File processing method, file association method, client, server, device, and medium
By deploying clients and servers in the enterprise network and using mapping logic to convert operation events into application behaviors, the problem of limited file types in existing technologies is solved, enabling high-coverage correlation analysis of various files and improving data security and stability.
Patent Information
- Application Number
- PCT/CN2025/076605
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-07
- Filing Date
- 2025-02-10
- Publication Date
- 2025-12-11
AI Technical Summary
Existing technologies cannot effectively analyze the relationships between files other than Office documents, images, and PDFs in enterprise office networks, resulting in insufficient data security.
By deploying clients and servers in the enterprise network, mapping logic is used to convert operation events into application behaviors, and independent protected files are generated after file operations. This establishes a relationship between files and application behaviors, enabling high-coverage relationship analysis.
It achieves high coverage correlation analysis of various file types, improves enterprise data security, avoids stability issues caused by injection schemes, and enhances user experience.
Smart Images

Figure CN2025076605_11122025_PF_FP_ABST
Abstract
Description
File processing method, association method, client, server, device and medium
[0001] Cross-reference to Related Applications
[0002] The present application claims priority to the Chinese patent application No. 202410740874.4, filed on June 7, 2024, and entitled “File processing method, association method, client, server, device and medium”, the content of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0003] The present disclosure relates to the technical field of computer, in particular to a file processing method, an association method, a client, a server, a device and a medium. BACKGROUND
[0004] At present, there are a large number of file flows in some enterprise office network environments. The files can be documents, pictures, drawings, codes, etc. Generally, due to the consideration of enterprise data security, the association relationship analysis of protected files in these files is required. The so-called association relationship analysis is to analyze the flow path of the files and the operations (such as copying, sending out, modifying, etc.) performed by the user on the files. In this way, the protected data is prevented from being leaked, or when the data is leaked, the leakage source is located based on the flow path of the files, and the data leakage range and impact are determined. SUMMARY
[0005] Therefore, the embodiments of the present disclosure provide a file processing method, a file association method, a client, a server, an electronic device, a computer readable storage medium and a computer program product, and the file coverage is high.
[0006] In one aspect, the present disclosure provides a file processing method, which comprises:
[0007] Obtaining an operation event of initiating an operation on a first file by a first application in a terminal device;
[0008] Mapping the operation event to an application behavior of the first application according to a preset mapping logic;
[0009] In a case where the first file has been labeled as a protected file, generating a second file independent of the first file in response to the operation on the first file, labeling the second file as a protected file, and associating the first file with the application behavior;
[0010] The association relationship between the first file and the application behavior is used for association relationship analysis of the first file.
[0011] Another aspect of the present disclosure provides a file association method, the method comprising:
[0012] receiving file association information sent by one or more terminal devices, wherein the file association information comprises an association relationship between a file in the terminal device and an application behavior, and the application behavior is mapped from an operation event, the operation event being an event of operating the file initiated by an application program in the terminal device;
[0013] performing association relationship analysis on the file based on the association relationship between the file and the application behavior.
[0014] Another aspect of the present disclosure provides a client, the client comprising:
[0015] an event obtaining module configured to obtain an operation event of operating a first file initiated by a first application program in a terminal device;
[0016] a mapping module configured to map the operation event to an application behavior of the first application program according to a preset mapping logic;
[0017] an association module configured to, in a case where the first file has been marked as a protected file, generate a second file independent of the first file in response to operating the first file, mark the second file as a protected file, and associate the first file with the application behavior, wherein the association relationship between the first file and the application behavior is used for association relationship analysis on the first file.
[0018] Another aspect of the present disclosure provides a server, the server comprising:
[0019] a file receiving module configured to receive file association information sent by one or more terminal devices, wherein the file association information comprises an association relationship between a file in the terminal device and an application behavior, and the application behavior is mapped from an operation event, the operation event being an event of operating the file initiated by an application program in the terminal device;
[0020] an association module configured to perform association relationship analysis on the file based on the association relationship between the file and the application behavior.
[0021] Another aspect of the present disclosure also provides a computer readable storage medium for storing a computer program, the computer program being executed by a processor to implement the method described above.
[0022] Another aspect of the present disclosure also provides an electronic device, comprising a processor and a memory for storing a computer program, which, when executed by the processor, implements the method as described above.
[0023] Another aspect of the present disclosure also provides a computer program product comprising a computer program, which, when executed by a processor, implements the method as described above. BRIEF DESCRIPTION OF DRAWINGS
[0024] The features and advantages of the present disclosure will be appreciated upon reference to the following drawings, which are schematic and which should not be interpreted in a limiting sense, and in which:
[0025] Fig. 1 shows an architecture diagram of a network according to an embodiment of the present disclosure;
[0026] Fig. 2 shows a flow diagram of a file processing method according to an embodiment of the present disclosure;
[0027] Fig. 3 shows a software deployment diagram in a terminal device according to an embodiment of the present disclosure;
[0028] Fig. 4 shows a relationship diagram between an operation event, an application behavior and a first application function according to an embodiment of the present disclosure;
[0029] Fig. 5 shows a flow diagram of a file association method according to an embodiment of the present disclosure;
[0030] Fig. 6 shows a diagram of a file association interface according to an embodiment of the present disclosure;
[0031] Fig. 7 shows a module diagram of a client according to an embodiment of the present disclosure;
[0032] Fig. 8 shows a module diagram of a server according to an embodiment of the present disclosure;
[0033] Fig. 9 shows a diagram of an electronic device according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0034] In order to make the objects, technical solutions and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be described clearly and completely below with reference to the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only some of the embodiments of the present disclosure, but not all the embodiments of the present disclosure. Based on the embodiments in the present disclosure, any other embodiments obtained by those skilled in the art without creative work fall within the scope of the present disclosure.
