Database risk identification method and device
By obtaining the number of operation record rows in the database and determining the dynamic log threshold, identifying the risk of large transactions, the database response problems caused by large transactions in distributed scenarios are solved, and the response timeliness and user experience of business services are improved.
Patent Information
- Application Number
- CN202311502002.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-10
- Publication Date
- 2025-05-13
AI Technical Summary
In distributed scenarios, large transaction transactions may cause the database main database to be unable to respond, which in turn leads to user transaction failure and affects the response timeliness of business services.
By obtaining the number of rows recorded by the database, determining the database dynamic log threshold based on the network bandwidth and statement response time, and determining the row threshold based on the threshold and single-line record capacity, the database dynamic risk data is generated to identify and warning of large transaction risks.
Effectively identify and warn of major business risks, ensure the timeliness of response and timeliness of business services, and improve user experience.
Smart Images

Figure CN119988402A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a database risk identification method and device. Background Art
[0002] Figure 1 This is a time sequence diagram of transaction submission and data transmission in a distributed scenario. Figure 1 As shown in the figure, in a distributed scenario, in order to ensure data security and shard consistency, the application architecture generally uses database synchronization / semi-synchronization technology to achieve final data consistency. After the database master receives the application's commit request, it does not directly return the application commit ok information, but first writes the transaction log to the disk and transmits it to the slave through the network. After the slave is written to the disk, it responds to the master with ACK (acknowledgement); after the master receives the slave's ACK, it responds to the application with commit ok information, and the transaction is successful.
[0003] In the process of transferring transaction logs from the master database to the slave database and the slave database responding to ACK, the data processing granularity is the size of a single transaction log, which is directly related to the amount of data being operated. Under certain network bandwidth, latency, and disk IO capabilities, the transaction size / log volume is directly related to the transaction response time. If a transaction operation has a large amount of data, it may cause other subsequent transactions to wait, which in turn causes the database master database to be unable to respond, resulting in a large number of user transactions failing. Summary of the invention
[0004] The main purpose of the embodiment of the present invention is to provide a database risk identification method to solve large transaction risks, ensure the response time of business services, and effectively improve user experience.
[0005] In order to achieve the above object, an embodiment of the present invention provides a database risk identification method, comprising:
[0006] Get the number of rows of operation records in the database;
[0007] Determine database dynamic log thresholds based on network loans and statement response time;
[0008] Determine the row number threshold according to the database dynamic log threshold and the single row record capacity;
[0009] Generate first database dynamic risk data according to a comparison result of the operation record row number and the row number threshold.
[0010] In one embodiment, it also includes:
[0011] Determine the database dynamic log capacity according to the system information table, the number of operation record rows and the coefficient;
[0012] Second database dynamic risk data is generated according to a comparison result between the database dynamic log capacity and the database dynamic log threshold.
[0013] In one embodiment, determining the database dynamic log capacity according to the system information table, the number of operation record rows and the coefficient includes:
[0014] Determine the table average record according to the system information table;
[0015] The dynamic log capacity of the database is determined according to the average records of the table, the number of operation record rows and the coefficient.
[0016] In one embodiment, it also includes:
[0017] Get the database statement type;
[0018] The coefficient is determined according to the database statement type.
[0019] In one embodiment, it also includes:
[0020] Determining risk statement judgment rules according to the database statement type;
[0021] The database statements are judged according to the risk statement judgment rules to generate database static risk data.
[0022] In one embodiment, it also includes:
[0023] Parse incremental logs to obtain multiple log data;
[0024] determining the log data capacity according to the plurality of log data;
[0025] Database verification risk data is generated according to a comparison result between the log data capacity and a preset log data capacity threshold.
[0026] In one embodiment, determining the log data capacity according to the plurality of log data includes:
[0027] Determine a start position and an end position according to information types of the plurality of log data;
[0028] The log data capacity is determined according to the start position and the end position.
