Log sensitive information detection method and system, electronic device, and storage medium

By detecting the location of named variables and program call interface functions at the source code level, the problem of high log desensitization resource occupancy and difficulty in comprehensively detecting sensitive information leakage in the existing technology is solved, and efficient and accurate log sensitive information detection and risk warning are achieved.

WO2025123744A1PCT designated stage expired Publication Date: 2025-06-19CHINA FAW CO LTD +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/112983
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-13
Filing Date
2024-08-19
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

In the process of log desensitization, the prior art relies on the log output form, has high resource occupancy and is difficult to fully detect the risk of sensitive information leakage.

Method used

Through the source code-based sensitive information detection method, naming variable information and program call interface function information are obtained, their location is determined based on the defined language and search rules, sensitive information is detected, and risk warning and desensitization are performed when risks are detected.

Benefits of technology

Automatic detection of log sensitive information is realized, and does not rely on log output form, and can accurately identify the location and leakage risks of sensitive information, improving detection efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024112983_19062025_PF_FP_ABST
    Figure CN2024112983_19062025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the present invention are a log sensitive information detection method and system, an electronic device, and a storage medium. The method comprises: in response to a sensitive information detection signal, on the basis of a defined language rule, acquiring naming variable information and program call interface function information comprised in source code; on the basis of a defined retrieval rule, determining position information of the naming variable information and the program call interface function information in the source code; on the basis of the position information, performing sensitive information detection on log output code added with the naming variable information and the program call interface function information; and when sensitive information is detected, give a risk alert for the sensitive information. The method is independent of the log output form, the position related to sensitive information can be detected, and whether there is a potential risk of sensitive information leakage can also be detected; the position of an issue in source code can be identified while the risk is detected, which is conducive to confirming and fixing the issue; the method is independent of dynamic operation of a program, the detection result is more accurate and comprehensive, and the efficiency is higher.
Need to check novelty before this filing date? Find Prior Art

Description

A method, system, electronic device and storage medium for detecting sensitive information in logs Technical Field

[0001] The present invention relates to the field of information technology, and in particular to a method, system, electronic device and storage medium for detecting sensitive information in logs. Background Art

[0002] System logs are used for software development and debugging, as well as system performance analysis. During the development process, developers may print all necessary debugging information in the logs, including sensitive information such as usernames and passwords for certain systems, unique device identifiers, and internal company user information fields. During development, this data is often test data or fabricated temporary data, and printing it in the logs poses no risk. However, after development is complete, these logging codes should be deleted or disabled in the official release. However, due to subjective negligence or imperfect processes, these codes may not be properly handled, resulting in sensitive information appearing in the final release, causing information leaks and serious harm.

[0003] To address this issue, log files require specialized processing to remove sensitive data and prevent leaks. This is known as desensitization. Log desensitization is a key area of ​​information security. Log desensitization typically receives more attention in large-scale systems, such as financial transaction systems, online shopping platforms, and banking systems. Logs from these systems are relatively standardized and highly structured, with clear interfaces and boundaries between submodules, facilitating inspection and processing. By using predefined rules and patterns, some potential information leakage risks can be identified.

[0004] Patent document CN116383885A discloses a log desensitization method comprising: obtaining a transaction log of a target transaction and determining a log format for the transaction log; obtaining preset field information, wherein the preset field information includes information on multiple fields to be desensitized in the transaction log, the multiple fields including: user information; determining the location of the field to be desensitized in the transaction log based on the log format and the preset field information; and desensitizing the transaction log based on the location of the field to be desensitized in the transaction log to obtain a desensitized transaction log. This method solves the technical problem in related technologies of using regular expression matching to search for sensitive fields in message logs for synchronous desensitization of message logs, resulting in high application system resource utilization.

[0005] The above solutions all start from log analysis, check the risk of information leakage afterwards, and carry out supplementary processing. However, there is still a large risk of information leakage.

[0006] Therefore, the present application provides a method for detecting sensitive information in logs to solve the above technical problems.

[0007] Summary of the Invention

[0008] The present invention provides a method, system, electronic device and storage medium for detecting sensitive information in logs, which can solve at least one of the technical problems mentioned above.

