A Method, Device, Medium, and Product for User Behavior Management Oriented to a Database

By introducing a behavior monitoring filter chain into the database, analyzing and identifying abnormal user behaviors and triggering corresponding control mechanisms, the problem of difficulty in deeply analyzing user behavior in the existing technology is solved, and a significant improvement in database security has been achieved.

CN118378264BActive Publication Date: 2025-05-30北京卫达信息技术有限公司
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202410521300.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-28
Publication Date
2025-05-30
Estimated Expiration
2044-04-28

AI Technical Summary

Technical Problem

The existing database audit system is difficult to analyze user behavior in depth, which makes it difficult to detect and prevent illegal operations in a timely manner, threatening database security.

Method used

The database-oriented user behavior management method is adopted to analyze user access requests through the behavior monitoring filter chain, identify abnormal behaviors, and trigger corresponding control mechanisms to store them in the security audit log.

Benefits of technology

It realizes in-depth analysis and real-time detection of user behavior, quickly block potential security threats, enhances the security of the database, and provides risk information and security optimization suggestions through security audit logs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118378264B_ABST
    Figure CN118378264B_ABST
Patent Text Reader

Abstract

This application relates to the technical field of data security, and in particular, to a user behavior management method, device, medium, and product for a database. The method includes: when a user access request is detected, using a behavior monitoring filter chain to perform user behavior analysis on the user access request. When the user behavior analysis result is abnormal, the abnormal user access request is controlled and processed according to the target control mechanism, and the abnormal user access request and the target control mechanism are stored in the security audit log. By using the behavior monitoring filter chain to conduct a detailed analysis of the user access request, when an abnormal behavior is found, the corresponding control mechanism can be quickly triggered, effectively preventing potential security threats and enhancing the security of the database. Finally, based on the security audit log, user behavior auditing is performed to obtain database risk information and security optimization information, so that database administrators can timely adjust the database security policy and improve the security of the database.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data security, and particularly to a user behavior management method, device, medium, and product for databases. Background Art

[0002] With the rapid development of information technology and the popularization of the Internet, databases have become the core tools for enterprises to store, manage, and analyze various types of data. Among the numerous data stored in databases, sensitive information such as user personal information, financial records, and business secrets occupies an important position. With the rapid development of network technology and the acceleration of the digitalization process, the problem of database information security has become increasingly prominent and has become the focus of attention of major enterprises.

[0003] As a key link in database information security, database user behavior management is directly related to the security and integrity of sensitive data. However, although existing database audit systems can record users' operation behaviors, they often lack in-depth analysis of user behaviors, making it difficult to detect and prevent illegal operations in a timely manner, threatening the security of the database.

[0004] Therefore, how to improve the security of databases is an urgent problem to be solved by those skilled in the art. Summary of the Invention

[0005] The purpose of the present application is to provide a user behavior management method, device, medium, and product for databases to solve at least one of the above technical problems.

[0006] The above-mentioned invention purpose of the present application is achieved through the following technical solutions:

[0007] In the first aspect, the present application provides a user behavior management method for databases, adopting the following technical solutions:

[0008] A user behavior management method for databases includes:

[0009] When a user access request is detected, use a behavior monitoring filter chain to perform user behavior analysis on the user access request to obtain a user behavior analysis result, where the behavior monitoring filter chain is a plurality of filtering conditions arranged according to filtering logic;

[0010] When the user behavior analysis result is abnormal, obtain the target control mechanism corresponding to the triggered filtering condition, perform control processing on the abnormal user access request according to the target control mechanism, and store the abnormal user access request and the target control mechanism in the security audit log;

[0011] Based on the security audit log, user behavior auditing is performed to obtain database risk information and security optimization information, so that database administrators can adjust database security policies in a timely manner and improve the security of the database.

[0012] By adopting the above technical solution, when a user access request is detected, the behavior monitoring filter chain is used to perform user behavior analysis on the user access request to obtain a user behavior analysis result. Furthermore, when the user behavior analysis result is abnormal, the target control mechanism corresponding to the trigger filtering condition is obtained, and the abnormal user access request is controlled and processed according to the target control mechanism, and the abnormal user access request and the target control mechanism are stored in the security audit log. Through the behavior monitoring filter chain, a detailed analysis of the user access request is carried out to detect and identify abnormal user behaviors in real time, so that when an abnormal behavior is found, the corresponding control mechanism is quickly triggered, effectively preventing potential security threats and enhancing the security of the database. Finally, based on the security audit log, user behavior auditing is performed to obtain database risk information and security optimization information, so that database administrators can adjust database security policies in a timely manner and improve the security of the database.

[0013] In a preferred example of the present application, it can be further configured that: the construction method of the behavior monitoring filter chain includes:

[0014] Obtain behavior monitoring requirement information, and based on the behavior monitoring requirement information, filter feature extraction is performed to determine filtering conditions and filtering logic, where the filtering conditions include: access frequency, access time, access source, operation type, and data modification range; the filtering logic includes: sequential execution, parallel execution, and combined execution;

[0015] Based on the filtering conditions and the filtering logic, a filter chain is constructed to obtain a behavior monitoring filter chain.

[0016] In a preferred example of the present application, it can be further configured that: after constructing the filter chain based on the filtering conditions and the filtering logic to obtain a behavior monitoring filter chain, it further includes:

[0017] Obtain behavior monitoring verification data, and based on the behavior monitoring verification data, perform performance verification on the behavior monitoring filter chain to obtain a performance verification result;

[0018] When the performance verification result is a failure, an abnormal warning is generated and the user's access to the database is suspended to improve the security of the database.

