Database anomaly detection method and system based on GMM algorithm and medium
By adopting the database anomaly detection method based on GMM algorithm in the database audit tracking platform, the problems of low efficiency and poor real-time database audit tracking in the existing technology are solved, and efficient and real-time user behavior abnormality detection and data audit tracking are achieved.
Patent Information
- Application Number
- CN202510124325.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-26
- Publication Date
- 2025-06-10
AI Technical Summary
In the prior art, various business data in databases are audited, tracked and detected abnormal operation of user databases is inefficient and has poor real-time performance.
The database exception detection method based on GMM algorithm is used to detect user behavior abnormalities by entering basic information, intercepting and proxying SQL statements, extracting and parsing database logs in real time, building audit and data trajectory information, training user behavior GMM model and calculating log likelihood values.
It realizes non-invasive access, high real-time database audit tracking and user behavior abnormality detection, and can flexibly set data audit tracking levels to improve data security, compliance and credibility.
Smart Images

Figure CN120123169A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of user behavior anomaly detection. In particular, it relates to a database anomaly detection method, system and medium based on the GMM algorithm. Background Art
[0002] The application database audit and trace platform of an enterprise is a platform to support the integrity, security, compliance, etc. of key business data of China Telecom. The platform provides account management, configuration management, data parsing, audit records, as well as application development SDK, database proxy middleware, etc. to support the audit and trace of the business system database, and detects user abnormal database operations based on the GMM algorithm, which is used to protect the enterprise's key data assets and ensure the security, compliance, retrospective analysis and accident liability division of the data.
[0003] With the continuous development of enterprises and IT systems, the scale and complexity of business data have become higher and higher. The audit and trace of various business data and the detection of user database abnormal operations are inefficient and lack real-time performance. How to effectively and real-time audit and trace various business data in the database and detect user database abnormal operations is an urgent problem to be solved by the database audit and trace platform. Summary of the Invention
[0004] The present invention provides a database anomaly detection method, system and medium based on the GMM algorithm to solve the problems of low efficiency and poor real-time performance in auditing and tracing various business data in the database and detecting user database abnormal operations in the prior art.
[0005] To achieve the above object, in a first aspect, the present invention relates to a database anomaly detection method based on the GMM algorithm for a database data audit and trace platform, including:
[0006] Enter basic information, where the basic information includes at least the data corresponding to the following data items: user name, database name, table name, column name, and data record identification field.
[0007] Intercept SQL statements through the application development SDK or database proxy, add audit information to the SQL statements through Hint tags, and proxy-execute the SQL statements;
[0008] Based on the basic information, extract database logs in real time, parse the logs to extract the data corresponding to the following data items on the Hint tags: the audit information, the SQL statements, database tables, field names, the values of the fields before and after the change, and the execution time, to obtain the database, fields, and record field change tracks that need to be audited and traced;
[0009] Construct audit and data trace information based on the database, fields, and record field change tracks required for the audit trace, and store the records;
[0010] Collect user behavior characteristic data, and train a behavior GMM model for each user;
[0011] Calculate the log-likelihood value of the user behavior data point under the GMM model, and determine whether the log-likelihood value is less than a set threshold. If so, the user behavior is abnormal; otherwise, the user behavior is normal.
[0012] To achieve the above object, in a second aspect, the present invention relates to a database anomaly detection system based on the GMM algorithm, which is used for a database data audit trace platform, including: a basic information module for entering basic information, and the basic information at least includes data corresponding to the following data items: user name, database name, table name, column name, and data record identification field.
[0013] A proxy service module for intercepting SQL statements through an application development SDK or a database proxy, adding audit information to the SQL statements through Hint tags, and proxy-executing the SQL statements;
[0014] A log module for extracting database logs in real time based on the basic information, parsing the logs to extract data corresponding to the following data items on the Hint tags: the audit information, the SQL statements, database tables, field names, values before and after field changes, and execution time, to obtain the database, fields, and record field change tracks required for the audit trace;
[0015] An audit storage module for constructing audit and data trace information based on the database, fields, and record field change tracks required for the audit trace, and storing the records;
[0016] A GMM model training module for collecting user behavior characteristic data and training a behavior GMM model for each user;
[0017] An anomaly detection module for calculating the log-likelihood value of the user behavior data point under the GMM model, and determining whether the log-likelihood value is less than a set threshold. If so, the user behavior is abnormal; otherwise, the user behavior is normal.