[0009] To achieve the purpose of the present invention, a method for detecting sensitive information in logs is provided, comprising:

[0010] In response to a sensitive information detection signal, obtaining named variable information and program call interface function information contained in the source code based on defined language rules;

[0011] Based on the defined search rules, determining the location information of the named variable information and the program call interface function information in the source code;

[0012] Based on the location information, performing sensitive information detection on the log output code attached with the named variable information and the program call interface function information;

[0013] When the sensitive information is detected, a risk warning is issued for the sensitive information.

[0014] In some specific embodiments, after performing sensitive information detection on the log output code attached with the named variable information and the program call interface function information based on the location information, the method further includes:

[0015] Based on the log output code, the acquired named variable information and the program call interface function information are verified to confirm whether the sensitive information is detected in the log.

[0016] In some specific embodiments, in response to a sensitive information detection signal, obtaining named variable information and program call interface function information contained in the source code based on defined language rules specifically includes:

[0017] The defined language rules include code programming rules;

[0018] Based on the programming rules, obtaining named variable information and program call interface function information contained in the source code;

[0019] The named variable information includes the database server address, data name, user name and user password;

[0020] The calling interface function information includes connecting data operations, logging into the system, and opening services.

[0021] In some specific embodiments, determining the location information of the named variable information and the program call interface function information in the source code based on the defined search rules specifically includes:

[0022] The defined search rules include:

[0023] Preset a keyword list to search for the named variable information;

[0024] Scanning the source code and retrieving the program call interface function information;

[0025] Based on the retrieved named variable information and the program call interface function information, the location information of the two in the source code is determined.

[0026] In some specific embodiments, based on the location information, sensitive information detection is performed on the log output code attached with the named variable information and the program call interface function information, specifically including:

[0027] Determining the log associated therewith based on the determined location information of the named variable information and the program call interface function information in the source code;

[0028] Perform sensitive information detection on the output code of the log to confirm whether the log output code contains the sensitive information.

[0029] In some specific embodiments, when the sensitive information is detected, a risk warning is issued for the sensitive information, specifically including:

[0030] When the sensitive information is detected, marking the sensitive information;

[0031] Based on the marks, corresponding risk warnings are issued.

[0032] In some specific embodiments, after providing a risk warning for the sensitive information, the method further includes:

[0033] The marked sensitive information is desensitized.

[0034] Based on the same concept, the present invention also provides a log sensitive information detection system, comprising:

[0035] An information acquisition module is configured to respond to a sensitive information detection signal and acquire named variable information and program call interface function information contained in the source code based on defined language rules;

[0036] a location information confirmation module configured to determine location information of the named variable information and the program call interface function information in the source code based on a defined retrieval rule;

[0037] a sensitive information detection module configured to perform sensitive information detection on the log output code attached with the named variable information and the program call interface function information based on the location information;

[0038] The sensitive information prompt module is configured to provide a risk prompt for the sensitive information when the sensitive information is detected.

[0039] Based on the same concept, the present invention also provides an electronic device, comprising: a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; a computer program is stored in the memory, and when the computer program is executed by the processor, the processor executes the steps of the above-mentioned log sensitive information detection method.

[0040] Based on the same concept, the present invention also provides a computer-readable storage medium, characterized in that it stores a computer program that can be executed by an electronic device. When the computer program runs on the electronic device, the electronic device executes the steps of the above-mentioned log sensitive information detection method.

[0041] Compared with the prior art, the present invention has the following beneficial effects:

[0042] The present invention discloses a method, system, electronic device and storage medium for detecting sensitive information in logs. The method automatically detects sensitive information based on source code, does not rely on the output form of the log, can detect the location of sensitive information involved, and further detect whether there is a risk of sensitive information leakage. When the risk is detected, the source code location of the problem can be clearly identified, which facilitates the confirmation and repair of the problem. The method does not rely on the dynamic operation of the program, and the detection results are more accurate, comprehensive and efficient. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] FIG1 is a flow chart of a method for detecting sensitive information in logs according to some specific embodiments of the present invention;

[0044] FIG2 is a flow chart of a method for detecting sensitive information in logs according to the present invention in some applications;

[0045] FIG3 is a schematic diagram of the structure of a log sensitive information detection system in some specific embodiments of the present invention;

[0046] FIG4 is a schematic structural diagram of an electronic device according to some specific embodiments of the present invention. DETAILED DESCRIPTION

[0047] To make the objectives, technical solutions, and advantages of this application more clear, this application will be further described in detail below with reference to the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.

