Database Autonomy Service (DAS) identifies sensitive data in databases across industries such as finance, energy, and automotive. You can use built-in identification templates to detect sensitive data in your instances, or create custom templates based on them.
Supported databases and regions
Databases | Regions |
| China (Hangzhou), China (Shanghai), China (Qingdao), China (Beijing), China (Zhangjiakou), China (Hohhot), China (Shenzhen), China (Chengdu), and China (Hong Kong) |
PolarDB for PostgreSQL (Compatible with Oracle) | China (Hangzhou) and Malaysia (Kuala Lumpur) |
Models and templates
Identification template
An identification template classifies and grades sensitive data according to industry standards, helping you verify compliance with security and regulatory requirements.
Identification models and identification features
Concept | Description |
Identification model | An identification model consists of one or more identification features. It determines the final identification result and is configurable. DAS provides built-in identification models for typical sensitive data and supports custom identification models. |
Identification feature | An identification feature detects sensitive data based on content, metadata, or dictionaries. It uses rules that combine regular expressions and operators such as 'contains' and 'does not contain' to define data characteristics. You can link multiple rules with AND/OR operators for more flexible detection. DAS provides built-in identification features for common sensitive data types and supports custom identification features. |
Template classification and task rules
An identification task scans data in a connected database to discover sensitive data, generates a scan report, and applies classification and grading to the results.
An identification task requires an enabled identification template. There are three types of enabled identification templates: primary, active, and general-purpose.
When you add a custom identification task, you can select only one primary template and up to two active templates.
Template type | Description |
Built-in template | Select a built-in template based on your business scenario. DAS provides templates for industries including finance, internal cloud security, power, Internet of Vehicles (IoV), and the general internet industry. |
Custom template | If the built-in templates do not meet your requirements, you can create up to ten custom templates by configuring identification features and identification models. |
Template role | Description |
Primary template | This template is used by default for system tasks. The default primary template is the classification and grading template for the internet industry. A primary template cannot be disabled. You can have only one primary template. You can set an active template as the primary template. Identification results in the DAS console are based on the primary template. |
Active template | You can enable built-in templates or custom templates as active templates. You can enable up to two active templates. |
General-purpose template | A template based on the Personal Information Security Specification This template is the default only for identification tasks that use built-in templates. |
Sensitivity levels
DAS sensitive data identification supports up to 10 sensitivity levels, from S1 to S10. A higher number indicates a higher sensitivity level.
In a built-in template, you cannot add or delete sensitivity levels. You can only edit the description.
In a custom template, you can add, edit, and delete sensitivity levels.
Identification templates and models
Template management
Built-in identification templates
Log on to the DAS console.
In the left-side navigation pane, choose .
By default, you are on the template management > Template Configuration tab. The Enabled identification templates area displays enabled templates as cards. The primary template is identified by the Primary tag. Supported operations include Set as Primary, View, and Disable. The Template Library area lists all built-in classification and grading templates and their statuses. You can use the switch to enable or disable a template, and perform operations such as Create Template, View, and Copy.
In the template list at the bottom of the template management tab's Template Configuration page, find the identification templates whose Type is built-in.
In the Status column, click the switch
or
to enable or disable the template.Click the Primary or Deactivate switch for an enabled identification template to set it as the primary template or to deactivate it.
NoteIf you do not configure an identification template, the default primary template is the Classification and Grading Template for the Internet Industry.
Custom identification templates
Create
Log on to the DAS console.
In the left-side navigation pane, choose .
On the template management > Template Configuration page, click Create Template.
On the Create Template page, configure the Basic Information (Template Name and Template Description), and then click Next.
In the Configure Template Node section, click Create Category. In the dialog box that appears, enter a Category for the sensitive data and click OK.
Click the manage
icon to the right of the added category, and then click Add Sibling Category or Add Subcategory to add a sibling or subcategory.This menu also includes the Add Model and Delete options.
NoteRepeat this step to add multiple categories.
Repeat the following steps to add an identification model under the sensitive data category.
Click the manage
icon to the right of the added category and click Add Model.In the Add Model dialog box, select the checkbox for the target identification model, set its status to enabled
, and then click OK.ImportantAn identification model takes effect in tasks only after you enable it in the template.
You can use the All models, All data labels, and All sources drop-down lists, or the model name search box to find a specific identification model.
Copy
Log on to the DAS console.
In the left-side navigation pane, choose .
On the template management > Template Configuration page, find the built-in or custom identification template that you want to copy and click Copy in the Operation column.
In the dialog box, modify the Template Name and Remarks, and then click Confirm.
NoteYou can click Edit in the Actions column for the new template to modify its name, model categories, and identification models.
