Database integrity verification method and device based on operation behaviors and medium

By generating dynamic data fingerprints through real-time monitoring of database operations and conducting risk assessments, the problem of coupling between database integrity verification logic and business logic is solved, achieving dynamic behavior-aware security protection and improving database security capabilities and system performance.

CN121327892APending Publication Date: 2026-01-13天元大数据信用管理有限公司
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511490752.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-17
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

In existing technologies, database integrity verification logic is deeply coupled with business logic, which cannot adapt to rapidly changing business needs, cannot achieve early warning and proactive protection, and has the risk of replay attacks and performance bottlenecks in high-concurrency scenarios.

Method used

By monitoring database operations in real time, generating dynamic data fingerprints and conducting risk assessments, and employing machine learning-based intelligent analysis, dynamic behavior perception-based security protection is achieved.

Benefits of technology

It improves database security protection capabilities, adapts to new attack types, ensures data integrity, and balances system performance and user experience, achieving early warning and proactive protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121327892A_ABST
    Figure CN121327892A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a database integrity verification method and device based on an operation behavior and a medium, and relates to the technical field of databases, the method comprises the steps that database operation is monitored in real time to extract database operation information, the database operation information comprises an operation type, operation data and an operation context, and the operation type is determined according to the operation type, the operation data and the operation context; the operation context comprises a user identifier, a session identifier and a timestamp; according to the operation data and the operation context in the database operation information, generating a dynamic data fingerprint corresponding to the database operation, and writing the dynamic data fingerprint into the secure storage area; and performing database operation risk assessment based on the database operation information and the dynamic data fingerprints to determine current operation risk information, and performing hierarchical response on database operation through the current operation risk information to realize database integrity verification. Traditional static data verification is upgraded into a security protection mode of dynamic behavior perception, and database security protection is realized through multi-level technology fusion.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present specification relates to the technical field of database, and particularly relates to a database integrity verification method based on operation behavior, equipment and medium. BACKGROUND

[0002] In the field of database information security technology, ensuring the integrity and tamper resistance of stored data is a core technical challenge. Existing technologies based on hard-coded verification schemes directly embed integrity verification logic into business code. This method results in a high coupling between verification rules and business logic, and any adjustment of verification rules requires modification of the source code and redeployment of the system, lacking flexibility and scalability.

[0003] Secondly, existing verification schemes based on database constraints use the data integrity constraint mechanism provided by the database management system. Although basic data verification can be achieved, only simple format and range verification is supported, and complex data tampering detection requirements cannot be met, and modification of constraint rules requires database structure changes, affecting system stability. Furthermore, verification schemes based on database triggers execute verification logic by setting triggers in the database. Although this method separates verification logic from business logic, it has problems such as poor database compatibility, large performance overhead, and difficult maintenance, especially in high-concurrency scenarios, which can easily become a system bottleneck. In addition, existing hash verification technology solutions can provide data integrity verification, but usually use static hash algorithms, and the generated hash value is fixed and cannot be changed, which has the risk of being attacked by replay attacks. At the same time, these schemes mostly use passive verification mode, which can only detect after data tampering occurs, and cannot implement pre-warning and active protection.

[0004] Therefore, in the face of increasingly complex database security threats, the verification logic in existing technologies is deeply coupled with business logic, which cannot adapt to rapidly changing business requirements and cannot implement pre-warning and active protection. SUMMARY

[0005] One or more embodiments of the present specification provide a database integrity verification method based on operation behavior, equipment and medium, which solves the technical problem that in the face of increasingly complex database security threats, the verification logic in existing technologies is deeply coupled with business logic, which cannot adapt to rapidly changing business requirements and cannot implement pre-warning and active protection.

[0006] One or more embodiments of the present specification adopt the following technical solutions: The one or more embodiments of the specification provide a database integrity verification method based on operation behavior, the method comprising: monitoring database operations in real time to extract database operation information, wherein the database operation information comprises operation type, operation data and operation context, the operation context comprises user identification, session identification and timestamp; generating a dynamic data fingerprint corresponding to the database operation according to the operation data and the operation context in the database operation information, and writing the dynamic data fingerprint into a secure storage area; performing database operation risk assessment based on the database operation information and the dynamic data fingerprint to determine current operation risk information, and performing hierarchical response on the database operation through the current operation risk information to realize database integrity verification.

[0007] The one or more embodiments of the specification provide a database integrity verification device based on operation behavior, comprising: at least one processor; and a memory in communication connection with the at least one processor; wherein The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the above method.

[0008] The one or more embodiments of the specification provide a non-volatile computer storage medium, which stores computer executable instructions, and the computer executable instructions are configured to execute the above method.

