Database Security Control Method, Device, Electronic Device, and Storage Medium

Through database soft exchange and similarity cycle analysis algorithm, combined with multi-threading and operating system cores, centralized management and control of database operation and maintenance is achieved, solving the problems of high development costs and stability in the existing technology, and improving the efficiency and security of database operation and maintenance.

CN114996238BActive Publication Date: 2025-07-18CHINA MOBILE GROUP JIANGSU +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202110231274.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-03-02
Publication Date
2025-07-18
Estimated Expiration
2041-03-02

AI Technical Summary

Technical Problem

The existing technology requires secondary development for each version of various database operation and maintenance tools, resulting in high development costs, long cycles, and may affect the stability of database tools, which cannot meet the requirements of IT rapid support and response.

Method used

The centralized control of database operation and maintenance is realized through database soft exchange, and the similarity cycle analysis algorithm is used to simulate the database and operation and maintenance tools for session maintenance communication, and the operating system kernel and multi-threaded mechanism are called for network traffic acquisition and analysis to realize security management and maintenance communication.

Benefits of technology

There is no need to transform the database tools, which realizes centralized control of database operations and maintenance, solves the problem of maintaining database tools during the waiting period for vault approval, and improves traffic processing capabilities and operation and maintenance efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114996238B_ABST
    Figure CN114996238B_ABST
Patent Text Reader

Abstract

The present invention provides a database security control method, apparatus, electronic device, and storage medium, including: sending database operation and maintenance instructions through a database operation and maintenance tool, and after the database soft switch performs security control on the database operation and maintenance instructions, forwarding them to the database; the database soft switch uses a similarity cycle analysis algorithm to simulate the database, enabling the database to perform session keep-alive communication with the database operation and maintenance tool; calling the operating system kernel, and using a multi-threaded mechanism and a fast read-write data cache queue to perform network traffic collection and analysis. In view of the problem that various database tools need to be customized and developed for database operation and maintenance control, the present invention realizes the centralized control of database operation and maintenance through the database soft switch, without the need to transform the database tools. At the same time, it solves the problem of maintaining the keep-alive of the database tools during the waiting period for the approval of the vault triggered by the instructions, and calls the operating system kernel, uses multi-threading and a fast read-write data cache queue to improve the traffic processing ability, ensuring the operation and maintenance efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of databases, and in particular to a database security control method, device, electronic device, and storage medium. Background Art

[0002] In order to ensure the security and stability of the IT system, daily database operation and maintenance operations need to be carried out in a dedicated bastion host. Among them, in the in-process link, "vault control" operations are performed on high-risk / sensitive operations, that is, security control of secondary authentication of operations, and in the post-process link, security control is performed on user operation log auditing.

[0003] At present, for the security control of IT database operation and maintenance, it is usually necessary to perform secondary transformation on various database operation and maintenance tools deployed in the bastion host. Before the database operation and maintenance tool converts the SQL instruction into a database-specific communication protocol message, the user's execution operation is intercepted, and the SQL statement is analyzed to achieve the purpose of in-process security control; at the same time, the operation log records of the operation and maintenance tool are audited to achieve post-process security control. However, in recent years, with the IT cloudification, the types of databases used in business systems are increasing, resulting in an increasing number of database operation and maintenance tools and rapid version updates. Adopting the original method of security control requires a large amount of cost for secondary development for each database, each database tool, and each version.

[0004] Due to relying on secondary transformation of various database operation and maintenance tools to achieve security control, the following problems exist in the actual security control of this method:

[0005] 1. It is necessary to perform secondary development for each version of various database operation and maintenance tools, with high development costs and long cycles. In the new context of IT system cloudification, it cannot meet the requirements of rapid IT support and response;

[0006] 2. For secondary development of third-party database tools, through code injection, it may affect the stability of the database tool itself, resulting in abnormal errors during its operation and affecting IT operation and maintenance work. Summary of the Invention

[0007] The present invention provides a database security control method, device, electronic device, and storage medium to solve the defects existing in the prior art.

[0008] In a first aspect, the present invention provides a database security control method, including:

[0009] Sending a database operation and maintenance instruction through a database operation and maintenance tool, and after the database soft switch performs security control on the database operation and maintenance instruction, forwarding it to the database;

[0010] The database softswitch uses a similarity loop analysis algorithm to simulate the database, enabling the database to perform session keep-alive communication with the database operation and maintenance tool;

[0011] Call the operating system kernel and use a multi-threaded mechanism and a fast read / write data cache queue to perform concurrent network traffic collection and analysis.

