Database security protection method

Through switch port mirroring and deep protocol analysis combined with real-time threat detection, the problem of identifying hidden attacks and dynamic threat lag in traditional database security protection methods is solved, precise protection and dynamic defense are achieved, and performance losses are reduced.

CN120378179APending Publication Date: 2025-07-25HENAN ZHONGYUAN CONSUMER FINANCE CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510577060.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

Traditional security protection methods cannot identify the hidden attack payload in database-specific protocols, resulting in missed detection of SQL injection variants, vulnerability exploitation, and abuse of encryption channels. The solution based on the static rule library has problems such as delay in rule updates and legal operations by manslaughtering, and dynamic threat response is lagging.

Method used

Switch port mirroring is used to replicate database traffic, conduct in-depth protocol analysis and real-time threat detection, and filter, feature matching and behavioral analysis of parsed data, identify abnormal operations, and realize dynamic defense.

Benefits of technology

It realizes precise protection and dynamic defense of the database, reduces performance losses, improves security and availability, and reduces manslaughter and missed inspections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378179A_ABST
    Figure CN120378179A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, in particular to a database security protection method, which comprises the following steps of: mirroring and copying database traffic by adopting a switch port; performing deep protocol analysis on the database traffic to obtain analyzed data; performing real-time threat detection on the analyzed data to obtain a detection result; and performing security protection on the database based on the detection result. According to the method, through technical fusion of deep protocol analysis and real-time threat detection, accurate protection and dynamic defense of the database can be realized, systematic defects in the aspects of performance loss and the like are reduced, and double breakthrough of safety and availability is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and particularly to a database security protection method in the field of communication technologies. Background Art

[0002] Traditional security protection methods cannot identify hidden attack payloads in database-specific protocols (such as Tabular DataStream (TDS), MySQL Database Management System (MySQL protocol)), resulting in the following risks: missed detection of SQL injection variants, exploitation of protocol vulnerabilities, and abuse of encrypted channels.

[0003] Traditional solutions based on static rule libraries have drawbacks such as delayed rule updates and false killing of legitimate operations, and the response to dynamic threats lags behind. Traditional solutions will have problems such as abuse of permissions and unauthorized access in complex scenarios, and the audit and traceability capabilities are relatively weak. Summary of the Invention

[0004] The purpose of the present invention is to provide a database security protection method, and the specific technical solutions adopted are as follows: In a first aspect, an embodiment of the present invention provides a database security protection method, which includes: Using switch port mirroring to copy database traffic; Performing in-depth protocol analysis on the database traffic to obtain parsed data; Performing real-time threat detection on the parsed data to obtain a detection result; Based on the detection result, performing security protection on the database.

[0005] In a second aspect, a database security protection system is provided, and the system includes: A replication module for using switch port mirroring to copy database traffic; An analysis module for performing in-depth protocol analysis on the database traffic to obtain parsed data; A detection module for performing real-time threat detection on the parsed data to obtain a detection result; A protection module for performing security protection on the database based on the detection result.

[0006] In a third aspect, a computer program product is provided, and the computer program product includes: computer program code, when the computer program code runs on a computer, enabling the computer to execute the database security protection method in any of the above possible implementation manners.

[0007] Fourthly, a computer-readable storage medium is provided. The computer-readable storage medium stores computer program code, which, when running on a computer, causes the computer to execute the database security protection method in any of the above possible implementation manners.

[0008] The present invention has the following beneficial effects: By adopting the method of switch port mirroring to copy database traffic, it is possible to obtain the data requirements for full-process analysis and not affect the original communication; then, deeply parsing the database traffic to obtain the parsed data; and performing real-time threat detection on the parsed data to obtain the detection result; in this way, by performing real-time threat detection after deeply parsing the database traffic, the detection result can be made more accurate. Finally, the database is protected based on the detection result. In this way, through the technical integration of deep protocol parsing and real-time threat detection, accurate protection and dynamic defense of the database can be achieved, and systematic defects such as performance loss can be reduced, realizing a double breakthrough in security and availability. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] In order to more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0010] Figure 1 It is a schematic flowchart of the implementation of a database security protection method provided by an embodiment of the present invention; Figure 2 It is a schematic diagram of the implementation framework of a database security protection method provided by an embodiment of the present invention; Figure 3 It is another schematic flowchart of the implementation of a database security protection method provided by an embodiment of the present invention Figure 4 It is another schematic flowchart of the implementation of a database security protection method provided by an embodiment of the present invention; Figure 5 It is a schematic diagram of the structure of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0011] To further elaborate on the technical means and effects adopted by the present invention to achieve the intended invention purpose, the following combines the accompanying drawings and preferred embodiments to detail the specific implementation manner, structure, features and effects of a database security protection method proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures or characteristics in one or more embodiments can be combined in any suitable form.

