A financial data processing method and system
By monitoring the server load status and timing analysis of the cache area read and write characteristics, SQL injection attacks in high-frequency transactions are identified, and the problem of vulnerability of distributed cache mechanisms is solved, and data security and network security protection of financial transaction systems are realized.
Patent Information
- Application Number
- CN202411605799.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-12
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2044-11-12
AI Technical Summary
The distributed caching mechanism in high-frequency transactions is vulnerable to malicious SQL injection attacks, resulting in financial data security threats. It is difficult for existing technologies to effectively identify and prevent such attack risks.
By monitoring the server load status, identifying the cache area database query delay in real time, using the cache area read and write characteristics for timing analysis, constructing the probability of attack judgment, identifying the risk of SQL injection attacks, and stopping the decentralization of security policies when risks occur and sending early warnings.
Effectively identify and prevent SQL injection attacks, reduce the risk of financial data tampering or theft, and improve the data security and network security of financial transaction systems.
Smart Images

Figure CN119577755B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical fields of data processing and data security, and particularly relates to a financial data processing method and system. Background Art
[0002] Financial trading systems generally rely on transaction processing mechanisms to process transaction information of financial data. After receiving a transaction request from a client, the server needs to verify the integrity and legality of the data, and gradually complete the transaction according to preset security steps. Then, the transaction result is stored in the database and fed back to the client to ensure the accuracy of the fund flow and account status. However, high-frequency trading has always been a technical difficulty in the field of financial data processing. Firstly, the emergence of high-frequency trading is sudden in terms of time, with uncertain user groups and timeliness of financial product popularity. These factors are the triggering opportunities for the bottlenecks of high-frequency trading. Secondly, high-frequency trading will cause serious problems such as a significant decrease in response speed and even system paralysis. One of the current solutions to the response speed under high-frequency access of high-frequency trading is to apply a distributed caching mechanism, which commonly includes the Redis mechanism and the Memcached mechanism. The principle is to cache data in memory to reduce the direct access times to the database, thereby improving the system response speed. However, the distributed caching mechanism is prone to the attack risk of malicious SQL injection in a high-frequency trading environment, threatening the security of funds and the trading system. This is because when there is no strict SQL statement verification mechanism in the caching system, especially when the system reduces some security policies, such as temporarily adjusting database permissions or skipping verification steps, attackers can use the loopholes formed by these policy relaxations to execute SQL commands or malicious SQL statements with higher permissions. Commonly, UNION SELECT is used to bypass permission verification, and then read or tamper with sensitive financial data. This type of attack method is often due to insufficient SQL input escaping or filtering formed by the server's concession on response speed, resulting in policy relaxation. Therefore, it is necessary to timely detect these malicious SQL injection attack risks and prevent the financial data security risks brought by policy relaxation. Summary of the Invention
[0003] The purpose of the present invention is to propose a financial data processing method and system to solve one or more technical problems existing in the prior art, and at least provide a beneficial option or create conditions.
[0004] To achieve the above purpose, according to one aspect of the present invention, a financial data processing method is provided. The method includes the following steps:
[0005] Obtain the server load status;
[0006] When the load status meets the high-frequency trading conditions, trigger the security policy relaxation for the database;
[0007] After the security policy delegation starts, the query latency of the buffer database is monitored in real time, and it is identified whether the risk of SQL injection attack occurs;
[0008] When the risk of SQL injection attack appears, stop the security policy delegation behavior and send a warning message;
[0009] Furthermore, the method for obtaining the server load status is as follows: The server load status is composed of server metrics, and the server metrics include one or more of the real-time values of CPU usage rate, cache hit rate, network bandwidth, and TCP connection count. At any moment, the various server metrics obtained in real time in the server constitute the server load status corresponding to that moment.
[0010] Furthermore, when the load status meets the high-frequency trading conditions, the method for triggering the security policy delegation for the database is as follows:
[0011] The server load status includes several server metrics;
[0012] For any server metric, a corresponding metric threshold is preset. When any server metric in the server load status exceeds its metric threshold, it is determined that the load status meets the high-frequency trading conditions, and the security policy delegation is triggered for the database, thereby relaxing the database read and write permissions and reducing the server load;
[0013] Among them, the security policy delegation includes, but is not limited to, the dynamic adjustment of access permissions or the establishment of hash values for caching sensitive data.