[0048] The terms used in the examples of this application are for the purpose of describing specific embodiments only and are not intended to limit this application. The singular forms "a," "the," and "the" used in the examples of this application and the appended claims are also intended to include plural forms, and unless the context clearly indicates otherwise, "a plurality" generally includes at least two.

[0049] It should be understood that the term "and / or" as used herein is merely a description of the relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " in this document generally indicates that the associated objects are in an "or" relationship.

[0050] It should be understood that although the terms first, second, third, etc. may be used to describe in the embodiments of the present application, these descriptions should not be limited to these terms. These terms are only used to distinguish the descriptions. For example, without departing from the scope of the embodiments of the present application, the first may also be referred to as the second, and similarly, the second may also be referred to as the first.

[0051] As used herein, the words "if" and "if" may be interpreted as "at the time of" or "when" or "in response to determining" or "in response to detecting," depending on the context. Similarly, the phrases "if it is determined" or "if (stated condition or event) is detected" may be interpreted as "when it is determined" or "in response to the determination" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)," depending on the context.

[0052] It should also be noted that the terms "include," "comprises," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a product or device comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such product or device. In the absence of further limitations, an element defined by the phrase "comprises a..." does not exclude the presence of other identical elements in the product or device comprising the element.

[0053] It should be noted in particular that any symbols and / or numbers in the specification that are not marked in the accompanying drawings are not drawing marks.

[0054] Referring to FIG1 , a method for detecting sensitive information in logs includes:

[0055] S101, in response to a sensitive information detection signal, obtaining named variable information and program call interface function information contained in the source code based on defined language rules;

[0056] Specifically, in this step, language rules are first defined, and named variable information and program call interface function information are obtained in the source code according to the defined language rules;

[0057] It can be understood that this step does not rely on logs, and the named variable information and program call interface function information are obtained from the source code. The defined language rules can be specifically defined for different databases and different programming languages. The purpose is to obtain named variable information and program call interface function information in different types of databases and different types of programming languages.

[0058] In some of these applications, in response to a sensitive information detection signal, named variable information and program call interface function (API function) information contained in the source code are obtained based on defined language rules, specifically including: the defined language rules include code programming rules; based on the programming rules, the named variable information and program call interface function information contained in the source code are obtained; wherein the named variable information includes a database server address (database_server), a data name (database_name), a user name (database_user), and a user password (database_password);

[0059] The calling interface function information includes connecting to data operations (connect_database), logging into the system (login_system), and opening services (open_service).

[0060] It can be understood that in this application, according to the programming code rules in the corresponding database, the named variable information and the program call interface function information in the source code are obtained accordingly. For example, the named variable information can be database_server, database_name, database_user and database_password, and the calling interface function information can be connect_database, login_system and open_service. The above-mentioned named variable information and program call interface function information are all key locations that may involve sensitive information. Therefore, the relevant information is obtained from the source code.

[0061] S102, determining the location information of the named variable information and the program call interface function information in the source code based on the defined search rules;

[0062] Specifically, in this step, first, a search rule is defined, and the location of the named variable information and the program call interface function information is confirmed in the source code according to the defined search rule;

[0063] It is understandable that the purpose of this step is to quickly locate the named variable information and the program call interface function information from the source code. The search rules can be set specifically and can be matched through regular expressions.

[0064] In some of the applications, based on defined retrieval rules, determining the location information of the named variable information and the program call interface function information in the source code, specifically including: the defined retrieval rules including a preset keyword list, searching for the named variable information; scanning the source code to retrieve the program call interface function information; and determining the location information of the named variable information and the program call interface function information in the source code based on the retrieved named variable information and the program call interface function information;

[0065] It can be understood that in this application, the named variable information is retrieved through a preset keyword list, and the keyword list can be flexibly selected according to the named variables to be obtained. Since the program call interface function information usually has fewer expressions in the program, it can be obtained by scanning the source code. Finally, based on the retrieved or scanned named variable information and the program call interface function information, the corresponding location information of the two is confirmed.

[0066] S103, based on the location information, performing sensitive information detection on the log output code attached with the named variable information and the program call interface function information;

[0067] Specifically, in this step, based on the location information of the named variable information and the program call interface function information in the source code, the log output code with the attached named variable information and the program call interface function information is subjected to sensitive information detection;

[0068] It is understandable that in this step, once the location information of the named variable information and the program call interface function information in the source code is determined, the corresponding log can be located and sensitive information detection can be performed based on the output code of the log.