[0012] In one embodiment, sending a database operation and maintenance instruction through the database operation and maintenance tool, and after the database softswitch performs security control on the database operation and maintenance instruction, forwarding it to the database, specifically includes:

[0013] After the database softswitch receives the instruction message of the database operation and maintenance instruction, it restores the SQL instruction through protocol parsing and determines whether the user performs a dangerous operation

[0014] If it is determined that the user performs a dangerous operation, trigger the vault approval; otherwise, directly forward the instruction message to the database.

[0015] In one embodiment, after the step of if it is determined that the user performs a dangerous operation, trigger the vault approval; otherwise, directly forward the instruction message to the database, it further includes:

[0016] Record the operation on the instruction message to form a log record, and perform security auditing based on the log record.

[0017] In one embodiment, the database softswitch uses a similarity loop analysis algorithm to simulate the database, enabling the database to perform session keep-alive communication with the database operation and maintenance tool, specifically includes:

[0018] Collect the response message set after the database operation and maintenance instruction is sent, and obtain several messages in the response message set;

[0019] Select any one of the several messages, and based on the similarity between the any one message and other messages, obtain the keep-alive message format and the specific value of the message;

[0020] Based on the keep-alive message format and the specific value of the message, obtain the operation command with the highest usage frequency in the response message set, and implement link keep-alive according to the operation command with the highest usage frequency.

[0021] In one embodiment, the step of selecting any one of the several messages, and based on the similarity between the any one message and other messages, obtaining the keep-alive message format and the specific value of the message, specifically includes:

[0022] Compare any one of the messages with other messages respectively. Obtain the similarity between any one of the messages and any other message by the ratio of the intersection of any one of the messages and any other message to the union of any one of the messages and any other message. Accumulate all the similarities between any one of the messages and other messages and then calculate the average value to obtain the average similarity of any one of the messages;

[0023] Calculate the similarity between each of the several messages and other messages one by one, and calculate the average similarity of all the messages;

[0024] After sorting the average similarities of all the messages, screen out the message set with the top preset proportion of sorting, and repeat the foregoing calculation steps until the number of message sets screened out does not exceed the preset number of message sets;

[0025] Analyze and verify the message formats of the message set to obtain the keep-alive message format and the specific message values.

[0026] In one embodiment, the calling of the operating system kernel, the use of the multi-thread mechanism and the fast read-write data cache queue for concurrent network traffic collection and analysis specifically includes:

[0027] Establish a direct communication collection thread with the network card to obtain the original traffic messages, forward the original traffic messages to the upper-layer application of the operating system, and forward them by the upper-layer application of the operating system to the database soft switch;

[0028] Form a thread group by corresponding one collection thread to one parsing thread, and use multiple thread groups to process multiple original traffic messages in parallel at the same time;

[0029] Allocate a cache queue space with a preset capacity to each thread group, and use read-write cursor marks to perform cyclic operations on the cache queue to form the fast read-write data cache queue.

[0030] In one embodiment, the allocating a cache queue space with a preset capacity to each thread group and using read-write cursor marks to perform cyclic operations on the data cache queue to form the fast read-write data cache queue specifically includes:

[0031] Set a message write cursor to indicate the message insertion position and a message read cursor to indicate the message read position respectively;

[0032] Put all the message data into the cache for waiting to be processed, write the message data into the cache according to the message write cursor. After the current insertion operation is completed, the message write cursor automatically moves down one bit and continues to insert the next message data;

[0033] Read the message data at the current position according to the message reading cursor and perform analysis and processing. After the current reading operation is completed, the message reading cursor automatically moves down one position and continues to read the next message data;

[0034] Point the next position pointer of the last position of the data cache queue to the first position of the data cache queue, and perform cyclic insertion and reading / writing in the data cache queue based on the message writing cursor and the message reading cursor respectively until no message data is inserted and all message data is read.

[0035] In a second aspect, the present invention further provides a database security control device, including:

[0036] A first processing module for sending a database operation and maintenance instruction through a database operation and maintenance tool, and after the database soft switch performs security control on the database operation and maintenance instruction, forwarding it to the database;

[0037] A second processing module for the database soft switch to simulate the database using a similarity loop analysis algorithm, so that the database performs session keep-alive communication with the database operation and maintenance tool;

[0038] A third processing module for calling the operating system kernel and using a multi-threaded mechanism and a fast read / write data cache queue to perform concurrent network traffic collection and analysis.

[0039] In a third aspect, the present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of any one of the above-mentioned database security control methods are implemented.

[0040] In a fourth aspect, the present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of any one of the above-mentioned database security control methods are implemented.

