Database login information security auditing method

By conducting security audits on login information of enterprise and institutional database systems, the problems of unauthorized login and damage to database systems were resolved. Through comparison and analysis of IP addresses, login accounts, terminal tools, and login times, violations were detected and corrected, ensuring secure login and legitimate use of database systems and protecting data security.

CN121173552APending Publication Date: 2025-12-19TANGSHAN IRON & STEEL GROUP +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511401365.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-28
Publication Date
2025-12-19

AI Technical Summary

Technical Problem

How to ensure the secure use of databases in enterprises and institutions, and prevent unauthorized access and damage to database systems, especially to prevent database account leaks, unauthorized logins, misuse of accounts, use of illegal tools, and other violations, as well as to detect network threats such as Trojan horse intrusions and hacker attacks.

Method used

By conducting security audits on login information of enterprise and institution database systems, comparing and analyzing four dimensions—IP address, login account, terminal tool, and login time—violations can be identified and corrected, and corresponding security measures can be taken.

Benefits of technology

It effectively protects the secure login and legitimate use of database systems, ensures the data security of enterprises and institutions, and detects and corrects violations such as database account leakage, unauthorized login, misuse of accounts, and use of illegal tools, as well as network threats such as Trojan horse intrusion and hacker attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121173552A_ABST
    Figure CN121173552A_ABST
Patent Text Reader

Abstract

The invention relates to a database login information security auditing method, and belongs to the technical field of database security control methods. According to the technical scheme, database account and user information collection is carried out on a database needing login security auditing in an enterprise and public institution, user login information is exported from a database auditing system according to an auditing period, and comparison and analysis are carried out from the four dimensions of an IP address, a login account, a terminal tool and login time; and network threat behaviors are found, and security measures are taken. The method has the beneficial effects that illegal login behaviors such as database account number leakage, illegal login, mixed account number use and illegal tool use can be found through comparison and analysis from four dimensions of an IP address, a login account number, a terminal tool and login time, meanwhile, network threat behaviors can be found, safety measures which can be taken can be pointed out, and the safety of a user is improved. Therefore, safe login and legal use of the database system are ensured, and data security of enterprises and public institutions is protected.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to a database login information security audit method, belonging to the technical field of database security control method. BACKGROUND

[0002] With the development and deepening of information technology and information system, enterprises and institutions increase the application of database system, and how to protect the safe use of database of enterprises and institutions and avoid illegal login and damage of database system become the problems that must be solved in the application of database system of enterprises and institutions. SUMMARY

[0003] The present application aims to provide a database login information security audit method, which can find illegal login behaviors such as database account leakage, illegal login, mixed account use and illegal tool use by comparing and analyzing the login information of database system of enterprises and institutions from four dimensions of IP address, login account, terminal tool and login time, and can also find network threat behaviors such as Trojan horse intrusion and hacker attack, and points out the security measures that can be taken, so as to ensure the safe login and legal use of database system, protect the data security of enterprises and institutions, and effectively solve the above problems in the background art.

[0004] The technical solution of the present application is: a database login information security audit method, comprising the following steps: Step S1, collecting database account and user information of database that needs to be audited in enterprises and institutions, including user name, post, responsibility, IP address, database account, permission, terminal tool and working time information, for statistics and record; Step S2, exporting user login information from the database audit system according to the audit period, including terminal IP, login account, terminal tool and login time information, for user login information audit; Step S3, comparing the IP address exported from the audit system with the database user IP address recorded in advance, if they are inconsistent, querying the user information corresponding to the IP address from the network department, and finding the user to confirm the legality of the login behavior, and correcting the illegal login behavior; if they are consistent, proceed to the next comparison work; Step S4, comparing the user information and database account information obtained from the audit system with the recorded user information and database account information, if they are inconsistent, inquiring the user about the reason for not using his own account to login, correcting the illegal use of account, if they are consistent, proceed to the next comparison work; Step S5, compare the user terminal tool obtained from the audit system with the terminal tool counted in the record, if inconsistent, correct the behavior of illegal and irregular use of account and terminal tool, if consistent, proceed to the next comparison work; Step S6, compare the user login time obtained from the audit system with the user working time counted in the record, if inconsistent, ask the user for the reason of logging into the system at non-working time, if consistent, complete the security audit work of the database login information; Step S7, repeat the comparison work of S3 to S6 for each login information obtained from the database audit system, until the comparison work of each database login information is completed.

