A database monitoring method, system and server

By monitoring and auditing database operations performed by database administrators through nameless pipelines on the server, the problems of missed audits and permission control in the existing technology are solved, and the security of the database is improved.

CN114328119BActive Publication Date: 2025-05-13SHENZHEN ANTECH TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202111669782.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-31
Publication Date
2025-05-13
Estimated Expiration
2041-12-31

AI Technical Summary

Technical Problem

The existing technology cannot effectively monitor and control database operations performed by database administrators through local nameless pipelines, resulting in missed audits and permission control being difficult and insufficient security.

Method used

By implementing the database monitoring method on the server, the first data written by the terminal is read, protocol analysis and copying is performed, and the database audit system is sent for auditing, and the database statements are matched and the operations with insufficient permissions are modified to perform permission control.

Benefits of technology

Real-time audit and permission control of database administrators through local unnamed pipeline operations is realized to prevent missed audits and improve database security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114328119B_ABST
    Figure CN114328119B_ABST
Patent Text Reader

Abstract

The present application discloses a database monitoring method, system and server. The method is applied to the server and includes: reading the first data written by the terminal into the first pipeline file, the first data including the operation information of the database; performing protocol parsing on the first data to obtain the first database statement, and copying the first data, and sending the copied first data to the database audit system for auditing; performing permission matching on the first database statement, if the permission matching fails, then changing the first database statement to obtain the second database statement; performing protocol conversion on the second database statement to obtain the second data and write it into the first pipeline file, so that the terminal operates the database according to the second data. On the one hand, the first data is copied and sent to the database audit system for auditing to prevent missed audits; on the other hand, the permission matching on the first database statement is performed, and the operation with insufficient permission is changed to perform permission control, thereby improving the security of the database.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and in particular to a database monitoring method, system and server. Background Art

[0002] In recent years, with the rapid development of Internet technology, database applications have become more and more extensive. As an important part of the Internet system, how to protect the security of database use has become increasingly important.

[0003] Interprocess Communication (IPC) refers to the transmission or exchange of information between different processes. Simply put, processes can send data to each other. IPC methods usually include pipes, including unnamed pipes and named pipes, message queues, semaphores, and shared storage unnamed pipes. Unnamed pipes are special files in the Linux system kernel. Features include: (1) It is half-duplex, that is, data can only flow in one direction, with fixed read and write ends. (2) It can only be used for communication between processes with kinship, that is, between parent and child processes or brother processes, to achieve file sharing that depends on parent and child processes. (3) It can be regarded as a special file, and ordinary read, write and other functions can be used to read and write it. However, it does not belong to any other file system and only exists in memory.

[0004] In the daily operation and maintenance process, the database administrator (DBA) often needs to log in to the database host to perform relevant database operations. However, when the DBA uses the SQLPlus tool that comes with the Oracle database for local interaction, it does not interact through the non-linear output (line out) port and the network port, but through the local IPC unnamed pipe. It is impossible to capture data traffic through the network protocol stack, and it is impossible to audit, control permissions, and desensitize in the traditional way. Therefore, the existing database audit, database firewall, and dynamic desensitization products cannot obtain this part of the access data traffic, which ultimately leads to missed audits and the inability to effectively control permissions and desensitize data.

[0005] Although the prior art can obtain SQLPlus traffic for auditing through HOOK technology, it only has auditing function and cannot perform permission control. Moreover, injecting HOOK on the relevant API of the operating system to obtain data, rewrite data, and output database operation logs is not only difficult, but also intrudes greatly on the operating system and is not secure enough. Therefore, during the invention process, the inventor found that it is necessary to propose a database security monitoring method to monitor the database operation behavior performed by the database administrator through the local unnamed pipe to enhance the security of the database. Summary of the invention

[0006] The present application provides a database monitoring method, system and server. On the one hand, the first data is copied and sent to the database audit system for auditing to prevent missed audits; on the other hand, the first database statement is matched with permissions, and operations with insufficient permissions are changed to perform permission control, thereby improving the security of the database.

[0007] The embodiment of the present invention provides the following technical solutions:

[0008] In a first aspect, an embodiment of the present invention provides a database monitoring method, which is applied to a server, wherein the server is communicatively connected with a terminal and a database audit system, and the server includes a database. The method includes:

[0009] Reading first data written by a terminal into a first pipeline file, the first data including operation information on a database;

[0010] Performing protocol parsing on the first data to obtain a first database statement, copying the first data, and sending the copied first data to a database audit system for auditing;

[0011] Performing permission matching on the first database statement, if the permission matching fails, modifying the first database statement to obtain a second database statement;

[0012] The second database statement is converted into a protocol to obtain second data and write the second data into the first pipeline file, so that the terminal operates the database according to the second data.