[0035] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be implemented in various forms and should not be interpreted as being limited to the embodiments set forth herein, but rather, these embodiments are provided so as to more completely and thoroughly understand the present disclosure. It is understood that the drawings and embodiments of the present disclosure are for exemplary purposes only and are not intended to limit the scope of protection of the present disclosure.
[0036] In the description of embodiments of the present disclosure, the term "comprising" and its conjugations should be understood to encompass the meaning of "including but not limited to". The term "based on" should be understood as "based at least in part on". The term "one embodiment" or "the embodiment" should be understood as "at least one embodiment". The term "some embodiments" should be understood as "at least some embodiments". Other explicit and implicit definitions can also be included below.
[0037] In this document, unless explicitly stated, performing a step "in response to A" does not mean performing the step immediately after A, but can include one or more intermediate steps.
[0038] It can be understood that the data involved in the technical solutions of the present disclosure (including but not limited to the data itself, the obtaining, use, storage or deletion of the data) should comply with the requirements of relevant laws and regulations and relevant provisions.
[0039] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the type of information involved in the present disclosure, the scope of use, the use scenario, etc. should be informed to the relevant user and the authorization of the relevant user should be obtained by appropriate means, wherein the relevant user can include any type of right subject, such as an individual, an enterprise or a group.
[0040] For example, in response to receiving the active request of the user, a prompt information is sent to the relevant user to explicitly prompt the relevant user that the operation requested to be performed will require the information of the relevant user to be obtained and used, so that the relevant user can voluntarily choose whether to provide the information to the software or hardware such as electronic device, application program, server or storage medium, etc. performing the operation of the technical solutions of the present disclosure according to the prompt information.
[0041] As an optional but non-limiting implementation manner, in response to receiving the active request of the relevant user, the prompt information can be sent to the relevant user in the form of a pop-up window, and the prompt information can be presented in the form of text in the pop-up window. In addition, the pop-up window can also carry selection controls for the user to select "agree" or "disagree" to provide information to the electronic device.
[0042] It can be understood that the above notification and user authorization process is only illustrative and does not limit the implementation of the present disclosure, and other ways that meet relevant laws and regulations can also be applied to the implementation of the present disclosure.
[0043] Office security generally involves network, identity, and terminal security management. Through the implementation of proprietary network networking, access control, management of terminals in the proprietary network, and information security protection, digital office can be more secure, efficient, and easy to use. Network-level security management can ensure that proprietary networks such as office networks can operate safely and efficiently, and thus ensure that business data can be securely transmitted and stored. Identity-level security management can improve the efficiency and security of user access to proprietary networks. Terminal-level security management can achieve unified management of terminal devices within the proprietary network, data leak prevention, and terminal threat protection, thereby ensuring the security of enterprise data.
[0044] In actual applications, network, identity, and terminal security management can achieve technical association in networking strategies, network access and control, remote access, unified terminal management, terminal detection and response, enterprise data leak prevention, and identity authentication management, thereby making digital office simpler, more efficient, and easier to implement.
[0045] Currently, the following three technologies are mainly used for file association analysis:
[0046] 1) Based on business database
[0047] This technology scans the database table, finds the key fields in the file through text and regular expression matching, and then analyzes the query statements of these fields to draw the file flow path.
[0048] 2) Based on file watermark technology
[0049] This technology inserts a new mark representing the file operator into the file every time the file is transferred, and then obtains the file flow path through the mark.
[0050] 3) Based on injection technology
[0051] This technology improves various application programs by inserting an audit code into the application program. When the user performs file sending and other operations through the application program, the audit code is executed to obtain the file flow path.
[0052] Among the above three methods, the method based on the business database can only analyze the association relationship of the files related to the database table; the method based on the file watermark can only analyze the association relationship of the files such as office documents, pictures, PDFs, and cannot analyze the association relationship of the pure text documents, codes, drawings, and other files; the method based on the injection technology can only analyze the association relationship of the files operated by the application program that has completed the injection improvement. In other words, the files covered by the above three methods are limited, and the enterprise data security cannot be completely guaranteed.
[0053] In view of this, the present disclosure proposes a network architecture and a method based on the network architecture, which can solve the above problems. Please refer to FIG. 1, which is a schematic diagram of the architecture of a network 100 provided by an embodiment of the present disclosure. In FIG. 1, the network 100 can be an enterprise network, and can include a server device 12 and a plurality of terminal devices 11. Among them, the terminal device 11 can be a work device used by an employee of the enterprise to access the enterprise network, such as a desktop computer, a notebook computer, a tablet computer, etc. The server device 12 can be a server.
[0054] Generally, since the network 100 is a private network or a proprietary network, in order to ensure the security of the data scattered on the work terminal devices 11 in the network 100, a security management software 13 can be used to manage the terminal devices 11. Specifically, the security management software 13 can include a client 131 and a server 132, wherein the client 131 can be installed in the terminal device 11, and the server 132 can be installed in the server device 12. The client 131 and the server 132 cooperate with each other to manage the data security of the network 100, such as managing the network resources allowed to be accessed by each terminal device 11, and analyzing the association relationship of the files in the terminal device 11.
[0055] Specifically, in some embodiments of the present disclosure, the server 132 can pre-set a file screening condition. The file screening condition represents the condition that the file to be analyzed for the association relationship needs to satisfy. The file screening condition includes but is not limited to the file attribute that the file to be analyzed for the association relationship needs to have. The file attribute includes but is not limited to the file content, the file title, the file size, the file type, etc. For example, through the file screening condition, the file whose title includes "code" can be specified to be analyzed for the association relationship, or the file whose size exceeds 15k can be specified to be analyzed for the association relationship.
