Database anti-ransomware method and device based on user SQL feature behavior analysis
Through the method based on user SQL feature behavior analysis, multi-source data aggregation and deep learning models are used to solve the problem of traditional database security protection systems being powerless in the face of new ransomware attacks, and the precise analysis of SQL operation data and efficient identification of ransomware behaviors is achieved, providing more powerful database security protection.
Patent Information
- Application Number
- CN202510126545.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-27
- Publication Date
- 2025-06-03
AI Technical Summary
Traditional database security protection systems appear powerless when facing new ransomware attacks, especially when identifying attacks that exploit SQL logic vulnerabilities, traditional devices cannot effectively intercept, resulting in data security being threatened.
Using an anti-ransomware method based on user SQL feature behavior analysis, through multi-source data aggregation algorithm, BERT model and Transformer model, SQL data sets are constructed, SQL statement structural features are extracted, and user SQL behavior models are trained to monitor and evaluate database anti-ransomware risks in real time.
It realizes accurate capture and analysis of SQL operation data, significantly improves the accuracy of ransomware recognition, reduces the risk of misjudgment of business operations, and provides more powerful database security protection.
Smart Images

Figure CN120086238A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of database security, and particularly to a database anti-ransomware method and device based on user SQL feature behavior analysis. Background Art
[0002] In the current booming digital age, databases have become the core elements of enterprise operations. They carry key business data such as the financial data of financial institutions, the patient information of medical institutions, and the transaction records of e-commerce platforms. Their security directly determines the rise and fall of enterprises. Traditional protection means are gradually showing weakness, giving rise to a new anti-ransomware method based on user SQL feature modeling.
[0003] Traditional security protection systems include IDS (Intrusion Detection System), IPS (Intrusion Prevention System), anti-virus software, and firewalls, etc., which have played an important role in network security, but are full of loopholes in the face of new ransomware attacks. IDS and IPS rely on known attack pattern feature libraries to detect network traffic features and are weak in identifying attacks that utilize SQL (Structured Query Language) logical vulnerabilities. Such attacks are hidden in normal SQL operations, and the network traffic is indistinguishable from daily business, easily bypassing monitoring, resulting in traditional devices being unable to effectively intercept. For example, it is difficult to distinguish between normal data queries and malicious encryption operations in terms of traffic features for IDS / IPS, and they cannot accurately identify, giving ransomware an opportunity.
[0004] Anti-virus software relies on signature databases to detect common viruses and malware and is helpless in the face of encrypted and obfuscated ransomware codes hidden in legitimate SQL instructions. It cannot parse the SQL semantic structure and is difficult to see through the disguise of malicious codes, being passive in the face of new threats. For example, complex polymorphic ransomware variants constantly change encryption methods and instruction combinations, and signature detection is like looking for a needle in a haystack, making it difficult for anti-virus software to respond and defend in a timely manner. Firewalls based on network address and port restrictions only coarsely control traffic at the network layer and cannot understand the deep semantics of SQL statements and user intentions. After an internal host is compromised, targeted attacks using legitimate SQL ports can break through the defense line because firewalls do not understand SQL malicious logic and cannot block malicious traffic. For example, when an internal employee's terminal is controlled to initiate a database ransomware attack, the firewall cannot judge the threat based on the SQL content, and data security is in jeopardy.
[0005] In traditional database management, it is inefficient and error-prone for DBAs to manually audit SQL operation logs, making it difficult to meet the real-time monitoring requirements of large-scale databases. Business expansion and complex architectures result in a vast amount of log data. Manual review is slow and error-prone, making it difficult to capture anomalies, leading to a lag in defense when the database is attacked by ransomware. For example, large financial institutions have frequent daily transactions. It is difficult for DBAs to quickly identify abnormal SQL encryption instructions from the vast amount of logs, and the cost of post-event remediation is high, resulting in heavy losses due to data leakage.
[0006] Ransomware developers continuously innovate their attack strategies, using zero-day vulnerabilities, multi-stage attacks, and encryption obfuscation techniques, making traditional protection more difficult. Zero-day vulnerability attacks strike on unknown vulnerabilities of manufacturers, and there are no patches for protection software to respond. Multi-stage attacks infiltrate and control the database step by step, with strong concealment in the initial stage. Encryption obfuscation techniques enhance the concealment of malicious code, hindering the analysis and identification of security tools. The combination of these means continuously impacts the bottom line of traditional protection, and the security situation of enterprise databases is severe. In summary, traditional security protection is losing ground under ransomware attacks, and enterprises urgently need innovative solutions.
[0007] The method based on the analysis of users' SQL feature behaviors deeply analyzes SQL behavior patterns and monitors anomalies in real time, promising to fill the gap in traditional protection, safeguard database security, help enterprises resist ransom threats in the digital wave, develop their businesses steadily, and protect the core value of data assets and operational continuity. Summary of the Invention
[0008] To solve the technical problems existing in the prior art: 1. Facing the diversity of data formats, protocols, and access permissions of different data sources, how to design a flexible and efficient adaptation mechanism to ensure that data can be collected smoothly without affecting the performance of the source system; 2. How to optimize the model architecture and parameters according to the characteristics of the SQL language to reduce semantic understanding deviations caused by the differences between SQL and natural language, and improve the feature extraction accuracy of SQL professional terms, functions, and special symbols. 3. How to improve the generalization of the model and design reasonable model evaluation indicators to comprehensively measure the performance of the model in complex attack scenarios, the embodiments of the present invention provide a database anti-ransom method and device based on the analysis of users' SQL feature behaviors. The technical solutions are as follows:
[0009] On the one hand, a database anti-ransom method based on the analysis of users' SQL feature behaviors is provided. This method is implemented by a database anti-ransom device, and the method includes:
[0010] S1. Use multi-source data aggregation algorithms, real-time and historical combination algorithms, and data cleaning and verification algorithms to construct an SQL data set.
[0011] S2. Extract SQL statement structure features from the SQL data set according to the pre-trained model BERT and semantic matching methods.