[0014] Furthermore, the method for monitoring the query latency of the buffer database in real time and identifying whether the risk of SQL injection attack occurs is as follows: Obtain the read and write characteristics of the buffer area every 1 to 60 seconds; the read and write characteristics of the buffer area include: extremely long access volume and high latency level;
[0015] Among them, the extremely long access volume is the number of cache-related data records whose response speed exceeds the preset threshold, and the high latency level is the average response speed of each cache-related data record that exceeds the preset threshold; cache-related data records refer to any data records involving cache mechanism processing.
[0016] Furthermore, the method for monitoring the query latency of the buffer database in real time and identifying whether the risk of SQL injection attack occurs is as follows: Set a time period as the monitoring period TL, TL ∈ [0.1, 24] hours. During the monitoring period, record the time scale for obtaining the read and write characteristics of the buffer area as the monitoring point; if the extremely long access volume of a monitoring point is larger than that of its previous monitoring point and the extremely long access volume of its previous monitoring point is not zero, then define this monitoring point as the first cache increment;
[0017] Obtain the buffer read / write characteristics of all first cache increment bits and write them into a sequence, denoted as the first increment bit sequence; if the high-latency level of a monitoring point is greater than the minimum value of the high-latency levels of all first cache increment bits within the monitoring period TL, and this monitoring point is not a first cache increment bit, then define this monitoring point as a second cache increment bit; obtain the buffer read / write characteristics of the second cache increment bit and write them into a sequence, denoted as the second increment bit sequence;
[0018] Divide the variance of the high-latency levels corresponding to all elements in the first increment bit sequence by the variance of the high-latency levels corresponding to all elements in the second increment bit sequence, and denote the obtained ratio as the latency increment bit order value Bivu;
[0019] The principle of obtaining the latency increment bit order value here is actually to compare and process the variances of the high-latency levels in the first increment bit sequence and the second increment bit sequence, quantify the degree of dispersion of the two sequences in terms of high-latency levels, thereby implying and comparing the fluctuation trends existing in the differences between the two increment bit sequences. In the process of mathematical analysis, it can be understood as achieving the effect of bias based on the degree of data dispersion. This fluctuation trend dynamically and effectively quantifies the long-term or persistent significance of the high-latency level at the monitoring point position in the buffer area. From the perspective of the risk of malicious SQL injection, the long-term or persistent response of the high-latency level at this monitoring point position reflects the concentration degree of the server's response to SQL input escape or filtering when malicious SQL injection occurs, and further explains the fluctuation trend of the server's response timeliness to SQL input escape or filtering, providing mathematical support for the application of the latency increment bit order value in time series analysis to observe the probability analysis of SQL injection characteristics.
[0020] Calculate the Mahalanobis distance between the buffer read / write characteristics of the current monitoring point and the buffer read / write characteristics of each other monitoring point, and denote it as the risk state value MhD; in the first increment bit sequence and the second increment bit sequence, respectively screen out all monitoring points whose risk state values are greater than the upper quartile of the risk state values in the corresponding sequence. All the screened monitoring points form a sequence, denoted as the risk analysis sequence; calculate the risk settlement value Rsst based on the risk analysis sequence: Rsst = exp(Bivu) × (hs<An.LS> - min.MhD) ÷ min.MhD; where i1 is the cumulative variable, hs<> is the harmonic mean function, exp() is the exponential function with the natural constant e as the base, An.LS is the sequence composed of the risk state values of each element in the risk analysis sequence, and min.MhD is the minimum value of the risk state values corresponding to all elements in the risk analysis sequence;
[0021] Obtain the percentile value of the risk settlement value obtained at the current monitoring point among all risk settlement values within the monitoring period TL. If this percentile value is greater than 0.8, it is determined that a high-level settlement occurs at the current moment. The proportion of the number of monitoring points with high-level settlements within the monitoring period TL is recorded as the high-level settlement ratio; when the high-level settlement ratio exceeds the preset ratio threshold, there is a risk of SQL injection attack at the current monitoring point; where the value range of the ratio threshold is [0.5, 1].
[0022] Since each monitoring point will obtain the corresponding high-level settlement when it serves as the current monitoring point and the high-level settlement status of this monitoring point will not be changed by subsequent data, there is no logical contradiction between the proportion of the number of monitoring points with high-level settlements within the monitoring period TL and the percentile value among all risk settlement values within the monitoring period TL.