[0009] The above-mentioned at least one technical solution adopted in the embodiments of this specification can achieve the following beneficial effects: Through the technical solutions of the embodiments of this specification, the traditional static data verification is upgraded to a dynamic behavior-aware security protection mode, and database security protection is achieved through multi-layered technical integration. First, deep monitoring of database operations is achieved through embedded probes in the database driver layer, breaking through the limitations of traditional solutions at the application layer or database layer. It can capture complete operation information at the lowest level of database operation, including operation type, operation data, and operation context containing user identifier, session identifier, and timestamp. Deep monitoring ensures the integrity and authenticity of operation information. In the process of dynamic data fingerprint generation, operation data and operation context are fused and processed. Through nonlinear transformation and encryption algorithms, dynamic fingerprints with spatiotemporal characteristics are generated, breaking the static characteristics of traditional hash verification, so that each data fingerprint has a unique contextual association. The field information of the operation data is deeply bound to user identity, session state, and time factors. Through dual processing of chaotic mapping and lightweight encryption, the data fingerprint is ensured to possess both irreversible encryption characteristics and high sensitivity to the operating environment, effectively defending against replay attacks and static analysis. This is because even the same operation data will generate completely different fingerprints in different contexts, greatly enhancing the system's anti-tampering capabilities. Machine learning-based intelligent analysis is employed, using a long short-term memory network to deeply model user operation sequences, accurately identifying the degree of deviation from normal behavior patterns. Compared to traditional rule matching, behavior analysis offers higher accuracy and adaptability. Differentiated protection strategies are adopted based on risk assessment results, achieving a balance between security protection and system performance, avoiding the limitations of the "one-size-fits-all" protection strategies in traditional solutions. The integrity verification principle based on behavior analysis not only effectively defends against known security threats but also adapts to new attack types, improving database security capabilities and ensuring data integrity while also considering system performance and user experience. Attached Figure Description

[0010] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings: Figure 1 A flowchart illustrating a database integrity verification method based on operational behavior, provided as an embodiment of this specification; Figure 2 This is a schematic diagram of a database integrity verification device based on operational behavior, provided as an embodiment of this specification. Detailed Implementation

[0011] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.

[0012] This specification provides a database integrity verification method based on operational behavior. It should be noted that the execution subject in this specification embodiment can be a server or any device with data processing capabilities. Figure 1 A flowchart illustrating a database integrity verification method based on operational behavior, as provided in the embodiments of this specification, is shown below. Figure 1 As shown, the main steps include the following: Step S101: Monitor database operations in real time to extract database operation information.

[0013] The database operation information includes operation type, operation data, and operation context, and the operation context includes user identifier, session identifier, and timestamp; Real-time monitoring of database operations to extract database operation information specifically includes: capturing the Structured Query Language (SCL) execution plan through an embedded probe in the database driver layer to parse the operation type from the SCL execution plan, where the operation type includes insert, update, and delete operations; obtaining the user identifier and session identifier from the database connection pool and obtaining the current timestamp through the system clock; extracting operation data from the database operation parameters, which includes the names and values ​​of the table fields being operated on; combining the user identifier, session identifier, and current timestamp to determine the operation context; and generating database operation information based on the operation type, the operation data, and the operation context.

[0014] In one embodiment of this specification, database integrity verification can be understood as proactive database integrity protection. First, database operations are monitored in real time and database operation information is extracted. This is achieved through an embedded probe embedded in the database driver layer. The embedded probe is embedded in the database connection component as a transparent proxy and automatically initializes and registers monitoring hook functions when the database driver is loaded. When the application initiates a database operation through the database connection pool, the embedded probe first intercepts the Structured Query Language (SCL) execution plan, which contains the complete SQL statement text, execution parameters, and metadata information.

[0015] The probe uses a syntax parser to perform lexical and syntactic analysis on SQL statements, identifying and classifying them into insert, update, or delete operations. This classification process is based on keyword matching and syntactic structure recognition of the SQL statements. Insert operations are identified using the INSERT keyword, update operations using the UPDATE keyword, and delete operations using the DELETE keyword. Simultaneously, the probe retrieves the user identifier and session identifier corresponding to the current connection from the database connection pool's session manager. The user identifier originates from the credential information established during database authentication, and the session identifier comes from the unique session token generated during database connection. These two identifiers together form the basis for tracing the operation's identity. Timestamp information is obtained by calling the operating system's nanosecond-precision clock interface, ensuring the accuracy and uniqueness of the timestamp.

[0016] The process of extracting operational data involves in-depth analysis of the SQL execution plan. The probe first identifies the names of the data tables involved in the statement, then parses the field assignment information in the SET clause, VALUES clause, or WHERE clause, and extracts the names of the table fields being operated on and their corresponding values. For parameter placeholders in the pre-compiled statement, the probe combines runtime parameter binding information to complete the specification of the field values.