[0012] S3. Train a user SQL behavior model based on Transformer according to the SQL statement structure characteristics to obtain a trained user SQL behavior model based on Transformer.
[0013] S4. Through the monitoring engine, real-time capture the SQL operation data executed by the user on the database, extract the characteristics of the SQL operation data, and input the characteristics of the SQL operation data into the trained user SQL behavior model based on Transformer to obtain the database anti-ransomware evaluation result.
[0014] Optionally, in S1, use the multi-source data aggregation algorithm, the real-time and historical combination algorithm, and the data cleaning and verification algorithm to construct an SQL data set, including:
[0015] S11. Use the multi-source data aggregation algorithm to obtain the SQL operation data of the user on the database.
[0016] S12. Through the real-time data capture algorithm, real-time capture the newly generated SQL operation data; through the historical data backtracking algorithm, obtain the SQL operation data within the preset historical time period.
[0017] S13. Through the data cleaning and verification algorithm, clean and verify the obtained SQL operation data to obtain an SQL data set.
[0018] Optionally, in S11, use the multi-source data aggregation algorithm to obtain the SQL operation data of the user on the database, including:
[0019] S111. Collect the SQL statement execution records from the log files of the database management system.
[0020] S112. Through the network packet sniffing data extraction algorithm, extract the SQL statements and the relevant context information of the SQL statements in the network packets.
[0021] S113. Through the operating system audit log parsing algorithm, filter out the events related to database operations in the audit logs and extract the SQL-related information in the events.
[0022] S114. Through the information collection algorithm for calling the application and database interaction interface, collect the information during the interaction between the application and the database.
[0023] Optionally, in S13, through the data cleaning and verification algorithm, clean and verify the obtained SQL operation data to obtain an SQL data set, including:
[0024] S131. Define a filtering rule set, filter the obtained SQL operation data according to the filtering rule set to obtain the filtered data.
[0025] S132. Construct a table structure relationship diagram and a data type hierarchy based on the metadata in the database, verify the filtered data, and obtain an SQL data set.
[0026] Optionally, in S2, according to the pre-trained model BERT and the semantic matching method, extract the SQL statement structure features from the data set, including:
[0027] S21. Use the pre-trained model BERT to obtain the word hidden layer representation in the data set, and identify the dependency relationships between keywords, table names, field names, and operators based on the dependency parser of the multi-head attention mechanism.
[0028] S22. Assign weights to the edges and nodes of the tree according to the dependency relationships to construct a weighted structure tree.
[0029] S23. Through the adaptive time window frequency statistical algorithm, automatically adjust the time window size and division method according to the fluctuation of the SQL operation frequency.
[0030] S24. Through the data access mode feature extraction algorithm, add semantic labels to the path nodes and edges in combination with the semantic matching results output by BERT to construct a data access path diagram.
[0031] S25. Construct a feature evaluation formula , which is used to measure the feature performance of the SQL statement in key dimensions.
[0032] Optionally, in S23, through the adaptive time window frequency statistical algorithm, automatically adjust the time window size and division method according to the fluctuation of the SQL operation frequency, including:
[0033] When the SQL operation frequency is in the stable stage, use a large time window and a statistical calculation function based on the large time window to generate a feature vector representing the frequency change pattern.
[0034] When the SQL operation frequency is in the non-stable stage, use a small time window and a statistical calculation function based on the small time window to generate a feature vector representing the frequency change pattern.
[0035] Among them, the adaptive time window frequency statistical algorithm is shown in the following formula (1):
[0036] (1)
[0037] In the formula, represents the feature vector used to represent the frequency change pattern, represents the statistical calculation function based on the large time window, represents the large time window, Indicates at the moment The SQL operation frequency, Indicates the frequency change amount, Indicates the preset frequency mutation determination threshold, Indicates the statistical calculation function based on a small time window, Indicates the small time window, Indicates the time window size.
[0038] Optionally, the feature evaluation formula in S25 , as shown in the following formula (2):
[0039] (2)
[0040] In the formula, Indicates the weight coefficient of the comprehensive measurement value of the structural feature, Indicates the comprehensive measurement value of the structural feature, Indicates the weight coefficient of the summary index of the operation frequency feature, Indicates the summary index of the operation frequency feature, Indicates the comprehensive weight coefficient of the key features covering the data access pattern, Indicates the comprehensive key features covering the data access pattern.
[0041] On the other hand, a database anti-ransomware device based on user SQL feature behavior analysis is provided. This device is applied to the database anti-ransomware method based on user SQL feature behavior analysis. The device includes:
[0042] A data acquisition module, used to construct an SQL data set by using a multi-source data aggregation algorithm, a real-time and historical combination algorithm, and a data cleaning and verification algorithm.
[0043] An extraction module, used to extract SQL statement structure features from the SQL data set according to the pre-trained model BERT and the semantic matching method.
[0044] A training module, used to train a user SQL behavior model based on Transformer according to the SQL statement structure features to obtain a trained user SQL behavior model based on Transformer.
[0045] An output module, used to capture the SQL operation data executed by the user on the database in real time through a monitoring engine, extract the features of the SQL operation data, and input the features of the SQL operation data into the trained user SQL behavior model based on Transformer to obtain the database anti-ransomware evaluation result.
[0046] Optionally, the data acquisition module is further used for:
[0047] S11. Use the multi-source data aggregation algorithm to obtain the SQL operation data of the user on the database.
[0048] S12. Through the real-time data capture algorithm, capture the newly generated SQL operation data in real time; through the historical data backtracking algorithm, obtain the SQL operation data within the preset historical time period.
[0049] S13. Through the data cleaning and verification algorithm, clean and verify the obtained SQL operation data to obtain the SQL data set.
[0050] Optionally, the data collection module is further used for:
[0051] S111. Collect the SQL statement execution records from the log files of the database management system.
[0052] S112. Through the network packet sniffing data extraction algorithm, extract the SQL statements and the relevant context information of the SQL statements in the network packets.
[0053] S113. Through the operating system audit log parsing algorithm, filter out the events related to database operations in the audit logs and extract the SQL-related information in the events.