[0056] The server 132 can send the file screening condition to the client 131. After receiving the file screening condition, the client 131 can perform the following operations:
[0057] At a specified time point, the files in the terminal device 11 are scanned, and it is determined whether the scanned files meet the preset file screening condition;
[0058] In response to the scanned files meeting the preset file screening condition, the scanned files are marked as protected files.
[0059] The files marked as protected files are the files that need to be analyzed for the association relationship. In this way, the files in the terminal device 11 can be divided into two categories, one category is the files that do not need to be analyzed for the association relationship, and the other category is the files that need to be analyzed for the association relationship.
[0060] Based on the network architecture shown in FIG. 1 and the two categories of files divided in advance, the present disclosure provides a file processing method, which can have a high file coverage rate when analyzing the association relationship of the files in the terminal device 11, thereby improving the data security of the terminal device 11. The file processing method can be applied to the client 131 or the terminal device 11 running the client 131. In combination with FIG. 2, a flowchart of the file processing method provided by an embodiment of the present disclosure is provided. In FIG. 2, the file processing method includes the following steps:
[0061] Step S21, obtaining an operation event of a first application in the terminal device 11 initiating an operation on a first file.
[0062] In combination with FIG. 3, a software deployment diagram in the terminal device 11 provided by an embodiment of the present disclosure is provided. In FIG. 3, the terminal device 11 is installed with the client 131 and at least one application different from the client 131. Different applications can be used to implement different functions. For example, the application A can be used for file sending and receiving management, the application B can be used for instant messaging between employees in an enterprise, the application C can be used for document writing and editing, and the application D can be used for drawing, etc. The first application can be one of the applications installed in the terminal device 11, such as the application A or the application B.
[0063] The first application program can initiate an operation on the first file in the storage device such as a disk of the terminal device 11 based on a function to be implemented. The first file can be a file that has been marked as a protected file or a file that has not been marked as a protected file. For example, assuming that the first application program can be used for document editing, the document edited by the first application program is the first file. In the process of editing the first file by the first application program, an opening operation on the first file in the storage device is first performed, then content is written into the first file, and finally the file is closed. For another example, assuming that the first application program can be used for sending a file, the file sent by the first application program is the first file. In the process of sending the first file by the first application program, an opening operation on the first file in the storage device is first performed, then content is read from the first file, and finally the read content is sent and the first file is closed. In this disclosure, the operation initiated by the application program on the file in the storage device is also referred to as a file operation. For example, the opening of the first file by the first application program, the writing of content into the first file, the reading of content from the first file, and the closing of the first file can be respectively regarded as a file operation.
[0064] The client 131 can obtain an operation event of the first application program on the first file. For example, the client 131 can communicate with the first application program between applications to obtain the operation event initiated by the first application program on the first file. The operation event can include but is not limited to a file opening operation event, a write operation event, a file closing operation event, a file deletion operation event, a file renaming operation event, and a file copying operation event.
[0065] In step S22, the operation event is mapped to an application behavior of the first application program according to a preset mapping logic.
[0066] With reference to FIG. 4, in this embodiment, the application behavior represents the behavior of the first application program determined according to the flow process of the first file in the terminal device 11. Specifically, the flow process of the first file in the terminal device 11 can include that the first file enters the terminal device 11, the first file is used in the terminal device 11, and the first file leaves the terminal device 11. The use of the first file in the terminal device 11 can further include but is not limited to that the first file is copied, moved, modified, edited, or compressed in the terminal device 11. On this basis, the application behavior corresponding to the entry of the first file into the terminal device 11 can be a file creation behavior, that is, the first application program needs to create the first file in the terminal device 11 after the first file enters the terminal device 11; the application behavior corresponding to the use of the first file in the terminal device 11 can be a file copying / moving / modifying / editing behavior; and the application behavior corresponding to the exit of the first file from the terminal device 11 can be a file sending behavior.
[0067] Each application behavior can correspond to one or more operation events. For example, taking the file modification behavior in FIG. 4 as an example. To complete a file modification behavior, the first application program needs to initiate the file operations of opening a first file, writing content to the first file, and closing the first file in the storage device of the terminal device 11, and thus the operation events corresponding to the file modification behavior can include a file opening operation event, a write operation event, and a file closing operation event.
[0068] Based on the above description, in step S12, the operation events obtained in step S11 are mapped to the application behavior of the first application program according to the preset mapping logic. The mapping logic can be used to define the correspondence between the operation events and the application behavior. In the mapping logic, one or more operation events can be mapped to one or more application behaviors when the one or more operation events meet a specified condition. For example, assuming that the first application program performs the opening operation event, the write operation event, and the file closing operation event on the first file, if the time sequence of the occurrence of the three operation events is that the file opening operation event occurs first, the write operation event occurs second, and the file closing operation event occurs last, and the time difference between the occurrence of the file opening operation event and the occurrence of the write operation event does not exceed a time threshold, then the three operation events can be mapped to the file modification behavior of the first application program.
[0069] Further, in combination with the functions provided by the first application program, the application behavior of the first application program can be further divided more specifically. For example:
[0070] When the first application program is a browser, the browser downloads a file, and a file is created in the storage device of the terminal device 11, and thus the behavior of downloading the file can be regarded as the file creation behavior of the browser;
[0071] When the first application program is a communication software, the communication software receives a file, and a file is created in the storage device of the terminal device 11, and thus the behavior of receiving the file can be regarded as the file creation behavior of the communication software;
[0072] When the first application program is a document editing software (such as office software), when a user initiates a file new creation or export operation through the document editing software, the document editing software creates a file in the terminal device 11, and thus the above new creation or export behavior can be regarded as the file creation behavior of the document editing software;
[0073] When the first application program is a file encryption software, when a file is encrypted, a new encrypted file is generated in the terminal device 11, and thus the encryption behavior can be regarded as the file copy behavior of the file encryption software;
[0074] Similarly, when the first application is the mailbox, the behavior of the mailbox sending the file from the terminal device 11 can be regarded as the file sending behavior of the mailbox.