[0017] After acquiring complete operation data, the user identifier, session identifier, and timestamp are combined and encapsulated to form a structured operation context. This context not only contains basic identity and time information but also records the temporal relationship of operations and session trajectories. Finally, the operation type, operation data, and operation context are correlated and integrated to generate complete database operation information. This information is serialized using a unified JSON format and includes three components: operation metadata, data content, and context information. This provides a complete data foundation for subsequent dynamic data fingerprint generation and risk assessment. The entire monitoring process is completed synchronously at the database driver layer, without relying on upper-layer application frameworks, ensuring the real-time performance and accuracy of monitoring. Simultaneously, memory mapping technology and a zero-copy mechanism optimize data transmission efficiency, avoiding significant impact on database operation performance.

[0018] Traditional solutions typically rely on application-layer interception or database triggers, which have significant architectural limitations. Application-layer interception requires modification of business code or reliance on extension points of specific frameworks, resulting in deep coupling between monitoring logic and business logic. Any architectural adjustments or technology stack changes may compromise the integrity of monitoring functionality. While database triggers decouple monitoring from business logic, they introduce additional database load, potentially becoming a system bottleneck in high-concurrency scenarios and proving difficult to adapt to distributed database environments. The technical solution in this specification achieves monitoring through embedded probes in the database driver layer, offering significant advantages in its technical architecture. As the essential pathway for database access, the driver layer can capture all database operations without omission, ensuring comprehensive and reliable monitoring. The embedded design makes the monitoring process completely transparent to upper-layer applications, enabling functional integration without modifying any business code, greatly reducing system maintenance costs and upgrade complexity. Simultaneously, driver-layer monitoring avoids the performance overhead of database triggers, ensuring high efficiency through kernel-level optimization. Traditional solutions often only obtain limited operational information, making it difficult to reconstruct the complete operational context. The technical solutions in the embodiments of this specification, through deep analysis of SQL execution plans and database connection states, can extract comprehensive operational information, including user identity, session history, and time series, providing a rich data foundation for subsequent security analysis. The complete construction of the operational context enables the system to accurately trace the source and intent of each operation, facilitating behavioral analysis and risk assessment. Furthermore, the implementation methods of the technical solutions in the embodiments of this specification have good versatility and adaptability. Since the monitoring function is built at the database driver level, it is not limited by specific business logic and technical architecture, and can be applied to various application systems based on standard database access. This allows for rapid deployment to existing systems, obtaining complete database operation monitoring capabilities without large-scale modifications, minimizing migration costs and technical risks while ensuring security.

[0019] Step S102: Based on the operation data and operation context in the database operation information, generate a dynamic data fingerprint corresponding to the database operation, and write the dynamic data fingerprint into the secure storage area.

[0020] Based on the operation data and operation context in the database operation information, a dynamic data fingerprint corresponding to the database operation is generated. Specifically, this includes: concatenating the field names and values ​​in the operation data into a data string in a preset order, and concatenating the user identifier, session identifier, and timestamp in the operation context into a context string; combining the data string and context string to determine the data to be encrypted; sequentially performing nonlinear transformation and encryption processing on the data to be encrypted to generate a dynamic data fingerprint; and storing the generated dynamic data fingerprint in a secure storage area, associated with the corresponding operation context. Alternatively, the process of sequentially performing nonlinear transformation and encryption processing on the data to be encrypted to generate a dynamic data fingerprint includes: performing a nonlinear transformation on the data to be encrypted using a chaotic mapping function to generate an intermediate hash value; encrypting the intermediate hash value using a preset lightweight encryption algorithm to generate the final dynamic data fingerprint; adding a timestamp index and a user identifier index to the dynamic data fingerprint and writing it to the secure storage area.

[0021] In one embodiment of this specification, the process of generating dynamic data fingerprints first requires standardization of the operation data and operation context in the database operation information. Field names and values ​​in the operation data are sorted according to the defined order of the database table structure. This sorting rule is based on the physical storage order of fields defined in the database metadata, ensuring that the same data content generates a consistent string sequence in different operations. For each field name and value, standardized encoding is performed in key-value pair form. Field names use the original names defined in the database system table, while field values ​​are normalized according to their data type. String data uses a unified character encoding and removes leading and trailing spaces, numeric data is converted to a normalized number format, and date and time data is converted to a standard timestamp representation.