[0054] S114. Through the information collection algorithm for calling the interaction interface between the application program and the database, collect the information during the interaction between the application program and the database.
[0055] Optionally, the data collection module is further used for:
[0056] S131. Define a filter rule set, filter the obtained SQL operation data according to the filter rule set to obtain the filtered data.
[0057] S132. Based on the metadata in the database, construct a table structure relationship diagram and a data type hierarchy, and verify the filtered data to obtain the SQL data set.
[0058] Optionally, the extraction module is further used for:
[0059] S21. Use the pre-trained model BERT to obtain the word hidden layer representation in the data set, and identify the dependency relationships between keywords, table names, field names, and operators based on the dependency parser of the multi-head attention mechanism.
[0060] S22. Assign weights to the edges and nodes of the tree according to the dependency relationships to construct a weighted structure tree.
[0061] S23. Through the adaptive time window frequency statistics algorithm, automatically adjust the time window size and division method according to the fluctuation of the SQL operation frequency.
[0062] S24. Add semantic labels to path nodes and edges through the data access pattern feature extraction algorithm, combined with the semantic matching results output by BERT, and construct a data access path graph.
[0063] S25. Construct a feature evaluation formula for measuring the feature performance of SQL statements in key dimensions.
[0064] Optionally, the extraction module is further used for:
[0065] When the SQL operation frequency is in the stable stage, use a large time window and a statistical calculation function based on the large time window to generate a feature vector representing the frequency change pattern.
[0066] When the SQL operation frequency is in the non-stable stage, use a small time window and a statistical calculation function based on the small time window to generate a feature vector representing the frequency change pattern.
[0067] Among them, the adaptive time window frequency statistical algorithm is shown in the following formula (1):
[0068] (1)
[0069] In the formula, represents the feature vector used to represent the frequency change pattern, represents the statistical calculation function based on the large time window, represents the large time window, represents at time the SQL operation frequency, represents the frequency change amount, represents the preset frequency mutation determination threshold, represents the statistical calculation function based on the small time window, represents the small time window, represents the time window size.
[0070] Optionally, the feature evaluation formula is shown in the following formula (2):
[0071] (2)
[0072] In the formula, represents the weight coefficient of the comprehensive measurement value of the structural feature, represents the comprehensive measurement value of the structural feature, represents the weight coefficient of the summary index of the operation frequency feature, represents the summary index of the operation frequency feature, represents the comprehensive weight coefficient of the key features covering the data access pattern, Represents the comprehensive key features covering data access patterns.
[0073] On the other hand, a database anti-ransomware device is provided, which includes: a processor; a memory, on which computer-readable instructions are stored, and when the computer-readable instructions are executed by the processor, any one of the database anti-ransomware methods based on user SQL feature behavior analysis as described above is implemented.
[0074] On the other hand, a computer-readable storage medium is provided, in which at least one instruction is stored, and the at least one instruction is loaded and executed by a processor to implement any one of the database anti-ransomware methods based on user SQL feature behavior analysis as described above.
[0075] The beneficial effects brought by the technical solutions provided in the embodiments of the present invention at least include:
[0076] In the embodiments of the present invention, aiming at the limitations of the prior art in data source integration, often due to the incompatibility of data source formats and protocols, some SQL data is lost or the acquisition is delayed, and the user behavior cannot be fully reflected. The multi-source data aggregation algorithm of the present invention has strong compatibility and high efficiency, can seamlessly dock various database architectures and application interfaces, and ensure the integrity of SQL statements and their context information. Accurately capture all user database interaction details, lay a solid data foundation for subsequent accurate analysis, and avoid security monitoring blind spots caused by data loss.
[0077] Aiming at the fact that the prior art relies more on simple syntax parsing or predefined rules in SQL feature extraction, it is difficult to capture complex semantic and logical relationships, resulting in incomplete and inaccurate feature expressions. The present invention combines the BERT model to deeply understand the SQL semantics, accurately extracts key features such as statement structure, operation frequency, and data access patterns, such as parsing the features of complex nested queries and multi-table association operations, comprehensively depicts the essence of SQL behavior, provides high-discrimination feature vectors for model training, significantly improves the recognition accuracy of ransomware behavior, and reduces the risk of misjudging business operations.
[0078] Aiming at the fact that when the existing model training methods have limited or unbalanced data, the model is prone to overfitting or underfitting, and the generalization ability is weak, making it difficult to cope with diverse SQL attack scenarios. The present invention uses unsupervised and semi-supervised learning to expand the utilization mode of training data, enhances the model's learning ability of SQL behavior patterns, such as mining potential behavior rules from unlabeled data, and improves the adaptability of the model in different business scenarios and attack types. BRIEF DESCRIPTION OF THE DRAWINGS
[0079] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0080] Figure 1 is a flowchart of a database anti-ransomware method based on user SQL feature behavior analysis provided by an embodiment of the present invention;
[0081] Figure 2 is a schematic process diagram of a database anti-ransomware method based on user SQL feature behavior analysis provided by an embodiment of the present invention;
[0082] Figure 3 is a block diagram of a database anti-ransomware device based on user SQL feature behavior analysis provided by an embodiment of the present invention;
[0083] Figure 4 is a schematic structural diagram of a database anti-ransomware device provided by an embodiment of the present invention. Specific Embodiments
[0084] The following will describe the technical solutions in the present invention with reference to the accompanying drawings.
[0085] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as an "example" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Rather, the use of the word "example" is intended to present concepts in a specific manner. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two.
[0086] In the embodiments of the present invention, "image" and "picture" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meanings they express are the same. "(of)", "corresponding", and "corresponding" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meanings they express are the same.
[0087] In the embodiments of the present invention, sometimes subscripts such as W 1 may be written in a non-subscript form such as W1. When the difference is not emphasized, the meanings they express are the same.
[0088] To make the technical problems, technical solutions and advantages to be solved by the present invention clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.
