierarchical assessment and incorporate it into the spatial dimension logic, supporting the dynamic correction of factors such as data freshness and flow duration. The spatial-adaptive fusion dimension is formed by fusing the correlation dimension of the corresponding scenario characteristics in the dynamic hierarchical assessment space with the spatial decay component. It is used to quantify the impact of scenario characteristics such as the subject and scope of data flow on hierarchical assessment and incorporate them into the spatial dimension logic, supporting the dynamic correction of changes in flow scenarios. The cross-dimensional correlation clarifies the coupling method of the two types of fusion dimensions in the process of hierarchical element mapping and compliance analysis, ensuring that the collaborative correction of the spatiotemporal decay impact adapts to the assessment needs of different business scenarios and lifecycle stages. After consistency verification, this combination forms the assessment carrier of the dynamic hierarchical assessment space, providing basic support for the subsequent mapping and matching of hierarchical element vector sets and the calculation of compliance benchmark security levels.
[0046] The fusion dimension combinations are verified item by item according to the preset dimensional consistency judgment rules, and the verified fusion dimension combinations are used as the evaluation carrier for generating a dynamic hierarchical evaluation space.
[0047] Furthermore, the assessment platform integrates the basic dimensional attributes of the dynamic hierarchical assessment space, the temporal and spatial decay characteristics of the spatiotemporal decay factor, and the collaborative adaptation relationship of the fusion dimension combination. It has the ability to dynamically adjust to the attributes of data flow business scenarios and the life cycle stages of data units. It can stably undertake the dimensional alignment and feature mapping of hierarchical element vector sets, embed the corrective effect of spatiotemporal decay on hierarchical assessment into the assessment execution process, and provide a standardized assessment basis adapted to dynamic flow scenarios for conducting compliance analysis based on the preset classification and hierarchical rule base and determining the compliance benchmark security level of the data unit in its current state.
[0048] Each dimension of the hierarchical element vector set is aligned and matched with the corresponding dimension of the evaluation carrier to form the mapping result of the hierarchical element vector set in the dynamic hierarchical evaluation space.
[0049] Extract the level determination dimensions and impact assessment criteria for security level determination from the preset classification and grading rule base, associate and match the mapping results of the grading element vector set with the level determination dimensions, and generate dimension matching features corresponding to the mapping results.
[0050] Furthermore, the pre-defined classification and grading rule base is a standardized set of rules that has been compiled and stored in advance based on relevant national data security laws and regulations, national standards for data classification and grading, and industry data security management specifications. It integrates rules for defining data classification dimensions, rules for determining data grading, rules for attributing security levels, rules for compliance verification, rules for adapting to spatiotemporal features, and rules for adapting to the lifecycle. It clearly records the basis for matching grading elements, the criteria for determining the degree of security impact, and the grading assessment requirements for different business scenarios and lifecycle stages. It can be adapted and linked with the dynamic grading assessment space and spatiotemporal decay factors, providing a unified, authoritative, and implementable basis for judgment and execution criteria for the compliance analysis of the grading element vector set mapping results and the determination of the compliance benchmark security level of the data unit in the current state. This ensures the standardization, accuracy, and scenario adaptability of the grading assessment and compliance judgment process.
[0051] Based on the impact assessment criteria in the classification and grading rule base, compliance verification operations are carried out on the dimension matching features to determine the security impact attributes corresponding to the data units.
[0052] Furthermore, the security impact attributes specifically include the sensitivity level attribute, which characterizes the degree of sensitivity of the data unit; the impact scope attribute, which characterizes the scope of subjects and domain boundaries affected by data leakage or unauthorized use; the harm level attribute, which characterizes the degree of harm to individual rights, business operations and public order caused by data security anomalies; the compliance matching attribute, which characterizes the degree of conformity between the data unit and the compliance judgment standards; and the control adaptation attribute, which characterizes the required security protection strength and control level of the data unit. This attribute provides a direct basis for determining the compliance benchmark security level of the data unit in its current state, ensuring that the security level judgment accurately matches the actual security risks and flow control needs of the data unit.
[0053] By combining the security impact attributes of the data unit with the preset compliance level judgment logic, the compliance baseline security level of the data unit in the current circulation state is determined.