[0012] Among them, in the description of the embodiments of the present invention, unless otherwise specified, " / " means "or". For example, A / B can mean A or B: "and / or" in the text is only a description of the association relationship of the associated objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of the present invention, "a plurality" means two or more than two.

[0013] Hereinafter, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as implying or suggesting relative importance or implicitly indicating the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features.

[0014] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.

[0015] The embodiments of the present invention provide a database security protection method. Please refer to Figure 1 , which shows a schematic diagram of the implementation process of a database security protection method provided by an embodiment of the present invention. The method can be implemented through the following steps: 101. Adopt switch port mirroring to copy database traffic.

[0016] Here, through the method of switch port mirroring, the database traffic is copied without affecting the original communication. The main purpose of the copied traffic is data collection, obtaining the original database communication traffic (including encrypted data), providing input for protocol parsing, and meeting the data supply requirements for the whole process analysis, which is the basic premise for subsequent protocol parsing and threat detection.

[0017] The technical implementation method is as follows: Port mirroring copies the traffic of the specified port (source port) to the monitoring port (destination port) through the switch to achieve lossless traffic collection. Among them, the topological structure is as Figure 2 shown. The database server provides service traffic to the switch source port; it is copied to the monitoring port through mirroring and output to the packet capture server.

[0018] Taking the port mirroring of H3C switches as an example, the implementation process of replicating database traffic is as follows: # Create a mirroring group mirroring-group 1 local # Configure the source port mirroring-group 1 mirroring-port GigabitEthernet 1 / 0 / 1 inbound # Monitor only the inbound direction mirroring-group 1 mirroring-port GigabitEthernet 1 / 0 / 1 outbound # Monitor only the outbound direction # Configure the destination port mirroring-group 1 monitor-port GigabitEthernet 1 / 0 / 24 # Save the configuration save Here, it runs on a dedicated server connected to the mirroring port of the network switch, and the mirroring mode captures network traffic.

[0019] 102. Perform in-depth protocol parsing on the database traffic to obtain the parsed data.

[0020] Here, extract the SQL statements from the database traffic and perform in-depth protocol parsing on the SQL statements to obtain the parsed data.

[0021] In some possible implementation manners, the above step 102 can be implemented through Figure 3 the steps shown below: 301. Extract at least keywords, identifiers, and operators from the database traffic.

[0022] Here, disassemble the four-layer structure of multiple database traffic private communication protocols and extract the SQL statements. Then, disassemble the SQL statements into basic units such as keywords, identifiers, and operators.

[0023] For example, SELECT * FROM users WHERE id=1; -- Example statement Use regular expressions to define Token rules and split the character stream into a sequence of **lexical units (Tokens)**: [SELECT, *, FROM, users, WHERE, id, =, 1, ;] 302. Build an abstract syntax tree based on the keywords, the identifiers, and the operators.

[0024] Here, the lexical units are organized into a tree structure according to the SQL syntax rules to construct an abstract syntax tree, and the legality of the statement structure is verified. The abstract syntax tree is constructed according to the SQL syntax rules (such as the ISO / IEC 9075 standard).

[0025] 303. Perform a structuring process on the abstract syntax tree to obtain a processed structure.

[0026] Here, by performing operations such as semantic annotation, structure optimization, and normalization on the abstract syntax tree, a processed structure is obtained.

[0027] In some possible implementation manners, the above step 303 can be implemented through the following Figure 4 shown steps: 401. Perform semantic annotation on the abstract syntax tree to obtain an annotated syntax tree.