[0075] In step S23, in the case that the first file has been marked as a protected file, a second file independent of the first file is generated in response to the operation on the first file, the second file is marked as a protected file, and the first file is associated with the application behavior.
[0076] The protected file is a file that needs to be analyzed in terms of the association relationship.
[0077] Generally, when the operation event of the first application on the first file is mapped to the application behavior of copying, saving as, compressing, etc., a second file independent of the first file is generated, and the second file and the first file can be similar or identical files. Therefore, in the case that the first file has been marked as a protected file, the second file also needs to be marked as a protected file.
[0078] After the first file is associated with the application behavior, the association relationship between the first file and the application behavior can be used for the association relationship analysis of the first file.
[0079] In this embodiment, since the second file is a new file obtained by operating the first file, the second file is not operated in the process of operating the first file. Therefore, the second file does not need to be associated with the application behavior. However, when the second file is operated and the corresponding application behavior is obtained, the obtained application behavior can be associated with the second file to analyze the association relationship of the second file.
[0080] Further, in this embodiment, in the case that the second file is marked as a protected file, the second file can be associated with the first file to identify that the second file is obtained by operating the first file. In this way, based on the association relationship between the files, the relationship graph between the files can be obtained. For example, based on the operation on the file A, the file B is obtained, and based on the operation on the file B, the file C is obtained. Therefore, the relationship graph between the files A, B and C can be file A>file B>file C. Based on the relationship graph between the files, the files can be analyzed in more detail in terms of the association relationship.
[0081] In summary, in the technical solutions of some embodiments of the present disclosure, on the one hand, by analyzing the operation event of operating the first file initiated by the first application program, the operation event is mapped to the application behavior of the first application program, and the association relationship analysis is performed on the first file according to the association relationship between the first file and the application behavior, so that the file coverage is high and the data security of the enterprise is effectively ensured, which is not limited by the file type and the first application program type. On the other hand, in the case where the first file has been marked as a protected file, a second file independent of the first file is generated in response to the operation on the first file, and the second file is marked as a protected file. In this way, the new file generated in the file operation process can also be analyzed in a timely manner to prevent file omission, and the same effect of high file coverage and ensuring the security of enterprise data is achieved.
[0082] In addition, the method of the present disclosure does not need to invade the first application program and the first file, and avoids problems such as the crash of the first application program caused by the injection scheme. When performing file association relationship analysis, the stability is greatly improved, and the user experience is good.
[0083] The file processing method of the present disclosure is further described below.
[0084] In some embodiments, in response to the operation on the first file, no second file independent of the first file is generated, and the first file can be associated with the application behavior. For the first file, if multiple application behaviors are generated for the first file, the multiple application behaviors can be associated with the first file. In this way, based on this association relationship, the flow path of the first file in the terminal device 11 can be formed, and the first file can be better analyzed in terms of association relationship.
[0085] Further, the first file can have a first file identifier, and the association between the first file and the application behavior can be the association between the first file identifier and the application behavior. In this way, when establishing the association relationship between the first file and the application behavior, the data storage amount can be greatly reduced. For example, assuming that the first file identifier is A1, the first application program generates application behavior 1, application behavior 2, and application behavior 3 for the first file, and the application behavior 1, the application behavior 2, and the application behavior 3 can be associated with the first file in a manner similar to the following.
[0086] A1: {application behavior 1, application behavior 2, application behavior 3}
[0087] In some embodiments, after associating the first file with the application behavior, the method of the present disclosure can further include:
[0088] The association relationship of the first file and the application behavior is taken as file association information, and the file association information is sent to the server-side device 12, so that the server-side device 12 analyzes the association relationship of the first file based on the file association information.
[0089] Wherein, how the server-side device 12 analyzes the association relationship of the first file based on the file association information can be referred to the subsequent description of the file association method, and details are not described here.
[0090] In some embodiments, the file association information sent to the server-side device 12 can also include at least one of the following information:
[0091] The time point when each application behavior occurs;
[0092] In the case of a text file, the file fingerprint of the first file;
[0093] The device identifier of the terminal device 11 or the user identifier corresponding to the user using the terminal device 11;
[0094] The application identifier of the first application;
[0095] The association relationship between the first file and the second file.
[0096] The above information can help the server-side device 12 to analyze the association relationship of the first file in more detail. For example, based on the time point when each application behavior occurs, an application behavior list of the first file can be generated in chronological order to analyze the flow path of the first file in the terminal device 11.
[0097] The above describes the technical solution when the first file has been marked as a protected file, and the following describes the technical solution when the first file has not been marked as a protected file.
[0098] In some embodiments, in the case that the first file has not been marked as a protected file, the method of the present disclosure can also include:
[0099] After the first file is operated, it is determined whether the first file is a file that needs to be protected;
[0100] If the first file is a file that needs to be protected, the first file is marked as a protected file, and the first file is associated with the application behavior.
[0101] Specifically, after the first file is operated, the application behavior obtained based on the operation event mapping is different, and the logic of determining whether the first file is a protected file is different. The following will be described respectively.
[0102] 1) The application behavior obtained based on the operation event mapping is a file creation behavior
[0103] In this case, it indicates that the first file is a newly created file in the terminal device 11 by the first application, and the first file can be not scanned, so the scanning of the first file can be triggered. If the first file meets the preset file screening condition, it can be determined that the first file is a file to be protected.