[0022] After standardizing all fields, the key-value pairs are concatenated using specific delimiters according to a preset field order to form a standardized data string. This data string completely records all data changes involved in the operation. Simultaneously, the user identifier, session identifier, and timestamp in the operation context are also concatenated according to a fixed format. The user identifier uses a unique user number from the database authentication system, the session identifier uses a globally unique identifier generated during database connection, and the timestamp is converted to a high-precision standardized time format. These three elements are connected using specific delimiters to form the context string.

[0023] Next, the data string and context string are combined in a fixed order, separated by a delimiter. The combined data forms a data block to be encrypted, containing complete information about the operation content and context. In the nonlinear transformation stage, the system uses a chaotic mapping function to process the data block. This function initializes a chaotic system with specific system parameters, mapping the input data to the phase space of the chaotic system for multiple rounds of iterative transformation. Each iteration performs nonlinear obfuscation and diffusion processing on the data based on the dynamic characteristics of the chaotic system. This transformation ensures that even small changes in the input data lead to significant differences in the output, generating an intermediate hash value with high randomness and unpredictability. After the nonlinear transformation, a lightweight encryption algorithm is used to encrypt the intermediate hash value. This algorithm employs a symmetric encryption mechanism suitable for real-time computation, using a multi-round Feistel network structure to obfuscate and diffuse the data. Each round uses a subkey derived from the system master key for encryption, ultimately generating a fixed-length dynamic data fingerprint.

[0024] To facilitate subsequent queries and verification, an index is created for each dynamic data fingerprint. The timestamp index is built based on the time point of the operation, supporting fast retrieval by time range. The user identifier index is built based on the operator's identity information, supporting data tracking by user dimension. Finally, the dynamic data fingerprint and its index information are written to a secure storage area through a secure channel. This area uses a data storage system with access control mechanisms to ensure that only authorized system components can access the stored fingerprint data, while data redundancy mechanisms ensure storage reliability. The entire generation process is completed in memory, avoiding disk temporary storage of sensitive data and ensuring the security of data processing.

[0025] Traditional methods typically generate fixed hash values ​​based solely on the data content itself, making them vulnerable to replay attacks and data tampering. The technical solutions in this specification establish a more robust and comprehensive data integrity protection mechanism by introducing operational context information and multi-layered security transformations. By incorporating contextual information such as user identifiers, session identifiers, and timestamps into the fingerprint generation process, each data fingerprint possesses spatiotemporal specificity and user association, effectively preventing replay attacks by attackers copying legitimate data fingerprints. Even if an attacker obtains valid data content, the generated fingerprint cannot pass the verification system's check because the specific operational context cannot be copied. This mechanism fundamentally solves the inherent defects of traditional hash verification in preventing replay attacks. The introduction of chaotic mapping functions makes data fingerprints highly random and unpredictable; even slight differences in input data can lead to significant changes in the output fingerprint, effectively preventing collision attacks and prediction attacks. The application of lightweight encryption algorithms ensures that even if fingerprint data is illegally obtained, attackers cannot reverse engineer the original data content, protecting data confidentiality. The indexing mechanism of the secure storage area enables fingerprint query and verification operations to be completed quickly, meeting real-time requirements. Standardized data processing workflows ensure the system can adapt to different types of database operation scenarios, exhibiting excellent versatility and scalability. The entire generation process is designed with the needs of real-world application environments in mind, providing robust security protection while maintaining system availability and ease of maintenance. It can meet the usage requirements of application scenarios with stringent data integrity requirements, providing a more reliable means of protecting critical business data.

[0026] Step S103: Based on database operation information and dynamic data fingerprints, perform database operation risk assessment to determine the current operation risk information. Based on the current operation risk information, perform graded responses to database operations to achieve database integrity verification.

[0027] Based on the database operation information and the dynamic data fingerprint, a database operation risk assessment is performed to determine the current operation risk information. Specifically, this includes: extracting the operation sequence of the same user within a preset time window from historical operation logs; calculating operation frequency characteristics and operation pattern characteristics based on the operation sequence; inputting the current database operation information, the dynamic data fingerprint sequence, and the operation frequency and operation pattern characteristics into a pre-trained risk assessment model; and outputting a risk score for the current operation through the risk assessment model to form the current operation risk information. Alternatively, inputting the current database operation information, the dynamic data fingerprint sequence, and the operation frequency and operation pattern characteristics into a pre-trained risk assessment model includes: obtaining the current user's historical dynamic data fingerprint from the secure storage area to form a dynamic data fingerprint sequence; calculating the feature deviation degree between the current operation and the historical operation pattern, where the feature deviation degree includes operation time interval deviation and operation type distribution deviation; evaluating the data sensitivity level of the operation data through a data classification model; inputting the dynamic data fingerprint sequence, feature deviation degree, and data sensitivity level into a long short-term memory network model; and calculating a risk score through the long short-term memory network model, which represents the degree to which the current operation deviates from the normal behavior pattern.