[0013] In some embodiments, the method further comprises:

[0014] If the permission match succeeds, the first database statement is not changed and is used as the second database statement.

[0015] In some embodiments, the terminal has a first permission, and performing permission matching on the first database statement includes:

[0016] identifying a target table in a first database statement;

[0017] If the permission level corresponding to the target table is higher than the first permission, the permission matching fails;

[0018] If the permission level corresponding to the target table is not higher than the first permission, the permission matching is successful.

[0019] In some embodiments, the method further comprises:

[0020] Determine whether the first database statement contains any high-risk operations;

[0021] If the first database statement contains high-risk operations or fails to match permissions, the first database statement is modified to obtain a second database statement;

[0022] If the first database statement does not contain any high-risk operations and the permission matching succeeds, the first database statement is not changed and is directly used as the second database statement.

[0023] In some embodiments, the terminal runs a client tool and a database service process, the client tool performs unidirectional data transmission with the database service process through a first pipe file, and the database service process performs unidirectional data transmission with the client tool through a second pipe file, and the method further includes:

[0024] Read the third data written by the terminal into the second pipeline file, perform protocol analysis on the third data to obtain fourth data, and copy the third data to send to the database audit system for audit, wherein the third data is the data sent by the database to the terminal;

[0025] The fourth data is desensitized to obtain fifth data, and the fifth data is converted into a protocol and then written into the second pipeline file.

[0026] In some embodiments, the method further comprises:

[0027] After obtaining the second data and writing it into the first pipeline file, sending the first information to the database audit system, wherein the first information includes operation information on the first data;

[0028] After the fifth data is converted into a protocol and written into the second pipeline file, second information is sent to the database audit system, wherein the second information includes operation information on the third data.

[0029] In some embodiments, before the reading terminal writes the first data of the first pipe file, the method further includes:

[0030] Obtain the process number corresponding to the client tool, and determine the process directory corresponding to the client tool according to the process number;

[0031] According to the file descriptor of the first pipe file and the file descriptor of the second pipe file, the first pipe file and the second pipe file are determined and monitored in the process directory.

[0032] In a second aspect, the present invention provides a server, characterized in that the server includes:

[0033] At least one processor; and a memory communicatively connected to the processor; wherein the memory stores instructions executable by the processor, and the instructions are executed by the processor so that the processor can execute the database monitoring method as described in the first aspect.

[0034] In a third aspect, an embodiment of the present invention provides a database monitoring system, characterized in that the system includes:

[0035] As in the first aspect, the server, the communication connection terminal and the database audit system, the server includes a monitoring module:

[0036] A monitoring module, used for reading first data written by a terminal into a first pipeline file, where the first data includes operation information on a database;

[0037] Performing protocol parsing on the first data to obtain a first database statement, copying the first data, and sending the copied first data to a database audit system for auditing;

[0038] Performing permission matching on the first database statement, if the permission matching fails, modifying the first database statement to obtain a second database statement;

[0039] The second database statement is converted into a protocol to obtain second data and write the second data into the first pipeline file, so that the terminal operates the database according to the second data.

[0040] In some embodiments, the system further comprises:

[0041] The server also includes a database, which is used to return third data according to the third information sent by the terminal;

[0042] The monitoring module is further used to read the third data written by the terminal into the second pipeline file, perform protocol analysis on the third data to obtain fourth data, and copy the third data to send to the database audit system for audit, wherein the third data is the data returned by the database to the terminal;

[0043] Desensitizing the fourth data to obtain fifth data, performing protocol conversion on the fifth data and then writing the fifth data into the second pipeline file;

[0044] The terminal is connected to the server. The terminal runs a client tool and a database service process. The client tool performs one-way data transmission with the database service process through the first pipeline file, and the database service process performs one-way data transmission with the client tool through the second pipeline file:

[0045] A client tool, configured to write first data to the first pipe file and receive fifth data transmitted through the second pipe file;

[0046] The database service process is used to receive the second data transmitted through the first pipe file, and send the third information to the database according to the second data;

[0047] and, receiving third data returned by the database, and writing the third data into the second pipeline file;

[0048] The database audit system is communicatively connected to the server and is used for receiving the first data and the third data sent by the server for auditing.

[0049] In a fourth aspect, an embodiment of the present invention provides a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable a server to execute the database monitoring method of the first aspect.