[0023] The calculation of the risk settlement value is obtained by processing the risk analysis sequence corresponding to the current monitoring point. Therefore, it effectively quantifies the risk of insufficient SQL input escape or filtering caused by the strategy delegation formed by the server's concession to the response speed. However, the acquisition of the risk analysis sequence is overly dependent on the second increment sequence, which will lead to an overly sensitive problem in the process of analyzing the risk analysis sequence, resulting in decision-making deviation, especially in the period when the delay increment value calculated by the first increment sequence and the second increment sequence fluctuates greatly. This problem is more prominent. However, the existing technology cannot effectively compensate for this overly sensitive phenomenon. To eliminate this influence, the present invention proposes a more preferred solution as follows:
[0024] Furthermore, the method for real-time monitoring of the cache database query delay and identifying whether a SQL injection attack risk occurs is: set a time period as the monitoring period PCEK, PCEK ∈ [0.1, 24] hours; record all cache read-write feature groups within the monitoring period as the first feature group sequence, where the cache read-write feature group includes the ultra-long access volume Lbsa and the high delay level Hlie;
[0025] Draw a scatter plot of the first feature group sequence on the two-dimensional xoy plane. The horizontal axis of the scatter plot is the ultra-long access volume, and the vertical axis is the high-latency level. Denote the average value of all ultra-long access volumes during the monitoring period as the first reference access volume FS_bsa, and the maximum value as the second reference access volume Sc_bsa. Denote the median value of all high-latency levels as the first reference latency level FS_lie, and the maximum value as the second reference latency level Sc_lie. Construct four dividing lines, namely x = FS_bsa, x = Sc_bsa, y = FS_lie, and y = Sc_lie, which divide the first quadrant of the plane into 4 closed regions. The closed regions do not include the dividing lines. Denote the closed region closest to the origin as the double-low risk domain. Starting from any point in the double-low risk domain, the three closed regions passed in the clockwise direction are denoted as the high-access risk domain, the double-high risk domain, and the high-response risk domain respectively. Denote the number of points in the double-high risk domain as the first outlier number FDp, and obtain the first cut number where sqrt is the square root function symbol, is the floor function symbol. That is, the value obtained by taking the square root of the first outlier number, multiplying it by 0.5, and then taking the floor is the first cut number. Divide the horizontal and vertical axes of each closed region into Fslip segments at equal intervals and cut them to form a grid. For each closed region, denote the ratio of the number of isolated points in the grid formed by the cutting in the region to the total number of points in the closed region as the attack risk weight Atrwe. An isolated point refers to a data point where, when there is only this data point in any grid where the data point is located, this data point is defined as an isolated point;
[0026] The attack risk weight is based on the characteristic that outliers with a high degree of alienation from the data group can be isolated with fewer segmentation times. Therefore, it can effectively identify abnormal monitoring moments under extreme fluctuation conditions, and is used to promote predicting the probability of non-regular change ranges at the next monitoring moment, so as to identify abnormal monitoring moments or corresponding data points when attackers are executing SQL commands with higher privileges or malicious SQL statement characteristics, improving the prediction accuracy and hit rate of future monitoring attack risk probabilities;
[0027] Denote the average value and standard deviation of the ultra-long access volumes of all isolated points in the high-access risk domain and the double-high risk domain as the third reference access volume TH_bsa and the first fluctuation level FS_flu respectively. The injection acceptance interval for the ultra-long access volume is [0, TH_bsa + FS_flu]. Denote the median value and standard deviation of the high-latency levels of all isolated points in the high-response risk domain and the double-high risk domain as the third reference latency level TH_lie and the second fluctuation level SC_flu respectively. The injection acceptance interval for the high-latency level is [0, TH_lie + SC_flu];
[0028] The calculation principle of its injection acceptance interval is to use the data of the abnormal buffer read / write feature group for sample training, extract the unique feature information of the outliers, and provide a reference for the reasonable dynamic range of the monitoring period. Then, during the monitoring stage, the new buffer read / write feature group data can be directly input to determine the risk of injection attack, improving the discrimination speed and efficiency.
[0029] After obtaining the buffer read / write features at the current moment, locate the attack risk weight of the closed area to which it belongs, and calculate the attack decision probability Atdep at the current moment: Atdep = sigmod(Atrwe × Lbsa × Hlie); where sigmoid() is the activation function, defined as: The output range is between 0 and 1.
[0030] If the attack decision probability at the current moment is greater than the preset probability or the values of the ultra-long access volume and high latency level do not fall within the injection acceptance interval, it is determined that the SQL injection attack risk occurs. The preset probability ranges from [0.3, 1].