[0018] To achieve the above object, in a third aspect, the present invention also relates to a computer-readable storage medium storing instructions that, when running, execute the above-mentioned database anomaly detection method based on the GMM algorithm.
[0019] A database anomaly detection method, system, and medium based on the GMM algorithm according to the present invention have the following beneficial effects compared with the prior art:
[0020] Non-invasive access: It supports users to integrate and access through the application development SDK, and multiple methods such as the client connecting to the database proxy to access the data audit tracking of the mysql database, meeting the requirements in different scenarios;
[0021] Real-time performance: It records the data change information in the database in real time, constructs audit records, meeting the requirements of viewing audit tracking information in real time and detecting abnormal database operation behaviors of users in real time;
[0022] Data trace: It records the detailed trace of the creation and transformation process of data during its life cycle, realizes the retrospective analysis of historical data, and can effectively improve the credibility and quality of data;
[0023] Flexibility: It can flexibly set the data audit tracking level from multiple granularities such as databases, tables, and columns, meeting the requirements of users to audit and track data as needed;
[0024] Accuracy of user behavior anomaly detection: Based on the GMM algorithm, a multi-dimensional user behavior feature model is trained for each user role, which can accurately detect the abnormal database operation behaviors of users in each role. Brief Description of the Drawings
[0025] Figure 1 It is a method flow chart of a database anomaly detection method based on the GMM algorithm in Embodiment 1 of the present invention;
[0026] Figure 2 It is a structural schematic diagram of a database anomaly detection system based on the GMM algorithm in Embodiment 2 of the present invention;
[0027] Figure 3 It is a structural schematic diagram of the GMM model training module of a database anomaly detection system based on the GMM algorithm in Embodiment 2 of the present invention. Detailed Embodiment
[0028] The present invention will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present invention, rather than limiting the present invention. Additionally, it should be noted that for the sake of description, only parts related to the present invention are shown in the drawings, rather than all structures.
[0029] Embodiment 1
[0030] A database anomaly detection method based on the GMM algorithm, please refer to Figure 1, for a database data audit and trace platform, in this embodiment, it is an enterprise application database audit and trace platform, which can be implemented by electronic device hardware with a central processing unit. The electronic device can be a personal computer, a smart terminal, a local area network, a server, etc. GMM: Gaussian Mixture Model (GMM) is a probability-based clustering algorithm that can be used for user behavior anomaly detection.
[0031] As Figure 1 shown, the present invention includes the following steps: S101 to S106.
[0032] S101 Enter basic information, and the basic information at least includes the data corresponding to the following data items: user name, database name, table name, column name, and data record identification field.
[0033] In this embodiment, the running environment includes but is not limited to: JVM, Docker; initializing the database data audit and trace platform information includes but is not limited to basic information such as user name, database name, table name, column name, and data record identification field.
[0034] The database audit and trace platform can flexibly select the databases and tables to be audited and traced according to the entered basic information, and select the columns that need to record the data change track.
[0035] S102 Intercept SQL statements through the application development SDK or the database proxy, add audit information to the SQL statements through the Hint label, and proxy the execution of the SQL statements.
[0036] Among them, the audit information added through the Hint label at least includes the data corresponding to the following data items: source IP, service name, user name, and user role. The supported clients include but are not limited to: Navicat and DBveaver. Among them, the database proxy refers to the database proxy middleware that forwards the foreground database request to the background database, and can intercept the database request and analyze the SQL statement in the request; the Hint label refers to the label annotation marked at a specific position of the SQL statement.
[0037] In this embodiment, it specifically includes S121 to S122.
[0038] S121: Intercept and proxy the execution of SQL statements by means of an application development SDK or a database proxy. For intercepting and proxying the execution of SQL statements in the development of application software, the present invention provides an application development SDK, integrates the SDK into the developed application software, and uses the methods provided in the SDK to intercept and proxy the execution of SQL statements; for intercepting and proxying the execution of SQL statements in clients (such as Navicat, DBveaver, etc.), the present invention provides a database proxy middleware, uses the database proxy middleware to proxy the database, the client connects to the database proxy middleware, and intercepts and proxies the execution of SQL statements through the database proxy middleware.
[0039] S122: Add audit information by means of Hint tags. In the SDK, obtain information such as the source IP, service name, user name, and user role from the Http request and the request header; in the database proxy middleware, obtain information such as the source IP, user name, and user role from the TCP connection and the authentication information, and add the information such as the source IP, service name, user name, and user role to the SQL statement by means of Hint tags.