Model management
Log on to the DAS console.
In the left-side navigation pane, choose .
Click the Identification Model tab, and then click Add Model.
In the Add Model panel, configure the model parameters, and then click OK.
Type
Parameter
Description
Basic Information
Model name
The name of the model. The name must be unique.
Model Description
The description of the model.
Tag
Select a data label for the model. Valid values: sensitive personal information, Personal Information, and General Information.
Data Category
In the drop-down list, associate the new model with an identification template, a sensitive data category, and a risk level.
You can associate the model only with custom identification templates.
Model Rule
Identification Features
From the drop-down list, select the identification features for the model.
You can select built-in and custom identification features.
If you select multiple features, they are combined with OR logic.
Identification Scope
From the drop-down list, select the asset types where the model applies. By default, the model applies to authorized and accessible DAS assets.
If you select multiple asset types, they are combined with OR logic.
Advanced Settings
Optional.
From the drop-down list, select the asset type that you want to configure.
Select how the conditions take effect. Valid values: AND and OR. To create multiple condition groups, click Add Group. The new group is a subset of the first group.
Configure the identification conditions. To add more conditions, click Add Condition.
Identification Threshold
Minimum Hits (Unstructured Data)
For unstructured data (such as NoSQL files), set the minimum number of times an identification feature must be found in a single file.
If the match count in a single file meets this threshold, the file is classified as sensitive data.
Hit Ratio (Structured Data)
Set the hit rate for structured data (for example, RDS).
If the percentage of matching records in a 200-record sample meets the specified hit rate, the data is classified as sensitive.
Other operations
View template details: Click Details in the Actions column for a template to view its rule configuration and identification threshold.
Delete an identification template: You can only delete custom identification templates, not built-in ones. In the Operation column of the target template, click the manage
icon, and then click Delete.Manage model categories: You can only set model categories for custom templates. In the Actions column of the target template, click Edit.
Switch the enabled identification model: Switching the enabled identification model does not affect running tasks. The change takes effect for the next task execution.
Manage sensitive data identification
Prerequisites
Grant asset authorization to the target instance in the instance list.
Click the Cloud Instances tab, find the target instance, and click Enable in the Security Center column.
Identification tasks
System default task
When you authorize a database and select the default sensitive data identification scan task, DAS creates a default scan task for the database using the primary identification template.
Parameter | Description |
Identification template | The system default task uses the primary identification template. This cannot be modified. Note If the primary identification template is a built-in identification template, the task also uses the general-purpose identification template. |
Scan period (default) | If you select the default sensitive data identification scan task during instance authorization, the task runs immediately after you confirm. Note You can configure the scan period for the system default task. The minimum interval between two scans is 24 hours. |
Scan scope | For authorized instance, database, and table names: Note
If you switch the primary identification template, a scan is not immediately triggered. The next scan uses the new identification template. |
Scan limits |
|
Scan result | The scan result is the sensitivity level of the identification template. |
Custom identification task
You can add a custom identification task to scan a specified database table using an enabled identification template. If the template you want to use is not enabled, enable it first.
Based on the custom scan scope and scan period, the first scan and any rescans are full scans. Periodic scans cover only new or modified data objects.
The scan result is the sensitivity level of the identification template.
N/Aindicates that the scan found no sensitive data.
Manage system default tasks
View default task
Log on to the DAS console.
In the left-side navigation pane, choose .
On the Task Management page, click the Identification Task tab, and then click System Default Task.
On the Identification Task Monitoring page, view the list of default tasks.
In the Actions column, you can perform the following operations on a system default task.
Rescan: Rescans all data. Use this action if the identification model is upgraded, you change the primary identification template, or the database content changes.
Pause: If a database service experiences problems, click Pause in the Actions column to temporarily stop the system default task that is running.
Stop: Prevents the task from running in the next period. If the task is currently running, stopping it does not affect the current run.
Enable: Re-enables a stopped task.
Adjust scan settings
System default tasks support periodic scanning. Set the scan period to match your database update frequency to detect sensitive data in new records. The minimum configurable scan period is 24 hours.
On the Discovery Task Monitoring page, select the checkbox for the desired task, click Scan settings above the task list, and configure the period and scan time.
To minimize the impact of scanning on your database, set the scan start time to off-peak hours.
If you observe a spike in CPU or memory usage during a scan, pause or stop the task immediately. You can go to the Task Management page and click Pause or Stop in the Actions column to stop the scan.
Create custom task
Log on to the DAS console.
In the left-side navigation pane, choose .
On the Identification Tasks tab, select the asset type for which you want to create an identification task, and click Create.