[0031] Beneficial effects: Since the attack decision probability is obtained through time series analysis based on the buffer read / write features, and the SQL injection increases the complexity of query processing, which requires the database to perform more table joins, data filtering, or sorting operations, significantly prolonging the execution time. At the same time, the essential difference between a normal request and an SQL injection attack lies in the data flow pattern, which can be reflected as the injection attack executed by an automated script having high-frequency, large-scale, and irregular database queries. These requests bring abnormal read / write frequencies to the database or cache layer in a short time. Therefore, the read / write features of the buffer constructed by the response time can effectively identify the SQL injection attack risk occurring in the scenario of security policy delegation triggered by high-frequency transactions, thereby reducing the risk of SQL injection attacks tampering with or stealing financial data and providing data security and network security for the financial trading system.
[0032] Furthermore, the method for stopping the security policy delegation behavior and sending a warning message when the SQL injection attack risk appears is: when the SQL injection attack risk is identified, stop all the security policy delegation behaviors being executed by the servers, and send a SQL injection attack risk warning to the administrator client.
[0033] Preferably, in the present invention, all undefined variables, if not clearly defined, can be manually set thresholds.
[0034] The present invention also provides a financial data processing system, which includes: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps in the financial data processing method are implemented. The financial data processing system can run on computing devices such as desktop computers, laptop computers, handheld computers, and cloud data centers. The operable system may include, but is not limited to, a processor, a memory, and a server cluster. The processor executes the computer program and runs in the following units of the system:
[0035] A server load monitoring unit for obtaining the server load status;
[0036] A security policy delegation unit for triggering the delegation of security policies to the database when the load status meets the high-frequency trading conditions;
[0037] An injection attack risk identification unit for monitoring the query latency of the buffer database in real time after the start of the security policy delegation and identifying whether an SQL injection attack risk occurs;
[0038] A security policy delegation termination unit for stopping the security policy delegation behavior and sending a warning message when an SQL injection attack risk appears.
[0039] The beneficial effects of the present invention are as follows: The present invention provides a financial data processing method and system. By performing time series analysis on the read and write characteristics of the buffer area, the attack judgment probability is used to construct the read and write characteristics of the buffer area to effectively identify the SQL injection attack risk occurring in the security policy delegation scenario triggered by high-frequency trading. Furthermore, the risk of SQL injection attacks tampering with or stealing financial data is reduced, providing data security and network security warnings for the financial trading system. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] By describing the embodiments shown in the accompanying drawings in detail, the above and other features of the present invention will become more obvious. The same reference numerals in the drawings of the present invention represent the same or similar elements. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings. In the drawings:
[0041] Figure 1 Shows a flowchart of a financial data processing method;
[0042] Figure 2 Shows a structural diagram of a financial data processing system. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0043] The following will be combined with the embodiments and drawings to clearly and completely describe the concept, specific structure and technical effects of the present invention so as to fully understand the purpose, scheme and effect of the present invention. It should be noted that the embodiments and features in the embodiments of this application can be combined with each other unless there is a conflict.
[0044] like Figure 1 The following is a flowchart of a financial data processing method. Figure 1 A financial data processing method according to an embodiment of the present invention is described below. The method includes the following steps:
[0045] Get server load status;
[0046] When the load status meets the high-frequency trading conditions, the security policy is triggered to be decentralized to the database;
[0047] After security policy decentralization begins, real-time monitoring of cache database query latency is performed to identify whether SQL injection attack risks are occurring.
[0048] When the risk of SQL injection attack occurs, the security policy decentralization behavior is stopped and an early warning message is sent;
[0049] Furthermore, the method for obtaining the server load status is: the server load status is composed of server indicators, which include one or more real-time values of CPU usage, cache hit rate, network bandwidth and number of TCP connections. The various server indicators obtained in real time in the server at any moment constitute the server load status corresponding to that moment.
[0050] CPU utilization directly reflects the server's load when processing computationally intensive tasks. In high-frequency trading, a large number of trading orders and complex algorithms need to be processed quickly. High CPU utilization will reduce transaction response speed and is the most authoritative explanation of server stability. However, even in a high-frequency trading environment, even low CPU utilization may cause delays due to memory or I / O bottlenecks. Therefore, it cannot be used as the sole load status standard.
[0051] Since the cache hit rate is crucial in the real-time nature of transaction data, the system must be able to quickly read information from the cache and reduce the latency in accessing storage. In situations of dense transaction volume, the cache hit rate will drop significantly. Therefore, the cache hit rate is an important component of high-frequency trading conditions.