[0054] Furthermore, the compliance benchmark security level characterizes the dynamic security compliance level of the data unit in its current circulation state, and is used for subsequent fuzzy matching comparison with the actual security level of the data unit.
[0055] The dynamic tiered assessment space adaptation coefficient is obtained from a pre-set dynamic adaptation coefficient table based on the business scenario attributes of data flow events and the lifecycle stage of data units. Different business scenarios and lifecycle stages correspond to different coefficient values. For example, the adaptation coefficient value of the shared and open stage in the financial industry is higher than that of the static storage stage in general industries. When the dynamic tiered assessment space adaptation coefficient increases, the overall compliance benchmark security level is improved, reflecting the positive correction of the security level by high-risk business scenarios or lifecycle stages, and reflecting the higher requirements for data security control in this scenario. When the dynamic tiered assessment space adaptation coefficient decreases, the compliance benchmark security level is reduced accordingly to adapt to the security assessment needs of low-risk scenarios.
[0056] The total number of valid classification elements is determined by the number of classification elements that have not been marked as abnormal after confidence verification. That is, after removing classification elements marked as abnormal, the remaining classification elements participating in this calculation are the number of classification elements. The total number of valid classification elements determines the number of valid features participating in the security level assessment. The larger the total number of valid classification elements, the more comprehensive the valid classification elements participating in the calculation, and the higher the reliability of the assessment results. At the same time, the value of the total number of valid classification elements indirectly affects the benchmark of subsequent normalization processing, ensuring that the size of the summation term matches the number of elements.
[0057] The confidence weight is based on the degree of correlation between the grading element and the preset security classification standard. It is obtained after initial correlation matching, weight hierarchy calibration, initial assignment, and calibration normalization, and the value range is (0,1]. Elements directly related to the core grading judgment standard have higher weights, while auxiliary related elements have lower weights. The confidence weight directly determines the contribution of the grading element to the summation result. The larger the confidence weight, the stronger the influence of the element on the overall result, ensuring that the core grading element occupies a dominant position in the security level judgment. The smaller the confidence weight, the weaker the influence of the element, avoiding secondary features from interfering with the core judgment logic and ensuring the pertinence of the assessment results.
[0058] The hierarchical element vector mapping value is obtained by aligning and matching the hierarchical element vector set with the dimensional features of the evaluation carrier. In other words, it is the quantified mapping value of the corresponding dimension of the hierarchical element in the dynamic hierarchical evaluation space. The qualitative characteristics of the hierarchical element are transformed into standardized quantitative values through preset mapping rules. The value range is set according to the element type and the quantification rules of the evaluation space. It directly reflects the strength of the basic security attribute of the hierarchical element, and its value represents the basic contribution of the element to the security level. For example, the higher the data sensitivity level and the wider the impact of an element, the larger the hierarchical element vector mapping value, and the stronger its positive contribution to the summation result, directly reflecting the impact of the element's own security attributes on the result.
[0059] The spatiotemporal decay adjustment coefficient is preset based on the security control requirements of the industry to which the data belongs, and its value is a positive real number. Higher values are set for highly sensitive industries to strengthen the correction effect of spatiotemporal changes on the security level, while lower values are set for general industries to suit scenarios with lower sensitivity to spatiotemporal changes. It is used to control the correction strength of the time decay characteristic value and the spatial decay characteristic value on the result. The larger the spatiotemporal decay adjustment coefficient value, the more significant the impact of changes in the time decay characteristic value and the spatial decay characteristic value on the decay term, that is, the stronger the correction effect of spatiotemporal changes in data flow on the security level. The smaller the spatiotemporal decay adjustment coefficient value, the smoother the decay effect, suitable for scenarios where spatiotemporal changes have a smaller impact on data security.
[0060] The time decay characteristic value is extracted from the metadata of data flow events and calculated based on the timeliness characteristics of data units, such as flow timestamps, data freshness, and lifecycle stage duration. The longer the data flow time and the lower the freshness, the larger the time decay characteristic value, and vice versa. It is a negative variable of the spatiotemporal decay term. The larger the time decay characteristic value, the smaller the decay term value, and the weaker the contribution of this hierarchical element, reflecting the decay effect of time on data security sensitivity. The smaller the time decay characteristic value, the closer the decay term value is to 1, and the higher the contribution retention of this element, reflecting the security sensitivity characteristics of fresh data.