[0089] An embodiment of the present invention provides a database anti-ransomware method based on user SQL feature behavior analysis. This method can be implemented by a database anti-ransomware device, which can be a terminal or a server. As Figure 1 、 Figure 2 shown in the flowchart of the database anti-ransomware method based on user SQL feature behavior analysis, the processing flow of this method can include the following steps:
[0090] S1. Use the multi-source data aggregation algorithm, the real-time and historical combination algorithm, and the data cleaning and verification algorithm to construct an SQL data set.
[0091] In a feasible implementation, the data collection module continuously collects SQL statements executed by users on the database and their related context information by using the multi-source data aggregation algorithm, the real-time and historical combination algorithm, and the data cleaning and verification algorithm.
[0092] Optionally, the above step S1 may include the following steps S11 - S13:
[0093] S11. Use the multi-source data aggregation algorithm to obtain SQL operation data of users on the database.
[0094] In a feasible implementation, the multi-source data aggregation algorithm not only collects SQL statement execution records from the log files of the database management system, but also deeply integrates the network packet sniffing data of the database server, the audit logs of the operating system, and the interface call information of the interaction between the application program and the database, ensuring comprehensive coverage of the operation tracks of users on the database, avoiding data omission, and constructing an all-round SQL operation data source.
[0095] Optionally, the above step S11 may include the following steps S111 - S114:
[0096] S111. Collect SQL statement execution records from the log files of the database management system.
[0097] S112. Extract SQL statements and related context information of SQL statements from network packets through the network packet sniffing data extraction algorithm.
[0098] In a feasible implementation, in the network data packet sniffing data extraction algorithm, the deep packet inspection (DPI) technology is first used to parse network data packets. For each captured data packet, it is first unpacked according to the TCP / IP protocol stack to obtain the header information and payload content of the data packet. Then, the network traffic related to the database is identified, usually by checking the destination port of the data packet (such as the common database ports 1433 for SQL Server, 3306 for MySQL, etc.) and the protocol type (such as the SQL protocol). Finally, the SQL statements and their related context information, such as source IP, destination IP, timestamp, etc., are extracted from the identified database-related data packets.
[0099] S113. Through the operating system audit log parsing algorithm, filter out the events related to database operations in the audit log and extract the SQL-related information in the events.
[0100] In a feasible implementation, in the operating system audit log parsing algorithm, for different operating systems (such as Windows event logs, Linux syslogs, etc.), corresponding log parsing tools or libraries are adopted. Traverse the records in the audit log and filter out the events related to database operations according to the predefined event IDs or log message formats. For example, in Windows, specific event IDs may correspond to the access of database files, the calls of processes to database services, etc. Extract the SQL-related information from the filtered events, such as the operation process ID, username, operation time, etc.
[0101] S114. Through the information collection algorithm for the application program and database interaction interface calls, collect the information during the interaction between the application program and the database.
[0102] In a feasible implementation, in the information collection algorithm for the application program and database interaction interface calls: Special monitoring code segments are embedded in the application program code, and these code segments are triggered at key interaction points such as when the application program establishes a connection with the database, executes SQL statements, and obtains query results. The monitoring code collects the detailed information during the interaction, including the names of the database API functions called, the input parameters (such as the SQL statement text, bound variable values, etc.), the return values, and the execution status.
[0103] S12. Through the real-time data capture algorithm, capture the newly generated SQL operation data in real time; through the historical data backtracking algorithm, obtain the SQL operation data within a preset historical time period.
[0104] In a feasible implementation, the real-time and historical combined algorithm can not only capture newly generated SQL operation data in real time, but also has the ability to periodically retrieve historical data. For example, it can batch collect and organize database operations over a past period on a weekly or monthly basis, so as to capture long-term operation trends and periodic behavior patterns, providing rich time-series data for subsequent analysis.
[0105] Specifically, for the real-time data capture algorithm: Use the real-time monitoring interface or trigger mechanism provided by the database. For example, set a trigger for SQL statement execution in the database management system. When a new SQL statement is executed, immediately capture its detailed information, including the SQL text, executing user, execution time, etc., and store this information in the real-time data buffer (R).
[0106] For the historical data retrieval algorithm: According to the set time period (such as weekly or monthly), retrieve SQL operation records over a past period from the system tables or log tables of the database through database query statements. For example, for a MySQL database, you can query the mysql.general_log table (if the general log is enabled) to obtain historical SQL statement execution records.
[0107] S13. Through the data cleaning and verification algorithm, clean and verify the obtained SQL operation data to obtain an SQL data set.
[0108] In a feasible implementation, the data cleaning and verification algorithm refers to using a strict data cleaning algorithm during the collection process to filter out invalid, duplicate, or abnormal SQL statement records caused by system failures. At the same time, through the built-in data verification mechanism, compare with the database metadata information to ensure the integrity and accuracy of the collected data. For example, check whether the collected table field information is consistent with the actual database structure to ensure that the data quality meets the requirements of subsequent analysis.
[0109] Optionally, the above step S13 may include the following steps S131 - S132:
[0110] S131. Define a set of filtering rules, and filter the obtained SQL operation data according to the set of filtering rules to obtain the filtered data.
[0111] In a feasible implementation, the data cleaning algorithm first uses a rule-based filtering algorithm and defines a comprehensive and detailed set of filtering rules covering aspects such as SQL syntax specifications, common invalid operation patterns, and business logic constraints. For example, in addition to deleting SQL statements with a length of 0 and removing statements containing specific illegal characters, SQL statements containing undefined function calls, or table names or field names that do not conform to the naming specifications (such as starting with a space or special symbol) are also excluded. In addition, outliers need to be processed. Identify and process outliers in SQL operation data based on statistical analysis. For example, calculate the mean and standard deviation of the execution time of SQL statements. For records whose execution time exceeds the mean plus several times the standard deviation (such as 3 times the standard deviation), mark them as outliers and further analyze the reasons, which may be long-term blocking operations caused by system failures or potential malicious attacks (such as slow DoS attack forms).
[0112] S132. Construct a table structure relationship diagram and a data type hierarchy based on the metadata in the database, and verify the filtered data to obtain an SQL data set.