[0052] In addition, network bandwidth is the prerequisite for judging other indicators. Network bandwidth determines the server's ability to process and transmit transaction data. The number of TCP connections reflects the concurrent transaction connections, thereby monitoring whether the concurrency of the trading system exceeds the server's preset service pressure.
[0053] Furthermore, when the load status meets the high-frequency trading conditions, the method of triggering the decentralization of the security policy for the database is:
[0054] The server load status includes several server indicators;
[0055] Each server indicator has a preset corresponding indicator threshold. When any server indicator in the server load status exceeds its indicator threshold, the load status is determined to meet the high-frequency trading conditions, and the database security policy is triggered to be decentralized, thereby relaxing the database read and write permissions and reducing the server load;
[0056] The decentralization of security policies includes, but is not limited to, dynamic adjustment of restricted access rights or establishment of hash values for caching sensitive data.
[0057] Adjusting access rights refers to temporarily increasing access rights for low-risk operations (such as read-only queries and reading and writing notes) to reduce delays caused by permission verification. Alternatively, a hierarchical relative permission method can be used. Hierarchical relative permissions refer to gradually relaxing permissions based on relative permission levels, allowing operations with relatively low permissions to be executed, while operations with high relative levels are delayed or temporarily disabled. Adjusting access rights can lead to the weakening of fine-grained permission control. This is because account permissions in financial transactions usually need to be strictly controlled at the operational level, such as only being able to view or trade specified assets. Temporarily skipping fine-grained permission control by adjusting permissions can allow attackers to access or modify unauthorized data through SQL injection. Especially in complex multi-level permission systems, temporary adjustments to permissions are more likely to cause control gaps.
[0058] Caching sensitive data with hash values involves caching frequently verified sensitive data, such as database user passwords and sensitive API keys, to reduce the frequency of direct database access, thereby reducing system query pressure. This approach increases the system's reliance on cache security, making it easier for cached data to bypass verification mechanisms and obtain sensitive data. This allows attackers to tamper with transaction instructions or hijack customer data through SQL injection attacks.
[0059] Furthermore, the method for real-time monitoring of cache database query latency and identifying the risk of SQL injection attacks is to obtain cache read and write characteristics every 30 seconds; cache read and write characteristics include: excessively long access times and high latency levels;
[0060] Among them, the number of excessively long accesses is the number of cache-related data records whose response speed exceeds the preset threshold, and the high latency level is the average response speed of each cache-related data record that exceeds the preset threshold; cache-related data records refer to any data records involved in the processing of the cache mechanism.
[0061] Wherein the data record includes transaction order data, transaction execution data, and the user's position data, and in its specific presentation form, it belongs to server requests involving transaction data. These server requests include transaction price, transaction quantity, trading pair, trigger condition, order direction, user ID or account information, timestamp, and order type.
[0062] Further, the method for real-time monitoring of the cache database query latency and identifying whether the SQL injection attack risk occurs is as follows: Set a time period as the monitoring period TL, with a value of 5 hours. During the monitoring period, record the time scale for obtaining the cache read and write characteristics as the monitoring point. If the amount of ultra-long access at a monitoring point is larger than that at its previous monitoring point and the amount of ultra-long access at its previous monitoring point is not zero, then define this monitoring point as the first cache increment.
[0063] Obtain the cache read and write characteristics of all the first cache increments and write them into a sequence, denoted as the first increment sequence. If the high latency level at a monitoring point is greater than the minimum value of the high latency levels of all the first cache increments within the monitoring period TL, and this monitoring point is not a first cache increment, then define this monitoring point as the second cache increment. Obtain the cache read and write characteristics of the second cache increment and write them into a sequence, denoted as the second increment sequence.
[0064] Divide the variance of the high latency levels corresponding to all the elements in the first increment sequence by the variance of the high latency levels corresponding to all the elements in the second increment sequence, and denote the obtained ratio as the latency increment order value Bivu.
[0065] Calculate and obtain the Mahalanobis distance between the cache read and write characteristics of the current monitoring point and the cache read and write characteristics of each other monitoring point, and denote it as the risk state value MhD. In the first increment sequence and the second increment sequence, respectively screen out all the monitoring points whose risk state values are greater than the upper quartile of the risk state values in the corresponding sequences. The sequence composed of all the screened monitoring points is denoted as the risk analysis sequence. Calculate the risk settlement value Rsst according to the risk analysis sequence: Rsst = exp(Bivu) × (hs<An.LS> - min.MhD) ÷ min.MhD; where i1 is the accumulative variable, hs<> is the harmonic mean function, exp() is the exponential function with the natural constant e as the base, An.LS is the sequence composed of the risk state values of each element in the risk analysis sequence, and min.MhD is the minimum value of the risk state values corresponding to all the elements in the risk analysis sequence.