[0050] The beneficial effects of the embodiments of the present invention are as follows: Different from the prior art, the present application discloses a database monitoring method, which is applied to a server, and the method includes: reading the first data written by the terminal into the first pipeline file, the first data including the operation information of the database; performing protocol parsing on the first data to obtain the first database statement, and copying the first data, and sending the copied first data to the database audit system for auditing; performing permission matching on the first database statement, and if the permission matching fails, changing the first database statement to obtain the second database statement; performing protocol conversion on the second database statement to obtain the second data and write it into the first pipeline file, so that the terminal operates the database according to the second data. On the one hand, the first data is copied and sent to the database audit system for auditing to prevent missed audits; on the other hand, the permission matching is performed on the first database statement, and the operation with insufficient permission is changed to perform permission control, thereby improving the security of the database. BRIEF DESCRIPTION OF THE DRAWINGS

[0051] One or more embodiments are exemplarily described by pictures in the corresponding drawings, and these exemplified descriptions do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, and unless otherwise stated, the figures in the drawings do not constitute proportional limitations.

[0052] Figure 1 It is a schematic diagram of an application scenario of a database monitoring method provided by an embodiment of the present invention;

[0053] Figure 2 It is a flowchart of a database monitoring method provided by an embodiment of the present invention;

[0054] Figure 3 yes Figure 2 A detailed flow chart of step S103 in FIG.

[0055] Figure 4 is another flow chart of a database monitoring method provided by an embodiment of the present invention;

[0056] Figure 5 It is a structural diagram of a database monitoring system provided by an embodiment of the present invention;

[0057] Figure 6 It is a structural diagram of a server provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0058] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0059] See also Figure 1 , Figure 1 It is a schematic diagram of an application scenario of a database monitoring method provided by an embodiment of the present invention;

[0060] like Figure 1 As shown, the application scenario includes a terminal 10, a server 20, and a database audit system 30, and the server 20 is communicatively connected with the terminal 10 and the database audit system 30 respectively.

[0061] The terminal 10 includes a mobile terminal and a fixed terminal. The mobile terminal includes a mobile phone, a tablet computer, a notebook, etc., and the fixed terminal includes a server, a computer, etc.

[0062] The servers 20 are classified into entry-level servers, workgroup-level servers, department-level servers and enterprise-level servers according to application levels, and general-purpose servers and dedicated servers according to usage;

[0063] The server 20 includes a database and a monitoring module deployed on the server 20:

[0064] The database includes a relational database and a non-relational database. In the embodiment of the present invention, a relational database is preferably used, including: a MySQL database, an Oracle database, a MariaDB database, etc.

[0065] The monitoring module may be a packaged agent program.

[0066] The database audit system 30 is an electronic device for database auditing equipped with database audit software, including computers, servers, etc.

[0067] See also Figure 2 , Figure 2 It is a flowchart of a database monitoring method provided by an embodiment of the present invention;

[0068] like Figure 2As shown, the database monitoring method is applied to a server, the server is connected to a terminal and a database audit system in communication, the server includes a database, and the method includes:

[0069] Step S101: reading first data written by a terminal into a first pipeline file, where the first data includes operation information on a database;

[0070] Specifically, the terminal runs a client tool and a database service process. The client tool is used to interact with the database. For example, if the database is an Oracle database, the client tool may be SQLPlus. If the database is a MySQL database, the client tool may be Navicat. There are many types of client tools, which will not be described here. The database service process is the medium for operating the database. The terminal can operate the database only through the database service process, and the data stored in the database can be managed through the database service process.

[0071] The first pipe file refers to the file corresponding to the unnamed pipe with the client tool as the write end and the database service process as the read end. The unnamed pipe is a special file of the Linux system kernel. Data can only flow in one direction and has fixed read and write ends.

[0072] A database administrator (DBA) inputs a database statement to a client tool, and the client tool converts the database statement into a protocol, obtains first data, and writes the first data into a first pipeline file, wherein the database statement is a structured query language (SQL), and the semantics of the SQL statement is the operation performed on the database, that is, the SQL includes the operation information on the database.

[0073] Among them, SQL statements include: data definition language, such as CREATE, DROP, ALTER and other statements; data operation language, such as INSERT, UPDATE, DELETE statements; data query language, such as SELECT statement; data control language, such as GRANT, REVOKE and other statements; transaction control language, such as COMMIT, ROLLBACK and other statements.

[0074] Before step S101, the method further includes:

[0075] Obtain the process number corresponding to the client tool, and determine the process directory corresponding to the client tool according to the process number;

[0076] According to the file descriptor of the first pipe file and the file descriptor of the second pipe file, the first pipe file and the second pipe file are determined and monitored in the process directory.

