IP Library Granted Patent US 11,080,427
Granted Patent B2
US 11,080,427 · App. 16/874,012 · Granted Aug 3, 2021

Method and apparatus for detecting label data leakage channel

Inventor: Zhen Wen (Hangzhou, CN)
Assignee: ALIBABA GROUP HOLDING LIMITED
G06F21/6272G06F21/6245H04L43/12
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,080,427
App. No.
16/874,012
Granted
Aug 3, 2021
Kind
B2
Abstract

The present disclosure provides label data leakage channel detection methods and apparatuses. According to one exemplary label data leakage channel detection method, detection labels are generated based on normal labels of a user. The detection labels can be associated with different data usage channels, so as to indirectly detect usage of the detection labels. Possible data leakage channels can be effectively detected based on massive data indexing and searching. One exemplary apparatus of the present disclosure includes a detection label adding module, a channel association module, an interception module, an intercepted information analysis module, a channel searching module, and an output module. The detection methods and apparatuses provided by the present disclosure have the advantages of high detection efficiency and the capability of processing massive and dynamic user label data.

Claims (44)

1. A leakage channel detection method for detecting a leakage channel of an internet network, the method comprising:

adding one or more detection labels for a user based on a normal label of the user;

generating a random value according to a channel ID of a channel and a user ID of the user;

selecting a detection label from the one or more detection labels of the user based on the random value; and

associating the selected detection label with the channel and the user ID associated with the user, which enables to detect a leakage of user label data over the channel.

2. The leakage channel detection method of claim 1 , wherein generating the random value comprises: selecting a Hash function from a preset Hash function set by taking the channel ID of the channel as a variable and generating the random value according to the Hash function.

3. The leakage channel detection method of claim 1 , wherein the user is in a user group of the channel that is sampled based on a credibility value of the channel, and the credibility value of the channel is determined according to historical behaviors of the channel.

4. The leakage channel detection method of claim 1 , wherein adding the one or more detection labels for the user based on the normal label of the user comprises:

generating the one or more detection labels based on the normal label of the user, a probability of each of the one or more detection labels co-occurring with the normal label being lower than a preset threshold.

5. The leakage channel detection method of claim 1 , further comprising:

deleting one detection label among the one or more the detection labels based on a probability of the one detection label co-occurring with a new normal label of the user; and

adding a new detection label for the user based on the new normal label of the user.

6. The leakage channel detection method of claim 1 , further comprising:

detecting whether the channel is a suspected leakage channel based on an association level between the selected detection label and information received from the channel.

7. A leakage channel detection apparatus for detecting a leakage channel of an internet network, comprising:

a memory storing a set of instructions; and

one or more processors configured to execute the set of instructions to cause the apparatus to perform:

adding one or more detection labels for a user based on a normal label of the user;

generating a random value according to a channel ID of a channel and a user ID of the user;

selecting a detection label from the one or more detection labels of the user based on the random value; and

associating the selected detection label with the channel and the user ID associated with the user, which enables to detect a leakage of user label data over the channel.

8. The leakage channel detection apparatus of claim 7 , wherein generating the random value comprises: selecting a Hash function from a preset Hash function set by taking the channel ID of the channel as a variable and generating the random value according to the Hash function.

9. The leakage channel detection apparatus of claim 7 , wherein the user is in a user group of the channel that is sampled based on a credibility value of the channel, and the credibility value of the channel is determined according to historical behaviors of the channel.

10. The leakage channel detection apparatus of claim 7 , wherein adding the one or more detection labels for the user based on the normal label of the user comprises:

generating the one or more detection labels based on the normal label of the user, a probability of each of the one or more detection labels co-occurring with the normal label being lower than a preset threshold.

11. The leakage channel detection apparatus of claim 7 , wherein the one or more processor is configured to execute the set of instructions to cause the apparatus to further perform:

deleting one detection label among the one or more the detection labels based on a probability of the one detection label co-occurring with a new normal label of the user; and

adding a new detection label for the user based on the new normal label of the user.

12. The leakage channel detection apparatus of claim 7 , wherein the one or more processor is configured to execute the set of instructions to cause the apparatus to further perform:

detecting whether the channel is a suspected leakage channel based on an association level between the selected detection label and information received from the channel.

13. A non-transitory computer readable medium that stores a set of instructions that is executable by one or more processors of a computing devices to perform a leakage channel detection method, comprising:

adding one or more detection labels for a user based on a normal label of the user;

generating a random value according to a channel ID of a channel and a user ID of the user;

selecting a detection label from the one or more detection labels of the user based on the random value; and

associating the selected detection label with the channel and the user ID associated with the user, which enables to detect a leakage of user label data over the channel.

14. The non-transitory computer readable medium of claim 13 , wherein generating the random value comprises: selecting a Hash function from a preset Hash function set by taking the channel ID of the channel as a variable and generating the random value according to the Hash function.

15. The non-transitory computer readable medium of claim 13 , wherein the user is in a user group of the channel that is sampled based on a credibility value of the channel, and the credibility value of the channel is determined according to historical behaviors of the channel.

16. The non-transitory computer readable medium of claim 13 , wherein adding the one or more detection labels for the user based on the normal label of the user comprises:

generating the one or more detection labels based on the normal label of the user, a probability of each of the one or more detection labels co-occurring with the normal label being lower than a preset threshold.

17. The non-transitory computer readable medium of claim 13 , wherein the set of instructions that is executable by at least one processor of the computing device to further perform:

deleting one detection label among the one or more the detection labels based on a probability of the one detection label co-occurring with a new normal label of the user; and

adding a new detection label for the user based on the new normal label of the user.

18. The non-transitory computer readable medium of claim 13 , wherein the set of instructions that is executable by at least one processor of the computing device to further perform:

detecting whether the channel is a suspected leakage channel based on an association level between the selected detection label and information received from the channel.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2026
From: ALIBABA GROUP HOLDING LIMITED
To: CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PRIVATE LIMITED
Reel/Frame 075478/0225 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2020
From: WEN, ZHEN
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 052663/0743 →
Priority Claims (1)
CN 201511028180.5 · Dec 31, 2015 · national
Continuity (3)
Continuation 16020872 · Jun 27, 2018
Continuation PCTCN2016110714 · Dec 19, 2016
Related Publication 20200272765A1 · Aug 27, 2020