[0019] In a preferred example of the present application, it can be further configured that: after using the behavior monitoring filter chain to perform user behavior analysis on the user access request to obtain a user behavior analysis result, it further includes:

[0020] When the user behavior analysis result is normal, based on the request URL in the user access request, determine the target access data;

[0021] Obtain the data sensitivity classification corresponding to the database, and based on the target access data and the data sensitivity classification, determine the target sensitivity level;

[0022] Based on the target sensitivity level, determine the target storage location, and store the log data corresponding to the user access request at the target storage location in the security audit log.

[0023] In a preferred example of the present application, it can be further configured that: the user behavior audit based on the security audit log to obtain database risk information and security optimization information includes:

[0024] Extract abnormal behaviors based on the security audit log to obtain an abnormal behavior set, where the abnormal behavior set is the sum of all abnormal behaviors in the security audit log;

[0025] Perform abnormal association based on the abnormal behavior set to obtain an abnormal behavior execution chain, where the abnormal behavior execution chain is an execution chain that strings together related abnormal behaviors according to the time before and after their occurrence;

[0026] Perform risk analysis based on the abnormal behavior set and the abnormal behavior execution chain to obtain database risk information, where the database risk information includes: risk level, risk category;

[0027] Perform optimization analysis based on the database risk information to determine security optimization information.

[0028] In a preferred example of the present application, it can be further configured that: after the user behavior audit based on the security audit log to obtain database risk information and security optimization information, it further includes:

[0029] Perform abnormal traceability based on the abnormal behavior execution chain to determine the source of the abnormal behavior;

[0030] Perform abnormal reconstruction and abnormal prediction based on the source of the abnormal behavior and the abnormal behavior execution chain to determine the attack method and action path corresponding to the abnormal behavior;

[0031] Perform optimization adjustment based on the attack method and action path to obtain the adjusted security optimization information.

[0032] In a second aspect, the present application provides an electronic device, adopting the following technical solution:

[0033] At least one processor;

[0034] Memory;

[0035] At least one application program, where the at least one application program is stored in the memory and configured to be executed by at least one processor, and the at least one application program is configured to: execute the above-mentioned database-oriented user behavior management method.

[0036] In a third aspect, the present application provides a computer-readable storage medium, adopting the following technical solution:

[0037] A computer-readable storage medium, on which a computer program is stored. When the computer program is executed on a computer, the computer is made to execute the above-mentioned database-oriented user behavior management method.

[0038] In a fourth aspect, the present application provides a computer program product, adopting the following technical solution:

[0039] A computer program product, including a computer program, where when the computer program is executed by a processor, the above-mentioned database-oriented user behavior management method is implemented.

[0040] In summary, the present application includes at least one of the following beneficial technical effects:

[0041] When a user access request is detected, the behavior monitoring filter chain is used to perform user behavior analysis on the user access request to obtain a user behavior analysis result. Furthermore, when the user behavior analysis result is abnormal, the target control mechanism corresponding to the trigger filtering condition is obtained, and the abnormal user access request is controlled and processed according to the target control mechanism, and the abnormal user access request and the target control mechanism are stored in the security audit log. By performing detailed analysis on the user access request through the behavior monitoring filter chain, abnormal user behaviors are detected and identified in real time, so that when an abnormal behavior is found, the corresponding control mechanism is quickly triggered, effectively preventing potential security threats and enhancing the security of the database. Finally, user behavior auditing is performed based on the security audit log to obtain database risk information and security optimization information, so that database administrators can timely adjust the database security policy and improve the security of the database.

[0042] Filtering feature extraction is performed based on the behavior monitoring requirement information to determine the filtering condition and filtering logic. Then, based on the filtering condition and filtering logic, a filtering chain is constructed to obtain a behavior monitoring filter chain. Through the accurate acquisition of the behavior monitoring requirement information and the requirement-based filtering feature extraction, a monitoring model that better fits the actual business scenario can be constructed, and by using the behavior monitoring filter chain to monitor user access, the monitoring efficiency is improved, and abnormal events can be quickly responded to and processed. Description of the Drawings

[0043] Figure 1It is a schematic flowchart of a user behavior management method for a database according to an embodiment of the present application;

[0044] Figure 2 It is a schematic structural diagram of a user behavior management device for a database according to an embodiment of the present application;

[0045] Figure 3 It is a schematic structural diagram of an electronic device according to an embodiment of the present application. Detailed implementation manners

[0046] The following is combined with Figures 1 to 3 to further elaborate on the present application.

[0047] This specific embodiment is only an interpretation of the present application and does not limit the present application. After reading this specification, those skilled in the art can make modifications to this embodiment without creative contributions as needed, but as long as they are within the scope of the present application, they are protected by the patent law.

[0048] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present application. It should be noted that in the alternative embodiments of the present application, for relevant data such as object information, when the embodiments in the present application are applied to specific products or technologies, permission or consent from the object needs to be obtained, and the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards in relevant countries and regions. That is to say, in the embodiments of the present application, if it involves data related to an object, it needs to be obtained under the authorization and consent of the object, the authorization and consent of relevant departments, and compliance with relevant laws, regulations, and standards in relevant countries and regions. In the embodiments, if personal information is involved, the acquisition of all personal information requires the consent of the individual. If sensitive information is involved, the separate consent of the information subject needs to be obtained, and the embodiments also need to be implemented under the authorization and consent of the object.

[0049] In addition, the term "and / or" in this article is only a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after, unless otherwise specified.