[0040] S103: Based on the basic information, extract the database logs in real time, parse the logs to extract the data corresponding to the following data items on the Hint tag: audit information, SQL statements, database tables, field names, values before and after the field changes, and execution time, to obtain the databases, fields, and record field change tracks required for audit tracking.
[0041] Among them, the information obtained by parsing the database logs at least includes the data corresponding to the following data items: table name, field name, values before and after the field changes, SQL operation type, execution time, and SQL statement.
[0042] In this embodiment, S130 may specifically include S131 to S132.
[0043] S131: Extract the database logs in real time, filter according to the database name, table name, and column name in step S101, parse the audit information (source IP, service name, user name, user role, etc.) extracted from the Hint tag in the logs, and parse the information such as SQL statements, database tables, column names, values before and after the field changes, and execution time in the logs.
[0044] S132: Filter according to the information entered in S101 to obtain the databases, fields, and record field change tracks required for audit tracking.
[0045] S104: Based on the databases, fields, and record field change tracks required for audit tracking, construct audit and data track information and store the records.
[0046] In this embodiment, audit records information and the data change track of fields are constructed and stored by associating the audit information associated with the value of the data record identification field and the data change track of the fields. Among them, the audit information includes, but is not limited to, the data corresponding to the following data items: table name, field name, values of the field before and after the change, execution time, SQL statement, source IP, and user name.
[0047] Specifically, according to the data record identification field in step S101 and the information parsed in steps S131 and S132, the audit records and the data change track of the fields are constructed, and the audit information and the data change track of the fields are associated through the value of the data record identification field.
[0048] The following uses an example to illustrate the data change track:
[0049]
[0050]
[0051] In a specific embodiment of the present invention, the audit records information includes, but is not limited to: table name, field name, values of the field before and after the change, execution time, SQL statement, source IP, service name, user name, user role, etc.
[0052] S105 collects user behavior characteristic data, and trains a behavior GMM model for each user.
[0053] The collection of user behavior characteristic data is specifically: collecting the behavior characteristic data of the user operating the database. The behavior characteristic data of the user operating the database at least includes the data corresponding to the following data items: user name, user role, source IP, database operation type, SQL statement, table name, service name, and operation time.
[0054] In this embodiment, specifically, S105 includes S151 to S155.
[0055] S151: Collect the stored audit records information as the behavior characteristic data of the user operating the database.
[0056] For the collection of the behavior characteristic data of the user operating the database, collect the stored audit records information (i.e., the behavior characteristic data of the user operating the database) from step S4, which mainly includes: user name, user role, source IP, database operation type, SQL statement, table name, service name, operation time, etc.
[0057] S152: Specifically encode the data corresponding to the following data items in the behavioral feature data: username, source IP, database operation type, table name, and service name. De-parameterize the SQL statements in the behavioral feature data, then numericalize the de-parameterized SQL statements in the behavioral feature data, and convert the access time features in the behavioral feature data into periodic features;
[0058] Specifically, convert the access time features into periodic features such as minutes, hours, and day of the week.
[0059] S153 Process the behavioral feature data using Z-score standardization or normalization.
[0060] S154: Select the number of clusters, use AIC or BIC to select the number k of Gaussian distributions in the optimal model, and based on the processed behavioral feature data, use GaussianMixture in the sklearn library to construct a GMM model, fill in the standardized feature data, and train to obtain a multi-dimensional user behavior feature model for estimating the probability distribution of database operation behaviors.
[0061] The following uses a code example to illustrate the specific process of training the GMM model:
[0062] Code example:
[0063]
[0064] n_components = k, where k is the number of clusters;
[0065] data_scaled: Standardized feature data;
[0066] S155 Use the username identifier to associate and train the obtained multi-dimensional user behavior feature model.
[0067] In some embodiments, it further includes S156, which retrains the model regularly to maintain the timeliness and accuracy of the model.
[0068] In the specific embodiments of the present invention, the behavioral feature data of the user operating the database includes, but is not limited to: username, user role, source IP, database operation type, SQL statement, table name, service name, operation time, etc.