[0028] In one embodiment of this specification, during the database operation risk assessment process, the complete operation sequence of the current user within a preset time window is first extracted from the historical operation log storage system. This time window is dynamically adjusted according to the system security policy and typically covers the user's most recent activity period. The extracted operation sequence contains detailed records of all database operations performed by the user within that time period, including the timestamp of each operation, operation type, involved data tables, operation conditions, and corresponding dynamic data fingerprint.

[0029] Based on this historical operation data, two key behavioral characteristics are calculated: operation frequency characteristics and operation pattern characteristics. Operation frequency characteristics are quantified by statistically analyzing the number of operations performed by the user per unit time, the distribution of operation intervals, and the trend of operation frequency changes. A sliding time window algorithm is used to calculate the user's operation frequency baseline in real time and detect the degree of deviation between the current operation frequency and the historical baseline. Operation pattern characteristics are established by analyzing the user's historical operation habits, including the user's commonly used data table access patterns, typical operation time distribution characteristics, and preferred query condition patterns. Pattern recognition algorithms are used to perform cluster analysis on the user's historical operation sequences to extract operation pattern templates that represent the user's normal behavioral characteristics.

[0030] After feature calculation, the historical dynamic data fingerprints of the current user are retrieved from the secure storage area. These fingerprints are arranged in chronological order to form a dynamic data fingerprint sequence, which records the data change trajectory of the user's historical operations. Feature deviation is calculated by comparing the current operation with historical operation patterns. Operation time interval deviation is quantified by analyzing the difference between the current operation's occurrence time and the user's typical operation time pattern, while operation type distribution deviation is evaluated by comparing the matching degree between the current operation type and the user's historical operation type distribution. Simultaneously, a pre-trained data classification model is used to evaluate the data sensitivity level of the operation data. This model, based on data classification strategies and access control rules, analyzes the importance of the data tables involved in the operation, the sensitivity level of the data fields, and the potential security impact of the operation, outputting a corresponding sensitivity rating.

[0031] After all feature preparation is complete, the dynamic data fingerprint sequence, feature bias, and data sensitivity level are input into a pre-trained Long Short-Term Memory (LSTM) network model for comprehensive analysis. This network model, through its unique memory unit structure and gating mechanism, effectively captures temporal dependencies and pattern change features in operation sequences. The input layer receives standardized feature vectors, the hidden layer extracts sequence features through iterative calculations over multiple time steps, and the output layer calculates the final risk score using a fully connected network and activation functions. During training, the LTM network learns the distinguishing boundary between normal user behavior patterns and abnormal operation patterns, accurately assessing the degree to which the current operation deviates from the normal behavior pattern.

[0032] The risk score output by the risk assessment model is a continuous numerical value, representing the probability of a security threat posed by the current operation. A higher score indicates a greater degree of operational anomaly. Based on this risk score, complete risk information for the current operation is generated, including risk level classification, risk factor analysis, and corresponding confidence assessments, providing an accurate and reliable basis for subsequent tiered response decisions. The entire risk assessment process employs a real-time stream processing architecture to ensure that risk assessment is completed before database operations are executed. Simultaneously, model compression and computational optimization techniques ensure assessment efficiency and meet the real-time requirements of high-concurrency scenarios.

[0033] Traditional methods typically rely on predefined static rules and thresholds, making them ill-suited to complex real-world application scenarios and constantly evolving security threats. The technical solutions in this specification, through the introduction of multi-layered feature analysis and deep learning models, establish a more intelligent and adaptive risk assessment system. By comprehensively utilizing multi-dimensional information such as operation frequency characteristics, operation pattern characteristics, and dynamic data fingerprint sequences, the system can comprehensively assess operational risks from different perspectives, avoiding the limitations of single-feature assessments. In particular, the introduction of dynamic data fingerprint sequences allows for tracking the complete trajectory of data changes, enabling in-depth analysis of the rationality of operational behaviors at the data level. The technical solutions in this specification achieve accurate modeling of temporal behavior patterns through a Long Short-Term Memory (LSTM) network model. This model can effectively learn the long-term dependencies and periodic characteristics of user behavior, accurately distinguishing between normal operational behavior and potential threat behavior. Compared to traditional statistical threshold-based methods, deep learning models can capture more complex and concealed abnormal patterns, significantly improving the accuracy and recall rate of risk identification and reducing the probability of false positives and false negatives. This system achieves continuous optimization of risk assessment capabilities through a continuous learning mechanism, dynamically updating the user behavior model based on new operational data to adapt to changes and evolution in operational patterns. This adaptability ensures that the risk assessment model maintains accuracy as the system's operating environment changes, avoiding the gradual ineffectiveness of traditional methods due to rigid rules. Simultaneously, the dynamic calculation mechanism of feature bias allows the system to automatically adjust assessment criteria based on changes in user behavior, ensuring the fairness and accuracy of risk assessment. Engineering optimization achieves a balance between complex algorithms and real-time requirements. Despite employing a relatively complex deep learning model, techniques such as model compression, computational optimization, and parallel processing ensure both assessment accuracy and real-time performance. This allows the solution to be widely applied in various production environments with high security requirements, providing more reliable and intelligent protection for database operation security.