[0041] The database security control method, device, electronic device, and storage medium provided by the present invention solve the problem of customizing and developing various database tools for database operation and maintenance control needs. Through the database soft switch, centralized control of database operation and maintenance is realized without modifying the database tools. At the same time, the problem of maintaining the keep-alive of database tools during the waiting period for vault approval triggered by instructions is solved. By calling the operating system kernel, using multi-threading, and a fast read / write data cache queue, the traffic processing ability is improved, and the operation and maintenance efficiency is guaranteed. Description of the Drawings

[0042] To more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the attached drawings required for the description of the embodiments or the prior art. Obviously, the attached drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other attached drawings can also be obtained based on these attached drawings.

[0043] Figure 1 It is a schematic diagram of the business processing flow for database operation and maintenance security control provided by the prior art;

[0044] Figure 2 It is a schematic diagram of the flow of the database security control method provided by the present invention;

[0045] Figure 3 It is a schematic diagram of the business processing flow of the database security control method provided by the present invention;

[0046] Figure 4 It is the overall business architecture diagram of the database softswitch provided by the present invention;

[0047] Figure 5 It is a schematic diagram of the similarity loop analysis algorithm provided by the present invention;

[0048] Figure 6 It is one of the schematic diagrams of the format of the keep-alive communication message provided by the present invention;

[0049] Figure 7 It is a schematic diagram of the message header and message body in the format of the keep-alive message provided by the present invention;

[0050] Figure 8 It is another schematic diagram of the format of the keep-alive communication message provided by the present invention;

[0051] Figure 9 It is a schematic diagram of the structure of the multi-threaded read-write data cache queue provided by the present invention;

[0052] Figure 10 It is a schematic diagram of quickly reading and writing the data cache queue through read-write cursors provided by the present invention;

[0053] Figure 11 It is a schematic diagram of the structure of the database security control device provided by the present invention;

[0054] Figure 12 It is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed implementation manners

[0055] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present invention without creative efforts shall fall within the protection scope of the present invention.

[0056] In view of the problems faced by the existing database operation and maintenance security control, the present invention proposes to implement database operation and maintenance security control through database soft switching, strip the existing control means implanted in the database operation and maintenance tools on the bastion host, and move the control means to the network transmission layer after stripping, so as to decouple the control means from the database operation and maintenance tools, and then restore and securely control the database SQL instructions through the soft switching deployed on the network layer.

[0057] The existing business processing flow is as Figure 1 shown. The database operation and maintenance security control is implemented on the bastion host, and needs to be customized for different tools, with too high coupling degree with the database operation and maintenance tools, and it is very troublesome to expand.

[0058] Figure 2 is a schematic flow chart of the database security control method provided by the present invention. As Figure 2 shown, it includes:

[0059] 101. Send a database operation and maintenance instruction through a database operation and maintenance tool. After the database soft switch securely controls the database operation and maintenance instruction, it forwards it to the database;

[0060] 102. The database soft switch simulates the database by using a similarity loop analysis algorithm, so that the database conducts session keep-alive communication with the database operation and maintenance tool;

[0061] 103. Invoke the operating system kernel, and use a multi-threaded mechanism and a fast read-write data cache queue to collect and analyze concurrent network traffic.

[0062] Specifically, the business processing flow of the present invention is as Figure 3 shown. The database operation and maintenance security control capability is abstracted and stripped to form a general capability, which is realized through traffic analysis at the network layer.

[0063] Receive and analyze the network traffic of the database operation and maintenance instructions of the database operation and maintenance tool through database softswitch. Based on the traffic analysis at the protocol layer, restore the database operation instructions. When high-risk / sensitive operations are found, trigger the "vault control", intercept and wait for the instructions. After the "vault" approval is passed, forward the instructions to the database server for execution, realizing the security control of database operation and maintenance at the network protocol layer, and decoupling the database security operation and maintenance control from the user's use of the database tool; during the waiting period of the vault approval, actively send simulated keep-alive data packets through the softswitch to maintain the link communication between the database and the operation and maintenance tool; at the same time, call the operating system kernel, and use multi-threading and fast read-write data cache queue to realize large-concurrency network traffic collection and analysis.

[0064] In view of the problem that various database tools need to be customized and developed for database operation and maintenance control in the present invention, centralized control of database operation and maintenance is realized through database softswitch, without the need to transform the database tools. At the same time, the problem of maintaining the keep-alive of the database tool during the waiting period for the instruction to trigger the vault approval is solved. By calling the operating system kernel, using multi-threading and fast read-write data cache queue to improve the traffic processing ability and ensure the operation and maintenance efficiency.

[0065] Based on the above embodiments, step 101 in the method specifically includes:

[0066] After the database softswitch receives the instruction message of the database operation and maintenance instruction, restore the SQL instruction through protocol parsing, and judge whether the user performs a dangerous operation

[0067] If it is judged that the user performs a dangerous operation, trigger the vault approval; otherwise, directly forward the instruction message to the database.