[0061] Spatial attenuation characteristic values are extracted from the metadata of data flow events and calculated based on spatial characteristics such as the flow subject, transmission range, access permissions, and usage scenarios of the data unit. The more flow subjects, the wider the access range, and the more open the usage scenarios, the larger the spatial attenuation characteristic value; conversely, the smaller it is. It is a negative variable of the spatiotemporal attenuation term. The larger the spatial attenuation characteristic value, the smaller the attenuation term value, and the weaker the contribution of this hierarchical element, reflecting the attenuation effect of the expansion of the flow space on data security sensitivity. The smaller the spatial attenuation characteristic value, the closer the attenuation term value is to 1, and the higher the contribution retention of this element, reflecting the data security sensitivity characteristics in closed scenarios.
[0062] The matching coefficient of the classification and grading rule base is obtained by associating and matching the mapping result of the grading element vector set with the level judgment dimension of the preset classification and grading rule base. The value range is (0,1]. The higher the degree of fit between the mapping result and the judgment conditions of the rule base, the larger the matching coefficient of the classification and grading rule base, and vice versa. The larger the value, the higher the degree of fit between the grading characteristics of the data unit and the preset classification and grading rules. The summation result is positively amplified to ensure the consistency between compliance judgment and standard rules. The smaller the value, the larger the deviation between the characteristics and the rules. The summation result is corrected to avoid non-standard elements dominating the security level judgment and to ensure the compliance of the assessment results.
[0063] The normalization factor is calculated based on the number of dimensions in the dynamic hierarchical assessment space, the maximum theoretical contribution value of the hierarchical elements, and the preset security level value range. It is used to standardize the weighted summation result of the numerator to a unified value range; to eliminate the incomparability of results caused by differences in the number of elements and value ranges in different data flow scenarios, and to make the compliance benchmark security level of different data units horizontally comparable; at the same time, the value of the normalization factor ensures that the final calculation result is within the preset security level value range, adapting to the needs of subsequent compliance verification, risk classification, and control decisions.
[0064] By constructing a dynamic hierarchical assessment space adapted to data flow business scenarios and lifecycle stages, and introducing a spatiotemporal decay factor and binding it to the assessment space to generate a standardized assessment carrier, the hierarchical element vector set is mapped to the assessment carrier and combined with a preset classification and hierarchical rule base to calculate the compliance benchmark security level of the data unit in its current state. This overcomes the limitations of traditional static hierarchical judgments that cannot adapt to the dynamic changes in data flow, accurately quantifies the decay impact of time and space factors on data security hierarchical attributes, and achieves adaptive matching between hierarchical assessment logic and data flow scenarios and stages. This significantly improves the scenario adaptability and dynamic accuracy of the compliance benchmark security level, providing a reliable benchmark basis that fits the actual flow state of the data unit for subsequent compliance comparison and audit judgment.
[0065] B3: Perform a fuzzy matching comparison between the compliance benchmark security level and the actual security level of the data unit, and generate a compliance audit record based on the fuzzy matching comparison result; In this embodiment of the invention, the step of performing a fuzzy matching comparison between the compliance benchmark security level and the actual security level of the data unit, and generating a compliance audit record based on the fuzzy matching comparison result, includes: Based on the hierarchical judgment criteria and element characteristics of the compliance benchmark security level, the identification information corresponding to the actual security level of the data unit is associated and aligned. The correlation alignment results are compared by fuzzy matching to obtain the compliance deviation status between the compliance benchmark security level and the actual security level. Based on the compliance deviation status, the corresponding compliance judgment result is determined, and the compliance judgment result is bound to the data flow event, data unit and hierarchical element vector set to generate the compliance audit record of the data flow event.
[0066] The step of performing fuzzy matching and comparison on the correlation alignment results to obtain the compliance deviation status between the compliance benchmark security level and the actual security level includes: The hierarchical element features corresponding to the compliance benchmark security level and the attribute identifier features corresponding to the actual security level in the association alignment results are checked item by item to obtain the feature matching difference items of the two types of features. Based on the attributes and scope of influence of the feature matching difference items, the security level deviation of the feature matching difference items is determined, and the security level deviation is classified and labeled to obtain the compliance deviation status between the compliance benchmark security level and the actual security level.