[0050] The following further describes the embodiments of the present application in conjunction with the accompanying drawings of the specification.

[0051] An embodiment of the present application provides a user behavior management method for a database, which is executed by an electronic device. The electronic device can be a server or a terminal device. Among them, the server can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal device can be a smart phone, a tablet computer, a notebook computer, a desktop computer, etc., but is not limited thereto. The terminal device and the server can be directly or indirectly connected through wired or wireless communication methods. This embodiment of the present application does not make any restrictions here. For example Figure 1 As shown, the method includes step S101, step S102, and step S103, where

[0052] Step S101: When a user access request is detected, use a behavior monitoring filter chain to perform user behavior analysis on the user access request to obtain a user behavior analysis result. Among them, the behavior monitoring filter chain is a plurality of filtering conditions arranged according to a filtering logic

[0053] For the embodiment of the present application, in order to enhance the security of the database, a detailed analysis of the user access request is performed through the behavior monitoring filter chain to detect and identify abnormal user behaviors in real time, so that when an abnormal behavior is found, the corresponding control mechanism is quickly triggered to effectively prevent potential security threats

[0054] Specifically, when a user access request is detected, use a behavior monitoring filter chain to perform user behavior analysis on the user access request to obtain a user behavior analysis result. Among them, the user access request includes but is not limited to: user identity information, request details (including: request method, request URL, request parameters), timestamp, source IP address, session information, etc. When performing user behavior analysis, the information items captured in the user access request are sequentially compared and analyzed through each filtering condition in the behavior monitoring filter chain, and according to the matching result with each filtering condition, it is judged whether the user behavior is abnormal to obtain the user behavior analysis result. That is, when any one of the filtering conditions fails to match, it is determined that the user behavior analysis result is abnormal; otherwise, it is determined that the user behavior analysis result is normal

[0055] Step S102: When the user behavior analysis result is abnormal, obtain the target control mechanism corresponding to the triggered filtering condition, perform control processing on the abnormal user access request according to the target control mechanism, and store the abnormal user access request and the target control mechanism in the security audit log

[0056] For the embodiments of the present application, when the user behavior analysis result is abnormal, it indicates that there are potential security risks in database management. For example, unauthorized access, malicious attacks, and data leakage, that is, abnormal users attempt to bypass the security mechanism, use illegal means to obtain data, or perform unauthorized operations. Therefore, when an abnormality occurs, the electronic device will first determine which or which filtering conditions are triggered, resulting in an abnormal user behavior analysis result. The triggered filtering conditions will serve as the basis for subsequent control processing. Furthermore, according to the filtering conditions triggered by the user access request, the target control mechanism corresponding to the triggered filtering conditions is found from the control mechanism database. Among them, the target control mechanism is a series of predefined security measures, such as organizing access, recording warnings, restricting permissions, triggering two-factor authentication, etc. The control mechanism database pre-stores the control mechanism corresponding to each filtering condition. Then, the abnormal user access request is controlled and processed according to the target control mechanism, and the abnormal user access request and the target control mechanism are stored in the security audit log. The security audit log is an important security record, which is convenient for subsequent security incident investigation, risk analysis, and security policy optimization. For the security audit log, it needs to be backed up regularly to prevent data loss or tampering. Of course, the log also needs to be properly managed, such as setting access permissions, regularly cleaning and archiving, etc., to ensure the availability and security of the log.

[0057] Step S103: Perform user behavior auditing based on the security audit log to obtain database risk information and security optimization information, so that database administrators can timely adjust the database security policy and improve the security of the database.

[0058] For the embodiments of this application, for the convenience of user behavior auditing, the security audit logs are cleaned to remove duplicate, incorrect, or irrelevant information, and field extraction and formatting are performed to convert the logs into structured data for easy data analysis. Using data mining and machine learning technologies, in-depth analysis of user behavior in the structured data is carried out to identify patterns, trends, and anomalies in user behavior, obtaining database risk information and security optimization information, so that database administrators can timely adjust database security policies and improve the security of the database. There are various implementation methods for user behavior auditing, which are not limited in the embodiments of this application. In one implementable method, abnormal behavior extraction is performed based on the security audit logs to obtain an abnormal behavior set, where the abnormal behavior set is the sum of all abnormal behaviors in the security audit logs; abnormal behavior association is performed based on the abnormal behavior set to obtain an abnormal behavior execution chain, where the abnormal behavior execution chain is an execution chain that concatenates related abnormal behaviors in the order of time occurrence; risk analysis is performed based on the abnormal behavior set and the abnormal behavior execution chain to obtain database risk information, where the database risk information includes: risk level, risk category; optimization analysis is performed based on the database risk information to determine security optimization information. To facilitate database administrators to intuitively understand the security status and optimization direction of the database, the database risk information and security optimization information are presented in the form of a report using a visualization tool. Through user behavior auditing, potential security risks can be timely discovered, and the implementation of security optimization suggestions helps to strengthen the security defense line of the database and improve the security of the database.

[0059] It can be seen that in the embodiments of this application, when a user access request is detected, user behavior analysis is performed on the user access request using a behavior monitoring filter chain to obtain a user behavior analysis result. Furthermore, when the user behavior analysis result is abnormal, the target control mechanism corresponding to the trigger filter condition is obtained, and the abnormal user access request is controlled and processed according to the target control mechanism, and the abnormal user access request and the target control mechanism are stored in the security audit log. Through the behavior monitoring filter chain, detailed analysis of the user access request is carried out to detect and identify abnormal user behavior in real time, so that when abnormal behavior is found, the corresponding control mechanism is quickly triggered, effectively preventing potential security threats and enhancing the security of the database. Finally, user behavior auditing is performed based on the security audit log to obtain database risk information and security optimization information, so that database administrators can timely adjust database security policies and improve the security of the database.