[0068] Wherein, after "if it is judged that the user performs a dangerous operation, trigger the vault approval; otherwise, directly forward the instruction message to the database", it further includes:

[0069] Record the operation of the instruction message to form a log record, and conduct security audit based on the log record.

[0070] Specifically, the database softswitch is deployed between the bastion host and the database server. When the user uses the database operation and maintenance tool to access the database, the operation and maintenance tool connects to the database softswitch, sends the operation and maintenance instruction to the softswitch, and after the security control of the softswitch, the softswitch forwards the instruction to the database service. The overall business architecture of the database softswitch is as Figure 4 shown.

[0071] After receiving the instruction message from the database tool, the database soft switch restores the SQL instruction through protocol parsing, and determines whether the user has performed dangerous operations such as deleting the database, deleting tables, and accessing sensitive data. If it is found that the user attempts to perform a dangerous operation, the database soft switch will intercept it and will not immediately forward the message instruction to the database resource. The intercepted instruction will not be discarded, but will be placed in the instruction cache to be released in the database soft switch. At the same time, the vault audit is triggered. After the reviewer approves, the soft switch forwards the message to the database service for execution. If the vault approval fails, the soft switch will feedback the failure information of the database tool, and at the same time discard the request message to achieve request blocking. All database operation and maintenance instructions will be centrally collected and recorded through the soft switch for subsequent security audits.

[0072] Here, the database soft switch realizes the secure connection of the database, and the user does not need to know the real IP address and port of the database. Secondly, the database soft switch changes the existing technical method of realizing security control by modifying database tools (multiple tools, multiple versions), unifies the operation and maintenance security control of different databases to the protocol layer, identifies dangerous operations before protocol forwarding, provides auditing and blocking capabilities, avoids unauthorized user operations, and ensures database security. Finally, all operation records will be recorded to form an audit log for subsequent security audits.

[0073] The database soft switch structure proposed by the present invention solves the problem that a large amount of manpower and time need to be invested in custom development of various database tools for database operation and maintenance control. Through the database soft switch, centralized control of database operation and maintenance is realized without modifying the database tools. The database operation and maintenance instructions are restored at the protocol layer to implement security control means such as instruction identification, dangerous instruction judgment, instruction approval, release, blocking, and auditing.

[0074] Based on any of the above embodiments, step 102 in the method specifically includes:

[0075] Collect the set of response messages after the database operation and maintenance instruction is issued, and obtain a number of messages in the set of response messages;

[0076] Select any one of the several messages, and obtain the keep-alive message format and the specific value of the message based on the similarity between the any one message and other messages;

[0077] Based on the keep-alive message format and the specific value of the message, obtain the operation command with the highest usage frequency in the set of response messages, and implement link keep-alive according to the operation command with the highest usage frequency.

[0078] Among them, selecting any one of the several messages, and obtaining the keep-alive message format and the specific message value based on the similarity between the any one message and other messages specifically includes:

[0079] Comparing the any one message with other messages respectively, obtaining the similarity between the any one message and any other message by the ratio of the intersection of the any one message and any other message to the union of the any one message and the any other message, accumulating all the similarities between the any one message and other messages and then calculating the average value to obtain the average similarity of the any one message;

[0080] Calculating the similarity between each of the several messages and other messages one by one, and calculating the average similarity of all messages;

[0081] After sorting the average similarities of all the messages, screening out the message sets with the top preset proportion of sorting, and repeating the foregoing calculation steps until the number of message sets does not exceed the preset number of message sets;

[0082] Analyzing and verifying the message formats of the message sets to obtain the keep-alive message format and the specific message value.

[0083] Specifically, the database tool converts the operation and maintenance instructions into network traffic data packets according to the database protocol standard and sends them to the soft switch. The soft switch will parse and restore the message after receiving the traffic. When it is necessary to trigger the vault, the forwarding of the message will be blocked temporarily. Generally, the vault approval will last for several minutes or longer. To avoid reporting a session timeout error due to the lack of response from the database server for a long time after the database tool instruction is sent, it is necessary for the soft switch to simulate the communication between the database server and the database tool, construct a database service response data message and return it to the database tool.

[0084] Although the keep-alive communication mechanisms of different databases are basically the same, in fact, there are certain differences in the keep-alive message formats of different databases and different versions of the same database. At the same time, the network traffic is filled with a large amount of impurities and noises. It is extremely laborious to analyze the messages by means of packet capture manually in order to obtain the keep-alive message format.