[0005] In the step S3, it is assumed that the data obtained from the database audit system and counted in the record of the database user and account information in steps S1 and S2 are completely accurate and correct, including the following steps: Step S301, by comparing whether the login IP address is consistent with the record IP address, it can be found that the user account is illegally stolen or the account is leaked; Step S302, by comparing whether the login IP is consistent with the record IP, it can be found that some users mix the account; Step S303, if inconsistency is found, the person in charge of the record of the account needs to be checked whether it is the person himself using the account on the terminal of other IP, if it is the person himself using the account on the terminal of other IP due to work needs, it is not a violation behavior.

[0006] In the step S4, it is assumed that the enterprise and institution has established a perfect database account password management system, and requires users to log in with their own account, and does not leak and mix accounts, including the following steps: Step S401, compare the login account with the record account, which is based on step S1, that is, the user information of the login account has been determined and is consistent with the record user information, and the terminal logged in is the record terminal of the user; Step S402, if the login account is inconsistent with the record account, ask whether the login account is used by the user of the record terminal, if yes, it can be judged that there is a behavior of mixing accounts or stealing accounts, and it is immediately corrected according to the relevant management regulations; Step S403, if the account is used by the user of the record account due to work needs on the login terminal computer, it is not a violation behavior.

[0007] In the step S5, it includes the following steps: Step S501, by comparing whether the login terminal tool and the record terminal tool are consistent, the user's illegal use of terminal tool behavior can be found, and accidental damage or data damage to the database caused by the user through illegal tools can be avoided; Step S502, by comparing whether the login terminal tool and the record terminal tool are consistent, if the terminal user is not the person operating by inquiring can find illegal behaviors such as Trojan horse or terminal misuse, and take virus killing and setting screen password protection login security measures to secure.

[0008] The step S6, by default, the enterprise and institution has standard shift system and working time system, including the following steps: Step S601, if the database login time is found to be inconsistent with the working time registered in the record, the account user registered in the record is confirmed whether it is the person who logs in the database at the non-working time, if it is the person, further inquiry the reason, if the reason is reasonable, it is considered as normal login, if the reason is unreasonable, the user is ordered to standardize the database login behavior; Step S602, if the user registered in the record is not deployed to log in the database at the non-working time, the account leakage problem or the user terminal computer is attacked by hacker, stolen or infected with Trojan virus problem may occur, the user needs to take the modification of database login account password, virus killing of terminal computer, modification of terminal computer login account password and setting of screen protection password.

[0009] The beneficial effects of the present application are: by performing security audit on the login information of the enterprise and institution database system, comparing and analyzing from four dimensions of IP address, login account, terminal tool and login time, the database account leakage, illegal login, mixed account and illegal tool use and other illegal login behaviors can be found, at the same time, Trojan intrusion and hacker attack and other network threat behaviors can also be found, and the security measures that can be taken are pointed out, so as to ensure the safe login and legal use of the database system, and protect the data security of the enterprise and institution. BRIEF DESCRIPTION OF DRAWINGS

[0010] Figure 1 The method flowchart of the present application. DETAILED DESCRIPTION

[0011] In order to make the purpose, technical scheme and advantages of the embodiment of the application clearer, the technical scheme in the embodiment of the application will be described clearly and completely in combination with the drawings in the embodiment. Obviously, the embodiment expressed is only a part of the embodiment of the application, not all the embodiments of the application. Based on the embodiment in the application, all other embodiments obtained by those skilled in the art without creative labor belong to the protection scope of the application.