[0060] Furthermore, in order to build a monitoring model that better fits the actual business scenario and improve the monitoring efficiency, in the embodiments of this application, the construction method of the behavior monitoring filter chain includes:

[0061] Obtain behavior monitoring requirement information, extract filtering features based on the behavior monitoring requirement information, and determine filtering conditions and filtering logics. Among them, the filtering conditions include: access frequency, access time, access source, operation type, and data modification range; the filtering logics include: sequential execution, parallel execution, and combined execution;

[0062] Construct a filtering chain based on the filtering conditions and filtering logics to obtain a behavior monitoring filtering chain.

[0063] For the embodiments of the present application, during the monitoring process of database access, specific monitoring criteria need to be clarified. Therefore, database administrators, security experts, and business-related personnel will preset clear monitoring requirements in advance and input the behavior monitoring requirement information into the electronic device. Of course, the behavior monitoring requirements can also be adjusted according to the actual situation. Then, extract filtering features based on the behavior monitoring requirement information to determine filtering conditions and filtering logics. Among them, the filtering conditions include but are not limited to: access frequency, access time, access source (the source IP address or device information of the user accessing the database), operation type (for example, query, insert, update, delete, etc.), and data modification range (for example, the amount of modified data, the data tables and fields involved in the modification). The filtering logics include: sequential execution, parallel execution, and combined execution. For sequential execution, check each filtering condition in the preset order, and trigger exception handling as long as one of the filtering conditions is met; for parallel execution, check all filtering conditions simultaneously, and handle exception handling as long as one of the filtering conditions is met; for combined execution, combine multiple filtering conditions according to the requirements. For example, "the filtering conditions of access frequency and access time need to be met simultaneously". Furthermore, construct a filtering chain based on the filtering conditions and filtering logics to obtain a behavior monitoring filtering chain. The behavior monitoring filtering chain is an ordered set of filtering conditions, and each filtering condition is a node in the behavior monitoring filtering chain, which is connected according to the filtering logic. Among them, the construction process can be implemented by programming. Of course, other methods can also be used for construction, and the embodiments of the present application will not be limited. Through the accurate acquisition of behavior monitoring requirement information and the extraction of filtering features based on the requirements, a monitoring model that better fits the actual business scenario can be constructed. Moreover, using the behavior monitoring filtering chain to monitor user access improves the monitoring efficiency and can quickly respond to and handle abnormal events.

[0064] It can be seen that in the embodiments of the present application, extract filtering features based on the behavior monitoring requirement information to determine filtering conditions and filtering logics. Then, construct a filtering chain based on the filtering conditions and filtering logics to obtain a behavior monitoring filtering chain. Through the accurate acquisition of behavior monitoring requirement information and the extraction of filtering features based on the requirements, a monitoring model that better fits the actual business scenario can be constructed. Moreover, using the behavior monitoring filtering chain to monitor user access improves the monitoring efficiency and can quickly respond to and handle abnormal events.

[0065] Further, in order to enhance the security of the database, in the embodiments of the present application, after constructing the behavior monitoring filter chain based on the filtering conditions and filtering logic, the following steps are further included:

[0066] Obtain behavior monitoring verification data, and perform performance verification on the behavior monitoring filter chain based on the behavior monitoring verification data to obtain a performance verification result;

[0067] When the performance verification result is a failure, an exception warning is generated, and the user's access to the database is suspended to enhance the security of the database.

[0068] For the embodiments of the present application, after constructing the behavior monitoring filter chain, performing performance verification on the behavior monitoring filter chain helps to improve the performance and accuracy of the filter chain, ensures that the behavior monitoring filter chain can accurately identify abnormal database accesses, and reduces interference and obstacles to the normal operations of users, thereby improving the user experience.

[0069] Specifically, obtain behavior monitoring verification data. The behavior monitoring verification data includes: abnormal behavior data and normal operation data. The behavior monitoring verification data marks whether the user behavior data is normal or abnormal, and the behavior monitoring verification data should cover various user behavior scenarios as much as possible to facilitate a comprehensive test of the performance and accuracy of the behavior monitoring filter chain. Then, input the behavior monitoring verification data into the behavior monitoring filter chain, simulate the process of the user accessing the database and performing user behavior monitoring, record the processing results of the behavior monitoring filter chain for each data sample, that is, whether the user behavior analysis result is abnormal or normal, and the response time of the processing process. Furthermore, based on the processing results of the behavior monitoring filter chain, compare with the evaluation criteria to evaluate the performance and accuracy of the behavior monitoring filter. That is, the evaluation criteria include but are not limited to: abnormal recognition accuracy rate, false alarm rate, missed alarm rate, response time, etc. When all indicators exceed the thresholds set by the evaluation criteria, it is determined that the performance verification result is successful; otherwise, it is determined that the performance verification result is a failure. When the performance verification result is successful, it indicates that the behavior monitoring filter chain meets the usage requirements, and the behavior monitoring filter chain is continuously used for user behavior analysis; when the performance verification result is a failure, an exception warning is generated, and the database administrator is notified by email, text message or other means, and the user's access to the database is suspended to prevent potential security risks and enhance the security of the database.

[0070] It can be seen that in the embodiments of the present application, performance verification is performed on the behavior monitoring filter chain based on the behavior monitoring verification data to obtain a performance verification result. Then, when the performance verification result is a failure, an exception warning is generated, and the user's access to the database is suspended to enhance the security of the database.