[0113] In a feasible implementation, the data verification algorithm constructs a detailed table structure relationship diagram and a data type hierarchy from the database metadata, not only checking whether the table names and field names in the SQL records exist in the metadata and whether the data types of the operations match, but also verifying whether the foreign key constraints and index usage conform to the database schema integrity rules defined by the metadata.
[0114] S2. Extract the SQL statement structure features from the SQL data set according to the pre-trained model BERT and the semantic matching method.
[0115] In a feasible implementation, the BERT-based feature extraction unit: combines the pre-trained model BERT and the semantic matching method to extract key features from the collected data set, such as SQL statement structure features, operation frequency features, data access pattern features, etc., to form a high-dimensional feature vector.
[0116] Optionally, the above step S2 may include the following steps S21 - S24:
[0117] S21. Use the pre-trained model BERT to obtain the word hidden layer representation in the data set, and identify the dependency relationships between keywords, table names, field names, and operators based on the dependency parser of the multi-head attention mechanism.
[0118] In a feasible implementation, after the SQL statement structure feature extraction algorithm obtains the word hidden layer representation using BERT, it uses a dependency parser based on the multi-head attention mechanism. The multi-head attention allows the model to simultaneously focus on information in different subspaces, capturing more comprehensively the complex semantic associations in the SQL statement, thereby accurately identifying the dependency relationships between keywords, table names, field names, and operators. For example, when processing an SQL statement containing multiple nested functions and complex conditional expressions, the multi-head attention can focus on the associations between different function parameters and conditional clauses, improving the accuracy of dependency relationship parsing. The self-attention mechanism involves three concepts: Query, Key, and Value, and its calculation process involves three intermediate weight matrices:
[0119] (1)
[0120] The self-attention mechanism module calculates and similarity, quantifies their correlation through a dot product operation, and weights accordingly, thereby generating the value of the target vector, that is:
[0121] (2)
[0122] S22. Assign weights to the edges and nodes of the tree according to the dependency relationship to construct a weighted structure tree.
[0123] In a feasible implementation, a weighted structure tree is constructed, and weights are assigned to the edges and nodes of the tree according to the importance or semantic relevance of the dependency relationship. The weight calculation can be based on the semantic similarity or attention score output by BERT, enabling the structure tree to better reflect the key structure information of the statement. Higher weights are assigned to key structure elements (such as the connection points between the main query and subqueries, and the associations of core filtering conditions), highlighting the important structure parts when quantifying structural features (such as tree depth, total node weight, etc.), enhancing the ability to distinguish complex nested and key structure statements, and providing more discriminative structural feature dimensions for the high-dimensional feature vector. In the scenario of in-depth analysis and feature extraction of SQL statements, a comprehensive feature evaluation formula is constructed to comprehensively and accurately measure the feature performance of SQL statements in key dimensions such as structure, operation frequency, and data access pattern:
[0124] (3)
[0125] In the formula, Represents the comprehensive measurement value of structural features, which is precisely quantified by constructing a weighted structure tree through dependency syntactic analysis. The edge weights are carefully set based on the semantic similarity and attention scores output by BERT, and a hierarchical weight adjustment strategy is incorporated to highlight the importance of key structural elements (such as the connection points between the main query and sub-queries, and the association of core filtering conditions), thereby comprehensively reflecting the structural complexity of the statement and the prominence of key parts. Represents the summary index of operation frequency features, which comprehensively presents operation frequency features through a combination of adaptive time window frequency statistics and cross-user and business module frequency correlation mining. Covers the comprehensive key features of data access patterns, including semantic-enhanced access path analysis, dynamic access range assessment, and information entropy-based access granularity measurement, etc., comprehensively and deeply analyzing the complexity and security of data access patterns.
[0126] With the help of BERT's semantic understanding ability, semantic role annotation is performed on SQL clauses to clarify the functions of each clause in the overall statement semantics (such as data filtering, data source specification, result aggregation, etc.), rather than simply relying on syntactic rules to identify clause types. For example, identifying custom function call clauses with special semantics in specific business scenarios and their roles in the data processing flow.
[0127] S23. Through the adaptive time window frequency statistical algorithm, automatically adjust the time window size and division method according to the fluctuation of SQL operation frequency.
[0128] In a feasible implementation, the adaptive time window frequency statistical algorithm introduces the DTW (Dynamic Time Warping) algorithm to automatically adjust the time window size and division method according to the fluctuation of SQL operation frequency. In the stable stage of operation frequency, a larger time window is used to obtain the long-term trend; when a frequency mutation is detected, the window is automatically narrowed to focus on the short-term change details, accurately capturing the turning points of frequency changes and abnormal fluctuation intervals. For example, in response to intermittent but high-intensity database scan attacks, DTW can promptly narrow the window to capture the high-frequency operations during the attack period, accurately reflecting the dynamic changes of frequency. The adjusted window statistical results (the number of operations under different windows, the key node values of the frequency change curve) enrich the feature vector and enhance the representation ability for complex frequency change patterns.
[0129] Let Represent the SQL operation frequency at time , Represent the frequency change amount (which can be measured by the difference in operation frequency within adjacent time intervals, etc.), Be the preset frequency mutation determination threshold, Represent the time window size, is a feature vector used to characterize the frequency change pattern, represents a statistical calculation function based on a large time window, represents a statistical calculation function based on a small time window. Then we have:
[0130] (4)
[0131] In the formula, is a feature vector used to characterize the frequency change pattern, represents a statistical calculation function based on a large time window, represents the large time window, represents at time the SQL operation frequency, represents the frequency change amount, represents a preset frequency mutation determination threshold, represents a statistical calculation function based on a small time window, represents the small time window, represents the time window size.
[0132] First, based on the comparison between the frequency change amount of the SQL operation frequency and the preset threshold, it is decided whether to use a large time window (when the operation frequency is relatively stable) or a small time window (when the frequency mutates). Then, based on the corresponding time window size, a feature vector characterizing the frequency change pattern is generated through the corresponding statistical calculation function. Through such an adaptive adjustment mechanism, the change characteristics of the SQL operation frequency in different situations can be better captured, and the overall analysis and characterization ability of complex frequency change patterns can be improved.