[0069] In some applications, based on the location information, sensitive information detection is performed on the log output code attached with the named variable information and the program call interface function information, specifically including determining the log associated with the named variable information and the program call interface function information based on the determined location information of the named variable information and the program call interface function information in the source code; performing sensitive information detection on the output code of the log to confirm whether the log output code contains the sensitive information;

[0070] It is understandable that in this application, according to the location of the named variable information and the calling interface function information in the source code, the associated log is queried and confirmed to confirm whether the log output code contains the sensitive information.

[0071] In some embodiments, to make sensitive information detection more accurate, after performing sensitive information detection on the log output code attached with the named variable information and the program call interface function information based on the location information, the method further includes verifying the obtained named variable information and the program call interface function information based on the log output code to confirm whether the sensitive information is detected in the log;

[0072] It can be understood that in this embodiment, by associating the log output code with the location of the named variable information and the calling interface function information in the source code, and performing one-to-one verification analysis and processing with the obtained named variable information and program calling interface function information, the accuracy of the sensitive information detection results can be further guaranteed.

[0073] S104: When the sensitive information is detected, a risk warning is issued for the sensitive information.

[0074] It is understandable that in this step, risk warnings for sensitive information are required;

[0075] In some of these applications, when the sensitive information is detected, the sensitive information is marked; and based on the mark, a corresponding risk warning is issued.

[0076] It is understandable that in this application, different sensitive information can be divided into corresponding risk levels, and different tags can be defined according to different risk levels, such as level 1, level 2, level 3, etc., and then different risk warnings can be set according to different risk levels. The risk warnings can be in text form and can specify the corresponding risk descriptions;

[0077] Furthermore, after issuing a risk warning for the sensitive information, the method further includes desensitizing the marked sensitive information.

[0078] In some applications, the desensitization process here can be to delete the detected sensitive information;

[0079] It is understandable that the above method can detect the location of sensitive information without relying on the output form of the log, and further detect whether there is a risk of sensitive information leakage. When the risk is detected, the source code location of the problem can be clearly identified, which facilitates the confirmation and repair of the problem. It does not rely on the dynamic operation of the program, and the detection results are more accurate, comprehensive and efficient.

[0080] The following describes an embodiment of the method for detecting sensitive information in logs according to the present invention in some applications with reference to FIG2 , as shown in FIG2 :

[0081] In order to better illustrate this patent solution, a database connection scenario is taken as an example.

[0082] A typical database connection operation first sets the database user name and password variables, and then calls the database connection API function to connect to the database service.

[0083] 1. There may be variables named as follows in the code (different databases and programming languages ​​have different names, but they are basically English words with related meanings):

[0084] database_server, database server address;

[0085] database_name, data name;

[0086] database_user, user name;

[0087] database_password, user password;

[0088] The data API functions you call may be named (different databases and programming languages ​​have different names, but they are basically English words with related meanings):

[0089] connect_database(), connect data operation;

[0090] Second, combined with the source code, possible sensitive information can be captured through variable naming and program calling interface functions (API functions).

[0091] 1. Identify sensitive variables: In program source code, variable naming often follows certain standards. For example, database_user and database_password, mentioned above, clearly convey their meaning. Variables with such names can be retrieved by matching against pre-set keyword lists or regular expression rules.

[0092] 2. Identify sensitive function calls: API functions called in the code usually have standardized naming methods, which are more strict and formal. For example, the aforementioned connect_database (connect to the database) and some commonly used API names include login_system (login to the system) and open_service (open a service, such as a web application or ftp). These interfaces usually require user name, password, and other information.

[0093] 3. The system's API functions are defined during coding, and compared to the total amount of code, the number of API functions involving sensitive information is small. It's entirely possible to find all code that calls such functions by scanning the code.

[0094] This example uses a username and password. Using similar logic, you can retrieve the code locations of other sensitive information. Other sensitive information may include: hardware device IDs, user personal information, financial information, etc.

[0095] Once the source code containing sensitive information is found, the algorithm scans the attached log output code and detects whether the log output contains sensitive information. If so, it will be marked or a risk warning will be issued.

[0096] To improve accuracy, you can also analyze and process the program's log output and verify it with the source code scan results to confirm whether the detected sensitive information appears in the log. This step is to improve accuracy, and the core algorithm is still the same as the steps above.

[0097] This method is not sensitive to the log output format and can more accurately identify sensitive information in various logs.

[0098] Different log output methods will affect the identification of information.