[0071] Further, to improve the audit efficiency and make the log management more orderly and efficient, so as to quickly locate and analyze data with different sensitivities, in the embodiment of the present application, after using the behavior monitoring filter chain to perform user behavior analysis on the user access request and obtaining the user behavior analysis result, it further includes:

[0072] When the user behavior analysis result is normal, based on the request URL in the user access request, determine the target access data;

[0073] Obtain the data sensitivity classification of the database, and based on the target access data and the data sensitivity classification, determine the target sensitivity level;

[0074] Based on the target sensitivity level, determine the target storage location, and store the log data corresponding to the user access request at the target storage location in the security audit log.

[0075] For the embodiment of the present application, when the database stores data, it will be divided into different data sensitivity classifications according to factors such as the importance, nature, and confidentiality of the data. To improve the audit efficiency, it is classified and stored in different locations in the security audit log according to the data sensitivity classification, making the log management more orderly and efficient, so as to quickly locate and analyze data with different sensitivities.

[0076] Specifically, when the user behavior analysis result is normal, the electronic device starts to process the user access request, extracts the request URL from the user access request. The request URL is the identifier of the data resource that the user hopes to access. Then, according to the request URL, find the corresponding target access data in the database resource directory. Then, obtain the data sensitivity classification information of the corresponding data in the database. Among them, the data sensitivity classification is usually set in advance and is divided according to factors such as the nature, importance, and confidentiality of the data. For example, it can be divided into different levels such as public, internal, and confidential. Furthermore, compare the extracted target access data with the data sensitivity classification to determine the target sensitivity level. The storage area of the security audit log is divided into multiple storage areas for storing the access operations corresponding to data with different data sensitivity classifications, so as to facilitate subsequent targeted audits and analyses. Furthermore, store the log data corresponding to the user access request (including user information, access time, operation type, etc.) according to the determined target storage location. In this way, sensitive data can be effectively isolated and protected to prevent unauthorized access and leakage.

[0077] It can be seen that in the embodiments of the present application, when the user behavior analysis result is normal, the target access data is determined based on the request URL in the user access request. Then, based on the target access data and the data sensitivity classification, the target sensitivity level is determined. Finally, based on the target sensitivity level, the target storage location is determined, and the log data corresponding to the user access request is stored at the target storage location in the security audit log. To improve the audit efficiency, the data is classified and stored at different locations in the security audit log according to the data sensitivity classification, making the log management more orderly and efficient, so as to quickly locate and analyze data with different sensitivities.

[0078] Further, in the embodiments of the present application, user behavior auditing is performed based on the security audit log to obtain database risk information and security optimization information, including:

[0079] Extract abnormal behaviors based on the security audit log to obtain an abnormal behavior set, where the abnormal behavior set is the sum of all abnormal behaviors in the security audit log;

[0080] Perform abnormal association based on the abnormal behavior set to obtain an abnormal behavior execution chain, where the abnormal behavior execution chain is an execution chain that strings together related abnormal behaviors according to the time sequence before and after their occurrence;

[0081] Perform risk analysis based on the abnormal behavior set and the abnormal behavior execution chain to obtain database risk information, where the database risk information includes: risk level, risk category;

[0082] Perform optimization analysis based on the database risk information to determine the security optimization information.

[0083] For the embodiments of the present application, the security audit log records the access to and operations on the database by users, including but not limited to: key information such as user ID, operation time, operation type, operation object, etc. Before extracting abnormal behaviors, the security audit log is preprocessed to facilitate subsequent analysis and processing. Among them, the preprocessing includes but not limited to: removing duplicate records, formatting log data, extracting key fields, etc. Obtain an abnormal behavior pattern, which is preset and stored in the electronic device, and the user can adjust it according to actual needs. The abnormal behavior pattern can be set from multiple dimensions such as operation frequency, operation time, operation type, access source, etc. Therefore, the security audit log is matched with the abnormal behavior pattern, and the matched abnormal behaviors are extracted to form an abnormal behavior set. The abnormal behavior set details the corresponding detailed information for each abnormal behavior. Therefore, abnormal association is performed based on the abnormal behavior set. Among them, the dimensions of abnormal association include: time association, behavior type association, resource association, and executor association. For abnormal time association, consider the time sequence of the occurrence of abnormal behaviors. If two or more abnormal behaviors occur continuously in a short period of time, then it is determined that there is an association; for behavior type association, the concomitant occurrence of certain types of abnormal behaviors indicates an association between the two. For example, after a first login and access failure, a brute-force cracking method is immediately used to access the database; for resource association, if multiple abnormal behaviors involve the same or related data and resources, it indicates an association between the two; for executor association, if the same executor continuously executes multiple abnormal behaviors, it indicates an association between the multiple abnormal behaviors. Furthermore, based on the associated abnormal behaviors in the abnormal behavior set, the abnormal behaviors are concatenated in the order of time occurrence to obtain an abnormal behavior execution chain. To ensure the accuracy and integrity of the abnormal behavior execution chain, some redundant or noisy behaviors that are associated but do not affect the overall execution process are removed during the formation of the execution chain. Through abnormal association analysis, an abnormal behavior execution chain is formed, which can deeply understand the occurrence pattern, association relationship, and potential risk scenarios of abnormal behaviors, help to reveal the attack path and purpose of the attacker, and provide strong support for formulating targeted defense strategies.