[0069] The following gives a specific implementation process of training the GMM model through an example, including steps 1 to 4:
[0070] Step 1: Data preparation
[0071] Step 11 Feature data fields:
[0072] Categorical variables: username, user_role, source_ip, operation_type, table_name, service_name;
[0073] Text variable: sql_query;
[0074] Time variable: operation_time.
[0075] Step 12: Data preprocessing:
[0076] Process categorical variables: Convert the above categorical variables such as username, user_role, source_ip, operation_type, table_name, service_name into numerical encodings using One - Hot Encoding or Label Encoding.
[0077] Process text variable: Convert the above sql_query text variable into a vector using an embedding model (such as BERT).
[0078] Process time variable: Convert the above operation_time variable into minutes, hours, weeks.
[0079] Step 2: Feature value processing:
[0080] Step 21: Concatenate all features to get: features.
[0081]
[0082]
[0083] Step 21 Feature value data standardization processing to get: features_scaled:
[0084] Import the python scikit - learn machine learning library:
[0085] Use the Z - score method to process to obtain standardized feature values.
[0086]
[0087] Step 3: Train the GMM model:
[0088] Use the pre - processed standardized feature data to train the GMM model;
[0089] Import the GaussianMixture of the Gaussian mixture model in the scikit - learn machine learning library.
[0090]
[0091] GMM model evaluation. When training the GMM model, the number of components (n_components) needs to be specified, and then the AIC values under different components are gradually evaluated:
[0092]
[0093] Select the number of components n_components corresponding to the model with the minimum AIC.
[0094] Step 4: Model saving and deployment:
[0095] Among them, the code for saving the model:
[0096]
[0097] Among them, the code for deploying the model:
[0098]
[0099] S106 calculates the log-likelihood value of the user behavior data point under the GMM model, and determines whether the log-likelihood value is less than the set threshold. If so, the user behavior is abnormal; otherwise, the user behavior is normal. In summary, a database anomaly detection method based on the GMM algorithm proposed by the present invention intercepts SQL statements in various ways such as providing an application development SDK and a database proxy middleware, and adds audit information in the way of Hint tags; extracts database logs in real time, parses the database logs and extracts Hint tag information in real time according to the configuration information, constructs database audit records and data change tracks; uses the database behavior data of each user in the audit log to construct a data set to train the GMM model, and detects the abnormal behavior of the user based on the trained GMM model. Protect the key data assets of enterprises and ensure the security, compliance, integrity and fault liability division of data.
[0100] Embodiment 2
[0101] A database anomaly detection system based on the GMM algorithm is used for a database data audit and tracking platform, which is implemented by the hardware of an electronic device with a central processing unit, and can be implemented by a personal computer, a smart terminal, a local area network, a server, etc. In this embodiment, please refer to Figures 2-3 , including a basic information module 21, a proxy service module 22, a log module 23, an audit storage module 24, a GMM model training module 25, and an anomaly detection module 26.
[0102] The basic information module 21 is used to enter basic information, and the basic information includes at least the data corresponding to the following data items: user name, database name, table name, column name, and data record identifier field.
[0103] The proxy service module 22 is used to intercept SQL statements through the application development SDK or the database proxy, add audit information to the SQL statements through the Hint label, and proxy the execution of the SQL statements.
[0104] In this embodiment, the audit information added through the Hint label includes at least the data corresponding to the following data items: source IP, service name, user name, and user role. The supported clients include, but are not limited to, Navicat and DBveave.
[0105] The log module 23 is used to extract database logs in real time based on the basic information, parse the logs to extract the data corresponding to the following data items on the Hint label: audit information, SQL statements, database tables, field names, values before and after the field changes, and execution time, so as to obtain the databases, fields, and record field change tracks that need to be audited.
[0106] In this embodiment, the information obtained by parsing the database logs includes at least the data corresponding to the following data items: table name, field name, values before and after the field changes, SQL operation type, execution time, and SQL statement.
[0107] The audit storage module 24 is used to construct audit and data track information based on the databases, fields, and record field change tracks that need to be audited, and store the records;
[0108] In this embodiment, constructing and storing the audit and data track information specifically means: constructing audit record information and field change tracks through the audit information associated with the value of the data record identifier field and the data change tracks of the fields, and storing the records. Among them, the audit information includes, but is not limited to, the data corresponding to the following data items: table name, field name, values before and after the field changes, execution time, SQL statement, source IP, and user name.
[0109] The GMM model training module 25 is used to collect user behavior feature data and train a behavior GMM model for each user.