[0085] Therefore, the present invention collects a large number of response messages received after the database operation and maintenance instructions are sent, uses the similarity loop analysis algorithm to analyze the similarity of the collected large number of messages to obtain the commonality of the keep-alive messages, analyzes these commonalities, deduces and summarizes the keep-alive message structure, and then combines the actual verification to determine whether the data packet will affect the use of the database tool, and finally determines the message format of the session keep-alive data packet. The similarity loop analysis algorithm is specifically as follows:

[0086] 1) Suppose there are n messages in the message set to be analyzed. Select one message (P1) and compare its content with that of other messages to obtain the similarity degrees S(P1, P2), S(P1, P3), S(P1, P4), …, S(P1, P n ). The similarity calculation method is the intersection of two messages (P1 and P2), that is, the same content, accounting for the proportion of the union of the two messages (P1 and P2). As shown in Figure 5 , the calculation formula is as follows:

[0087]

[0088] The similarity S value is between [0, 1]. The larger the S value, the higher the similarity between the two messages.

[0089] Then accumulate the similarities between message P1 and other messages, and then take the average value:

[0090] P avg1 = ∑(S i ) / (n - 1);

[0091] 2) Select another message (P2) and compare its content with that of other messages to obtain the similarity degrees S(P2, P1), S(P2, P3), S(P2, P4), …, S(P2, P n ), and calculate the average similarity value:

[0092] P avg2 = ∑(S i ) / (n - 1);

[0093] 3) Complete the similarity calculation between each message (P n ) and other messages one by one, and calculate all the average similarity values;

[0094] 4) Sort the average similarity values of each message rank(P avg1 , P avg2 , P avg3 , …, P avgn );

[0095] 5) According to the average similarity value P avgi from high to low, screen out the messages in the message set that are ranked in the top preset proportion. Here, the proportion can be customized. For example, the top 70%. Repeat the operations of the foregoing steps and keep looping until the number of the screened message set does not exceed the preset number of message sets. Here, the preset number of message sets can be customized. For example, 10;

[0096] 6) Analyze and verify the formats of the finally screened messages to obtain the keep-alive message format and the specific message values.

[0097] It should be noted that the advantage of the similarity loop analysis algorithm is that through multiple similarity calculations and sorting, it can screen out a small set of packets with the highest similarity to other packets from a large set of packets. Developers only need to analyze these small sets of packets to obtain the format and specific values of the keep-alive packets.

[0098] Currently, the database types in the market are mainly divided into commercial databases (closed-source databases) and open-source databases. Commercial databases are represented by the Oracle database, and open-source databases are represented by the Mysql database. The communication protocol format of commercial databases is not publicly available, and a large amount of effort is required to research and analyze it through traditional means. Although the protocol used by open-source databases has source code, the efficiency of researching the source code is also different. The following is an explanation for two different types of databases respectively:

[0099] I. Taking the commercial database Oracle as an example

[0100] Through the loop similarity analysis method, it is finally obtained that the keep-alive packet format contains a general packet header, which includes information such as packet checksum, packet length, and packet type. Different types of data implement data transmission with different functions, as shown in Table 1:

[0101] Table 1

[0102] Common Packet Header 8 Common Packet Header Data Variable Data

[0103] Among them, the general packet header format is shown in Table 2:

[0104] Table 2

[0105]

[0106] In Table 2, Packet Packet Chksm and Header Chksm are usually unchanged, and the value is 0.

[0107] The Type field is the packet type field. Table 3 lists the type descriptions corresponding to the type values:

[0108] Table 3

[0109]

[0110]

[0111] When errors or other situations occur, other types may be used, mainly including the following types of data:

[0112] 1) When a query statement error occurs, the marker type will be used;

[0113] 2) If the client requests the server unsuccessfully (such as a non - existent service ID), the server will send a refuse type;

[0114] 3) When the client logs in, it will send a connection type, and the server will return a redirect type of data;

[0115] 4) After the redirection port connection is completed, the client resends the connection type data, the server returns the acceptance type data, and then normal communication can be carried out.

[0116] After summarizing after the message header, the most critical several commands appearing in the message data are shown in Table 4:

[0117] Table 4

[0118]

[0119]

[0120] It is found that the ox0401 command has the highest usage frequency in the analyzed message set. It contains the return structures of all database operations, data such as error command codes, error descriptions, operation types, etc. It can be used to construct message data packets to achieve link keep - alive. Therefore, based on the above analysis results, the keep - alive communication message format between the soft - switch and the database tool can be constructed, as Figure 6 shown.