[0104] Further, according to the related description of step S22, according to the function of the first application, when the first application performs the file creation behavior, the first file can be a file downloaded or received by the first application, so whether the first file is a file to be protected can also be determined based on the specific source of the first file. Specifically, if the first file is a file downloaded by the first application from a specified network address into the terminal device 11, it can be determined that the first file is a file to be protected; or if the first file is a file sent by a specified second application to the first application, it can be determined that the first file is a file to be protected. The above-mentioned specified network address or specified second application can be set in advance on the server 132 and issued to the client 131 by the server 132.
[0105] 2) The application behavior obtained based on the operation event mapping is a file modification behavior
[0106] In this case, it indicates that the first file is not a newly created file in the terminal device 11, and the first file has been scanned. In the previous scanning, the first file does not meet the file screening condition and is not identified as a protected file. However, after the first application modifies the first file, the first file can change (such as the content of the file changes), so that the first file meets the file screening condition. Therefore, the scanning of the first file can be triggered again to determine whether the first file meets the file screening strategy after the first file is modified. If it meets, the first file can be marked as a protected file.
[0107] 3) The application behavior obtained based on the operation event mapping is not the above-mentioned file creation behavior and file modification behavior
[0108] In this case, whether the first file needs to be marked as a protected file can be determined according to the strategy corresponding to the application behavior. For example, in the case where the mapped application behavior is an export behavior, if the specified destination address of the export is, the first file can be marked as a protected file. The strategy corresponding to the application behavior can be set in advance on the server 132 and issued to the client 131 by the server 132.
[0109] In the above embodiment, in the case where the first file is not marked as a protected file, after the operation on the first file is performed, it is determined again whether the first file needs to be marked, which can prevent file omission and further improve file coverage.
[0110] The following further describes how to map the operation events to application behaviors.
[0111] In some embodiments, the files operated by the first application program can be divided into two categories. The first category of files can be files directly related to the function of the first application program. For example, a browser has a file download function, and the files downloaded through the browser can be the first category of files. The second category of files can be auxiliary files generated by the first application program for implementing the function. For example, when the browser downloads a file, it also records logs in a log file. The log file is a second category of files. Generally, when the association relationship of the files in the terminal device 11 is analyzed, only the first category of files needs to be analyzed. However, the client 131 cannot distinguish the first category of files from the second category of files when collecting the operation events on the files. Therefore, when the operation events of the first file are collected in step S21, the following can be performed: as long as it is detected that the first application program starts to perform file operations, the operation events are obtained. The problem is that the operation events collected cannot distinguish the operation events on the first category of files from the operation events on the second category of files. For example, the client 131 obtains the following two sets of operation events:
[0112] File A: {file opening operation event, write operation event, file closing operation event}
[0113] File B: {file opening operation event, write operation event, file closing operation event}
[0114] Since it cannot be determined whether the files A and B are directly related to the function of the first application program, the operation events cannot be mapped. In view of this, the present disclosure proposes a method for solving the problem: if it is determined that the first file is directly related to the function of the first application program according to the characteristics of the operation events, the operation events on the first file are converted into the application behaviors of the first application program, and if it is determined that the first file is not directly related to the function of the first application program, the operation events on the first file do not need to be converted into the application behaviors of the first application program.
[0115] Specifically, in some embodiments, the operation events are mapped to the application behaviors of the first application program according to the preset mapping logic in step S12, which can include:
[0116] The first time point when the operation event occurs and the second time point when the first file is created are acquired, and the operation event is mapped to the application behavior of the first application according to a time difference between the first time point and the second time point.
[0117] For ease of understanding, the following is described by way of example. It is assumed that the first application has a file downloading or receiving function, if the first file is a file newly downloaded or received by the first application (i.e., a file directly related to the function of the first application), the first application will perform a write operation immediately after creating the file, i.e., in the operation event collected for the first file, the first time point when the write operation event occurs can be relatively close to the second time point when the first file is created; if the first file is a log file or a file already downloaded or received by the first application, when performing log recording and modifying the first file, since the log and the first file have existed in the terminal device 11 for a long time, the first time point when the write operation event occurs can be relatively far from the second time point when the first file is created.
[0118] Based on the above description, it can be understood that, in the operation event collected for the first file, if the operation event is a write operation event, and the time difference between the first time point and the second time point is not greater than the first time difference threshold, it can be determined that the first file is a file directly related to the function of the first application, and then the operation event can be mapped to the file creation behavior of the first application, i.e., the first file is a file newly downloaded or received by the first application.
[0119] Of course, when the first time point when the write operation event occurs is far from the second time point when the first file is created, the first file can be further distinguished from a log file or a file downloaded or received by the first application according to other logic, for example, under normal circumstances, the number of times of performing a write operation event on a log file is relatively large, and then if the number of times of write operation events of the first file does not exceed a number threshold, it can be determined that the first file is a file directly related to the function of the first application, and then the operation event can be mapped to the file modification behavior of the first application.
[0120] Based on a similar principle to the above write operation event, in response to the operation event being a read operation event, and the time difference between the first time point and the second time point being greater than a second time difference threshold, the operation event can be mapped to the file sending behavior of the first application.
[0121] In the above embodiments, whether the first file is directly related to the function of the first application is identified based on a first time point when the operation event occurs and a second time point when the file is created, and the operation event of the first file is mapped to the application behavior of the first application only when the first file is directly related to the function of the first application, which can greatly reduce the data processing amount, improve the data processing speed, and is more in line with the actual business needs.
[0122] In addition to identifying the category to which the first file belongs based on the first time point and the second time point, in some embodiments, whether the first file is directly related to the function of the first application can also be determined according to the storage path of the first file, and then it is determined whether the operation event of the first file is converted into the application behavior. Specifically, since the function of the first application is usually provided for users to use, if the storage path of the first file is a path that the user cannot usually know (such as a hidden path), the first file must not be directly related to the function of the first application, and the operation event of the first file can not need to be converted into the application behavior of the first application; and if the storage path of the first file is a path that the user can know, the first file can be directly related to the function of the first application, and the operation event of the first file can be converted into the application behavior of the first application.