[0028] Here, bind the database metadata (table / column information), and verify the access permissions and data types.

[0029] Carry out metadata verification to verify the existence of tables / columns; perform permission checks to confirm the operation permissions of the executing user; then perform type deduction to judge the type consistency in WHERE id='1' to obtain an AST with semantic annotation.

[0030] 402. Perform logical specification processing on the annotated syntax tree to obtain a normalized logical tree.

[0031] Here, the logical specification processing includes: simplifying nested queries, pre-computing constant expressions, etc. to generate a normalized logical tree. Constant folding, such as: WHERE id=1+1 → WHERE id=2; predicate pushdown, such as: bringing the filtering condition forward to before JOIN; subquery expansion, such as: converting an IN subquery into a JOIN operation.

[0032] 403. Perform normalization processing on the normalized logic to obtain the processed structure.

[0033] Here, the normalization processing includes: unifying the case, deleting redundant spaces, parameterizing variable values, and generating a standard AST. Standardization operations include unifying the case of keywords (select → SELECT); deleting extra spaces / comments; parameterizing (WHEREid=1 → WHERE id=?); and finally outputting the standardized AST structure (i.e., the processed structure).

[0034] 304. Identify the operation type corresponding to the database traffic based on the processed structure to obtain the parsed data.

[0035] Here, by parsing statements, basic operations, management operations, transaction operations, storage operations, etc. are identified to obtain the parsed data. In some possible implementation manners, the above step 304 may be implemented through the following steps 341 to 343 (not shown in the figure): 341. Extract the parsing statement from the database traffic.

[0036] Here, by extracting the SQL statement from the database traffic, the parsing statement is obtained.

[0037] 342. Based on the processed structure, identify the basic operations, management operations, transaction operations, and storage operations of the parsing statement.

[0038] Here, the operation types of the SQL statements initiated by the client are identified, including: Basic operations: SELECT (query), INSERT (insert), UPDATE (update), DELETE (delete) Management operations: CREATE (create), ALTER (modify), DROP (delete), GRANT (authorize) Transaction operations: BEGIN (start transaction), COMMIT (commit), ROLLBACK (rollback) Stored procedures: EXECUTE (execute), CALL (call).

[0039] 343. Determine the basic operations, the management operations, the transaction operations, and the storage operations as the parsed data. In this way, by performing in-depth protocol parsing on the SQL statements extracted from the database traffic, the accuracy of the parsed data can be improved.

[0040] 103. Perform real-time threat detection on the parsed data to obtain a detection result.

[0041] Here, by performing filtering detection and feature matching on the parsed data, etc., real-time threat detection can be realized, thereby obtaining a detection result. In some possible implementation manners, the above step 103 may be implemented through the following steps 131 and 132 (not shown in the figure): 131. Perform filtering detection on the parsed data to obtain filtered data.

[0042] Here, at least feature filtering, behavior filtering, semantic filtering, and context filtering are performed on the parsed data to obtain the filtered data. For example, multiple filtering detections are adopted, including the following aspects: Feature filtering: Matching known attack patterns such as SQL injection and vulnerability exploitation; Behavior filtering: Identifying abnormal requests that deviate from the user's historical operation habits (such as executing batch deletions in the early morning); Semantic filtering: Detecting high-risk operations (such as DROP TABLE and accessing sensitive tables); Context filtering: Analyzing environmental risks such as access time and IP source.

[0043] 132. Feature matching detection is performed on the filtered data to obtain the detection result.

[0044] Through the above steps 131 and 132, by fusing rule matching, behavior analysis, vulnerability feature libraries, etc., known / unknown threats can be covered.

[0045] In some possible implementation manners, first, based on the filtered data, known attack features are matched; for example, matching known attack features includes the following categories: SQL injection: Containing syntax for logical bypass (UNION SELECT, WAITFORDELAY); Vulnerability exploitation: Invoking dangerous functions (xp_cmdshell) or triggering CVE vulnerabilities; Data leakage: Frequent access to sensitive tables.

[0046] Secondly, an access habit model is established based on the known attack features.