[0133] S24. Through the data access pattern feature extraction algorithm, combine the semantic matching results output by BERT to add semantic labels to the path nodes and edges, and construct a data access path graph.
[0134] In a feasible implementation, when the data access pattern feature extraction algorithm constructs a data access path graph, it adds semantic tags to path nodes and edges in combination with the BERT semantic matching results. For example, the semantic weight of an edge is marked according to the degree of association between the table name and the field name in the business semantics (such as the core business semantics in which the customer table and the order table are associated through "customer ID"), reflecting the semantic importance and business relevance of the data access path. Based on the semantic tags, the semantic richness of the path (such as indicators like tag diversity and semantic association tightness) and the coverage of critical semantic paths are calculated and incorporated into the high-dimensional feature vector to better distinguish normal business data access paths from malicious data exploration or tampering paths. For example, the significant differences in semantic features between the data access paths of ransomware that are random or have no clear semantic purpose and normal paths. For the data access granularity, the information entropy is introduced to measure the uncertainty and diversity of field access. The information entropy of different field combinations being accessed is calculated. A high information entropy indicates a large uncertainty in the access granularity (possibly a malicious full-table scan or random field access), and a low information entropy corresponds to a clear and regular field access pattern (normal business query). The information entropy value is used as a granularity feature dimension to enhance the quantitative evaluation of abnormal data access granularity, effectively identify the abnormal access range and granularity features during the data reconnaissance and stealing stage before ransomware encryption, and improve the accuracy and timeliness of database anti-ransomware monitoring.
[0135] S3. Train a Transformer-based user SQL behavior model according to the SQL statement structure features to obtain a trained Transformer-based user SQL behavior model.
[0136] In a feasible implementation, the Transformer-based modeling module: uses the extracted feature vectors to train the user SQL behavior model, and this model continuously self-optimizes and adjusts to adapt to the dynamic changes of normal business operations and accurately define the boundary of normal behavior.
[0137] The carefully extracted feature vectors are input into the training process of the user SQL behavior model. The Transformer architecture, with its powerful parallel computing ability and excellent processing ability for long sequence data, can fully learn and capture the complex patterns and dynamic change rules of user SQL behavior. During the training process, the model continuously self-optimizes and adjusts based on the continuously input new feature vectors. It uses the adaptive learning mechanism of the deep neural network to continuously correct the parameter weights inside the model to closely fit the dynamic evolution trend of normal business operations, so as to be able to accurately define the boundary range of normal behavior.
[0138] S4. The monitoring engine captures in real time the SQL operation data executed by the user on the database, extracts the features of the SQL operation data, and inputs the features of the SQL operation data into the trained user SQL behavior model based on Transformer to obtain the database anti-ransomware evaluation result.
[0139] The present invention mainly relates to the technical field of database security, and particularly focuses on the research and application of protection strategies and related technical means for protecting databases from ransomware attacks through in-depth analysis and modeling of user SQL operation behaviors, aiming to provide a strong security guarantee solution for various enterprise-level information systems that rely on databases to store and manage key data.
[0140] The present invention designs a general and efficient adaptation framework to handle the differences in data formats, protocols, and access permissions of different data sources; aiming at the SQL characteristics, it optimizes the BERT architecture and parameters to reduce semantic understanding deviations and improve the feature extraction accuracy of SQL professional elements, such as analyzing the semantic features of nested queries; it prevents the model from being over-adjusted due to abnormal data or business fluctuations, maintains stability, and can quickly adapt when new attacks come, achieving the balance between stability and change.
[0141] According to the technical solution carefully designed by the present invention, in the crucial real-time monitoring stage, the monitoring engine always remains highly active and captures newly generated SQL operations in real time. Once a new SQL statement appears, the monitoring engine immediately uses an efficient algorithm to quickly extract its features and promptly inputs these features into the already trained behavior model for comprehensive evaluation. The model makes an accurate judgment on the new SQL operation based on the pre-learned normal behavior patterns and boundary conditions, promptly discovers any abnormal operations that deviate from the normal behavior patterns, thereby effectively preventing ransomware from launching attacks on the database through abnormal SQL operations, comprehensively ensuring the safe and stable operation of the database, and protecting the data assets of enterprises and organizations.
[0142] In the embodiments of the present invention, aiming at the limitations in data source integration in the prior art, often due to the incompatibility of data source formats and protocols, some SQL data is lost or the collection is delayed, which cannot fully reflect user behaviors. The multi-source data aggregation algorithm of the present invention has strong compatibility and high efficiency, can seamlessly connect to various database architectures and application interfaces, and ensure the integrity of SQL statements and their context information. It accurately captures all the details of user-database interactions, laying a solid data foundation for subsequent accurate analysis, and avoiding security monitoring blind spots caused by data loss.
[0143] In view of the fact that existing technologies rely mostly on simple syntax parsing or predefined rules for SQL feature extraction, making it difficult to capture complex semantic and logical relationships, resulting in incomplete and inaccurate feature expressions. The present invention combines the BERT model to deeply understand SQL semantics, accurately extracts key features such as statement structure, operation frequency, and data access patterns. For example, it can parse complex nested query and multi-table association operation features, comprehensively depict the essence of SQL behavior, provide high-discrimination feature vectors for model training, significantly improve the accuracy of ransomware behavior recognition, and reduce the risk of misjudging business operations.
[0144] In view of the fact that when using existing model training methods, in the case of limited or unbalanced data, the model is prone to overfitting or underfitting, with weak generalization ability and difficulty in coping with diverse SQL attack scenarios. The present invention uses unsupervised and semi-supervised learning to expand the utilization mode of training data, enhance the model's learning ability of SQL behavior patterns, such as mining potential behavior rules from unlabeled data, and improving the adaptability of the model under different business scenarios and attack types.