[0123] At this point, the description of the file processing method of the present disclosure is completed.
[0124] Corresponding to the file processing method, the present disclosure also provides a file association method. The file association method can be applied to the server 132 or the server device 12 running the server 132. In combination with FIG. 5, a flowchart of the file association method provided by an embodiment of the present disclosure is shown. In FIG. 5, the file association method includes the following steps:
[0125] Step S51, receiving file association information sent by one or more terminal devices 11, wherein the file association information includes the association relationship between the file in the terminal device 11 and the application behavior, and the application behavior is obtained by mapping the operation event, and the operation event is the event of the application program in the terminal device 11 initiating an operation on the file.
[0126] Wherein, the mapping of the file association information, the application behavior and the operation event can be referred to the related description of the above file processing method, which will not be repeated here.
[0127] Step S52, performing association relationship analysis on the file based on the association relationship between the file and the application behavior.
[0128] Specifically, the server device can display a file association interface, in which one or more application behaviors associated with the file can be displayed, or a relationship graph between files can be displayed. For ease of understanding, referring to FIG. 6, a schematic diagram of a file association interface provided by an embodiment of the present disclosure is shown. In FIG. 6, in response to the input of file A in the input area of the file to be associated, the application behaviors associated with file A can be displayed. When the application behaviors are displayed, they can be displayed from multiple dimensions, such as in FIG. 6, in the left area, the application behaviors associated with file A are displayed in chronological order of occurrence of the application behaviors; in the right area, the number of times of each application behavior associated with file A is displayed.
[0129] It can be understood that the display mode of the application behaviors in the file association interface can be adjusted according to actual needs, and the file association interface shown in FIG. 6 does not constitute a limitation on the present disclosure.
[0130] In some embodiments, the same file can exist in different terminal devices 11, such as file A sent from terminal device A to terminal device B. If file A is operated by an application program in terminal device A and terminal device B, then terminal device A and terminal device B will upload the association relationship between file A and the application behavior. Under normal circumstances, the application behaviors associated with file A in terminal device A and terminal device B should be aggregated and uniformly displayed in the file association interface. In this way, the association relationship analysis of the same file between different terminal devices 11 can be performed, and the effect is better.
[0131] However, in order to perform the association relationship analysis of the same file between different terminal devices 11, it is necessary to first solve how to find out the files belonging to the same file in the file association information uploaded by different terminal devices 11. In view of this, some embodiments of the present disclosure provide the following solutions:
[0132] When receiving the file association information sent by the plurality of terminal devices 11, the file association information uploaded by the plurality of terminal devices 11 is aggregated;
[0133] In the aggregated file association information, the similarity between different files is determined, and a plurality of target files with a similarity greater than a similarity threshold are obtained;
[0134] The plurality of target files are taken as the same target protected file, and the file association analysis of the target protected file is performed based on the application behaviors associated with the plurality of target files.
[0135] The plurality of target files with the similarity greater than the similarity threshold value can be considered as the same file. The plurality of target files are taken as the same target protected file. The file association analysis is performed on the target protected file based on the application behaviors associated with the plurality of target files. The association relationship analysis on the same file between different terminal devices 11 is realized, and the association effect is better.
[0136] Further, in the case that the files include text files, the file association information can further include file fingerprints of the text files. The determination of the similarity between different files can include:
[0137] The similarity between different text files is determined based on the file fingerprints of the text files uploaded by the terminal devices 11.
[0138] The file fingerprint consumes less storage than the file entity. The similarity between different text files is determined by the file fingerprint, which can reduce the storage consumption.
[0139] Further, the files include non-text files, and the file association information can include file identifiers of the non-text files. The determination of the similarity between different files can include:
[0140] The file entity of each non-text file is determined according to the file identifier of the non-text file.
[0141] The similarity between different non-text files is determined based on the file entity of the non-text file.
[0142] Specifically, the file entity can be obtained from the terminal devices 11 according to the file identifier, and the similarity is calculated based on the file entity. In this way, the feasibility of the scheme is ensured.
[0143] At this point, the related description of the file association method of the present disclosure is completed.
[0144] The calculation process of the file fingerprint in the above file processing method and file association method is described below.
[0145] In some embodiments, for any file, the file content of the file can be parsed, and document segmentation can be performed. The so-called document segmentation is to divide the file content into nouns, verbs, etc. according to the word form. Further, word form filtering is performed to retain nouns, verbs, adjectives, and place words. Then, the weight of each word is calculated using the TF-IDF method, and then the file fingerprint of the file can be obtained from the word weight based on the simhash method.
[0146] Referring to FIG. 7, a module schematic diagram of a client provided by an embodiment of the present disclosure is provided. In FIG. 7, the client includes:
[0147] An event obtaining module is configured to obtain an operation event of initiating an operation on a first file by a first application in a terminal device;
[0148] A mapping module is configured to map the operation event to an application behavior of the first application according to a preset mapping logic;
[0149] An association module is configured to, in a case where the first file has been marked as a protected file, in response to the operation on the first file, generate a second file independent of the first file, mark the second file as a protected file, and associate the first file with the application behavior; wherein the association relationship between the first file and the application behavior is used for association relationship analysis on the first file.
[0150] In some embodiments, the association module is further configured to:
[0151] in response to the operation on the first file, associate the first file with the application behavior without generating the second file independent of the first file.
[0152] In some embodiments, after marking the second file as a protected file, the association module is further configured to:
[0153] associate the second file with the first file to identify the second file as being obtained after the operation on the first file.
[0154] In some embodiments, in a case where the first file has not been marked as a protected file, the association module is further configured to:
[0155] determine whether the first file is a file to be protected after the operation on the first file;
[0156] if the first file is the file to be protected, mark the first file as a protected file and associate the first file with the application behavior.