[0121] II. Take the open - source database Mysql as an example

[0122] Through the loop similarity analysis method, it is finally obtained that the keep - alive message format contains a message header and a message body. Among them, the message header occupies 4 fixed bytes, and the length of the message body is determined by the length field in the message header. The message structure is as Figure 7 shown.

[0123] The message header consists of the message length and the sequence number. Among them, the message length is used to mark the actual data length value of the current request message, in bytes, occupying 3 bytes, and the maximum value is 0xFFFFFF, that is, close to 16MB (1 byte less than 16MB). The sequence number is used to ensure the correct message order during a complete request / response interaction process. Each time the client initiates a request, the sequence number value starts from 0.

[0124] The message body is used to store the content of the request and the response data, and the length is determined by the length value in the message header.

[0125] After the database tool initiates a command request, the server will return the corresponding execution result to the client. After receiving the response message, the client needs to first check the value of the first byte to distinguish the type of the response message, as shown in Table 5.

[0126] Table 5

[0127]

[0128]

[0129] Through similarity analysis, it is found that the ok response message has the highest usage frequency in the message set. It contains the return structures of all database operations, data such as error command codes, error descriptions, operation types, etc. Based on this, message data packets can be constructed to achieve link keep-alive. Therefore, according to the above similarity analysis results, the keep-alive communication message format between the database and the operation and maintenance tool can be constructed, as Figure 8 shown.

[0130] The present invention solves the problem of maintaining the keep-alive of the database tool when it is necessary to trigger the vault approval, ensuring that the business is not interrupted.

[0131] Based on any of the above embodiments, step 103 in the method specifically includes:

[0132] Establish a direct communication collection thread with the network card, obtain the original traffic message, forward the original traffic message to the upper-layer application of the operating system, and forward it by the upper-layer application of the operating system to the database soft switch;

[0133] Form a thread group by corresponding one collection thread to one parsing thread, and process multiple original traffic messages in parallel by multiple thread groups;

[0134] Allocate a cache queue space with a preset capacity to each thread group, and use read and write cursor markers to perform circular operations on the cache queue to form the fast read and write data cache queue.

[0135] Among them, the step of allocating a cache queue space with a preset capacity to each thread group and using read and write cursor markers to perform circular operations on the data cache queue to form the fast read and write data cache queue specifically includes:

[0136] Respectively set a message write cursor to represent the message insertion position and a message read cursor to represent the message read position;

[0137] Put all message data into the cache for waiting to be processed, write the message data into the cache according to the message write cursor, and after the current insertion operation is completed, the message write cursor automatically moves down one position to continue inserting the next message data;

[0138] Read and analyze the message data at the current position according to the message read cursor, and after the current read operation is completed, the message read cursor automatically moves down one position to continue reading the next message data;

[0139] Point the next position pointer of the last position in the data cache queue to the first position of the data cache queue, and perform cyclic insertion and read / write in the data cache queue based on the message write cursor and the message read cursor respectively until no message data is inserted and all message data is read.

[0140] Specifically, in the daily operation and maintenance of massive data assets in the cloud environment, throughput performance is an issue that must be considered in database soft switching, such as Figure 9 As shown, the present invention mainly realizes the large-traffic and high-concurrency processing function through the following strategies.

[0141] I. Invoke the operating system kernel to calculate and improve the traffic concurrency processing ability

[0142] 1. Invoke the operating system kernel to implement traffic collection and analysis

[0143] Traffic collection performance is an important factor affecting the overall traffic analysis performance. Therefore, by invoking the system kernel in this method, the collection thread can directly communicate with the network card to obtain the original traffic messages, avoiding the performance loss caused by the network card transferring the traffic to the upper-layer application of the operating system first and then to the soft switch through the upper-layer application.

[0144] 2. Multithreaded parallel processing

[0145] During the traffic collection and analysis process, the processing processes between traffic message collection and traffic message analysis are completely independent, and there is no need to consider the situation of data synchronization and thread deadlock between multiple threads. This is an optimal application scenario for multithreaded parallel processing. The present invention uses one collection thread corresponding to one parsing thread to form a thread group, and uses multiple thread groups to simultaneously and parallelly process the receiving, parsing, and SQL restoration tasks of multiple traffic messages, making full use of the CPU processor resources to complete more message processing within a fixed time, thereby improving the throughput performance of the soft switch.

[0146] II. Quickly read and write the data cache queue

[0147] The quick read and write of the data cache queue is designed to improve the performance of thread read and write operations. The system allocates a certain size of cache queue space for each thread group, and there is a one-to-one correspondence between the cache queue and the thread group. Point the next position pointer of the last position in the data cache queue to the first position of the queue to form a logically circular space for the program to use cyclically.