[0084] Furthermore, risk analysis is performed based on the abnormal behavior set and the abnormal behavior execution chain. That is, key risk features are extracted from the abnormal behavior set, such as abnormal behavior frequency, duration, scope of influence, etc.; the abnormal behavior execution chain is analyzed to identify associated nodes and potential risk paths. Furthermore, risk assessment is performed based on the key risk features and potential risk paths to obtain a risk level. Among them, during the process of performing risk assessment, a preset risk assessment model or algorithm is combined; according to the nature, motivation, and potential consequences of the abnormal behavior, the risk is classified to obtain risk categories, such as data leakage, unauthorized access, malicious attack, misoperation, etc. Preferably, database risk information such as risk levels and risk categories is summarized to form a detailed risk report or risk matrix. Then, optimization analysis is performed based on the database risk information to determine security optimization information. Performing risk analysis based on the abnormal behavior set and the abnormal behavior execution chain can accurately assess the risk level and risk category of the database. Through quantitative and qualitative analysis methods, the risk can be refined and evaluated, providing a decision-making basis for the security management of the database.

[0085] It can be seen that in the embodiment of the present application, abnormal behavior extraction is performed based on the security audit log to obtain an abnormal behavior set. Then, abnormal association is performed based on the abnormal behavior set to obtain an abnormal behavior execution chain. Through abnormal association analysis, an abnormal behavior execution chain is formed, which can deeply understand the occurrence pattern, association relationship, and potential risk scenarios of abnormal behavior, helping to reveal the attacker's attack path and purpose, and providing strong support for formulating targeted defense strategies. Furthermore, risk analysis is performed based on the abnormal behavior set and the abnormal behavior execution chain to obtain database risk information, and optimization analysis is performed based on the database risk information to determine security optimization information. Performing risk analysis based on the abnormal behavior set and the abnormal behavior execution chain can accurately assess the risk level and risk category of the database. Through quantitative and qualitative analysis methods, the risk can be refined and evaluated, providing a decision-making basis for the security management of the database.

[0086] Further, in order to improve the overall security protection ability of the database and help better cope with database security risks, in the embodiment of the present application, after performing user behavior auditing based on the security audit log to obtain database risk information and security optimization information, it further includes:

[0087] Performing abnormal traceability based on the abnormal behavior execution chain to determine the source of the abnormal behavior;

[0088] Performing abnormal reconstruction and abnormal prediction based on the source of the abnormal behavior and the abnormal behavior execution chain to determine the attack method and action path corresponding to the abnormal behavior;

[0089] Performing optimization adjustment based on the attack method and action path to obtain the adjusted security optimization information.

[0090] For the embodiments of the present application, behavior path tracing is performed based on the abnormal behavior execution chain to determine the propagation path of the abnormal behavior in the database, and the behavior path and security audit logs are comprehensively analyzed to determine the source of the abnormal behavior. For example, a specific user, IP address, or external attacker. Then, according to the source of the abnormal behavior and the abnormal behavior execution chain, the complete process of the abnormal behavior is reconstructed, and the reconstructed abnormal behavior is analyzed to identify the attack techniques used by the attacker. For example, SQL injection, cross-site scripting attack, etc. At the same time, machine learning or pattern recognition technology is used to predict the development trend of the abnormal behavior, that is, based on historical abnormal behaviors and the current security status, the possible next action path of the attacker is predicted. Then, optimization and adjustment are performed based on the attack techniques and action paths to obtain the adjusted security optimization information. For example, strengthening input validation, updating firewall rules, and strengthening the protection of relevant resources and data (resources corresponding to the predicted next action path of the attacker). Through abnormal behavior tracing and optimization and adjustment, it helps to better cope with database security risks and improve the overall security protection ability of the database.

[0091] It can be seen that in the embodiments of the present application, abnormal behavior tracing is performed based on the abnormal behavior execution chain to determine the source of the abnormal behavior. Then, based on the source of the abnormal behavior and the abnormal behavior execution chain, abnormal behavior reconstruction and abnormal behavior prediction are performed to determine the attack techniques and action paths corresponding to the abnormal behavior. Finally, optimization and adjustment are performed based on the attack techniques and action paths to obtain the adjusted security optimization information. Through abnormal behavior tracing and optimization and adjustment, it helps to better cope with database security risks and improve the overall security protection ability of the database.

[0092] The above embodiments introduce a user behavior management method for databases from the perspective of the method process. The following embodiments introduce a user behavior management device for databases from the perspective of virtual modules or virtual units. For details, see the following embodiments.

[0093] The embodiments of the present application provide a user behavior management device for databases, as Figure 2 shown. The user behavior management device for databases may specifically include:

[0094] A user behavior analysis module 210, configured to perform user behavior analysis on a user access request using a behavior monitoring and filtering chain when detecting the user access request, so as to obtain a user behavior analysis result, where the behavior monitoring and filtering chain is a plurality of filtering conditions arranged according to a filtering logic;

[0095] Anomaly control module 220 is used to obtain the target control mechanism corresponding to the trigger filtering condition when the user behavior analysis result is abnormal, control and process the abnormal user access request according to the target control mechanism, and store the abnormal user access request and the target control mechanism in the security audit log;

[0096] User behavior auditing module 230 is used to conduct user behavior auditing based on the security audit log to obtain database risk information and security optimization information, so that database administrators can adjust the database security policy in a timely manner to improve the security of the database.