[0077] Specifically, the operating system of the terminal is a Linux operating system. Under the Linux operating system, all processes correspond to a process number. All processes can be viewed through a first command to find the process number corresponding to the client tool, such as command ps-a. According to the process number corresponding to the client tool, the process directory corresponding to the client tool can be determined through a second command. For example, if the process number corresponding to the client tool is 1120, the second command lsof-p1120 can be entered to list all files opened by the specified process number 1120, that is, to open the process directory corresponding to the client tool, and according to the file descriptor of the first pipe file and the file descriptor of the second pipe file, the first pipe file and the second pipe file are determined and monitored in the process directory. It should be noted that the first pipe file and the second pipe file are temporary files and are created only when the client tool and the server process need to communicate. For example, the two file descriptors of the first pipe file are pipefd[0] and pipefd[1]. Pipefd[0] represents the read end, and pipefd[1] represents the write end. According to the file descriptor pipefd[1], the client tool is monitored to write the first data to the first pipe file.

[0078] Step S102: performing protocol parsing on the first data to obtain a first database statement, copying the first data, and sending the copied first data to a database audit system for auditing;

[0079] Specifically, if the database is an Oracle database, the Oracle database can use the TNS protocol (Transparent Network Substrate, TNS) as the data exchange protocol, wherein the first data is an SQL statement, and protocol parsing of the first data refers to parsing and restoring the SQL commands and parameters in the TNS protocol, that is, obtaining the first database statement entered by the DBA through the client tool. Furthermore, before performing protocol parsing on the first data, the first data is copied and sent to the database audit system for auditing, so as to audit the operation of the DBA to locally connect to the database through an unnamed pipe.

[0080] Step S103: performing permission matching on the first database statement, and if the permission matching fails, modifying the first database statement to obtain a second database statement;

[0081] Please refer to Figure 3 , Figure 3 yes Figure 2 A detailed flowchart of step S103 in FIG.

[0082] like Figure 3 As shown, step S103 includes:

[0083] Step S1031: identifying the target table and operation instruction in the first database statement;

[0084] Specifically, after obtaining the first database statement, it is first necessary to perform semantic analysis on it. Semantic analysis refers to splitting and identifying the SQL statement in the first data, so as to parse out the operation instruction. The syntax of the SQL statement in the information contained in the first data can be analyzed by SQL syntax analysis software or SQL syntax analysis method to obtain the operation instruction. The operation instruction includes access operations such as creating a table, modifying a table, deleting a table, modifying a field, and querying data. Access operations can be divided into two categories, one is to reference, manage, read and modify existing data objects in the database, and the other is to add new data to the database, such as creating a table, adding records, etc.

[0085] After obtaining the operation instruction, the target table can be determined. The target table refers to the data operated by the operation instruction. For example, if a select statement instruction is executed to query the content in table A, then table A is the target table corresponding to the select operation instruction; for example, if a new table B is created in the database, the data in field 2 in table B is the data specified in field 1 in table A, then table A is the target table corresponding to the table creation operation instruction. The operation instructions are not described in detail here.

[0086] Step S1032: Whether the authority level corresponding to the target table is higher than the first authority;

[0087] Specifically, it is determined whether the permission level corresponding to the target table is higher than the first permission. Each target table in the database has a preset permission level. The account of the DBA that logs into the client tool at the terminal also has a permission level, that is, the first permission. For example, the permission level of the target table is A-level, and the first permission of the DBA is only B-level. The A-level permission is higher than the B-level permission, so the permission matching fails. When the DBA connects to the database locally through an unnamed pipe, if its operation is not monitored, the DBA may perform operations higher than the first permission. Therefore, it is necessary to perform permission matching on the DBA's operations on the database, that is, to perform permission matching on the first database statement, and to change the operations that the DBA does not have permission to perform, so as to invalidate the operations and ensure the security of the database.

[0088] If the permission matching fails, that is, the permission level corresponding to the target table is higher than the first permission, step S1035 is executed;

[0089] If the permission match is successful, that is, the permission level corresponding to the target table is not higher than the first permission, step S1033 is executed.

[0090] Step S1033: whether the first database statement contains any high-risk operation;

[0091] Specifically, determine whether the first database statement contains any high-risk operation. The operation in the high-risk operation refers to the operation instruction of the first database statement obtained in step S1031. Whether the operation instruction of the first database statement on the database is high-risk needs to be determined by a preset high-risk operation identification rule. The user can set the operation instruction of the SQL statement to a high-risk operation according to actual needs. For example, set the delete operation instruction to a high-risk operation. Then, when the first database statement contains a delete operation instruction, it is determined that the first database statement contains a high-risk operation. Therefore, even if the permission level of the target table corresponding to the operation instruction is not higher than the first permission, step S1035 will be executed.