[0066] Obtain the percentile value of the risk settlement value obtained at the current monitoring point among all risk settlement values within the monitoring period TL. If this percentile value is greater than 0.8, it is determined that a high-level settlement occurs at the current moment. The proportion of the number of monitoring points with high-level settlements within the monitoring period TL is recorded as the high-level settlement ratio. When the high-level settlement ratio exceeds the preset ratio threshold, there is a risk of SQL injection attack at the current monitoring point. The value range of the ratio threshold is 0.85.
[0067] Since each monitoring point will obtain the corresponding high-level settlement when it is the current monitoring point and the high-level settlement status of this monitoring point will not be changed by subsequent data, there is no logical contradiction between the proportion of the number of monitoring points with high-level settlements within the monitoring period TL and the percentile value among all risk settlement values within the monitoring period TL.
[0068] Furthermore, the method for real-time monitoring of the database query delay in the buffer area and identifying whether a SQL injection attack risk occurs is as follows: Set a time period as the monitoring period PCEK, and the value of PCEK is 5 hours. Denote all buffer area read-write feature groups within the monitoring period as the first feature group sequence, where the buffer area read-write feature group includes the ultra-long access volume Lbsa and the high delay level Hlie.
[0069] Draw a scatter plot of the first feature group sequence on the two-dimensional xoy plane, where the horizontal axis of the scatter plot is the ultra-long access volume and the vertical axis is the high delay level. Denote the average value of all ultra-long access volumes within the monitoring period as the first reference access volume FS_bsa, the maximum value as the second reference access volume Sc_bsa, the median value of all high delay levels as the first reference delay level FS_lie, and the maximum value as the second reference delay level Sc_lie. Construct four dividing lines, namely x = FS_bsa, x = Sc_bsa, y = FS_lie, and y = Sc_lie, to divide the first quadrant of the plane into 4 closed regions. The closed regions do not include the dividing lines. Denote the closed region closest to the origin as the double-low risk domain. Starting from any point within the double-low risk domain, the three closed regions passed in the clockwise direction are respectively denoted as the high-access risk domain, the double-high risk domain, and the high-response risk domain. Denote the number of points within the double-high risk domain as the first outlier number FDp, and obtain the first cutting number where sqrt is the square root function symbol, is the floor function symbol. That is, the value obtained by taking the square root of the first outlier number, multiplying it by 0.5, and then taking the floor is the first cutting number. Divide the horizontal and vertical axes of each closed region into Fslip segments at equal intervals and cut to form a grid. For each closed region, denote the proportion of the number of isolated points in the grid formed by the cutting within the closed region to the total number of points in the closed region as the attack risk weight Atrwe. An isolated point refers to a data point that is defined as an isolated point when there is only this data point in the grid where any data point is located.
[0070] The average value and standard deviation of the extremely long access volumes of all isolated points in the high-access-risk domain and the double-high-risk domain are respectively denoted as the third benchmark access volume TH_bsa and the first fluctuation level FS_flu, and the injection acceptance interval of the extremely long access volume is [0, TH_bsa + FS_flu]; the median value and standard deviation of the high-latency levels of all isolated points in the high-response-risk domain and the double-high-risk domain are respectively denoted as the third benchmark latency level TH_lie and the second fluctuation level SC_flu, and the injection acceptance interval of the high-latency level is [0, TH_lie + SC_flu];
[0071] After obtaining the read-write characteristics of the buffer area at the current moment, locate the attack risk weight of the closed area to which it belongs, and calculate the attack decision probability Atdep at the current moment: Atdep = sigmod(Atrwe × Lbsa × Hlie); where sigmoid() is the activation function, defined as: The output range is between 0 and 1;
[0072] If the attack decision probability at the current moment is greater than the preset probability or the values of the extremely long access volume and the high-latency level do not fall within the injection acceptance interval, it is determined that the SQL injection attack risk occurs, and the preset probability is taken as 0.8.
[0073] Further, the method for stopping the security policy delegation behavior and sending a warning message when the SQL injection attack risk appears is: when the SQL injection attack risk is identified, stop the security policy delegation behavior being executed by all servers, and send a SQL injection attack risk warning to the administrator client.