[0034] Based on the current operation risk information, a tiered response is implemented for the database operation. Specifically, this includes: determining the risk score in the current operation risk information; when the risk score is lower than a preset low-risk threshold, performing fingerprint consistency verification on the dynamic data fingerprint using historical dynamic fingerprints pre-stored in the secure storage area; if the fingerprint consistency verification passes, the operation is allowed; when the risk score is not lower than the low-risk threshold and not higher than a preset high-risk threshold, a secondary authentication process is triggered; when the risk score is higher than the high-risk threshold, the database operation is blocked and an alarm message is generated. Triggering the secondary authentication process specifically includes: extracting the user identifier from the operation context to query the associated authentication method information based on the user identifier; sending an authentication request to the authentication server based on the authentication method information, wherein the authentication request includes the user identifier and operation type; receiving the authentication result returned by the authentication server; when the authentication result is successful, the database operation is allowed; when the authentication result is unsuccessful, the database operation is blocked and an authentication failure log is recorded.

[0035] In one embodiment of this specification, a standardized risk score is first extracted from the current operational risk information. This score is a continuous value calculated by a risk assessment model based on multi-dimensional feature analysis, reflecting the degree to which the current operation deviates from the normal behavioral pattern. This risk score is then compared with two preset key thresholds, which are derived through statistical analysis of historical security events and dynamic adjustments based on system security policies.

[0036] When the risk score is below a preset low-risk threshold, the system determines that the current operation is within a safe range and initiates a fingerprint consistency verification process. First, it retrieves historical dynamic fingerprints related to the current operation from the secure storage area. These historical fingerprints are arranged chronologically and contain data fingerprint records of the user's recent operations. The dynamic data fingerprint generated by the current operation is compared item by item with the retrieved historical dynamic fingerprints. The comparison process uses a specific similarity calculation algorithm to analyze the degree of consistency between the two fingerprints in terms of numerical features, trends, and patterns. If the fingerprint consistency verification passes, it indicates that the current operation conforms to the user's historical behavior patterns and data change rules. An execution permission command is sent to the database driver layer, allowing the operation to execute normally. Simultaneously, an audit log recording the successful verification is recorded.

[0037] When the risk score is neither lower than the low-risk threshold nor higher than the high-risk threshold, the current operation is deemed to pose a certain risk, requiring further verification of the operator's identity and triggering a secondary authentication process. First, the user identifier is extracted from the operation context. Based on this identifier, the authentication method configuration information stored in the user management system is queried. This configuration information includes various preset authentication methods and their priority order. The most suitable authentication method for the current risk level is selected based on the authentication method configuration information. Common authentication methods include, but are not limited to, SMS verification codes, email verification links, biometric recognition, or multi-factor authentication combinations. After selecting an authentication method, a structured authentication request is sent to the authentication server. This request includes necessary information such as the user identifier, current operation type, risk level, and session identifier. Upon receiving the request, the authentication server executes the corresponding authentication process according to the preset authentication policy, such as generating and sending a verification code to the user's bound mobile device, or pushing the authentication request to the user's authentication application. After the user completes the authentication operation within the specified time, the authentication server returns the authentication result. If the authentication result is successful, it indicates that the user's identity has been confirmed, allowing the database operation to continue, and simultaneously recording the successful authentication audit information. If the authentication result fails, the database operation will be blocked immediately, preventing any data changes from being executed, and detailed authentication failure log information will be recorded, including the reason for failure, authentication method, timestamp, and other key information.

[0038] When the risk score exceeds a preset high-risk threshold, the current operation is deemed a significant security threat. The system immediately activates a blocking mechanism, using the database driver layer's operation interception function to prevent the execution of SQL statements and generating detailed alarm information. This alarm information includes complete data such as the risk score, operation content, user identifier, session information, and risk assessment basis. This information is sent to the security monitoring system in real time, triggering audible and visual alarms and notification mechanisms to alert security management personnel for timely intervention. Throughout the tiered response process, the system continuously monitors the operation's execution status and the system's response effectiveness, dynamically adjusting response strategy parameters based on actual conditions to ensure an optimal balance between security protection effectiveness and system performance.