[0067] It needs to be specifically explained that, based on the grading judgment criteria corresponding to the compliance benchmark security level and the core element characteristics of the grading element vector set, the attribute identification information corresponding to the actual security level of the data unit is correlated one by one with the judgment dimensions and element characteristics of the compliance benchmark security level, so as to complete the correlation and alignment processing of the relevant information of the two types of security levels.
[0068] For the results after association and alignment, the hierarchical element features corresponding to the compliance benchmark security level and the attribute identifier features corresponding to the actual security level are checked item by item to verify their compatibility, and feature matching differences that do not match between the two types of features are identified.
[0069] Based on the inherent attributes of the feature matching difference item and its impact on the data security classification, the security level deviation situation corresponding to the difference item is determined. According to the preset deviation classification standard, the various deviation situations are classified and labeled to obtain the compliance deviation status between the compliance benchmark security level and the actual security level.
[0070] Furthermore, the pre-defined deviation classification standard is a set of standardized rules that are formulated and stored in advance based on relevant national data security laws and regulations, national standards for data classification and grading, industry data security management and control specifications, and data flow compliance audit business requirements. It is used to uniformly and quantitatively classify and judge deviations between the compliance benchmark security level and the actual security level.
[0071] It clearly stipulates the attribute determination rules, impact scope assessment rules, deviation degree level classification rules, and compliance judgment benchmarks corresponding to different deviation levels for feature matching discrepancies. Among them, the attribute determination rules are used to define the type of hierarchical element and judgment dimension to which the discrepancy belongs; the impact scope assessment rules are used to assess the impact boundary of the discrepancy on the data security hierarchical judgment; the deviation degree level classification rules divide the deviation into different levels such as no deviation, slight deviation, moderate deviation, and severe deviation based on the confidence weight, quantity, and impact degree of the discrepancy. At the same time, it sets differentiated deviation judgment thresholds in combination with the business scenario of data flow and life cycle stage, providing an objective and consistent judgment basis for the classification and labeling of compliance deviation status, eliminating the subjective bias of manual judgment, ensuring the accuracy and standardization of the classification of security level deviation during fuzzy matching comparison, and providing reliable support for the determination of subsequent compliance judgment results and the generation of compliance audit records.
[0072] Based on the calibration results of the compliance deviation status, the compliance judgment result corresponding to the data unit is determined. The compliance judgment result is then associated and bound with the corresponding data flow event information, data unit basic information, and hierarchical element vector set information to generate the compliance audit record corresponding to the data flow event.
[0073] Furthermore, the compliance audit record specifically includes the unique identifier information of the corresponding data flow event, the basic attributes and business affiliation information of the data unit, the identifier of the associated hierarchical element vector set and the index of the abnormal element tracing record, the calculation basis and final result of the compliance benchmark security level, the attribute identifier information of the actual security level of the data unit, the dimension matching details of the association alignment, the verification results and details of the feature matching difference items, the classification and labeling results of the compliance deviation status and the deviation impact assessment, the final compliance judgment result, and the timestamp and execution node identifier of the audit record generation. The above information is integrated to form a complete and verifiable audit link, which can not only fully reproduce the entire process of compliance comparison, but also provide traceable support for subsequent data flow risk handling, compliance rectification and optimization and iteration of the classification and hierarchical rule base.
[0074] By associating and aligning the compliance benchmark security level with the actual security level of the data unit and comparing them with fuzzy matching, the system accurately determines the compliance deviation status of the two and determines the compliance judgment result. This generates a compliance audit record that covers the comparison information, deviation situation and judgment basis of the entire process. It can objectively and accurately reflect the security and compliance status of the data unit in the current circulation state, form a complete and traceable audit link, effectively improve the judgment accuracy and traceability reliability of data circulation compliance audit, and provide detailed and reliable basis support for subsequent data security risk handling, compliance rectification and optimization and iterative improvement of classification and grading rule base.
[0075] B4: If the fuzzy matching comparison result deviates from compliance, an alarm event is triggered at each level, the classification and grading rule base is automatically optimized and iterated, and the data flow event is blocked or marked.