[0110] Collecting user behavior feature data specifically means: collecting the behavior feature data of users operating on the database. The behavior feature data of users operating on the database includes at least the data corresponding to the following data items: user name, user role, source IP, database operation type, SQL statement, table name, service name, and operation time.
[0111] Anomaly detection module 26 is used to calculate the log-likelihood value of user behavior data points under the GMM model, and determine whether the log-likelihood value is less than a set threshold. If so, the user behavior is abnormal; otherwise, the user behavior is normal.
[0112] In some embodiments, as Figure 3 shown, the GMM model training module 25 further includes:
[0113] Behavior feature data collection sub-module 251 is used to collect the stored audit record information as the behavior feature data of the user operation database.
[0114] Feature data preprocessing sub-module 252 is used to perform encoding processing on the data corresponding to the following data items in the behavior feature data: username, source IP, database operation type, table name, and service name, perform de-parameterization processing on the SQL statements in the behavior feature data, then numericalize the de-parameterized SQL statements in the behavior feature data, and convert the access time feature in the behavior feature data into a periodic feature.
[0115] Standardized feature data sub-module 253 is used to perform feature processing on the behavior feature data using the Z-score standardization or normalization method.
[0116] Training GMM model sub-module 254 is used to select the number k of Gaussian distributions in the optimal model as the clustering number using the AIC or BIC method. Based on the behavior feature data after feature processing, use the GaussianMixture in the sklearn library to construct the GMM model, fill in the standardized feature data, train to obtain a multi-dimensional user behavior feature model, and associate and train the multi-dimensional user behavior feature model using the username identifier.
[0117] A database anomaly detection system based on the GMM algorithm in this embodiment has the same implementation process, method, and effect as the database anomaly detection method based on the GMM algorithm described in Embodiment 1, and will not be elaborated here.
[0118] Embodiment 3
[0119] The present invention relates to a computer-readable storage medium, in which instructions are stored. When the instructions run, they execute a database anomaly detection method based on the GMM algorithm in Embodiment 1. Its implementation process, method, and effect when running are the same as the database anomaly detection method based on the GMM algorithm described in Embodiment 1, and will not be elaborated here.
[0120] It should be noted that in this text, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent in such a process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the process, method, article or device including that element.
[0121] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present invention.
Claims
1. A database anomaly detection method based on GMM algorithm, characterized in that: Used for database data audit trail platform, including: Enter basic information, which includes at least data corresponding to the following data items: user name, database name, table name, column name, and data record identification field; Intercept SQL statements through application development SDK or database proxy, add audit information to the SQL statements through Hint tags, and execute the SQL statements on behalf of them; Based on the basic information, the database log is extracted in real time, and the data corresponding to the following data items on the Hint tag are extracted by parsing the log: the audit information, the SQL statement, the database table, the field name, the value before and after the field change, and the execution time, so as to obtain the database, field and record field change track required for audit tracking; Based on the database, fields and record field change tracks required for audit tracking, build audit and data track information and store records; Collect user behavior feature data and train each user to obtain the user's behavior GMM model; Calculate the log-likelihood value of the user behavior data point under the GMM model and determine whether the log-likelihood value is less than the set threshold. If so, the user behavior is abnormal, otherwise the user behavior is normal.
2. According to the GMM algorithm-based database anomaly detection method according to claim 1, it is characterized in that: The audit information added by Hint tag includes at least the data corresponding to the following data items: source IP, service name, user name and user role. Supported clients include but are not limited to: Navicat and DBveaver.
3. The database anomaly detection method based on the GMM algorithm according to claim 2 is characterized in that: The information obtained by parsing the database log includes at least data corresponding to the following data items: table name, field name, field value before and after change, SQL operation type, execution time and the SQL statement.
4. The database anomaly detection method based on the GMM algorithm according to claim 1 is characterized in that: The constructing of audit and data track information and storing records is specifically: through the audit information associated with the value of the data record identification field and the data change track of the field, the audit record information and the field change track are constructed and the records are stored, wherein the audit information includes but is not limited to data corresponding to the following data items: the table name, the field name, the value before and after the field change, the execution time, the SQL statement, the source IP and the user name.
5. The database anomaly detection method based on the GMM algorithm according to claim 1 is characterized in that: The collecting of user behavior characteristic data specifically includes: collecting the behavior characteristic data of the user operating the database, and the behavior characteristic data of the user operating the database at least includes data corresponding to the following data items: the user name, the user role, the source IP, the database operation type, the SQL statement, the table name, the service name and the operation time.