[0074] An embodiment of the present invention provides a financial data processing system, as Figure 2 shown in the structural diagram of a financial data processing system of the present invention. A financial data processing system of this embodiment includes: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps in the above-mentioned embodiment of the financial data processing method.
[0075] The system includes: a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it runs in the following units of the system:
[0076] A server load monitoring unit for obtaining the server load status;
[0077] A security policy delegation unit for triggering the delegation of security policies to the database when the load status meets the high-frequency trading conditions;
[0078] An injection attack risk identification unit, which is used to monitor the query latency of the buffer database in real time after the start of security policy delegation and identify whether the risk of SQL injection attack occurs;
[0079] A security policy delegation termination unit, which is used to stop the security policy delegation behavior and send a warning message when the risk of SQL injection attack appears.
[0080] The described financial data processing system can run on computing devices such as desktop computers, laptop computers, palmtop computers, and cloud servers. The described financial data processing system, the system that can run may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the above examples are only examples of a financial data processing system and do not constitute a limitation on a financial data processing system. It may include more or fewer components than the examples, or combine some components, or different components. For example, the described financial data processing system may also include input / output devices, network access devices, buses, etc.
[0081] The so-called processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The processor is the control center of the operating system of the described financial data processing system, and connects various parts of the entire operating system of the financial data processing system through various interfaces and lines.
[0082] The memory can be used to store the computer programs and / or modules. By running or executing the computer programs and / or modules stored in the memory and invoking the data stored in the memory, the processor realizes various functions of the financial data processing system. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.); the data storage area can store data created according to the use of the mobile phone (such as audio data, phone book, etc.). In addition, the memory may include high-speed random access memory and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices.
[0083] Although the description of the present invention has been quite detailed and several of the embodiments have been described in particular, it is not intended to be limited to any of these details or embodiments or any particular embodiment, so as to effectively cover the intended scope of the present invention. In addition, the present invention has been described above with embodiments foreseeable by the inventors for the purpose of providing a useful description, and non-substantive modifications to the present invention that are not currently foreseeable may still represent equivalent modifications of the present invention.
Claims
1. A financial data processing method, characterized in that, The method comprises the following steps: Obtain server load status; when the load status meets high-frequency trading conditions, trigger security policy decentralization for the database; after security policy decentralization begins, monitor cache database query latency in real time and identify whether SQL injection attack risks are occurring; if SQL injection attack risks occur, stop security policy decentralization and send an early warning message; The method for real-time monitoring of cache database query latency and identifying the risk of SQL injection attacks is as follows: set a time period as the monitoring period TL, TL∈[0.1,24] hours. Within the monitoring period, the time scale of obtaining cache read and write characteristics is recorded as a monitoring point; if the number of excessive long accesses at a monitoring point is greater than that of the previous monitoring point and the excessive long access number of the previous monitoring point is not zero, then the monitoring point is defined as the first cache increment; Obtain the cache read and write characteristics of all first cache increments and write them into a sequence recorded as the first increment sequence; if the high delay level of a monitoring point is greater than the minimum high delay level of all first cache increments within the monitoring period TL, and the monitoring point is not the first cache increment, then define the monitoring point as the second cache increment; obtain the cache read and write characteristics of the second cache increment and write them into a sequence recorded as the second increment sequence; Divide the variance of the high delay level corresponding to all elements in the first increment sequence by the variance of the high delay level corresponding to all elements in the second increment sequence, and record the obtained ratio as the delay increment level value Bivu; The Mahalanobis distance between the read-write characteristics of the cache area of the current monitoring point and the read-write characteristics of the cache area of each other monitoring point is calculated and recorded as the risk effect value MhD; in the first increasing sequence and the second increasing sequence, all monitoring points whose risk effect values are greater than the upper quartile of the risk effect value in the corresponding sequence are respectively screened out, and the sequence composed of all the screened monitoring points is recorded as the risk analysis sequence; the risk settlement value Rsst is calculated according to the risk analysis sequence: Rsst = exp(Bivu) × (hs<An.LS> -min.MhD)÷min.MhD; hs<> is the harmonic mean function, exp() is the exponential function with the natural constant e as the base, An.LS is the sequence composed of the risk effect state values in the risk analysis sequence, and min.MhD is the minimum value of the risk effect state values corresponding to all elements in the risk analysis sequence; Obtain the percentile of the risk settlement value obtained at the current monitoring point among all risk settlement values within the monitoring period TL. If the percentile is greater than 0.8, it is determined that high-level settlement has occurred at the current moment. The proportion of monitoring points that have experienced high-level settlement within the monitoring period TL is recorded as the high-level settlement ratio. When the high-level settlement ratio exceeds the preset ratio threshold, the current monitoring point is at risk of SQL injection attack; the ratio threshold value range is [0.5, 1].