[0145] Figure 3 It is a block diagram of a database anti-ransomware device based on user SQL feature behavior analysis shown according to an exemplary embodiment. This device is used for the database anti-ransomware method based on user SQL feature behavior analysis. Refer to Figure 3 and this device includes a data collection module 310, an extraction module 320, a training module 330, and an output module 340. Among them:
[0146] The data collection module 310 is used to construct an SQL data set by using multi-source data aggregation algorithms, real-time and historical combination algorithms, and data cleaning and verification algorithms.
[0147] The extraction module 320 is used to extract SQL statement structure features from the SQL data set according to the pre-trained model BERT and semantic matching methods.
[0148] The training module 330 is used to train a user SQL behavior model based on Transformer according to the SQL statement structure features, and obtain a trained user SQL behavior model based on Transformer.
[0149] The output module 340 is used to capture in real time the SQL operation data executed by the user on the database through a monitoring engine, extract the features of the SQL operation data, input the features of the SQL operation data into the trained user SQL behavior model based on Transformer, and obtain the database anti-ransomware evaluation result.
[0150] In the embodiments of the present invention, aiming at the limitations of the prior art in data source integration, often due to the incompatibility of data source formats and protocols, some SQL data is lost or the collection is delayed, and the user behavior cannot be comprehensively reflected. The multi-source data aggregation algorithm of the present invention has strong compatibility and high efficiency, can seamlessly dock with various database architectures and application interfaces, and ensure the integrity of SQL statements and their context information. Accurately capture all details of user database interactions, lay a solid data foundation for subsequent accurate analysis, and avoid security monitoring blind spots caused by data loss.
[0151] Regarding the prior art, the extraction of SQL features mostly relies on simple syntax parsing or predefined rules, and it is difficult to capture complex semantic and logical relationships, resulting in incomplete and inaccurate feature expressions. The present invention combines the BERT model to deeply understand SQL semantics, accurately extracts key features such as statement structure, operation frequency, and data access patterns, such as parsing the features of complex nested queries and multi-table association operations, comprehensively depicts the essence of SQL behavior, provides high-discrimination feature vectors for model training, significantly improves the accuracy of ransomware behavior recognition, and reduces the risk of misjudging business operations.
[0152] Regarding the existing model training methods, when the data is limited or unbalanced, the model is prone to overfitting or underfitting, and the generalization ability is weak, making it difficult to cope with diverse SQL attack scenarios. The present invention uses unsupervised and semi-supervised learning to expand the utilization mode of training data, enhance the model's learning ability of SQL behavior patterns, such as mining potential behavior rules from unlabeled data, and improving the adaptability of the model in different business scenarios and attack types.
[0153] Figure 4 It is a schematic structural diagram of a database anti-ransomware device provided by an embodiment of the present invention, as Figure 4 shown. The database anti-ransomware device may include the above-mentioned Figure 3 database anti-ransomware device based on user SQL feature behavior analysis shown. Optionally, the database anti-ransomware device 410 may include a first processor 2001.
[0154] Optionally, the database anti-ransomware device 410 may further include a memory 2002 and a transceiver 2003.
[0155] Among them, the first processor 2001, the memory 2002, and the transceiver 2003, such as, may be connected through a communication bus.
[0156] Next, in combination with Figure 4 Specific introductions will be made to the various components of the database anti-ransomware device 410:
[0157] Among them, the first processor 2001 is the control center of the database anti-ransomware device 410, which can be a single processor or a collective term for multiple processing elements. For example, the first processor 2001 is one or more central processing units (CPUs), or can be an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention, such as: one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).
[0158] Optionally, the first processor 2001 can execute various functions of the database anti-ransomware device 410 by running or executing software programs stored in the memory 2002 and calling data stored in the memory 2002.
[0159] In a specific implementation, as an embodiment, the first processor 2001 can include one or more CPUs, such as Figure 4 the CPU0 and CPU1 shown in
[0160] In a specific implementation, as an embodiment, the database anti-ransomware device 410 can also include multiple processors, such as Figure 4 the first processor 2001 and the second processor 2004 shown in
[0161] Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). Here, the processor can refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).
[0162] Optionally, the memory 2002 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 2002 can be integrated with the first processor 2001 or can exist independently and be coupled to the first processor 2001 through the interface circuit of the database anti-ransomware device 410 ( Figure 4 not shown in the figure), and the embodiments of the present invention do not make specific limitations in this regard.
[0163] The transceiver 2003 is used to communicate with a network device or with a terminal device.
[0164] Optionally, the transceiver 2003 can include a receiver and a transmitter ( Figure 4 not shown separately in the figure). Among them, the receiver is used to implement the receiving function, and the transmitter is used to implement the sending function.
[0165] Optionally, the transceiver 2003 can be integrated with the first processor 2001 or can exist independently and be coupled to the first processor 2001 through the interface circuit of the database anti-ransomware device 410 ( Figure 4 not shown in the figure), and the embodiments of the present invention do not make specific limitations in this regard.
[0166] It should be noted that Figure 4 the structure of the database anti-ransomware device 410 shown in the figure does not constitute a limitation on the router. The actual knowledge structure recognition device can include more or fewer components than shown in the figure, or combine some components, or have different component arrangements.
[0167] In addition, the technical effects of the database anti-ransomware device 410 can refer to the technical effects of the database anti-ransomware method based on user SQL feature behavior analysis described in the above method embodiments, and will not be elaborated here.
[0168] It should be understood that the first processor 2001 in the embodiments of the present invention may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0169] It should also be understood that the memory in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0170] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center by wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.
[0171] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood by referring to the context before and after.
[0172] In the present invention, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.
[0173] It should be understood that in various embodiments of the present invention, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0174] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.
[0175] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the devices, apparatuses, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0176] In several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of the devices or units can be in electrical, mechanical, or other forms.