[0039] Traditional security solutions typically employ a "one-size-fits-all" approach, either allowing operations completely or blocking access entirely. This binary decision-making model is ill-suited to complex and ever-changing real-world application scenarios. The technical solutions described in this specification introduce a refined, tiered response mechanism, establishing a more intelligent and flexible security protection system. Through a multi-level response strategy based on risk scoring, the technical solutions in this specification can take appropriate protective measures according to the threat level, avoiding over-protection that could interfere with normal business operations while ensuring that high-risk operations are blocked promptly and effectively. In particular, the secondary authentication mechanism in medium-risk scenarios maintains a balance between security and user experience; this refined response strategy is lacking in traditional security solutions. In the technical solutions of the embodiments of this specification, low-risk operations only require lightweight fingerprint consistency verification, greatly reducing the time overhead of security verification; medium-risk operations provide an additional security barrier through secondary authentication; only high-risk operations trigger a complete blocking and alarm process. This differentiated processing method ensures that security resources can be concentrated on real threat protection, improving overall operational efficiency. The technical solutions of the embodiments of this specification reduce unnecessary operational interruptions through intelligent response strategies. Based on multi-dimensional risk assessment and refined response grading, they can accurately distinguish between normal operations and abnormal behaviors, ensuring security while maximizing the smooth operation of business. Through parameterized threshold configuration and a scalable response mechanism, they provide good adaptability. Security administrators can flexibly adjust risk thresholds and response rules according to business needs and security policies, and can continuously optimize them as the business environment changes. They can adapt to application scenarios of different sizes and organizational structures, providing reliable security for various database systems.

[0040] The technical solutions implemented in this specification upgrade traditional static data verification to a dynamic behavior-aware security protection mode, achieving database security protection through multi-layered technical integration. Firstly, an embedded probe in the database driver layer enables deep monitoring of database operations, overcoming the limitations of traditional solutions at the application or database layer. This allows for the capture of complete operation information at the lowest level of database operations, including operation type, operation data, and operation context containing user identifiers, session identifiers, and timestamps. Deep monitoring ensures the integrity and authenticity of operation information. During dynamic data fingerprint generation, operation data and operation context are fused, generating dynamic fingerprints with spatiotemporal characteristics through nonlinear transformation and encryption algorithms. This breaks the static nature of traditional hash verification, ensuring each data fingerprint has unique contextual association. The field information of the operation data is deeply bound to user identity, session state, and time factors. Through dual processing of chaotic mapping and lightweight encryption, the data fingerprint possesses both irreversible encryption characteristics and maintains high sensitivity to the operating environment, effectively defending against replay attacks and static analysis. Even the same operation data will generate completely different fingerprints in different contexts, greatly enhancing the system's anti-tampering capabilities. Employing machine learning-based intelligent analysis, this approach uses Long Short-Term Memory (LSTM) networks to deeply model user action sequences, accurately identifying deviations from normal behavioral patterns. Compared to traditional rule-based matching, behavior analysis offers higher accuracy and adaptability. Differentiated protection strategies are implemented based on risk assessment results, achieving a balance between security and system performance, avoiding the limitations of traditional "one-size-fits-all" protection strategies. The integrity verification principle based on behavior analysis not only effectively defends against known security threats but also adapts to new attack types, improving database security capabilities and ensuring data integrity while simultaneously considering system performance and user experience.

[0041] This specification also provides an embodiment of a database integrity verification device based on operational behavior, such as... Figure 2 As shown, the device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the above-described method.

[0042] This specification also provides a non-volatile computer storage medium storing computer-executable instructions configured to perform the above-described method.

[0043] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments of apparatus, devices, and non-volatile computer storage media are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0044] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0045] The devices, media, and methods provided in the embodiments of this specification are one-to-one correspondences. Therefore, the devices and media also have similar beneficial technical effects as their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the devices and media will not be repeated here.

[0046] Those skilled in the art will understand that embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this specification may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0047] This specification is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0048] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0049] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0050] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0051] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0052] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0053] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0054] The above description is merely one or more embodiments of this specification and is not intended to limit this specification. Various modifications and variations can be made to the one or more embodiments of this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of one or more embodiments of this specification should be included within the scope of the claims of this specification.

Claims

1. A method for database integrity check based on operational behavior, characterized in that, The method comprises: Real-time monitoring of database operations to extract database operation information, wherein the database operation information comprises operation type, operation data and operation context, and the operation context comprises user identification, session identification and timestamp; According to the operation data and the operation context in the database operation information, a dynamic data fingerprint corresponding to the database operation is generated, and the dynamic data fingerprint is written into a secure storage area; Based on the database operation information and the dynamic data fingerprint, database operation risk assessment is carried out to determine the current operation risk information, and the database operation is responded by the current operation risk information to realize database integrity verification.