6. The database anomaly detection method based on the GMM algorithm according to claim 1 is characterized in that: The training for each user to obtain the user's behavior GMM model also includes: Collect and store audit record information as behavioral feature data of user operation database; Encoding the data corresponding to the following data items in the behavior feature data: user name, source IP, database operation type, table name, and service name, de-parameterizing the SQL statements in the behavior feature data, and then digitizing the de-parameterized SQL statements in the behavior feature data, and converting the access time features in the behavior feature data into periodic features; Performing feature processing on the behavior feature data by using Z-score standardization or normalization; Select the number of clusters, use AIC or BIC to select the optimal number k of Gaussian distributions in the model, build a GMM model based on the behavioral feature data after feature processing using GaussianMixture in the sklearn library, fill in the standardized feature data, and train to obtain a multidimensional user behavior feature model to estimate the probability distribution of database operation behavior; The multi-dimensional user behavior feature model is obtained by using user name identification association training.
7. A database anomaly detection system based on the GMM algorithm, characterized in that: Used for database data audit trail platform, including: A basic information module is used to input basic information, which includes at least data corresponding to the following data items: user name, database name, table name, column name, and data record identification field; The proxy service module is used to intercept SQL statements through the application development SDK or the database proxy, add audit information to the SQL statements through the Hint tag, and execute the SQL statements on behalf of the proxy; The log module is used to extract database logs in real time based on the basic information, parse the logs to extract the data corresponding to the following data items on the Hint tag: the audit information, the SQL statement, the database table, the field name, the value before and after the field change, and the execution time, and obtain the database, field, and record field change track required for audit tracking; An audit storage module, for constructing audit and data track information and storing records based on the database, fields and record field change tracks required for audit tracking; The GMM model training module is used to collect user behavior feature data and train each user to obtain the user's behavior GMM model; The anomaly detection module is used to calculate the log-likelihood value of the user behavior data point under the GMM model and determine whether the log-likelihood value is less than the set threshold. If so, the user behavior is abnormal, otherwise the user behavior is normal.
8. The database anomaly detection method based on the GMM algorithm according to claim 7 is characterized in that: The audit information added by Hint tag includes at least the data corresponding to the following data items: source IP, service name, user name and user role. Supported clients include but are not limited to: Navicat and DBveave; The information obtained by parsing the database log includes at least data corresponding to the following data items: table name, field name, field value before and after change, SQL operation type, execution time and the SQL statement; The constructing and storing audit and data track information specifically includes: constructing audit record information and field change track and storing records through the audit information associated with the value of the data record identification field and the data change track of the field, wherein the audit information includes but is not limited to data corresponding to the following data items: the table name, the field name, the value before and after the field change, the execution time, the SQL statement, the source IP and the user name; The collecting of user behavior characteristic data specifically includes: collecting the behavior characteristic data of the user operating the database, and the behavior characteristic data of the user operating the database at least includes data corresponding to the following data items: account name, the user role, the source IP, database operation type, the SQL statement, the table name, the service name and operation time.
9. The database anomaly detection method based on the GMM algorithm according to claim 7, characterized in that: The GMM model training module also includes: The behavior characteristic data collection submodule is used to collect and store audit record information as behavior characteristic data of the user operation database; The feature data preprocessing submodule is used to encode the data corresponding to the following data items in the behavior feature data: user name, source IP, database operation type, table name and service name, de-parameterize the SQL statements in the behavior feature data, and then digitize the de-parameterized SQL statements in the behavior feature data, and convert the access time features in the behavior feature data into periodic features; A standardization feature data submodule is used to perform feature processing on the behavior feature data by using Z-score standardization or normalization; The GMM model training submodule is used to select the number k of Gaussian distributions in the optimal model as the number of clusters by using AIC or BIC, and to construct a GMM model based on the behavioral feature data after feature processing using GaussianMixture in the sklearn library, fill in the standardized feature data, and train to obtain a multidimensional user behavior feature model, which is obtained by using user name identification association training.
10. A computer-readable storage medium, characterized in that: The storage medium stores instructions, which, when executed, execute a database anomaly detection method based on a GMM algorithm according to any one of claims 1 to 6.
Citation Information
Cited By
Database SQL auditing method and device and medium
CN122111987A