[0099] For example, there are two log messages in the log file. The developer prints out the username (beijing) and password (332211) for debugging.

[0100] A: connect Beijing_market_database with user=beijing and password=332211

[0101] B:beijing-332211

[0102] Different developers have different habits when printing logs. Log A has clearer information, while Log B has more ambiguous information. If you use post-mortem log analysis to identify sensitive information, Log A is easy to identify, while Log B is likely to be missed.

[0103] This method does not rely on log output content, but instead filters based on code information, which can identify sensitive information more effectively and accurately.

[0104] Through the above method, it is possible to achieve:

[0105] Automatically detect sensitive information based on source code.

[0106] This detection method is insensitive to the log content and format. It does not rely on the output form of the log, and can detect the location of sensitive information and further detect whether there is a risk of sensitive information leakage.

[0107] When risks are detected, the source code location of the problem can be clearly identified, making it easier to confirm and fix the problem.

[0108] Independent of the program's dynamic execution, detection results are more accurate and comprehensive. A software system can have multiple logical branches. During dynamic execution, it's impossible to manually control which logical branch the system actually runs. Some branches may not be executed, especially in complex systems. Consequently, relevant logging code will not be executed, and thus, information-leaking code will not be executed. This situation cannot be detected by post-mortem log analysis. Source code detection avoids these problems, enabling a complete scan of the source code without omissions.

[0109] More efficient. When the system is running, the same code logic is executed repeatedly, and logs are printed repeatedly (logs are printed every time the corresponding code is executed), resulting in a very large log volume. This may require the development of analysis tools and a large amount of analysis work. Using source code analysis methods is much more efficient, as there is no duplication in the source code, and the amount of detection is much less than post-log analysis.

[0110] For the method steps disclosed in the above embodiments, for the purpose of simple description, the method steps are expressed as a series of action combinations. However, those skilled in the art should be aware that the embodiments of the present invention are not limited by the order of the actions described, because according to the embodiments of the present invention, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present invention.

[0111] As shown in FIG3 , the present invention also provides a log sensitive information detection system, comprising:

[0112] The information acquisition module 201 is configured to respond to the sensitive information detection signal and obtain the named variable information and program call interface function information contained in the source code based on the defined language rules;

[0113] A location information confirmation module 202 is configured to determine location information of the named variable information and the program call interface function information in the source code based on a defined search rule;

[0114] A sensitive information detection module 203 is configured to perform sensitive information detection on the log output code attached with the named variable information and the program call interface function information based on the location information;

[0115] The sensitive information prompt module 204 is configured to issue a risk prompt for the sensitive information when the sensitive information is detected.

[0116] It is worth noting that although only some basic functional modules are disclosed in the embodiment of the present invention, it does not mean that the composition of the present system is limited to the above basic functional modules. On the contrary, what this embodiment wants to express is that on the basis of the above basic functional modules, those skilled in the art can arbitrarily add one or more functional modules in combination with the existing technology to form an infinite number of embodiments or technical solutions. In other words, this system is open rather than closed. Just because this embodiment only discloses individual basic functional modules, it cannot be considered that the scope of protection of the claims of the present invention is limited to the disclosed basic functional modules. At the same time, for the convenience of description, the above devices are described in terms of functions, which are divided into various units and modules. Of course, when implementing the present invention, the functions of each unit and module can be implemented in the same or one or more software and / or hardware.

[0117] As shown in Figure 4, the present invention also provides an electronic device, including: a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus; the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the log sensitive information detection method.

[0118] Figure 4 is a schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. As shown in Figure 4, the electronic device provided by an embodiment of the present invention includes: one or more processors 710 and a storage device 720. The processor 710 in the electronic device can be one or more, and Figure 4 uses one processor 710 as an example. The storage device 720 is used to store one or more programs. The one or more programs are executed by the one or more processors 710, so that the one or more processors 710 implement the log sensitive information detection method described in any of the embodiments of the present invention.

[0119] The electronic device may further include an input device 730 and an output device 740 .

[0120] The processor 710 , storage device 720 , input device 730 and output device 740 in the electronic device may be connected via a bus or other means. FIG4 takes the bus connection as an example.

[0121] The storage device 720 in the electronic device serves as a computer-readable storage medium and can be used to store one or more programs. These programs can be software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the method for detecting sensitive information in logs provided in the embodiments of the present invention. The processor 710 executes the software programs, instructions, and modules stored in the storage device 720 to execute various functional applications and data processing of the electronic device, thereby implementing the method for detecting sensitive information in logs provided in the above-mentioned method embodiments.