[0092] If there is a high-risk operation, execute step S1035;

[0093] If there is no high-risk operation, execute step S1034.

[0094] Step S1034: the first database statement is not modified, and the first database statement is directly used as the second database statement;

[0095] Specifically, if the permission matching for the first database statement succeeds and there is no high-risk operation in the first database statement, it means that the DBA's operation on the database complies with the specification, and the first database statement is directly used as the second database statement without changing its operation.

[0096] Step S1035: modify the first database statement to obtain a second database statement;

[0097] Specifically, if permission matching fails or there are high-risk operations, it means that the DBA's operation on the database does not meet the specifications, and the first database statement needs to be changed. There are many ways to change, but the purpose is to make the first database statement invalid. For example, the first database statement is uniformly rewritten as select * from a, and table a is a table that does not exist in the database. Then the data returned by the database will prompt that table a does not exist, thereby achieving the purpose of making the first database statement invalid.

[0098] Furthermore, the first database statement may be directly intercepted. If processed in this manner, there is no need to modify the first database statement to obtain the second database statement, nor is there any need to rewrite the second database statement into the first pipeline file after performing protocol conversion.

[0099] Step S104: performing protocol conversion on the second database statement to obtain second data and write the second data into the first pipeline file, so that the terminal operates the database according to the second data;

[0100] Specifically, the second database statement is converted into the TNS protocol, and the second data after the protocol conversion is rewritten into the first pipeline file. The first process can receive the second data after the protocol conversion in the first pipeline file, and operate the database according to the second data, that is, send the third information corresponding to the second data to the database.

[0101] Furthermore, when the second data after protocol conversion is written into the first pipeline file, a behavior log, i.e., the first information, will be sent to the database audit system. The behavior log refers to the operation result of the monitoring module on the first data. For example, the behavior log is that at xx time, xx has been changed and rewritten as xx. The behavior log can also simply be that xx has been changed or xx has not been changed.

[0102] Please refer to Figure 4 , Figure 4 is another flow chart of a database monitoring method provided by an embodiment of the present invention;

[0103] like Figure 4 As shown, the terminal runs a client tool and a database service process, the client tool performs unidirectional data transmission with the database service process through a first pipeline file, and the database service process performs unidirectional data transmission with the client tool through a second pipeline file, and the method also includes:

[0104] Step S201: read the third data written by the terminal into the second pipeline file, perform protocol analysis on the third data to obtain fourth data, copy the third data, and send it to the database audit system for audit, wherein the third data is the data sent by the database to the terminal.

[0105] Specifically, the DBA writes first data to the first pipeline file through a client tool. After the monitoring module on the server reads the first data, it processes the first data into second data and rewrites it into the first pipeline file. When the database service process receives the second data, it sends third information to the database based on the second data to operate the database.

[0106] After receiving the third information, the database returns the third data to the server process. For example, if the third information corresponding to the second data is the information of field 1 in query table A, the database returns the data of field 1 in table A. After receiving the third data, the server process writes the third data into the second pipeline file for transmission to the client tool. It should be noted that if the second data permission match fails or there is a high-risk operation and is intercepted by the monitoring module, the database will not return the third data.

[0107] After the server process receives the third data and writes the third data into the second pipe file, the monitoring module reads the third data written by the server process into the second pipe file and performs protocol parsing on the third data. Specifically, if the database is an Oracle database, the Oracle database can use the TNS protocol as the data exchange protocol, and the third data is TNS protocol data. The third data is parsed through the TNS protocol to obtain the fourth data. Furthermore, before performing the TNS protocol parsing on the third data, the third data is copied and sent to the database audit system for auditing, so as to audit the operation of the DBA to locally connect to the database through the unnamed pipe.

[0108] Step S202: desensitizing the fourth data to obtain fifth data, performing protocol conversion on the fifth data and then writing it into the second pipeline file;

[0109] Specifically, after TNS protocol parsing, the fourth data is obtained. In order to prevent the leakage of personal information in the database, the fourth data needs to be desensitized. Furthermore, the format of the fourth data is first determined, and whether the fourth data contains sensitive information is determined based on the format of the fourth data. If the fourth data contains sensitive information, the type of sensitive information is further determined, and desensitization is performed according to the desensitization rules corresponding to this type of sensitive information.