[0047] Among them, the access habit module is used to detect abnormal behaviors in database operation behaviors. Allowing compliant operations and establishing an access habit model are mainly used to analyze the database operation behaviors of users or application programs to detect abnormal behaviors that deviate from the normal baseline. The structure of the model is based on the long short-term memory network (LSTM, Long Short-Term Memory) because the long short-term memory network is good at processing time series data and is suitable for capturing the time patterns of user operations. The specific model structure is as follows: The input layer is used to receive operation sequence data (SQL type, time interval, operation object); The embedding layer is used to map discrete operation types into continuous vectors (such as SELECT → [0.2, -0.5,...]); The LSTM layer is used to capture long-term operation habit dependencies and memorize typical behavior patterns; The attention layer is used to weight and focus on key operation nodes (such as high-frequency DELETE operations); The fully connected layer is used to generate prediction results by synthesizing features (probability distribution of expected next operations).

[0048] Next, based on the access habit module, match the vulnerability exploitation features.

[0049] Here, match the CVE vulnerability exploitation features, comprehensively determine the risk level of SQL operations, and perform the level determination in the following manner: Feature matching (weight 40%), based on the risk level of the hit rule (high risk / medium risk / low risk); Behavior deviation (weight 30%), based on the deviation degree (0 - 1) output by the LSTM model; Semantic risk (weight 20%), based on the sensitivity of the operation object (such as sensitive data tables); Context anomaly (weight 10%), based on non - working hours, new devices, etc.

[0050] Calculate the total score by weighted calculation, and perform the corresponding handling operations according to the grading threshold: Low risk (0 - 30 points): Release and record; Medium risk (31 - 60 points): Release after secondary authentication; High risk (61 - 85 points): Delay the response and give an alarm; Emergency risk (86 - 100 points): Immediately block the connection; In a specific example, the above - mentioned feature matching process can be implemented through the following code: class DetectionEngine: def __init__(self): self.rules = {"type": "privilege", "pattern":r"(GRANT\s+ALTER|REVOKE\s+SELECT)"}, {"type": "injection", "pattern":r"'\s+OR\s+1=1--"}, {"type": "operation", "operations":["DROP", "TRUNCATE"]} def detect_threats(self, parsed_sql): threats = [] # High - risk operation detection for token in parsed_sql['tokens']: ​if token.value.upper() in ['DROP', 'TRUNCATE']: threats.append({ 'type': 'High - risk operation', 'detail': f"Detected dangerous operation: {token.value}" }) # SQL injection detection if re.search(r"('\s*OR\s+[\d\w]+=[\d\w]+)", parsed_sql['raw']): threats.append({'type': 'SQL injection'}) # Privilege escalation detection if parsed_sql['user'] not in parsed_sql['allowed_objects']: threats.append({'type': 'Privilege escalation'}) return threats Finally, based on the vulnerability exploitation characteristics, judge the risk level of the parsing operation to obtain the detection result. In this way, by performing real - time detection on the parsed data, the dynamic protection of the database can be achieved.

[0051] 104. Based on the detection result, perform security protection on the database.

[0052] Here, corresponding response operations are performed according to the risk level in the detection result, so as to achieve the security protection of the database.

[0053] In some possible implementation manners, the above - mentioned step 104 can be implemented through the following steps 141 and 142 (not shown in the figure): 141. Based on the risk level in the detection result, execute the response matching the risk level to obtain a response result.

[0054] Here, the detection result includes threat types such as SQL injection attacks, high - risk vulnerability exploitations, and abnormal privilege operations, as well as the risk level scoring situation of SQL operation risks (0 - 100 points). Hierarchical responses are executed according to the detection result, including: directly blocking high - risk operations, rewriting suspicious statements, delaying the release of low - frequency requests or triggering manual review, and synchronously linking with network - layer security protection tools to update interception rules, etc.

[0055] In some possible implementations, first, based on the risk level, high-risk operations in the detection results are determined; for example, when an absolutely high-risk instruction (such as DROP TABLE) is detected, the risk score is greater than 85 points (such as batch deletion of sensitive data in the early morning), or the same session triggers three medium-risk alarms in a row, the connection is immediately blocked and the firewall is linked to block the source IP.