The navigation tree on the left groups asset types by data category, such as structured data. The groups include sub-items such as RDS, PolarDB, and PolarDB-X 2.0. Select the target asset type and click Create Identification Task on the right.
In the Create panel, configure the task parameters, and then click Confirm.
Category
Parameter
Description
Identification Scope
Identification Scope of Structured Data
Select the scan scope for structured data, such as ApsaraDB RDS and PolarDB. Options:
Global Scan: Scans all your structured data assets.
Specify Scan Scope: Configure Instance Name, Database Name, and Scan Limit.
Configure the instance name and database name. To add multiple instances, click Add Identification Scope.
Configure Scan Limit. The first 200 rows are scanned by default, with a maximum of 1,000 rows.
Other configurations
Tagging Result Overwriting
Specify how to handle detected sensitive data that has been previously corrected. Options:
Skip manual tagging results: Retains the original manual correction results. This option is recommended.
Overwrite manual tagging results: Overwrites the manual correction results with the new identification results.
In the Operation column, you can perform the following operations on a custom identification task.
Rescan: Rescans all data. Use this action if the identification model is upgraded, you change the primary identification template, or the database content changes.
Suspend: If a database service experiences problems, click Pause in the Actions column to temporarily stop the task that is running.
Terminate: Prevents the task from running in the next period. If the task is currently running, stopping it does not affect the current run.
Enable: Re-enables a stopped task.
Manage custom tasks
You can create a custom identification task to scan a specific database with any enabled template, not just the primary template.
The system supports a maximum of five active identification tasks. Each periodic scan task occupies one active task slot. After you configure five periodic tasks, you cannot create new identification tasks.
Correct results
The recovery operation restores the identification model to its state before correction.
Log on to the DAS console.
In the left-side navigation pane, choose .
On the page, click the Revision Tasks tab.
In the left-side data type navigation pane, click the asset type that you want to correct.
Click Correct or Recover in the Actions column for the target sensitive data. Follow the on-screen instructions to modify the Corrected model, and then click OK.
Identification results
After a sensitive data identification task completes, you can view and export the results on the Asset Overview page. Scan results refresh every 5 minutes.
View results
Log on to the DAS console.
In the left-side navigation pane, choose .
On the Asset Type tab, click the data type that you want to view.
After you click the data type, sensitive data statistics for that asset type are displayed on the right, including Sensitive instances, Sensitive databases, Sensitive tables, and Sensitive columns, along with week-over-week changes. The data table below shows information for each instance, such as Instance ID/Name/UID, Region, Database type, Total DBs | Sensitive DBs, Sensitivity level, and Data label. You can expand an instance to view database-level sensitive data details and the last scan time. You can filter data by Region, Sensitivity level, and Instance ID, and click Table Details to view table-level information.
To view the details of sensitive data in a data asset instance, click Table Details in the Actions column.
In the details panel on the right, view the sensitive data statistics.
The sensitive data statistics include: a Data classification and grading statistics donut chart (showing the proportion of each sensitivity level, such as S2 and S3), a Sensitive data label statistics donut chart (showing the distribution of categories such as Sensitive Personal Information, Personal Information, and General Information), a Data identification rate bar chart (showing the total number of columns, sensitive columns, and their ratio), and a Top 5 hit models horizontal bar chart (such as Personal Phone Number, Passport Number, and Mobile Number). Below the charts are Hit model and Sensitivity level drop-down filters and a search function. At the bottom, a data details table lists columns such as Table Name, Total Rows, Total Columns, Sensitive Columns, Data Labels, Hit Data, and Actions. You can click Column Details to view specific sensitive column information.
In the sensitive data list, you can click Column details in the Operation column to view the rule details for data that was identified as sensitive in each column.
If the Revision option is available in the Operation column, you can correct the sensitive data identification results.
Taking the
audit_logtable as an example, the Column Details page displays information such as Column name, Data label, Identification result, Sensitivity level, Correction status, and Data sampling result. For example, the identification result for theidcolumn is "Primary key", the sensitivity level is S1, and the correction status is "Not corrected". The Correct and Recover actions are available on the right side of each row.
Export results
Log on to the DAS console.
In the left-side navigation pane, choose .
Click Create. Configure the export task, and then click OK.
In the Basic information section, enter a task name and select the template used for the identification task. You can select only enabled templates.
In the Export dimension section, select Asset type or Asset instance.
Asset type: Select all engine instances.
Asset instance: Select the engine instances whose data you want to export.
After you create an export task, you can view its status in the export task list. Larger datasets take longer to export.
Download results
Wait until the Export Status changes to Completed, and then click Download in the Actions column of the target export task.
You must download the exported data within three days of task completion. After this period, the task expires and the data is no longer available for download.