[0110] Specifically, sensitive information includes ID number, mobile phone number, address, name, mail, email, company or religion, etc., which can be defined according to user needs. It is understandable that data containing sensitive information has a specific format, such as ID number and mobile phone number have specific formats. After identifying the specific format, it can be determined whether the data contains sensitive information and the type of sensitive information corresponding to the specific format can be identified. In the desensitization process, the desensitization rules are set according to the type of sensitive information, such as hiding the middle 4 digits of the mobile phone number. Among them, identifying the sensitive type of the fourth data can be achieved through a trained classification algorithm or its combined deformation, and the classification algorithm can be a text classification algorithm, such as a TextCNN algorithm or a softmax classification algorithm.

[0111] The fifth data is obtained after desensitizing the fourth data, and the fifth data is written into the second pipeline file after protocol conversion to be received by the client tool. Furthermore, while the fifth data after protocol conversion is written into the second pipeline file, a behavior log, i.e., the second information, is sent to the database audit system. The behavior log refers to the operation result of the monitoring module on the fourth data. For example, the behavior log is that at xx time, xx has been changed to xx after the change. The behavior log can also simply be that the fourth data has been changed, or the fourth data has not been changed.

[0112] By desensitizing the fourth data, the personal information stored in the database is successfully protected to prevent leakage of personal information, and the third data is copied and sent to the database audit system for audit to prevent missed audits and enhance the security of the database.

[0113] The database monitoring method disclosed in the present application, on the one hand, copies the first data and sends it to the database audit system for audit to prevent missed audits; on the other hand, performs permission matching on the first database statement and changes the operation with insufficient permission to perform permission control, thereby improving the security of the database; finally, desensitizes the third data returned by the database to the server process, thereby further improving the security of the database and protecting the personal information in the database.

[0114] Please refer to Figure 5 , Figure 5 It is a structural diagram of a database monitoring system provided by an embodiment of the present invention;

[0115] like Figure 5 As shown, the database monitoring system 100 includes a terminal 40, a server 50 and a database audit system 60: the terminal 40 includes a client tool 41, a first pipeline file 42, a server process 43, and a second pipeline file 44; the server 50 includes a monitoring module 51 and a database 52; the server 50 is respectively communicated with the terminal 40 and the database audit system 60.

[0116] The terminal 40 is connected to the server 50 in communication, and runs a client tool 41 and a server process 43, as well as a first pipeline file 42 and a second pipeline file 44 for transmitting data between the client tool 41 and the server process 43:

[0117] The client tool 41 performs unidirectional data transmission with the server process 43 through the first pipe file 42, and is used to write first data to the first pipe file and receive fifth data transmitted by the server process 43 through the second pipe file.

[0118] The server process 43 performs unidirectional data transmission with the client tool 41 through the second pipe file 44, and is used to receive the second data transmitted by the client tool 41 through the first pipe file, send third information to the database according to the second data, and receive the third data returned by the database according to the third information.

[0119] It is understandable that if there is no monitoring module 51, the server process 43 receives the first data written by the client tool 41 through the first pipe file, and sends the third information to the database 52 according to the first data, the database 52 returns the third data according to the third information, the server process 43 receives the third data returned by the database 52, and writes it into the second pipe file 44, the client tool 41 receives the third data through the second pipe file 44, and the client tool operates this part of the database through the local unnamed pipe. Because the data traffic cannot be captured through the network protocol stack, it is impossible to use traditional methods for auditing, authority control, and desensitization. If there is no monitoring module 51, illegal attackers or operation and maintenance personnel can modify, query or delete the database data through the client tool without being monitored, causing major security risks.

[0120] The server 50 includes a monitoring module 51 and a database 52:

[0121] A monitoring module 51, configured to read first data written by a terminal into a first pipeline file, wherein the first data includes operation information on a database;

[0122] Performing protocol parsing on the first data to obtain a first database statement, copying the first data, and sending the copied first data to a database audit system for auditing;

[0123] Performing permission matching on the first database statement, if the permission matching fails, modifying the first database statement to obtain a second database statement;

[0124] The second database statement is converted into a protocol to obtain second data and write the second data into the first pipeline file, so that the terminal operates the database according to the second data.

[0125] The specific steps are the same as S101-S104 and will not be repeated here. Through the above method, the monitoring module 51 can audit and control the operations of illegal attackers or operation and maintenance personnel who privately modify, query or delete database data through client tools, change the insufficient or high-risk operations performed by illegal attackers or operation and maintenance personnel, and ensure the security of the database.

[0126] The monitoring module 51 is further used to read the third data written by the terminal into the second pipe file, perform protocol analysis on the third data to obtain fourth data, and copy the third data to send to the database audit system for auditing, wherein the third data is the data returned by the database to the terminal;

[0127] The fourth data is desensitized to obtain fifth data, and the fifth data is converted into a protocol and then written into the second pipeline file.