[0076] In this embodiment of the invention, if the fuzzy matching comparison result has a compliance deviation, a graded alarm event is triggered, the classification and grading rule base is automatically optimized and iterated, and the data flow event is blocked or marked, including: Based on the fuzzy matching comparison results, the degree of compliance deviation is identified, and the corresponding data security risk level is classified. Based on the data security risk level, a preset alarm handling strategy is matched, and corresponding alarm events are triggered in a graded manner; Based on the hierarchical element characteristics and rule matching anomaly information that cause compliance deviations in the compliance audit records, the classification and hierarchical rule base is corrected and updated according to the rule matching anomaly information; Based on the deviation type between the data security risk level and the data flow event, the data flow event is blocked or marked and written into the compliance audit record.
[0077] It should be specifically explained that the compliance deviation status corresponding to the fuzzy matching comparison results is analyzed item by item. By combining the preset deviation classification standards, the number of feature matching difference items, confidence weight and impact range, the degree of compliance deviation is accurately identified, and the corresponding data security risk level is determined according to the preset risk level classification rules.
[0078] Furthermore, the data security risk level is a standardized risk level that is pre-divided based on the compliance deviation status of fuzzy matching comparison, the preset deviation classification standard, the attribute type, quantity, confidence weight, and impact scope of the feature matching difference items, as well as the risk sensitivity of the data flow business scenario attributes and the data unit life cycle stage.
[0079] Specifically, the risk levels are categorized as no risk, low risk, medium risk, high risk, and extremely high risk. The no-risk level corresponds to a state where the compliance baseline security level and the actual security level are not deviated from each other. The low-risk level corresponds to a state where secondary classification elements have slight deviations with minimal impact. The medium-risk level corresponds to a state where important classification elements have moderate deviations, affecting local business control. The high-risk level corresponds to a state where core classification elements have severe deviations, affecting data security compliance judgments. The extremely high-risk level corresponds to a state where core classification elements are completely mismatched, posing significant data security and compliance risks. This risk level provides a quantitative basis for triggering alerts, matching handling strategies, optimizing the classification and grading rule base, and executing data flow event blocking or marking, ensuring the accuracy and adaptability of risk handling.
[0080] Based on the identified data security risk level, the appropriate alarm handling method is matched from the preset alarm handling strategy library. According to the alarm triggering conditions, push channels and response requirements corresponding to different risk levels, alarm events of the corresponding level are triggered in a graded manner.
[0081] Furthermore, the pre-set alarm handling strategy library is a standardized set of alarm and linkage handling strategies that are compiled and stored in advance based on data security compliance management specifications, data security risk level classification standards, and business emergency response procedures.
[0082] Specifically, this includes alarm triggering conditions, alarm level labeling rules, alarm push channels and receiving entities, alarm response time limits, risk handling linkage execution instructions, and alarm closed-loop verification rules, all matched one-to-one with each data security risk level. The alarm triggering conditions clearly define the compliance deviation degree and feature matching difference trigger thresholds corresponding to different risk levels. The alarm level labeling rules map data security risk levels to standardized alarm levels. The alarm push channels and receiving entities differentiate between low-risk to extremely high-risk scenarios, including system log retention, business administrator notifications, security management platform pop-ups, and direct alarm connections from the emergency response team. The alarm response time limits are set according to risk level, with tiered time limits for routine verification, rapid response, and emergency handling. The risk handling linkage execution instructions link the iteration of the classification and grading rule base after alarm triggering, and the linkage logic of blocking or marking data flow events. The alarm closed-loop verification rules clarify the confirmation, feedback, and archiving standards after alarm handling is completed. This provides a unified and standardized execution basis for tiered alarm triggering events and accurate risk handling, ensuring the timeliness of risk response and the compliance of the handling process.
[0083] Extract the hierarchical element characteristics, rule matching anomaly information, and judgment deviation basis that cause compliance deviations from compliance audit records. Locate the problems of missing judgment dimensions, matching basis deviations, or insufficient scenario adaptation in the preset classification and hierarchical rule base. Based on the anomaly information, correct and supplement the judgment rules and adaptation logic of the classification and hierarchical rule base to complete the automatic optimization and iteration of the rule base.
[0084] Based on the level of data security risk and the type of compliance deviation of data transfer events, transmission blocking, transfer termination, or risk identification marking are performed on data transfer events with compliance risks. The handling methods, results, and time are recorded in the compliance audit record to form a complete risk handling closed loop.
