Banking, insurance, logistics, transportation, medical and other industries
With the continuous development of the Internet and cloud technology, there are risks such as complexity, concealment and proliferation of personal financial data, personal privacy data, personnel-related corporate information, corporate business data, and national confidential data. Ensuring the safe use of data, reasonable and compliant application of data, and meeting national and industry regulatory requirements have become the top issues facing various industries.
To this end, Beiming Software has developed a data security solution. Through the built-in industry data classification and grading templates and business data feature identification rules and algorithms, it has achieved automatic classification and hierarchy of multiple industry data. Through flexible fine-grained permission control strategies and security control strategies, combined with business processing, application use, external data exchange, production test operation and maintenance and other business scenarios, it supports enterprises in various industries to implement marking, identification, classification and grading of important data, and implement data lifecycle security monitoring, security protection and risk audit and evaluation mechanisms to ensure data visibility, compliance and security controllability, significantly improving data use value assurance capabilities.
1.Continuous dynamic discovery and dynamic supervision of data assets
Data security solutions continuously and dynamically supervise the dynamic change characteristics of data in business activities, complete classification and grading in accordance with laws, regulations and relevant standards, ensure the legality of data sources and the compliance of data usage, and gradually enable the data to meet basic transaction conditions while empowering business operations.
2.Superb protocol conversion capabilities and massive gateway data forwarding capabilities
Data security solutions are based on a cluster architecture design that supports on-demand scaling and has the processing capacities up to millions of QPS (queries per second). With an 8-core 16GB processing capability, the single-node data forwarding capacity is no less than 10,000 times per second, and the increase in data call latency does not exceed 30%.
3.Fine-grained identity authentication and permission management
Through fine-grained permission control, the platform controls the scope of data access, helps users reduce the risk of sensitive data leakage on the "data consumption side", supports row-level permission of configuration data and permission policies based on the ABAC model, supports dynamic configuration of data permissions, and supports custom dimensional data permission management.
4.Rich data source access capabilities
Data security solutions implement plug-in adaptation mechanisms, access data services across domains, support rapid adaptation to customer-specific data source types, and provide services through data security gateways. Supported data sources include mainstream relational databases such as MySQL, Oracle, DB2, SQL Server, PostgreSQL, Informix, Doris, and Vertica, as well as NoSQL databases and big data platforms like Redis, MongoDB, and Hive.
5.Building a one-stop data security management and control system based on brain-like technology
Data security solutions provide a variety of methods such as association analysis, behavior analysis, AI and abnormality detection. Relying on brain-like technology, they identify and predict known and unknown risks through small sample size or even no samples, support intelligent processing, and provide customers with a leading data security management and control closed-loop system.
Beiming Software's data security products include a data asset mapping system, a data security gateway, and a smart data brain.
Beiming Software Data Security Product Architecture Diagram
1. Automatic identification and securitycontrol
The platform realizes the automatic identification and security classification of sensitive information through the built-in industry data classification and grading templates; through a flexible labeling system, it quickly identifies important data and core data as needed; and supports users in conducting data security compliance risk self-inspection. At the same time, the platform builds a data flow security system to achieve security control in data collection, storage, exchange and other aspects.
2. Security risk monitoring system
The platform builds a data security risk monitoring system to help enterprises detect data crawling, abnormal access and other behaviors in a timely manner, trace back to analyze data theft, data leakage and other incidents, and locate the responsible person.
3.Self-inspection of compliance riskand continuous operation of data security
The data security solutions help industry customers self-inspect data security compliance risks, build industry data applications under the premise of legal compliance requirements, help industry customers achieve efficient continuous operation of data security, and realize timely discovery and efficient disposal of data security risks.
Beiming Software’s Data Security Empowers Enterprise Security Capabilities
Scenario 1:Data security in the financial industry
The financial industry is guided by compliance and regulatory requirements, with information technology risks as the main direction, and the data security solutions closely follow science and technology regulatory policies to carry out information technology risk management services, empower financial institutions, and build a financial technology ecosystem. The platform automatically classifies and grades all data through data asset maps, effectively helping customer’s technical teams to quickly sort and classify and manage data assets. For multiple data sources such as customer information and counter information, the platform can quickly and accurately identify table-level data assets and field-level data assets. The identification accuracy of table-level assets under the customer category reaches more than 85%, the identification accuracy under the business and operation management category reaches more than 76%, and the comprehensive identification accuracy of field-level data assets reaches more than 83%.
Scenario 2: Medical industry data security
The platform uses automatic data asset identification technology to help data compliance management departments quickly locate a small amount of personal sensitive information data that needs to be processed urgently from massive data, clarify compliance management priorities, and improve efficiency. According to the requirements of the GB/T 35273-2020 "Information Security Technology - Personal Information Security Specification", the personal sensitive information within table-level data assets of medical big data is identified. For weak characteristic data such as case information and physiological feature information, accuracy can be improved through intelligent labeling and training. When compared with manual classification and grading results, the comprehensive classification and grading accuracy reaches over 92%.