[0157] In some embodiments, the association module is specifically configured to:
[0158] if the first file meets a preset file screening condition, determine that the first file is the file to be protected; and / or
[0159] if the first file is a file created by the first application in response to a user operation and the first application is a specified target application, determine that the first file is the file to be protected; and / or
[0160] if the first file is a file downloaded by the first application from a specified network address into the terminal device, determine that the first file is the file to be protected; and / or
[0161] If the first file is a file sent by a specified second application to the first application, it is determined that the first file is a file to be protected.
[0162] In some embodiments, after associating the first file with the application behavior, the association module is further configured to:
[0163] The association relationship between the first file and the application behavior is used as file association information, and the file association information is sent to a server device, so that the server device analyzes the association relationship of the first file based on the file association information.
[0164] In some embodiments, the association module is further configured to use at least one of the following information as the file association information:
[0165] The time point when each application behavior occurs;
[0166] In the case where the first file is a text file, the file fingerprint of the first file;
[0167] The device identifier of the terminal device or the user identifier corresponding to the user using the terminal device;
[0168] The application identifier of the first application;
[0169] The association relationship between the first file and the second file.
[0170] In some embodiments, before collecting the operation event, the event acquisition module is further configured to:
[0171] At a specified time point, scanning the files in the terminal device, and determining whether the scanned files meet the preset file screening condition;
[0172] In response to the scanned file meeting the preset file screening condition, marking the scanned file as a protected file.
[0173] In some embodiments, the mapping module is specifically configured to:
[0174] Obtaining a first time point when the operation event occurs and a second time point when the first file is created, and mapping the operation event to the application behavior of the first application according to the time difference between the first time point and the second time point; and / or
[0175] Determining the storage path of the first file when the operation event occurs, and mapping the operation event to the application behavior of the first application according to the storage path.
[0176] In some embodiments, the mapping module is specifically configured to:
[0177] If the operation event comprises a write operation event and the time difference between the first time point and the second time point is not greater than the first time difference threshold, the operation event is mapped as a file creation behavior of the first application program.
[0178] In some embodiments, the mapping module is specifically configured to:
[0179] If the operation event comprises a read operation event and the time difference between the first time point and the second time point is greater than the second time difference threshold, the operation event is mapped as a file sending behavior of the first application program.
[0180] Referring to FIG. 8, a schematic diagram of modules of a server according to an embodiment of the present disclosure is provided. In FIG. 8, the server comprises:
[0181] a file receiving module configured to receive file association information sent by one or more terminal devices, wherein the file association information comprises an association relationship between a file in the terminal device and an application behavior, and the application behavior is obtained by mapping an operation event, and the operation event is an event of operating the file initiated by an application program in the terminal device;
[0182] an association module configured to perform association relationship analysis on the file based on the association relationship between the file and the application behavior.
[0183] In some embodiments, the association module is specifically configured to:
[0184] when the file association information sent by the plurality of terminal devices is received, the file association information uploaded by the plurality of terminal devices is summarized;
[0185] in the summarized file association information, a similarity between different files is determined, and a plurality of target files with a similarity greater than a similarity threshold are obtained;
[0186] the plurality of target files are taken as a same target protected file, and file association analysis is performed on the target protected file based on the application behaviors associated with the plurality of target files.
[0187] In some embodiments, in a case where the file comprises a text file, the file association information further comprises a file fingerprint of each text file; and the association module is specifically configured to:
[0188] based on the file fingerprints of each text file uploaded by each terminal device, a similarity between different text files is determined.
[0189] In some embodiments, in a case where the file comprises a non-text file, the file association information comprises a file identifier of each non-text file; and the association module is specifically configured to:
[0190] based on the file identifier of each non-text file, a file entity of each non-text file is determined.
[0191] Based on the file entities of the respective non-text files, a similarity between different non-text files is determined.
[0192] Referring to FIG. 9, a schematic diagram of an electronic device is provided according to an embodiment of the present disclosure. The electronic device includes a processor and a memory. The memory is configured to store a computer program. When the computer program is executed by the processor, the method described above is implemented.
[0193] The processor can be a central processing unit (CPU). The processor can also be other general-purpose processors, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or a combination thereof.
[0194] The memory is a non-transitory computer readable storage medium, which can be configured to store non-transitory software programs, non-transitory computer executable programs and modules, such as program instructions / modules corresponding to the method in the embodiments of the present disclosure. The processor executes various functions and data processing of the processor by running the non-transitory software programs, instructions and modules stored in the memory, i.e. implements the method in the method embodiments described above.
[0195] The memory can include a program storage area and a data storage area. The program storage area can store an operating system and at least one application required by a function. The data storage area can store data created by the processor and the like. In addition, the memory can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory can optionally include a memory remotely arranged with respect to the processor, and these remote memories can be connected to the processor through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0196] The present disclosure also provides a computer readable storage medium configured to store a computer program. When the computer program is executed by the processor, the method described above is implemented.
[0197] The present disclosure also provides a computer program product including a computer program. When the computer program is executed by the processor, the method described above is implemented.
[0198] While embodiments of the present disclosure have been described in conjunction with the appended drawings, various modifications and changes can be suggested by persons skilled in the art, and all such modifications and changes are believed to fall within the scope of the present disclosure.