[0056] Secondly, the preset interception rules are used to block the high-risk operations and rewrite the statements corresponding to the high-risk operations to obtain the response results; for example, defensive rewriting is performed on suspicious operations with high-risk items in risk scores, such as rewriting DELETE during non-working hours to SELECT 1, modifying OR 1=1 in fuzzy injection attacks to AND 1=0, hiding real data for access to sensitive fields (such as SELECT card_no→SELECT '***'), etc.

[0057] For example, interception rules are divided into static rules (manually preset BLOCK EXEC xp_cmdshell), dynamic rules (automatically generated DENY 192.168.1.100 FOR 1h) and intelligent rules (learned and generated ALERT IF SELECT *FROM mysql.user), which are synchronized in real time to firewalls, WAFs and other network layer devices through APIs to update protection policies.

[0058] In a specific example, “based on the risk level in the detection result, executing a response matched by the risk level to obtain a response result” can be achieved by the following process: class PolicyEnforcer: ACTION_MAP = { 'High-risk operation': 'BLOCK', 'SQL injection': 'BLOCK_AND_ALERT', 'Unauthorized access': 'AUDIT' } def apply_policy(self, threats): actions = [] for threat in threats: action = self.ACTION_MAP.get(threat['type'], 'ALLOW') if action.startswith('BLOCK'): return { 'action': 'BLOCK', 'reason': threat['detail'], 'sql_hash': hash(threat['sql']) } return {'action': 'ALLOW'} Finally, audit records are made for the response result, and the preset interception rules are updated.

[0059] Here, by recording the complete operation process, using open-source anti-tampering technology, fast retrieval based on timestamp, operation type, and risk level is supported, and an audit report that meets the requirements is automatically generated.

[0060] For example, it can be achieved through the following process: class AuditLogger: def log_event(self, event): log_entry = { 'timestamp': datetime.utcnow().isoformat(), 'client_ip': event['client'], 'user': event['user'], 'sql': event['sql'], 'action': event['action'], 'threats': event.get('threats', []) } # Write to ELK or a dedicated log database es.index(index='db-audit', body=log_entry) 142. Based on the response result, security protection is performed on the database.

[0061] In an embodiment of the present invention, by replicating database traffic in the way of switch port mirroring, it is possible to obtain the data requirements for full - process analysis and not affect the original communication. Then, perform in - depth protocol analysis on the database traffic to obtain the parsed data, and perform real - time threat detection on the parsed data to obtain the detection result. In this way, by performing real - time threat detection after in - depth protocol analysis of the database traffic, the detection result can be made more accurate. Finally, perform security protection on the database based on the detection result. In this way, through the technical integration of in - depth protocol analysis and real - time threat detection, it is possible to achieve precise protection and dynamic defense of the database, reduce systematic defects such as performance loss, and achieve a double breakthrough in security and availability.

[0062] An embodiment of the present invention provides a database security protection system, which includes: A replication module, configured to replicate database traffic by using switch port mirroring; An analysis module, configured to perform in - depth protocol analysis on the database traffic to obtain the parsed data; A detection module, configured to perform real - time threat detection on the parsed data to obtain the detection result; A protection module, configured to perform security protection on the database based on the detection result.

[0063] In some possible implementation manners, the analysis module is further configured to at least extract keywords, identifiers, and operators from the database traffic; construct an abstract syntax tree based on the keywords, the identifiers, and the operators; perform structured processing on the abstract syntax tree to obtain a processed structure; and identify the operation type corresponding to the database traffic based on the processed structure to obtain the parsed data.

[0064] In some possible implementation manners, the analysis module is further configured to perform semantic annotation on the abstract syntax tree to obtain an annotated syntax tree; perform logical specification processing on the annotated syntax tree to obtain a normalized logical tree; and perform normalization processing on the normalized logic to obtain the processed structure.

[0065] In some possible implementation manners, the analysis module is further configured to extract parsing statements from the database traffic; identify basic operations, management operations, transaction operations, and storage operations of the parsing statements based on the processed structure; and determine the basic operations, the management operations, the transaction operations, and the storage operations as the parsed data.