2. The method for database integrity check based on operation behavior according to claim 1, characterized in that, Real-time monitoring of database operations to extract database operation information, specifically comprising: Capture the structured query language execution plan through the embedded probe in the database driver layer to parse the operation type from the structured query language execution plan, wherein the operation type includes insert, update and delete operation; Obtain user identification and session identification from the database connection pool, and obtain the current timestamp through the system clock; Extract operation data from the database operation parameters, and the operation data includes the table field name and field value operated; Combine the user identification, the session identification and the current timestamp to determine the operation context, and generate the database operation information based on the operation type, the operation data and the operation context.

3. The method of claim 1, wherein, According to the operation data and the operation context in the database operation information, a dynamic data fingerprint corresponding to the database operation is generated, specifically comprising: Splice the field name and field value in the operation data into a data string in a predetermined order, and splice the user identification, the session identification and the timestamp in the operation context into a context string; Combine the data string and the context string to determine the data to be encrypted; Perform nonlinear transformation and encryption processing on the data to be encrypted in sequence to generate a dynamic data fingerprint, and store the generated dynamic data fingerprint and the corresponding operation context in a secure storage area.

4. The method of claim 3, wherein, Perform nonlinear transformation and encryption processing on the data to be encrypted in sequence to generate a dynamic data fingerprint, specifically comprising: Use a chaotic mapping function to perform nonlinear transformation on the data to be encrypted to generate an intermediate hash value, and use a preset lightweight encryption algorithm to perform encryption processing on the intermediate hash value to generate a final dynamic data fingerprint; Add timestamp index and user identification index to the dynamic data fingerprint, and write it into a secure storage area.

5. The method of claim 1, wherein, Based on the database operation information and the dynamic data fingerprint, database operation risk assessment is carried out to determine the current operation risk information, specifically comprising: Extract the operation sequence of the same user within a preset time window from the historical operation log; Calculate the operation frequency feature and the operation mode feature based on the operation sequence; Input the current database operation information, dynamic data fingerprint sequence, and the operation frequency feature and operation mode feature into a pre-trained risk assessment model; The risk assessment model outputs a risk score of the current operation, forming current operation risk information.

6. The method of claim 5, wherein, The current database operation information, the dynamic data fingerprint sequence, the operation frequency feature, and the operation mode feature are input into a pre-trained risk assessment model, specifically including: The historical dynamic data fingerprints of the current user are obtained from the secure storage area, forming a dynamic data fingerprint sequence; The feature deviation degree of the current operation and the historical operation mode is calculated, wherein the feature deviation degree includes operation time interval deviation and operation type distribution deviation; The data sensitivity level of the operation data is evaluated by a data classification model; The dynamic data fingerprint sequence, the feature deviation degree, and the data sensitivity level are input into a long short-term memory network model; The risk score is calculated by the long short-term memory network model, and the risk score represents the degree of deviation of the current operation from the normal behavior mode.

7. The method of claim 1, wherein, The database operation is responded to by the current operation risk information, specifically including: The risk score in the current operation risk information is determined; When the risk score is lower than a preset low risk threshold, the dynamic data fingerprint is verified for fingerprint consistency by the historical dynamic fingerprint pre-stored in the secure storage area, and the operation is allowed to be executed when the fingerprint consistency verification is passed; When the risk score is not lower than the low risk threshold and not higher than a preset high risk threshold, a secondary authentication process is triggered; When the risk score is higher than the high risk threshold, the database operation is blocked and an alarm information is generated.

8. The method of claim 7, wherein, The secondary authentication process is triggered, specifically including: The user identifier is extracted from the operation context to query the associated authentication method information based on the user identifier; According to the authentication method information, an authentication request is sent to an authentication server, wherein the authentication request includes the user identifier and the operation type; An authentication result returned by the authentication server is received, and when the authentication result is successful, the database operation is allowed to be executed; When the authentication result is failed, the database operation is blocked and an authentication failure log is recorded.

9. An operation-behavior-based database integrity verification device, characterized by comprising: The device includes: at least one processor; and a memory connected with the at least one processor in communication; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1-8.

10. A non-volatile computer storage medium storing computer-executable instructions, characterized in that, The computer executable instructions are configured to perform the method of any one of claims 1-8. The computer executable instructions are configured to perform the method of any one of claims 1-8.

Citation Information

Cited By

  • Database data tampering-oriented security detection method and device, equipment and medium

    CN122113093A