Claims
1. A method for processing a file, the method comprising: obtaining an operation event of a first application in a terminal device initiating an operation on a first file; mapping the operation event to an application behavior of the first application according to a preset mapping logic; in a case where the first file has been marked as a protected file, generating a second file independent of the first file in response to the operation on the first file, marking the second file as a protected file, and associating the first file with the application behavior; wherein the association of the first file with the application behavior is used for association analysis of the first file. 2.The method of claim 1, further comprising: in response to the operation on the first file, not generating a second file independent of the first file, and associating the first file with the application behavior. 3.The method of claim 1, wherein after marking the second file as a protected file, the method further comprises: associating the second file with the first file to identify the second file as being obtained after the operation on the first file. 4.The method of claim 1, wherein in a case where the first file has not been marked as a protected file, the method further comprises: after the operation on the first file, determining whether the first file is a file to be protected; if the first file is a file to be protected, marking the first file as a protected file, and associating the first file with the application behavior. 5.The method of claim 4, wherein the determining whether the first file is a file to be protected comprises: if the first file meets a preset file screening condition, determining that the first file is a file to be protected; and / or if the first file is a file created by the first application in response to a user operation and the first application is a specified target application, determining that the first file is a file to be protected; and / or if the first file is a file downloaded by the first application from a specified network address to the terminal device, determining that the first file is a file to be protected; and / or if the first file is a file sent by a specified second application to the first application, determining that the first file is a file to be protected. 6.The method of any one of claims 1, 2, or 4, wherein after associating the first file with the application behavior, the method further comprises: associating the first file with the application behavior as file association information, and sending the file association information to a server device, so that the server device performs association analysis on the first file based on the file association information. 7.The method of claim 6, wherein the file association information further comprises at least one of the following information: a time point when each of the application behaviors occurs; in a case where the first file is a text file, a file fingerprint of the first file; a device identifier of the terminal device or a user identifier corresponding to a user using the terminal device; an application identifier of the first application program; an association relationship between the first file and the second file. 8.The method of claim 1, wherein before the operation event is collected, the method further comprises: scanning files in the terminal device at a specified time point, and determining whether a scanned file meets a preset file screening condition; in response to the scanned file meeting the preset file screening condition, marking the scanned file as a protected file. 9.The method of claim 1, wherein the mapping the operation event to the application behavior of the first application program according to the preset mapping logic comprises: acquiring a first time point when the operation event occurs and a second time point when the first file is created, and mapping the operation event to the application behavior of the first application program according to a time difference between the first time point and the second time point; and / or determining a storage path of the first file when the operation event occurs, and mapping the operation event to the application behavior of the first application program according to the storage path. 10.The method of claim 9, wherein the mapping the operation event to the application behavior of the first application program according to the time difference between the first time point and the second time point comprises: if the operation event includes a write operation event, and a time difference between the first time point and the second time point is not greater than a first time difference threshold, mapping the operation event to a file creation behavior of the first application program. 11.The method of claim 9, wherein the mapping the operation event to the application behavior of the first application program according to the time difference between the first time point and the second time point comprises: if the operation event includes a read operation event, and a time difference between the first time point and the second time point is greater than a second time difference threshold, mapping the operation event to a file sending behavior of the first application program. 12.A file association method, the method comprising: receiving file association information sent by one or more terminal devices, wherein the file association information comprises an association relationship between a file in the terminal device and an application behavior, and the application behavior is mapped from an operation event, the operation event being an event of operating the file initiated by an application program in the terminal device; based on the association relationship between the file and the application behavior, performing association relationship analysis on the file. 13.The method of claim 12, wherein the performing association relationship analysis on the file based on the association relationship between the file and the application behavior comprises: when receiving file association information sent by multiple terminal devices, aggregating the file association information uploaded by the multiple terminal devices; in the aggregated file association information, determining a similarity between different files to obtain multiple target files with a similarity greater than a similarity threshold. The multiple target files are protected as one target protected file, and file association analysis is performed on the target protected file based on application behaviors associated with the multiple target files.
14. The method of claim 13, wherein in a case where the files include text files, the file association information further includes file fingerprints of the respective text files. The similarity between different files is determined, including: The similarity between different text files is determined based on file fingerprints of the respective text files uploaded by the respective terminal devices.
15. The method of claim 13, wherein in a case where the files include non-text files, the file association information includes file identifiers of the respective non-text files. The similarity between different files is determined, including: The file entity of each non-text file is determined according to the file identifier of the respective non-text file. The similarity between different non-text files is determined based on the file entity of the respective non-text file.
16. A client, comprising: an event obtaining module configured to obtain an operation event of a first application program in a terminal device initiating an operation on a first file; a mapping module configured to map the operation event to an application behavior of the first application program according to preset mapping logic; an association module configured to, in a case where the first file has been marked as a protected file, generate a second file independent of the first file in response to the operation on the first file, mark the second file as a protected file, and associate the first file with the application behavior, wherein the association relationship between the first file and the application behavior is used for association relationship analysis on the first file.
17. A server, comprising: a file receiving module configured to receive file association information sent by one or more terminal devices, wherein the file association information includes an association relationship between a file in the terminal device and an application behavior, and the application behavior is mapped from an operation event, the operation event being an event of an application program in the terminal device initiating an operation on the file; an association module configured to perform association relationship analysis on the file based on the association relationship between the file and the application behavior.
18. A computer readable storage medium for storing a computer program, the computer program being executed by a processor to implement the method of any one of claims 1 to 11, or to implement the method of any one of claims 12 to 15.
19. An electronic device, comprising a processor and a memory, the memory being configured to store a computer program, the computer program being executed by the processor to implement the method of any one of claims 1 to 11, or to implement the method of any one of claims 12 to 15.
20. A computer program product comprising a computer program which, when executed by a processor, implements the method of any one of claims 1 to 11, or implements the method of any one of claims 12 to 15.
Citation Information
Patent Citations
Operation behavior identification method, device and system
CN110502894A
Data circulation classification management method and system
CN113407502A
File identification processing method and device
CN113901001A
File processing method, association method, client, server, device and medium
CN118627113A
Intelligent event collection for rolling back an endpoint state in response to malware
US20190392147A1