[0148] Such as Figure 10As shown in the figure, two cursors, namely read cursor and write cursor, are used to record different read and write positions. The message write cursor represents the insertion position. The traffic collection thread writes message data into the cache according to the message write cursor. After the system completes an insertion, the message write cursor automatically moves down one position to continue inserting the next message. All messages are placed in the cache waiting to be processed. The message read cursor represents the read position. The traffic analysis thread reads the message content at this position according to the message read cursor for analysis and processing, and marks the usage status after completion without releasing the cache space.

[0149] The cursors read and insert cyclically on the queue until no message is inserted and all messages are read. A fast read and write data cache queue is used for message storage, avoiding frequent creation and release of cache space, and greatly improving the read and write performance of data.

[0150] The present invention improves the traffic processing ability by calling the operating system kernel, using multi-threading and a fast read and write data cache queue, ensuring the operation and maintenance efficiency.

[0151] The database security control device provided by the present invention will be described below. The database security control device described below can be mutually corresponding and referred to the database security control method described above.

[0152] Figure 11 is a schematic structural diagram of the database security control device provided by the present invention, as Figure 11 shown, including: a first processing module 1101, a second processing module 1102, and a third processing module 1103; wherein:

[0153] The first processing module 1101 is used to send database operation and maintenance instructions through a database operation and maintenance tool. After the database soft switch performs security control on the database operation and maintenance instructions, it forwards them to the database. The second processing module 1102 is used for the database soft switch to simulate the database by using a similarity loop analysis algorithm, enabling the database to perform session keep-alive communication with the database operation and maintenance tool. The third processing module 1103 is used to call the operating system kernel and adopt a multi-threading mechanism and a fast read and write data cache queue for concurrent network traffic collection and analysis.

[0154] Aiming at the problem that various database tools need to be customized and developed for database operation and maintenance control, the present invention realizes the centralized control of database operation and maintenance through a database soft switch, without the need to transform the database tools. At the same time, it solves the problem of maintaining the keep-alive of database tools during the waiting period for the vault approval triggered by instructions, calls the operating system kernel, uses multi-threading and a fast read and write data cache queue to improve the traffic processing ability, and ensures the operation and maintenance efficiency.

[0155] Figure 12 Illustrates a schematic structural diagram of an electronic device, as Figure 12As shown, the electronic device may include: a processor 1210, a communications interface 1220, a memory 1230, and a communication bus 1240. Among them, the processor 1210, the communications interface 1220, and the memory 1230 complete communication with each other through the communication bus 1240. The processor 1210 may call the logical instructions in the memory 1230 to execute the database security control method, which includes: sending database operation and maintenance instructions through a database operation and maintenance tool, and after the database soft switch performs security control on the database operation and maintenance instructions, forwarding them to the database; the database soft switch simulates the database using a similarity loop analysis algorithm to enable the database to perform session keep-alive communication with the database operation and maintenance tool; calling the operating system kernel and using a multi-threaded mechanism and a fast read-write data cache queue to perform concurrent network traffic collection and analysis.

[0156] In addition, when the logical instructions in the above-mentioned memory 1230 can be implemented in the form of software functional units and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0157] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the database security control method provided by the above-mentioned various methods. The method includes: sending database operation and maintenance instructions through a database operation and maintenance tool, and after the database soft switch performs security control on the database operation and maintenance instructions, forwarding them to the database; the database soft switch simulates the database using a similarity loop analysis algorithm to enable the database to perform session keep-alive communication with the database operation and maintenance tool; calling the operating system kernel and using a multi-threaded mechanism and a fast read-write data cache queue to perform concurrent network traffic collection and analysis.

[0158] On the other hand, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is configured to execute the database security control method provided above. The method includes: sending a database operation and maintenance instruction through a database operation and maintenance tool, and after the database soft switch performs security control on the database operation and maintenance instruction, forwarding it to the database; the database soft switch simulates the database by using a similarity loop analysis algorithm, so that the database performs session keep-alive communication with the database operation and maintenance tool; calling the operating system kernel, and using a multi-thread mechanism and a fast read-write data cache queue to perform concurrent network traffic collection and analysis.

[0159] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative effort.

[0160] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solution, in essence, or the part that makes a contribution to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disc, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0161] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. Database security control method, characterized in that, Including: Sending database operation and maintenance instructions through a database operation and maintenance tool, and after the database soft switch performs security control on the database operation and maintenance instructions, forwarding them to the database; The database soft switch uses a similarity loop analysis algorithm to simulate the database, enabling the database to perform session keep-alive communication with the database operation and maintenance tool; specifically including: collecting the response message set after the database operation and maintenance instructions are sent, and obtaining several messages in the response message set; selecting any one of the several messages, and based on the similarity between the any one message and other messages, obtaining the keep-alive message format and the specific message value; based on the keep-alive message format and the specific message value, obtaining the operation command with the highest usage frequency in the response message set, and implementing link keep-alive according to the operation command with the highest usage frequency; Invoking the operating system kernel, and using a multi-threaded mechanism and a fast read-write data cache queue to perform concurrent network traffic collection and analysis.