[0066] In some possible implementations, the detection module is further configured to perform filtering detection on the parsed data to obtain filtered data; and perform feature matching detection on the filtered data to obtain the detection result.

[0067] In some possible implementations, the detection module is further configured to perform at least feature filtering, behavior filtering, semantic filtering, and context filtering on the parsed data to obtain the filtered data.

[0068] In some possible implementations, the detection module is further configured to match known attack features based on the filtered data; establish an access habit model based on the known attack features; wherein, the access habit module is configured to detect abnormal behaviors in database operation behaviors; match vulnerability exploitation features based on the access habit module; and determine the risk level of the parsing operation based on the vulnerability exploitation features to obtain the detection result.

[0069] In some possible implementations, the protection module is further configured to execute a response matching the risk level based on the risk level in the detection result to obtain a response result; and perform security protection on the database based on the response result.

[0070] In some possible implementations, the protection module is further configured to determine high-risk operations in the detection result based on the risk level; use a preset interception rule to block the high-risk operations and rewrite the statements corresponding to the high-risk operations to obtain the response result; audit and record the response result, and update the preset interception rule.

[0071] Optionally, the transmission medium may be a wired link (such as, but not limited to, coaxial cable, optical fiber, and Digital Subscriber Line (DSL), etc.) or a wireless link (such as, but not limited to, Wireless Fidelity (WIFI), Bluetooth, and mobile device network, etc.). It should be noted that: for the system provided in the above embodiments, only the above division of each functional module is used for illustration. In practical applications, the above functions may be allocated to different functional modules according to needs, that is, the internal structure of the computer device is divided into different functional modules to complete all or part of the functions described above. In addition, the method embodiments provided in the above embodiments belong to the same concept, and the specific implementation process is detailed in the method embodiments, which will not be elaborated here.

[0072] Figure 5 is a schematic structural diagram of a computer device provided by an embodiment of the present invention. Exemplarily, as Figure 5As shown, the computer device 500 includes: a memory 501, a processor 502, and a computer program 503 stored in the memory 501 and running on the processor 502. When the processor 502 executes the computer program 503, the computer device can execute any one of the database security protection methods introduced above.

[0073] In addition, an embodiment of the present invention also protects a system, which may include a memory and a processor. An executable program code is stored in the memory, and the processor is used to call and execute the executable program code to execute a database security protection method provided by an embodiment of the present invention. In this embodiment, the system can be divided into functional modules according to the above method examples. For example, it can correspond to each functional module, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware. It should be noted that the division of modules in this embodiment is illustrative, only a logical function division, and there may be other division methods in actual implementation. It should be noted that all relevant contents of each step involved in the above method embodiment can be cited in the function description of the corresponding functional module, and will not be repeated here.

[0074] It should be understood that the system provided in this embodiment is used to execute the above-mentioned database security protection method, so the same effect as the above implementation method can be achieved. In the case of adopting an integrated unit, the system may include a processing module and a storage module. When the system is applied to a device, the processing module can be used to control and manage the actions of the device. The storage module can be used to support the device to execute mutual program codes, etc. The processing module can be a processor or a controller, which can implement or execute various exemplary logic blocks, modules, and circuits described in combination with the disclosure of the present invention. The processor can also be a combination that realizes computing functions, such as a combination of one or more microprocessors, a combination of digital signal processing (DSP) and a microprocessor, etc. The storage module can be a memory.

[0075] In addition, the system provided by the embodiment of the present invention may specifically be a chip, a component, or a module. The chip may include a connected processor and a memory. The memory is used to store instructions. When the processor calls and executes the instructions, the chip can execute a database security protection method provided by the above embodiment. This embodiment also provides a computer-readable storage medium, in which computer program code is stored. When the computer program code runs on a computer, the computer executes the above-related method steps to implement a database security protection method provided by the above embodiment.