[0128] The specific steps are the same as S201-S202 and will not be repeated here. Through the above method, the monitoring module 51 can desensitize the data queried by illegal attackers or operation and maintenance personnel through client tools to prevent the leakage of personal information or confidential information in the database, thereby further ensuring the security of the database.

[0129] The database 52 includes a relational database and a non-relational database. In the embodiment of the present invention, it is preferably a relational database, including: MySQL database, Oracle database, MariaDB database, etc., which is used to return the third data according to the third information sent by the terminal.

[0130] The database audit system 60 is communicatively connected to the server 50, and is used to receive the first data and the third data sent by the server for auditing, and can receive the first information and the second information, the first information includes the operation information of the first data, and the second information includes the operation information of the third data. When the first data permission match fails or there is a high-risk operation, the first information can also cause the database audit system 60 to alarm to notify relevant personnel that someone is trying to modify, query or delete the database data, and notify the relevant personnel of the specific changes in the first data, that is, the second data. The database audit system 30 is an electronic device for database auditing equipped with database audit software, including computers, servers, etc.

[0131] Please refer to Figure 6 , Figure 6 It is a structural diagram of a server provided by an embodiment of the present invention.

[0132] like Figure 6 As shown, the server 70 includes: one or more processors 71 and a memory 72, Figure 6 A processor 71 is taken as an example.

[0133] The processor 71 and the memory 72 may be connected via a bus or other means. Figure 6 The example of connecting through bus is taken in the following.

[0134] Processor 71 reads the first data written by the terminal into the first pipeline file, the first data including the operation information of the database; performs protocol analysis on the first data to obtain the first database statement, copies the first data, and sends the copied first data to the database audit system for audit; performs permission matching on the first database statement, and if the permission matching fails, changes the first database statement to obtain the second database statement; performs protocol conversion on the second database statement to obtain the second data and write it into the first pipeline file, so that the terminal operates the database according to the second data. On the one hand, the first data is copied and sent to the database audit system for audit to prevent missed audits; on the other hand, the permission matching is performed on the first database statement, and the operation with insufficient permission is changed to perform permission control, thereby improving the security of the database.

[0135] The memory 72 is a non-volatile computer-readable storage medium that can be used to store non-volatile software programs, non-volatile computer executable programs and modules, such as program instructions / modules of the database monitoring method in the embodiment of the present application. The processor 71 executes various functional applications and data processing of the server by running the non-volatile software programs, instructions and modules stored in the memory 72, that is, implementing the database monitoring method of the above method embodiment.

[0136] The memory 72 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and applications required for at least one function; the data storage area may store data created according to the use of the server, etc. In addition, the memory 72 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some embodiments, the memory 72 may optionally include a memory remotely arranged relative to the processor 71, and these remote memories may be connected to the controller via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0137] One or more modules are stored in the memory 72, and when executed by one or more processors 71, the database monitoring method in any of the above method embodiments is executed, for example, the above described Figure 2 The method comprises steps S101 to S104.

[0138] It should be noted that the above-mentioned product can execute the method provided in the embodiment of the present application, and has the functional modules and beneficial effects corresponding to the execution method. For technical details not described in detail in the present embodiment, please refer to the method provided in the embodiment of the present application.

[0139] The embodiment of the present application provides a non-volatile computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are executed by one or more processors, such as Figure 6 A processor 71 in the embodiment may enable the one or more processors to execute the database monitoring method in any of the above method embodiments, and execute the above described Figure 2 The method comprises steps S101 to S104.

[0140] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; under the idea of ​​the present invention, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other changes in different aspects of the present invention as above, which are not provided in detail for the sake of simplicity; although the present invention is described in detail with reference to the above embodiments, ordinary technicians in this field should understand that it is still possible to modify the technical solutions recorded in the above embodiments, or to replace some of the technical features therein; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention. Through the description of the above embodiments, ordinary technicians in this field can clearly understand that each embodiment can be implemented by means of software plus a general hardware platform, and of course, it can also be implemented by hardware. Ordinary technicians in this field can understand that all or part of the processes in the above embodiment method can be completed by computer programs to instruct related hardware. The program can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes of the embodiments of the above methods. The storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM).