[0012] A method for database login information security audit, comprising the following steps: Step S1, collecting database account and user information of the database needing login security audit in enterprises and institutions, including user name, post, responsibility, IP address, database account, permission, terminal tool and working time information, for statistics and record; Step S2, exporting user login information from the database audit system according to the audit period, including terminal IP, login account, terminal tool and login time information, for user login information audit; Step S3, comparing the IP address exported from the audit system with the database user IP address recorded in advance, if inconsistent, querying the user information corresponding to the IP address from the network department, and finding the user to confirm the legality of the login behavior, and correcting the illegal login behavior; if consistent, proceed to the next comparison work; Step S4, comparing the user information and database account information obtained from the audit system with the recorded user information and database account information, if inconsistent, inquiring the user for the reason of not using his own account to log in, correcting the illegal use of account, and if consistent, proceed to the next comparison work; Step S5, comparing the user terminal tool obtained from the audit system with the terminal tool recorded in the statistics, if inconsistent, correcting the behavior of illegal and irregular use of account and terminal tool, and if consistent, proceed to the next comparison work; Step S6, comparing the user login time obtained from the audit system with the user working time recorded in the statistics, if inconsistent, inquiring the user for the reason of logging into the system at non-working time, and if consistent, completing the security audit work of the database login information; Step S7, repeating the comparison work of S3 to S6 for each login information obtained from the database audit system, until the comparison work of each database login information is completed.

[0013] In the step S3, it is assumed that the data obtained from the database audit system and the data recorded in the step S1 and step S2 are completely accurate and correct, comprising the following steps: Step S301, by comparing whether the login IP address is consistent with the recorded IP address, it can be found that the user account is illegally stolen or the account is leaked; Step S302, by comparing whether the login IP is consistent with the recorded IP, it can be found that some users mix the account behavior; Step S303, if the inconsistency is found, the person responsible for the account in the record needs to check whether the person himself / herself uses the account on the terminal of other IP, if the person himself / herself uses the account on the terminal of other IP due to work needs, it is not a violation behavior.

[0014] In the step S4, the enterprise and institution has established a perfect database account password management system, and requires the user to log in with his / her own account, and the account cannot be disclosed and mixed, including the following steps: Step S401, compare the login account with the record account, which is based on the step S1, that is, the user information of the login account has been determined, and is consistent with the record user information, that is, the terminal logged in is the record terminal of the user; Step S402, if the login account is inconsistent with the record account, it is asked whether the user of the record terminal uses the login account to log in, if yes, it can be judged that there is a mixed account or a stolen account behavior, and it is immediately corrected according to the relevant management regulations; Step S403, if the account is used by the user of the record account due to work needs on the login terminal computer, it is not a violation behavior.

[0015] In the step S5, the following steps are included: Step S501, by comparing the login terminal tool with the record terminal tool, the user's illegal use of terminal tool can be found, and accidental damage or data damage to the database by the user through illegal tools can be avoided; Step S502, by comparing the login terminal tool with the record terminal tool, if the terminal user is found to be operated by others through inquiry, illegal behaviors such as Trojan horse or terminal theft can be found, and security reinforcement measures such as virus killing and setting screen password protection login security measures are taken.

[0016] In the step S6, the enterprise and institution have standard shift system and working hours system by default, including the following steps: Step S601, if the database login time is found to be inconsistent with the working hours registered in the record, the user of the account registered in the record is asked whether it is the person himself / herself who logs in the database at the non-working hours, if it is the person himself / herself, the reason is further asked, if the reason is reasonable, it is considered as normal login, if the reason is unreasonable, the user is ordered to standardize the database login behavior; Step S602, if the non-working time login database of the deployment record user, the account leakage problem may occur or the user terminal computer is hacked, stolen or infected with Trojan virus problem, then the user needs to take the modification database login account password, terminal computer virus check, modify terminal computer login account password and set screen saver password.

[0017] In practical application, the specific implementation content of the present application includes the following parts: As Figure 1 In enterprises and institutions, the database account and user information of the database needing to be logged in for security audit are collected, including user name, post, responsibility, IP address, database account, permission, terminal tool, working time and other information for statistics and record.

[0018] The second part is to export user login information from the database audit system according to the audit cycle, including terminal IP, login account, terminal tool, login time and other information, which is used for user login information audit.