[0177] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0178] In addition, the functional units in each embodiment of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0179] When the above-mentioned function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0180] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A database anti-ransomware method based on user SQL feature behavior analysis, characterized in that: The method comprises: S1. Use multi-source data aggregation algorithm, real-time and historical combination algorithm, and data cleaning and verification algorithm to build SQL data set; S2. Extracting SQL statement structure features from the SQL data set according to the pre-trained model BERT and the semantic matching method; S3, training a Transformer-based user SQL behavior model according to the SQL statement structure features to obtain a trained Transformer-based user SQL behavior model; S4. Capture the SQL operation data executed by the user on the database in real time through the monitoring engine, extract the features of the SQL operation data, input the features of the SQL operation data into the trained Transformer-based user SQL behavior model, and obtain the database anti-ransomware assessment result.
2. The database anti-ransomware method based on user SQL characteristic behavior analysis according to claim 1 is characterized in that: The S1 uses a multi-source data aggregation algorithm, a real-time and historical combination algorithm, and a data cleaning and verification algorithm to construct an SQL data set, including: S11. Using a multi-source data aggregation algorithm, obtain the user's SQL operation data on the database; S12. Capture newly generated SQL operation data in real time through a real-time data capture algorithm; obtain SQL operation data within a preset historical time period through a historical data backtracking algorithm; S13. Clean and verify the acquired SQL operation data through a data cleaning and verification algorithm to obtain a SQL data set.
3. The database anti-ransomware method based on user SQL characteristic behavior analysis according to claim 2 is characterized in that: The step of using a multi-source data aggregation algorithm to obtain the user's SQL operation data on the database in S11 includes: S111, collecting SQL statement execution records from the log files of the database management system; S112, extracting SQL statements and related context information of the SQL statements in the network data packets through a network data packet sniffing data extraction algorithm; S113, using the operating system audit log parsing algorithm, screening out events related to database operations in the audit log, and extracting SQL related information in the events; S114: Collect information during the interaction between the application and the database by calling an information collection algorithm at the application and database interaction interface.
4. The database anti-ransomware method based on user SQL characteristic behavior analysis according to claim 2 is characterized in that: The step S13 cleans and verifies the acquired SQL operation data through a data cleaning and verification algorithm to obtain a SQL data set, including: S131, defining a filtering rule set, filtering the acquired SQL operation data according to the filtering rule set to obtain filtered data; S132: construct a table structure relationship diagram and a data type hierarchy based on the metadata in the database, verify the filtered data, and obtain an SQL data set.
5. The database anti-ransomware method based on user SQL characteristic behavior analysis according to claim 1 is characterized in that: The step S2 extracts SQL statement structure features from the data set according to the pre-trained BERT model and the semantic matching method, including: S21, using the pre-trained model BERT to obtain the hidden layer representation of the words in the data set, and identifying the dependency relationship between keywords, table names, field names and operators based on the dependency syntax analyzer of the multi-head attention mechanism; S22, assigning weights to the edges and nodes of the tree according to the dependency relationship, and constructing a weighted structure tree; S23. Automatically adjust the time window size and division method according to the fluctuation of SQL operation frequency through an adaptive time window frequency statistics algorithm; S24. Using the data access pattern feature extraction algorithm and the semantic matching results output by BERT, semantic labels are added to the path nodes and edges to construct a data access path graph. S25. Constructing feature evaluation formula , used to measure the characteristic performance of SQL statements in key dimensions.
6. The database anti-ransomware method based on user SQL characteristic behavior analysis according to claim 5 is characterized in that: The step S23 uses an adaptive time window frequency statistics algorithm to automatically adjust the time window size and division method according to the fluctuation of the SQL operation frequency, including: When the SQL operation frequency is in a stable stage, a large time window and a statistical calculation function based on the large time window are used to generate a feature vector that represents the frequency change pattern; When the SQL operation frequency is in an unstable stage, a small time window and a statistical calculation function based on the small time window are used to generate a feature vector that represents the frequency change pattern; Among them, the adaptive time window frequency statistics algorithm is shown in the following formula (1): (1) In the formula, represents the eigenvector used to characterize the frequency variation pattern, Represents a statistical calculation function based on a large time window, Represents a large time window, Indicates at time The frequency of SQL operations, represents the frequency change, Indicates the preset frequency mutation determination threshold, Represents a statistical calculation function based on a small time window, represents a small time window, Indicates the time window size.
7. The database anti-ransomware method based on user SQL characteristic behavior analysis according to claim 5 is characterized in that: The feature evaluation formula in S25 , as shown in the following formula (2): (2) In the formula, represents the weight coefficient of the comprehensive measurement value of structural characteristics, represents the comprehensive measure of structural features, represents the weight coefficient of the summary index of the operation frequency characteristics, represents the summary index of operation frequency characteristics, represents the comprehensive weight coefficient of key features covering data access patterns, Represents a synthesis of key features covering data access patterns.
8. A database anti-ransomware device based on user SQL characteristic behavior analysis, the database anti-ransomware device based on user SQL characteristic behavior analysis is used to implement the database anti-ransomware method based on user SQL characteristic behavior analysis as claimed in any one of claims 1 to 7, characterized in that: The device comprises: Data collection module, used to build SQL data sets using multi-source data aggregation algorithms, real-time and historical combination algorithms, and data cleaning and verification algorithms; An extraction module, used to extract SQL statement structure features from the SQL data set according to a pre-trained model BERT and a semantic matching method; A training module, used for training a Transformer-based user SQL behavior model according to the SQL statement structure characteristics to obtain a trained Transformer-based user SQL behavior model; The output module is used to capture the SQL operation data executed by the user on the database in real time through the monitoring engine, extract the features of the SQL operation data, input the features of the SQL operation data into the trained Transformer-based user SQL behavior model, and obtain the database anti-ransomware evaluation result.
9. A database anti-ransomware device, characterized in that: The database anti-ransomware device includes: processor; A memory having computer-readable instructions stored thereon, wherein when the computer-readable instructions are executed by the processor, the method according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program codes, which can be called by a processor to execute the method according to any one of claims 1 to 7.
Citation Information
Cited By
Data protection system and method based on PostgreSQL database
CN122197093A
A data protection system and method based on PostgreSQL database
CN122197093B