[0097] For the embodiments of the present application, when a user access request is detected, the user behavior analysis of the user access request is performed using the behavior monitoring filter chain to obtain the user behavior analysis result. Furthermore, when the user behavior analysis result is abnormal, the target control mechanism corresponding to the trigger filtering condition is obtained, the abnormal user access request is controlled and processed according to the target control mechanism, and the abnormal user access request and the target control mechanism are stored in the security audit log. By performing a detailed analysis of the user access request through the behavior monitoring filter chain, abnormal user behaviors are detected and identified in real time, so that when an abnormal behavior is found, the corresponding control mechanism is quickly triggered, effectively preventing potential security threats and enhancing the security of the database. Finally, user behavior auditing is performed based on the security audit log to obtain database risk information and security optimization information, so that database administrators can adjust the database security policy in a timely manner to improve the security of the database.

[0098] A possible implementation manner of the embodiments of the present application, a user behavior management device for a database, further includes:

[0099] A filter chain construction module is used to obtain behavior monitoring requirement information, extract filtering features based on the behavior monitoring requirement information, determine filtering conditions and filtering logic, where the filtering conditions include: access frequency, access time, access source, operation type, and data modification range; the filtering logic includes: sequential execution, parallel execution, and combined execution;

[0100] Construct a filter chain based on the filtering conditions and filtering logic to obtain a behavior monitoring filter chain.

[0101] A possible implementation manner of the embodiments of the present application, a user behavior management device for a database, further includes:

[0102] A verification module is used to obtain behavior monitoring verification data and perform performance verification on the behavior monitoring filter chain based on the behavior monitoring verification data to obtain a performance verification result;

[0103] When the performance verification result is a failure, an anomaly warning is generated and the user's access to the database is suspended to improve the security of the database.

[0104] A possible implementation of the embodiment of the present application, the user behavior management device for a database further includes:

[0105] A classification storage module, configured to, when the user behavior analysis result is normal, determine target access data based on the request URL in the user access request;

[0106] Obtain the data sensitivity classification corresponding to the database, and determine the target sensitivity level based on the target access data and the data sensitivity classification;

[0107] Based on the target sensitivity level, determine the target storage location, and store the log data corresponding to the user access request at the target storage location in the security audit log.

[0108] A possible implementation of the embodiment of the present application, when the user behavior audit module 230 performs user behavior audit based on the security audit log to obtain database risk information and security optimization information, it is used for:

[0109] Extract abnormal behaviors based on the security audit log to obtain an abnormal behavior set, where the abnormal behavior set is the sum of all abnormal behaviors in the security audit log;

[0110] Perform abnormal association based on the abnormal behavior set to obtain an abnormal behavior execution chain, where the abnormal behavior execution chain is an execution chain that strings together related abnormal behaviors according to the time sequence before and after;

[0111] Perform risk analysis based on the abnormal behavior set and the abnormal behavior execution chain to obtain database risk information, where the database risk information includes: risk level, risk category;

[0112] Perform optimization analysis based on the database risk information to determine security optimization information.

[0113] A possible implementation of the embodiment of the present application, the user behavior management device for a database further includes:

[0114] An abnormal traceability module, configured to perform abnormal traceability based on the abnormal behavior execution chain to determine the source of the abnormal behavior;

[0115] Perform abnormal reconstruction and abnormal prediction based on the source of the abnormal behavior and the abnormal behavior execution chain to determine the attack method and action path corresponding to the abnormal behavior;

[0116] Perform optimization adjustment based on the attack method and the action path to obtain the adjusted security optimization information.

[0117] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working process of the above-described user behavior management device for a database can refer to the corresponding process in the foregoing method embodiments and will not be elaborated herein.

[0118] An embodiment of the present application provides an electronic device, such as Figure 3 shown. Figure 3 The electronic device 300 shown includes: a processor 301 and a memory 303. Among them, the processor 301 and the memory 303 are connected, such as connected through a bus 302. Optionally, the electronic device 300 may further include a transceiver 304. It should be noted that in actual applications, the transceiver 304 is not limited to one, and the structure of the electronic device 300 does not constitute a limitation to the embodiments of the present application.

[0119] The processor 301 may be a CPU (Central Processing Unit, central processor), a general-purpose processor, a DSP (Digital Signal Processor, data signal processor), an ASIC (Application Specific Integrated Circuit, application-specific integrated circuit), an FPGA (Field Programmable Gate Array, field programmable gate array) or other programmable logic devices, transistor logic devices, hardware components or any combination thereof. It can implement or execute various exemplary logic blocks, modules and circuits described in combination with the disclosure of the present application. The processor 301 may also be a combination for implementing computing functions, such as a combination including one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0120] The bus 302 may include a path for transmitting information between the above components. The bus 302 may be a PCI (Peripheral Component Interconnect, peripheral component interconnect standard) bus or an EISA (Extended Industry Standard Architecture, extended industry standard structure) bus, etc. The bus 302 may be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 3 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.

[0121] The memory 303 can be a ROM (Read Only Memory), or other types of static storage devices that can store static information and instructions, a RAM (Random Access Memory), or other types of dynamic storage devices that can store information and instructions. It can also be an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.

[0122] The memory 303 is used to store the application program code for implementing the solution of this application and is controlled by the processor 301 for execution. The processor 301 is used to execute the application program code stored in the memory 303 to implement the content shown in the foregoing method embodiments.

[0123] Among them, the electronic device includes but is not limited to: mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. It can also be a server, etc. Figure 3 The illustrated electronic device is only an example and should not impose any limitations on the functions and usage scope of the embodiments of this application.

[0124] The embodiments of this application provide a computer-readable storage medium on which a computer program is stored. When it runs on a computer, it enables the computer to execute the corresponding content in the foregoing method embodiments.