[0019] The third part compares the IP address exported from the audit system with the database user IP address recorded in advance. If they are inconsistent, the network department is queried for the user information corresponding to the IP address, and the legal login behavior of the user is found to correct the illegal login behavior. If they are consistent, the next comparison work is performed as shown in Figure 1

[0020] The default steps S1 and S2 are completely accurate and correct. The data obtained from the database audit system is completely accurate and correct. This part includes the following steps: Step S301, by comparing the login IP address with the recorded IP address, the illegal use or account leakage of the user account can be found; Step S302, by comparing the login IP with the recorded IP, the behavior of some users mixing accounts can be found; Step S303, if inconsistency is found, the person in charge of the record needs to check whether it is the person himself using the account on other IP terminal computer due to work needs, and if it is the person himself using the account on other IP terminal computer due to work needs, it is not a violation behavior; The fourth part compares the user information and database account information obtained from the audit system with the recorded user information and database account information. If they are inconsistent, the user is questioned for the reason of not using his own account to log in, and the illegal use of the account is corrected. If they are consistent, the next comparison work is performed; ​The default enterprise and institution has established a perfect database account password management system, and requires users to log in with their own account, and cannot disclose and mix accounts, including the following steps: Step S401, compare the login account with the registered account, which needs to be based on S1, that is, the user information of the login account has been determined, and is consistent with the registered user information, that is, the terminal logged in is the registered terminal of the user; Step S402, if the login account and the registered account are not consistent, it is necessary to inquire whether the user of the registered terminal is using the login account to log in, if so, it can be judged that there is a behavior of mixing accounts or stealing accounts (if the registered user of the login account is unaware), which needs to be corrected immediately according to relevant management regulations; Step S403, if the account is the login operation of the registered account user due to work needs on the login terminal computer, it is not a violation behavior.

[0021] The fifth part compares the user terminal tool obtained from the audit system with the terminal tool counted in the registration, and if they are inconsistent, the illegal and irregular use of the account and terminal tool is corrected, and if they are consistent, the next step of comparison is performed; The specific implementation steps are as follows: Step S501, which is performed on the basis of completing steps S3 and S4. By comparing the login terminal tool with the registered terminal tool, it can be found that the user has illegally used the terminal tool, avoiding accidental damage or data damage to the database by the user through illegal tools; Step S502, by comparing the login terminal tool with the registered terminal tool, if it is found that the terminal user is not operated by himself through inquiry, it can be found that the Trojan horse or the terminal is stolen, and other illegal behaviors can be found, and virus killing and setting screen password protection login security measures can be taken to strengthen security.

[0022] The user login time obtained from the audit system is compared with the user working time counted in the registration, if they are inconsistent, the user is questioned about the reason for logging in the system at non-working time, and if they are consistent, the security audit of the database login information is completed; The specific steps are as follows: Step S601, if it is found that the database login time is inconsistent with the working time registered in the registration, the registered account user needs to confirm whether it is himself who logs in the database at the non-working time, if it is himself, further inquiry is needed, if the reason is reasonable, it is considered as normal login, if the reason is unreasonable, the user needs to be ordered to standardize the database login behavior; If the non-working time login database of the deployment record user does not occur, the account leakage problem or the user terminal computer is attacked by hackers, stolen or infected with Trojan virus and the like, then the user needs to take a series of security protection measures such as modifying the database login account password, virus killing of the terminal computer, modifying the terminal computer login account password, setting the screen protection password and the like; In the seventh part, the comparison work of S3 to S6 is repeated for each login information obtained from the database audit system until the comparison work of each database login information is completed, and then the security audit work of the database login information is completed.

[0023] The present application can find the database account leakage, illegal login, mixed account, illegal tool use and other illegal login behaviors by comparing and analyzing the login information of the enterprise and institution database system from the four dimensions of IP address, login account, terminal tool and login time, and can also find the Trojan intrusion, hacker attack and other network threat behaviors, and points out the security measures that can be taken, thereby ensuring the safe login and legal use of the database system and protecting the data security of the enterprise and institution.

[0024] The above examples are only used to illustrate but not to limit the technical solutions of the present application, although the present application is described in detail with reference to the above examples, those skilled in the art should understand that the present application can still be modified or replaced equivalently without departing from the spirit and scope of the present application, any modification or partial replacement should be covered in the scope of the claims of the present application.