Claims

1. A database monitoring method, applied to a server, characterized in that: The server is in communication with the terminal and the database audit system, the server includes a database, and the method includes: Reading first data written by the terminal into a first pipeline file, wherein the first data includes operation information on the database; Performing protocol parsing on the first data to obtain a first database statement, copying the first data, and sending the copied first data to the database audit system for auditing; Performing permission matching on the first database statement, and if the permission matching fails, modifying the first database statement to obtain a second database statement; The second database statement is converted into a protocol to obtain second data and written into the first pipeline file, so that the terminal operates the database according to the second data, the terminal runs a client tool and a database service process, the client tool performs unidirectional data transmission with the database service process through the first pipeline file, the database service process performs unidirectional data transmission with the client tool through the second pipeline file, and the terminal has a first permission; The performing permission matching on the first database statement includes: identifying a target table in the first database statement; If the permission level corresponding to the target table is higher than the first permission, the permission matching fails; If the permission level corresponding to the target table is not higher than the first permission, the permission matching is successful; Reading the third data written by the terminal into the second pipe file, performing protocol parsing on the third data to obtain fourth data, and copying the third data to send to the database audit system for auditing, wherein the third data is the data sent by the database to the terminal; Desensitizing the fourth data to obtain fifth data, performing protocol conversion on the fifth data and then writing the fifth data into the second pipeline file; After obtaining the second data and writing it into the first pipeline file, sending first information to the database audit system, wherein the first information includes operation information on the first data; After the fifth data is converted into a protocol and then written into the second pipe file, second information is sent to the database audit system, wherein the second information includes operation information on the third data.

2. The method according to claim 1, characterized in that The method further comprises: If the permission match succeeds, the first database statement is not changed, and the first database statement is used as the second database statement.

3. The method according to claim 2, characterized in that The method further comprises: Determining whether the first database statement contains any high-risk operations; If the first database statement contains the high-risk operation or the permission matching fails, modify the first database statement to obtain the second database statement; If the first database statement does not contain the high-risk operation and the permission matching succeeds, the first database statement is not changed and is directly used as the second database statement.

4. The method according to claim 1, characterized in that: Before reading the first data written by the terminal into the first pipeline file, the method further includes: Obtaining a process number corresponding to the client tool, and determining a process directory corresponding to the client tool according to the process number; According to the file descriptor of the first pipe file and the file descriptor of the second pipe file, the first pipe file and the second pipe file are determined and monitored in the process directory.

5. A server, characterized in that: The server comprises: At least one processor; and a memory communicatively connected to the processor; wherein the memory stores instructions executable by the processor, and the instructions are executed by the processor so that the processor can execute the database monitoring method described in any one of claims 1-4.

6. A database monitoring system, characterized in that: The system comprises: The server, communication connection terminal and database audit system according to claim 5, wherein the server includes a monitoring module: The monitoring module is used to read the first data written by the terminal into the first pipeline file, where the first data includes operation information on the database; Performing protocol parsing on the first data to obtain a first database statement, copying the first data, and sending the copied first data to the database audit system for auditing; Performing permission matching on the first database statement, and if the permission matching fails, modifying the first database statement to obtain a second database statement; Performing protocol conversion on the second database statement to obtain second data and writing the second data into the first pipeline file, so that the terminal can operate the database according to the second data, and the terminal has the first authority; The terminal is communicatively connected to the server, the terminal runs a client tool and a database service process, the client tool performs unidirectional data transmission with the database service process through the first pipe file, and the database service process performs unidirectional data transmission with the client tool through the second pipe file; The monitoring module is specifically used to identify the target table in the first database statement; If the permission level corresponding to the target table is higher than the first permission, the permission matching fails; If the permission level corresponding to the target table is not higher than the first permission, the permission matching is successful; The monitoring module is further used to read the third data written by the terminal to the second pipe file, perform protocol analysis on the third data to obtain fourth data, and copy the third data to send to the database audit system for auditing, wherein the third data is the data sent by the database to the terminal; Desensitizing the fourth data to obtain fifth data, performing protocol conversion on the fifth data and then writing the fifth data into the second pipeline file; The monitoring module is further configured to send first information to the database audit system after the second data is obtained and written into the first pipeline file, wherein the first information includes operation information on the first data; After the fifth data is converted into a protocol and then written into the second pipe file, second information is sent to the database audit system, wherein the second information includes operation information on the third data.

7. The system according to claim 6, characterized in that The system further comprises: The server further includes a database, configured to return the third data according to the third information sent by the terminal; The client tool is used to write the first data to the first pipeline file and receive fifth data transmitted through the second pipeline file; The database service process is used to receive the second data transmitted through the first pipe file, and send the third information to the database according to the second data; and, receiving the third data returned by the database, and writing the third data into the second pipeline file; The database audit system is communicatively connected to the server and is used to receive the first data and the third data sent by the server for auditing.

Citation Information

Patent Citations

  • Database command line filtering and audit blocking method and device

    CN105635046A

  • Database blocking method and device

    CN112131205A

  • Method for monitoring database system without being connected to database system

    JP2006338415A