[0085] Based on fuzzy matching comparison results, the degree of compliance deviation is identified and corresponding data security risk levels are classified. According to the risk level, a preset alarm handling strategy is matched to trigger alarm events in a graded manner. Combined with abnormal information in the compliance audit record, the classification and grading rule base is automatically optimized and iterated. At the same time, according to the risk level and deviation type, the data flow event is blocked or marked and handled, and written to the compliance audit record. This enables real-time identification, graded response and closed-loop handling of data flow compliance risks, which greatly improves the timeliness and accuracy of data security risk management. Through the automatic iteration of the rule base, the grading assessment and compliance judgment logic are continuously optimized, reducing compliance deviation problems from the source and comprehensively ensuring the security, compliance and stability of the entire data flow process.
[0086] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0087] This application embodiment can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0088] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A method for classifying and grading compliance auditing in the data flow process, characterized in that, The method includes: B1: Extract the metadata information corresponding to the data unit in the data flow event, generate a hierarchical element vector set of the data flow event, calculate the confidence weight of each hierarchical element in the hierarchical element vector set, and perform confidence verification and labeling operations on the hierarchical element vector set. B2: Construct a dynamic hierarchical evaluation space, introduce a spatiotemporal decay factor, map the hierarchical element vector set to the dynamic hierarchical evaluation space, and calculate the compliance benchmark security level of the data unit in the current state based on a preset classification and hierarchical rule base. B3: Perform a fuzzy matching comparison between the compliance benchmark security level and the actual security level of the data unit, and generate a compliance audit record based on the fuzzy matching comparison result; B4: If the fuzzy matching comparison result deviates from compliance, an alarm event is triggered at each level, the classification and grading rule base is automatically optimized and iterated, and the data flow event is blocked or marked.
2. The classification and hierarchical compliance audit method for data flow as described in claim 1, characterized in that, The step of extracting metadata information corresponding to data units in a data flow event to generate a hierarchical element vector set for the data flow event, calculating the confidence weight of each hierarchical element in the hierarchical element vector set, and performing confidence verification and labeling operations on the hierarchical element vector set includes: Based on the business attributes of data flow events, effective feature items in metadata information are filtered, and the effective feature items are decomposed and combined in a hierarchical manner to obtain the hierarchical feature vector set corresponding to the data flow event. Based on the degree of correlation between the grading elements and the preset security classification grading standards, each grading element in the grading element vector set is assigned a corresponding confidence weight. Perform an overall confidence check on the hierarchical element vector set, identify the hierarchical element vectors that fail the check, and mark the hierarchical element vectors as anomalies. The hierarchical element vectors marked with anomalies are traced, located, and isolated, and anomaly element traceability records associated with corresponding data flow events are generated.
3. The classification and grading compliance audit method for data flow as described in claim 2, characterized in that, The step of assigning a corresponding confidence weight to each grading element in the grading element vector set based on the correlation between the grading elements and the preset security classification grading standards includes: The classification elements are matched with the classification element dimensions in the preset security classification standard to obtain the initial association result of the classification elements. Based on the affected objects and the criteria for determining the degree of impact in the aforementioned safety classification standard, the initial association results are weighted and hierarchically labeled. Based on the weight hierarchy calibration results, initial confidence weights are assigned to the hierarchical elements, and the initial confidence weights are calibrated and normalized to obtain the confidence weights of the hierarchical elements.
4. The classification and hierarchical compliance audit method for data flow as described in claim 1, characterized in that, The process involves constructing a dynamic hierarchical evaluation space, introducing a spatiotemporal decay factor, mapping the hierarchical element vector set to the dynamic hierarchical evaluation space, and calculating the compliance benchmark security level of the data unit in its current state based on a preset classification and hierarchical rule base. This includes: Based on the business scenarios and lifecycle stages of the data flow events, a dynamic hierarchical evaluation space is constructed. The spatiotemporal decay factor is adapted and bound to the dynamic hierarchical evaluation space to obtain the evaluation carrier of the dynamic hierarchical evaluation space. Align and match the hierarchical element vector set with the dimensional features of the evaluation carrier to obtain the mapping result of the hierarchical element vector set; Based on the level determination criteria of the preset classification and grading rule base, the mapping result is subjected to compliance analysis, and the compliance baseline security level of the data unit in the current state is determined based on the compliance analysis result.