Claims

1. A method for security auditing of database login information, characterized in that... Includes the following steps: Step S1: Collect database account and user information for databases that require login security auditing in enterprises and institutions, including user name, position, responsibilities, IP address, database account, permissions, terminal tools and working time information, and compile statistics and file records. Step S2: Export user login information from the database audit system according to the audit cycle, including terminal IP, login account, terminal tool and login time information, for user login information auditing; Step S3 involves comparing the IP addresses exported from the audit system with the pre-registered database user IP addresses. If they do not match, the system queries the network department for the user information corresponding to the IP address, finds the user, confirms the legitimacy of the login behavior, and corrects any illegal login behavior. If they match, proceed to the next comparison step; Step S4 involves comparing the user information and database account information obtained from the audit system with the user information and database account information filed for record. If they do not match, the user will be questioned about the reason for not logging in with their own account, and the illegal use of the account will be corrected. If they match, the next comparison step will be carried out. Step S5 involves comparing the user terminal tools obtained from the audit system with the terminal tools counted in the filing. If they do not match, the illegal or irregular use of accounts and terminal tools will be corrected. If they match, the next comparison step will be performed. Step S6: Compare the user login time obtained from the audit system with the user working time statistics in the filing. If they are inconsistent, question the user about the reason for logging into the system outside of working hours. If they are consistent, the security audit of the database login information is completed. Step S7: Repeat the comparison process from S3 to S6 for each login record obtained from the database auditing system until the comparison process for each database login record is completed.

2. The method for database login information security auditing according to claim 1, characterized in that: In step S3, it is assumed that the data collected and recorded in steps S1 and S2 regarding database user and account information, as well as the data obtained from the database audit system, are completely accurate. This includes the following steps: Step S301: By comparing whether the login IP address is consistent with the registered IP address, it can be found that the user account has been illegally stolen or the account has been leaked. Step S302: By comparing the login IP with the registered IP, it is possible to discover the behavior of some users using multiple accounts. In step S303, if an inconsistency is found, it is necessary to verify with the person in charge of the account in the filing whether the account was used by the person on a terminal with a different IP address. If the person used the account on a computer with a different IP address due to work needs, it is not a violation.

3. The method for database login information security auditing according to claim 1, characterized in that: In step S4, it is assumed that the enterprise or institution has established a sound database account and password management system, and requires users to log in using their own accounts, and prohibits the disclosure and misuse of accounts. This includes the following steps: Step S401: Compare whether the login account matches the registration account. This step is based on step S1. It means that the user information of the login account has been determined and is consistent with the registration user information, that is, the login terminal is the user's registration terminal. Step S402: If the login account is inconsistent with the registration account, ask whether the user of the registration terminal has logged in using the login account. If so, it can be determined that there is a mix-up of accounts or theft of accounts, and it should be corrected immediately in accordance with the relevant management regulations. Step S403: If the login operation is performed on the computer terminal by the user of the registered account due to work needs, it is not considered a violation.

4. The method for database login information security auditing according to claim 1, characterized in that: Step S5 includes the following steps: Step S501: By comparing whether the login terminal tool and the registered terminal tool are consistent, the user's illegal use of the terminal tool can be detected, thus preventing the user from causing accidental damage to the database or data corruption through illegal tools; Step S502: By comparing whether the login terminal tool is consistent with the registered terminal tool, if it can be found that the terminal user is not the one operating it, illegal activities such as Trojan horse or terminal theft can be discovered by asking the terminal user. Security reinforcement measures are taken by virus scanning and setting screen password to protect login security.

5. The method for database login information security auditing according to claim 1, characterized in that: In step S6, by default, enterprises and institutions have standard shift systems and working hours, which include the following steps: Step S601: If it is found that the database login time is inconsistent with the working time registered in the filing, confirm with the user of the account registered in the filing whether it is the user who logged into the database during the non-working time. If it is the user, inquire further about the reason. If the reason is reasonable, it is considered a normal login. If the reason is unreasonable, order the user to regulate the database login behavior. In step S602, if a user who is not registered logs into the database outside of working hours, it may indicate an account leak, a hacker attack, theft, or Trojan virus infection of the user's terminal computer. In this case, the user needs to change the database login account password, perform a virus scan on the terminal computer, change the terminal computer login account password, and set a screen saver password.