[0076] This embodiment also provides a computer program product. When the computer program product runs on a computer, it causes the computer to execute the above-related steps to implement a database security protection method provided in the above embodiment. Among them, the system, computer-readable storage medium, computer program product, or chip provided in this embodiment are all used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding method provided above, and will not be elaborated here. Through the description of the above embodiments, those skilled in the art can understand that for the convenience and simplicity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the system is divided into different functional modules to complete all or part of the functions described above. In the embodiments provided by the present invention, it should be understood that the disclosed system and method can be implemented in other ways. For example, the system embodiments described above are only illustrative. For example, the division of modules or units is only a logical functional division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the system or unit can be in an electrical, mechanical or other form.

[0077] It should be noted that the above sequence of the embodiments of the present invention is only for description and does not represent the superiority or inferiority of the embodiments. The processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous. Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. The above content is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention.

Claims

1. A database security protection method, characterized in that, The method includes: Using switch port mirroring to copy database traffic; Performing in-depth protocol parsing on the database traffic to obtain parsed data; Performing real-time threat detection on the parsed data to obtain a detection result; Based on the detection result, performing security protection on the database.

2. The database security protection method according to claim 1, characterized in that, The performing in-depth protocol parsing on the database traffic to obtain parsed data includes: Extracting at least keywords, identifiers, and operators from the database traffic; Based on the keywords, the identifiers, and the operators, constructing an abstract syntax tree; Performing structured processing on the abstract syntax tree to obtain a processed structure; Based on the processed structure, identifying the operation type corresponding to the database traffic to obtain the parsed data.

3. The database security protection method according to claim 2, wherein The performing structured processing on the abstract syntax tree to obtain a processed structure includes: Performing semantic annotation on the abstract syntax tree to obtain an annotated syntax tree; Performing logical specification processing on the annotated syntax tree to obtain a normalized logical tree; Performing normalization processing on the normalized logic to obtain the processed structure.

4. A database security protection method according to claim 2, characterized in that, The based on the processed structure, identifying the operation type corresponding to the database traffic to obtain the parsed data includes: Extracting parsing statements from the database traffic; Based on the processed structure, identifying the basic operations, management operations, transaction operations, and storage operations of the parsing statements; Determining the basic operations, the management operations, the transaction operations, and the storage operations as the parsed data.

5. A database security protection method according to claim 1, characterized in that, The performing real-time threat detection on the parsed data to obtain a detection result includes: Performing filtering detection on the parsed data to obtain filtered data; Performing feature matching detection on the filtered data to obtain the detection result.

6. A database security protection method according to claim 5, characterized in that, The performing filtering detection on the parsed data to obtain filtered data includes: Performing at least feature filtering, behavior filtering, semantic filtering, and context filtering on the parsed data to obtain the filtered data.

7. A database security protection method according to claim 5, characterized in that, The performing feature matching detection on the filtered data to obtain the detection result includes: Based on the filtered data, matching known attack features; Based on the known attack features, establishing an access habit model; wherein, the access habit module is used to detect abnormal behaviors in database operation behaviors; Based on the access habit module, matching vulnerability exploitation features; Based on the vulnerability exploitation features, judging the risk level of the parsing operation to obtain the detection result.

8. A database security protection method according to claim 1, characterized in that, The based on the detection result, performing security protection on the database includes: Based on the risk level in the detection result, executing the response matched by the risk level to obtain a response result; Based on the response result, performing security protection on the database.

9. A database security protection method according to claim 8, characterized in that, The based on the risk level in the detection result, executing the response matched by the risk level to obtain a response result includes: Based on the risk level, determining the high-risk operations in the detection result; Using a preset interception rule to block the high-risk operations and rewrite the statements corresponding to the high-risk operations to obtain the response result; After executing the response matching the risk level based on the risk level in the detection result and obtaining a response result, the method further includes: auditing and recording the response result and updating the preset interception rule.

10. A database security protection system, characterized in that, The system includes: A replication module, configured to replicate database traffic by using switch port mirroring; A parsing module, configured to perform in-depth protocol parsing on the database traffic to obtain parsed data; A detection module, configured to perform real-time threat detection on the parsed data to obtain a detection result; A protection module, configured to perform security protection on the database based on the detection result.

Citation Information

Cited By

  • Database autonomous protection method based on dual-system architecture

    CN121561920A