[0122] The storage device 720 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the electronic device, etc. In addition, the storage device 720 may include a high-speed random access memory and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some instances, the storage device 720 may further include a memory remotely located relative to the processor 710, and these remote memories may be connected to the device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0123] The input device 730 may be used to receive input digital or character information and generate key signal input related to user settings and function control of the electronic device. The output device 740 may include a display device such as a display screen.

[0124] The present invention also provides a computer-readable storage medium storing a computer program executable by an electronic device. When the computer program runs on the electronic device, the electronic device executes the steps of the log sensitive information detection method.

[0125] Specifically, the computer storage medium of the embodiment of the present invention can adopt any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or component, or any combination of the above. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program, which can be used by or in combination with an instruction execution system, device or device.

[0126] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for detecting sensitive information in logs, characterized in that: include: In response to a sensitive information detection signal, based on a defined language rule, obtaining named variable information and program call interface function information contained in the source code; Based on the defined search rules, determining the location information of the named variable information and the program call interface function information in the source code; Based on the location information, performing sensitive information detection on the log output code attached with the named variable information and the program call interface function information; When the sensitive information is detected, a risk warning is issued for the sensitive information.

2. The method for detecting sensitive information in logs according to claim 1, characterized in that: After performing sensitive information detection on the log output code attached with the named variable information and the program call interface function information based on the location information, the method further includes: Based on the log output code, the acquired named variable information and the program call interface function information are verified to confirm whether the sensitive information is detected in the log.

3. The method for detecting sensitive information in logs according to claim 1, characterized in that: In response to the sensitive information detection signal, based on the defined language rules, the named variable information and program call interface function information contained in the source code are obtained, specifically including: The defined language rules include code programming rules; Based on the programming rules, obtaining the named variable information and program call interface function information contained in the source code; The named variable information includes the database server address, data name, user name and user password; The calling interface function information includes connecting data operations, logging into the system, and opening services.

4. The method for detecting sensitive information in logs according to claim 1, characterized in that: Based on the defined search rules, determining the location information of the named variable information and the program call interface function information in the source code specifically includes: The defined search rules include: Preset a keyword list to retrieve the named variable information; Scanning the source code and retrieving the program call interface function information; Based on the retrieved named variable information and the program call interface function information, the location information of the two in the source code is determined.

5. The method for detecting sensitive information in logs according to claim 1, characterized in that: Based on the location information, sensitive information detection is performed on the log output code attached with the named variable information and the program call interface function information, specifically including: Based on the determined named variable information and the location information of the program call interface function information in the source code, determining the log associated therewith; Perform sensitive information detection on the output code of the log to confirm whether the log output code contains the sensitive information.

6. The method for detecting sensitive information in logs according to claim 1, characterized in that: When the sensitive information is detected, a risk warning is issued for the sensitive information, specifically including: When the sensitive information is detected, marking the sensitive information; Based on the marks, corresponding risk warnings are given.

7. The method for detecting sensitive information in logs according to claim 6, characterized in that: After providing risk warning for the sensitive information, the method further includes: The marked sensitive information is desensitized.

8. A log sensitive information detection system, characterized in that: include: An information acquisition module, configured to respond to a sensitive information detection signal and acquire named variable information and program call interface function information contained in the source code based on a defined language rule; A location information confirmation module, configured to determine location information of the named variable information and the program call interface function information in the source code based on a defined search rule; A sensitive information detection module, configured to perform sensitive information detection on the log output code attached with the named variable information and the program call interface function information based on the location information; The sensitive information prompt module is configured to provide a risk prompt for the sensitive information when the sensitive information is detected.

9. An electronic device, characterized in that: include: A processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; a computer program is stored in the memory, and when the computer program is executed by the processor, the processor executes the steps of the method described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: It stores a computer program executable by an electronic device, and when the computer program runs on the electronic device, the electronic device executes the steps of the method described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Log monitoring-based sensitive log scanning method and apparatus, and computer device

    CN109614814A

  • Sensitive information detection method and device, storage medium and computer device

    CN110598411A

  • Risk code positioning method, device and equipment and storage medium

    CN112035354A

  • Log sensitive information detection method and system, electronic equipment and storage medium

    CN117910030A

  • Detecting sensitive data exposure via logging

    US20200285772A1