2. The database security control method according to claim 1, wherein The sending of database operation and maintenance instructions through a database operation and maintenance tool, and after the database soft switch performs security control on the database operation and maintenance instructions, forwarding them to the database, specifically including: After the database soft switch receives the instruction message of the database operation and maintenance instruction, restoring the SQL instruction through protocol parsing, and judging whether the user performs a dangerous operation If it is judged that the user performs a dangerous operation, triggering a vault approval, otherwise directly forwarding the instruction message to the database.

3. The database security control method according to claim 2, wherein, After the step of if it is judged that the user performs a dangerous operation, triggering a vault approval, otherwise directly forwarding the instruction message to the database, further including: Recording the operation on the instruction message to form a log record, and performing security auditing based on the log record.

4. The database security control method according to claim 1, wherein The selecting any one of the several messages, and based on the similarity between the any one message and other messages, obtaining the keep-alive message format and the specific message value, specifically including: Comparing the any one message with other messages respectively, and obtaining the similarity between the any one message and other any one message by the ratio of the intersection of the any one message and other any one message to the union of the any one message and other any one message, adding up all the similarities between the any one message and other messages and then obtaining the average value to get the average similarity of the any one message; Calculating the similarity between each of the several messages and other messages one by one, and calculating the average similarity of all messages; After sorting the average similarities of all the messages, screening out the message sets with the top preset ratio of sorting, and repeating the foregoing calculation steps until the number of message sets does not exceed the preset number of message sets; Analyzing and validating the message format of the message set to obtain the keep-alive message format and the specific message value.

5. The database security control method according to claim 1, wherein The invoking the operating system kernel, and using a multi-threaded mechanism and a fast read-write data cache queue to perform concurrent network traffic collection and analysis, specifically including: Establishing a direct communication collection thread with the network card to obtain the original traffic message, forwarding the original traffic message to the upper-layer application of the operating system, and forwarding it to the database soft switch by the upper-layer application of the operating system; One collection thread corresponds to one parsing thread to form a thread group, and multiple thread groups process multiple original traffic packets in parallel at the same time; A cache queue space with a preset capacity is allocated to each thread group, and a read-write cursor is used to mark and perform circular operations on the cache queue to form the fast read-write data cache queue.

6. The database security control method according to claim 5, wherein The step of allocating a cache queue space with a preset capacity to each thread group and using a read-write cursor to mark and perform circular operations on the data cache queue to form the fast read-write data cache queue specifically includes: A message write cursor is respectively set to represent the message insertion position, and a message read cursor is set to represent the message read position; All message data are placed in the cache for waiting to be processed. According to the message write cursor, the message data are written into the cache. After the current insertion operation is completed, the message write cursor automatically moves down one bit to continue inserting the next message data; According to the message read cursor, the message data at the current position are read and analyzed. After the current read operation is completed, the message read cursor automatically moves down one bit to continue reading the next message data; The next position pointer of the last position of the data cache queue points to the first position of the data cache queue. Based on the message write cursor and the message read cursor, circular insertion and read-write are respectively performed on the data cache queue until no message data is inserted and all message data are read.

7. Database security control device, characterized in that, It includes: A first processing module, which is used to send database operation and maintenance instructions through a database operation and maintenance tool, and the database soft switch performs security control on the database operation and maintenance instructions and then forwards them to the database; A second processing module, which is used for the database soft switch to simulate the database by using a similarity loop analysis algorithm, so that the database and the database operation and maintenance tool perform session keep-alive communication; specifically includes: collecting the response message set after the database operation and maintenance instructions are sent, and obtaining several messages in the response message set; selecting any one of the several messages, and based on the similarity between the any one message and other messages, obtaining the keep-alive message format and the specific value of the message; based on the keep-alive message format and the specific value of the message, obtaining the operation command with the highest usage frequency in the response message set, and realizing link keep-alive according to the operation command with the highest usage frequency; A third processing module, which is used to call the operating system kernel and perform concurrent network traffic collection and analysis by using a multi-thread mechanism and a fast read-write data cache queue.

8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, the steps of the database security control method according to any one of claims 1 to 6 are implemented.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the database security control method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Data exporting method and device

    CN110008262A

  • System and method for implementing fixed network searching user integrated data base using soft exchange

    CN1913550A