5. The classification and grading compliance audit method for data flow as described in claim 4, characterized in that, The process of adapting and binding the spatiotemporal decay factor with the dynamic hierarchical evaluation space to obtain the evaluation carrier of the dynamic hierarchical evaluation space includes: Based on the dimensional attribute characteristics of the dynamic hierarchical evaluation space, the associated dimensions used to adapt the spatiotemporal decay factor are determined. Based on the timeliness characteristics and scenario attributes of the data flow events, the spatiotemporal decay factor is decomposed into features, and the feature decomposition results are matched and fused with the associated dimensions to obtain the fusion dimension combination of the dynamic hierarchical evaluation space. A consistency check is performed on the fusion dimension combination, and an evaluation carrier for the dynamic hierarchical evaluation space is generated based on the check result.
6. The classification and grading compliance audit method for data flow as described in claim 4, characterized in that, The method, based on a preset classification and grading rule base, performs compliance analysis on the mapping results and determines the compliance baseline security level of the data unit in its current state based on the compliance analysis results, including: Extract the level determination dimensions and impact assessment criteria from the classification and grading rule base, and perform correlation matching between the mapping result and the level determination dimensions to generate dimension matching features of the mapping result; Based on the aforementioned impact assessment criteria, compliance verification is performed on the dimension matching features to obtain the security impact attributes corresponding to the data unit, and the compliance baseline security level of the data unit in its current state is calculated.
7. The classification and hierarchical compliance audit method for data flow as described in claim 6, characterized in that, The formula for calculating the compliance benchmark security level is as follows: ; In the formula, This indicates the compliance baseline security level of the data unit in its current state. This represents the fit coefficient of the dynamic hierarchical evaluation space. This represents the total number of valid hierarchical elements in the hierarchical element vector set. Indicates the first The confidence weights of each hierarchical element. Indicates the first The hierarchical element vector mapping value of each hierarchical element. Indicates the first Time decay characteristic values of each hierarchical element Indicates the first Spatial attenuation characteristic values of each hierarchical element This is the spatiotemporal decay adjustment coefficient. This represents the matching coefficient of the classification and grading rule base. This is the normalization factor.
8. The method for classification and hierarchical compliance auditing in the data flow process as described in claim 1, characterized in that, The step of performing a fuzzy matching comparison between the compliance benchmark security level and the actual security level of the data unit, and generating a compliance audit record based on the fuzzy matching comparison result, includes: Based on the hierarchical judgment criteria and element characteristics of the compliance benchmark security level, the identification information corresponding to the actual security level of the data unit is associated and aligned. The correlation alignment results are compared by fuzzy matching to obtain the compliance deviation status between the compliance benchmark security level and the actual security level. Based on the compliance deviation status, the corresponding compliance judgment result is determined, and the compliance judgment result is bound to the data flow event, data unit and hierarchical element vector set to generate the compliance audit record of the data flow event.
9. A method for classifying and grading compliance auditing in the data flow process as described in claim 8, characterized in that, The step of performing fuzzy matching and comparison on the correlation alignment results to obtain the compliance deviation status between the compliance benchmark security level and the actual security level includes: The hierarchical element features corresponding to the compliance benchmark security level and the attribute identifier features corresponding to the actual security level in the association alignment results are checked item by item to obtain the feature matching difference items of the two types of features. Based on the attributes and scope of influence of the feature matching difference items, the security level deviation of the feature matching difference items is determined, and the security level deviation is classified and labeled to obtain the compliance deviation status between the compliance benchmark security level and the actual security level.
10. A method for classifying and grading compliance auditing in the data flow process as described in claim 1, characterized in that, If the fuzzy matching comparison result deviates from compliance, a tiered alarm event is triggered, the classification and tiering rule base is automatically optimized and iterated, and the data flow event is blocked or marked, including: Based on the fuzzy matching comparison results, the degree of compliance deviation is identified, and the corresponding data security risk level is classified. Based on the data security risk level, a preset alarm handling strategy is matched, and corresponding alarm events are triggered in a graded manner; Based on the hierarchical element characteristics and rule matching anomaly information that cause compliance deviations in the compliance audit records, the classification and hierarchical rule base is corrected and updated according to the rule matching anomaly information; Based on the deviation type between the data security risk level and the data flow event, the data flow event is blocked or marked and written into the compliance audit record.