2. The financial data processing method according to claim 1, wherein The method for obtaining the server load status is: the server load status is composed of server indicators, which include one or more real-time values of CPU usage, cache hit rate, network bandwidth and number of TCP connections. The various server indicators obtained in real time in the server at any moment constitute the server load status corresponding to that moment.
3. A financial data processing method according to claim 1, characterized in that When the load status meets the high-frequency trading conditions, the method of triggering the decentralization of the database security policy is as follows: any server indicator has a preset corresponding indicator threshold. When any server indicator in the server load status exceeds its indicator threshold, it is determined that the load status meets the high-frequency trading conditions, and the database security policy is triggered to be decentralized, thereby relaxing the database read and write permissions and reducing the server load; The decentralization of security policies includes, but is not limited to, dynamic adjustment of restricted access rights or establishment of hash values for caching sensitive data.
4. A financial data processing method according to claim 1, characterized in that, The method for real-time monitoring of cache database query latency and identifying whether SQL injection attack risks occur is as follows: set a time period as a monitoring period PCEK, PCEK∈[0.1,24] hours; record all cache read and write feature groups within the monitoring period as the first feature group sequence, where the cache read and write feature groups include excessively long access times Lbsa and high latency levels Hlie; Draw a scatter plot of the first feature group sequence on the two-dimensional xoy plane, and record the average value of all super-long visits during the monitoring period as the first benchmark visit volume FS_bsa, the maximum value as the second benchmark visit volume Sc_bsa, the median value of all high delay levels as the first benchmark delay level FS_lie, and the maximum value as the second benchmark delay level Sc_lie. Construct four dividing lines, namely x=FS_bsa, x=Sc_bsa, y=FS_lie and y=Sc_lie, and divide the first quadrant of the plane into 4 closed areas. The closed area closest to the origin is recorded as the double For the low-risk domain, starting from any point in the double-low-risk domain, the three closed areas passed through in a clockwise direction are respectively recorded as the high-access risk domain, the double-high risk domain, and the high-response risk domain; the number of points in the double-high risk domain is recorded as the first outlier number FDp, and the first cut number Fslip = ⌊0.5×sqrt(FDp)⌋ is obtained; the horizontal and vertical axes of each closed area are divided into Fslip segments at equal intervals and cut to form a grid. For each closed area, the ratio of the number of isolated points in the grid formed by the cut in the area to the total number of points in the closed area is recorded as the attack risk weight Atrwe; The mean and standard deviation of the excessively long accesses of all isolated points in the high access risk domain and the double high risk domain are respectively the third benchmark access TH_bsa and the first fluctuation level FS_flu, and the injection acceptance interval of the excessively long accesses is [0, TH_bsa + FS_flu]. The median and standard deviation of the high delay levels of all isolated points in the high response risk domain and the double high risk domain are respectively the third benchmark delay level TH_lie and the second fluctuation level SC_flu, and the injection acceptance interval of the high delay level is [0, TH_lie + SC_flu]. After obtaining the read / write characteristics of the buffer at the current moment, locate the attack risk weight of the closed area to which it belongs and calculate the attack decision probability Atdep at the current moment; if the attack decision probability at the current moment is greater than the preset probability or the values of the ultra-long access volume and the high latency level do not fall within the injection acceptance interval, it is determined that the SQL injection attack risk occurs, and the value range of the preset probability is [0.5, 1].
5. A financial data processing method according to claim 1, characterized in that The method of stopping the security policy delegation behavior and sending a warning message when the SQL injection attack risk appears is: when the SQL injection attack risk is identified, stop all the security policy delegation behaviors being executed by the servers, and send a SQL injection attack risk warning to the administrator client.
6. A financial data processing system, characterized in that, The financial data processing system includes: a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps in the financial data processing method described in any one of claims 1-5. The financial data processing system runs on computing devices such as desktop computers, laptop computers, palm computers, and cloud data centers.
Citation Information
Patent Citations
Injection vulnerability detection method and apparatus
CN108509792A