[0125] An embodiment of the present application provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the method in any of the above embodiments. Compared with the related art, in the embodiment of the present application, when a user access request is detected, a user behavior analysis is performed on the user access request by using a behavior monitoring filter chain to obtain a user behavior analysis result. Furthermore, when the user behavior analysis result is abnormal, a target control mechanism corresponding to the trigger filtering condition is obtained, and the abnormal user access request is controlled and processed according to the target control mechanism, and the abnormal user access request and the target control mechanism are stored in the security audit log. By performing a detailed analysis of the user access request through the behavior monitoring filter chain, abnormal user behaviors are detected and identified in real time, so that when an abnormal behavior is found, the corresponding control mechanism is quickly triggered, effectively preventing potential security threats and enhancing the security of the database. Finally, based on the security audit log, a user behavior audit is performed to obtain database risk information and security optimization information, so that database administrators can timely adjust the database security policy and improve the security of the database.

[0126] It should be understood that although the steps in the flowchart of the accompanying drawings are shown in sequence according to the indication of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps is not strictly limited in order, and they can be executed in other orders. Moreover, at least a part of the steps in the flowchart of the accompanying drawings may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or sub-steps or stages of other steps.

[0127] The above are only some implementation manners of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A user behavior management method for a database, characterized in that: include: When a user access request is detected, a user behavior analysis is performed on the user access request using a behavior monitoring filter chain to obtain a user behavior analysis result, wherein the behavior monitoring filter chain is a plurality of filter conditions arranged according to a filter logic; When the user behavior analysis result is abnormal, the target control mechanism corresponding to the trigger filtering condition is obtained, the abnormal user access request is controlled and processed according to the target control mechanism, and the abnormal user access request and the target control mechanism are stored in the security audit log; Conduct user behavior audits based on the security audit logs to obtain database risk information and security optimization information, so that database administrators can adjust database security policies in a timely manner to improve database security; Wherein, the method of performing user behavior analysis on the user access request by using the behavior monitoring filter chain and obtaining the user behavior analysis result further includes: When the user behavior analysis result is normal, the target access data is determined based on the request URL in the user access request; Obtaining a data sensitivity classification corresponding to a database, and determining a target sensitivity level based on the target access data and the data sensitivity classification; Based on the target sensitivity level, determine a target storage location, and store the log data corresponding to the user access request at the target storage location in the security audit log; The user behavior audit based on the security audit log to obtain database risk information and security optimization information includes: obtaining abnormal behavior patterns, and matching the security audit log with the abnormal behavior patterns to obtain an abnormal behavior set, wherein the abnormal behavior set is the sum of all abnormal behaviors in the security audit log; Based on the abnormal behavior set, abnormal association is performed to obtain an abnormal behavior execution chain, wherein the abnormal behavior execution chain is an execution chain that connects the associated abnormal behaviors in series according to the time before and after they occur, and the dimensions of abnormal association include: time association, behavior type association, resource association and executor association; Perform risk analysis based on the abnormal behavior set and the abnormal behavior execution chain to obtain database risk information, wherein the database risk information includes: risk level and risk category; Perform optimization analysis based on the database risk information to determine security optimization information; After performing user behavior audit based on the security audit log to obtain database risk information and security optimization information, the method further includes: Based on the abnormal behavior execution chain, the behavior path is tracked to determine the propagation path of the abnormal behavior in the database. According to the propagation path of the abnormal behavior in the database and the security audit log, the source of the abnormal behavior is determined; according to the source of the abnormal behavior and the abnormal behavior execution chain, the complete process of the abnormal behavior is reconstructed, and the reconstructed abnormal behavior is analyzed to identify the attack methods used by the attacker; using pattern recognition technology, the development area of ​​the abnormal behavior is predicted to obtain the attacker's next action path; based on the attack methods used by the attacker and the next action path, optimization and adjustment are performed to obtain adjusted security optimization information.

2. The method for managing user behavior in a database according to claim 1, characterized in that: The construction method of the behavior monitoring filter chain includes: Obtaining behavior monitoring demand information, and performing filtering feature extraction based on the behavior monitoring demand information, and determining filtering conditions and filtering logic, wherein the filtering conditions include: access frequency, access time, access source, operation type, and data modification range; the filtering logic includes: sequential execution, parallel execution, and combined execution; A filter chain is constructed based on the filter condition and the filter logic to obtain a behavior monitoring filter chain.

3. The method for managing user behavior in a database according to claim 2, characterized in that: After the filter chain is constructed based on the filter condition and the filter logic to obtain the behavior monitoring filter chain, the method further includes: Acquire behavior monitoring verification data, and perform performance verification on the behavior monitoring filter chain based on the behavior monitoring verification data to obtain a performance verification result; When the performance verification result is a failure, an abnormal warning is generated and the user's access to the database is suspended to improve the security of the database.

4. An electronic device, characterized in that: include: at least one processor; Memory; At least one application, wherein the at least one application is stored in a memory and configured to be executed by at least one processor, and the at least one application is configured to: execute the database-oriented user behavior management method according to any one of claims 1 to 3.

5. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and when the computer program is executed in a computer, the computer is caused to execute the database-oriented user behavior management method according to any one of claims 1 to 3.

6. A computer program product, characterized in that The method comprises a computer program, wherein the computer program is executed by a processor to implement the database-oriented user behavior management method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • A big data detection and audit system

    CN109446817A

  • Database access-oriented user behavior management and control method and system

    CN112241551A

  • Service identification and risk analysis method and system based on event sequence association fusion

    CN115225386A

  • Authorization management method and device, electronic equipment and storage medium

    CN117763580A