[0029] The embodiment of the present invention further provides a database risk identification device, comprising:
[0030] The acquisition module is used to obtain the number of operation records in the database;
[0031] A database dynamic log threshold module is used to determine the database dynamic log threshold according to network loans and statement response time;
[0032] A row number threshold module, used to determine the row number threshold according to the database dynamic log threshold and the single row record capacity;
[0033] The first dynamic risk data module is used to generate first database dynamic risk data according to a comparison result between the number of operation record rows and the row number threshold.
[0034] In one embodiment, it also includes:
[0035] A database dynamic log capacity module, used to determine the database dynamic log capacity according to the system information table, the number of operation record rows and the coefficient;
[0036] The second dynamic risk data module is used to generate second database dynamic risk data according to the comparison result of the database dynamic log capacity and the database dynamic log threshold.
[0037] In one embodiment, the database dynamic log capacity module includes:
[0038] A table average record unit, used to determine a table average record according to the system information table;
[0039] The database dynamic log capacity unit is used to determine the database dynamic log capacity according to the average record of the table, the number of operation record rows and the coefficient.
[0040] In one embodiment, it also includes:
[0041] Database statement type module, used to obtain database statement type;
[0042] A coefficient module is used to determine the coefficient according to the database statement type.
[0043] In one embodiment, it also includes:
[0044] A risk statement judgment rule module, used to determine a risk statement judgment rule according to the database statement type;
[0045] The database static risk data module is used to judge the database statements according to the risk statement judgment rules and generate database static risk data.
[0046] In one embodiment, it also includes:
[0047] Log parsing module, used to parse incremental logs and obtain multiple log data;
[0048] A log data capacity module, used to determine the log data capacity according to the plurality of log data;
[0049] The database verification risk data module is used to generate database verification risk data according to the comparison result between the log data capacity and a preset log data capacity threshold.
[0050] In one embodiment, the log data capacity module includes:
[0051] A position unit, used to determine a start position and an end position according to information types of the plurality of log data;
[0052] The log data capacity unit is used to determine the log data capacity according to the start position and the end position.
[0053] An embodiment of the present invention further provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor implements the steps of the database risk identification method when executing the computer program.
[0054] An embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of the database risk identification method are implemented.
[0055] An embodiment of the present invention further provides a computer program product, including a computer program / instruction, which implements the steps of the database risk identification method when the computer program / instruction is executed by a processor.
[0056] The database risk identification method and device of the embodiment of the present invention determine the database dynamic log threshold according to the network loan and statement response time to further determine the row number threshold, and then generate the first database dynamic risk data according to the comparison result of the operation record row number and the row number threshold, which can solve the risk of large transactions, ensure the response time of business services, and effectively improve the user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0058] Figure 1 It is a timing diagram of transaction submission and data transmission in a distributed scenario;
[0059] Figure 2 is a flow chart of a database risk identification method in an embodiment of the present invention;
[0060] Figure 3 is a flow chart of generating static risk data of a database in an embodiment of the present invention;
[0061] Figure 4 is a flow chart of generating dynamic risk data of a second database in an embodiment of the present invention;
[0062] Figure 5 is a flow chart of S301 in an embodiment of the present invention;
[0063] Figure 6 is a flow chart of determining coefficients in an embodiment of the present invention;
[0064] Figure 7 is a flow chart of generating database verification risk data in an embodiment of the present invention;
[0065] Figure 8 is a flow chart of S602 in an embodiment of the present invention;
[0066] Fig. 9 is a flow chart of dynamic vehicle inspection in an embodiment of the present invention;
[0067] Fig.10 is a flow chart of static inspection in an embodiment of the present invention;
[0068] Fig.11 Schematic diagram of the verification process in an embodiment of the present invention;
[0069] Fig.12 is a structural block diagram of a database risk identification device in an embodiment of the present invention;
[0070] Fig.13 is a schematic diagram of a database risk identification device in another embodiment of the present invention;
[0071] Fig.14 A schematic block diagram of the system structure of the electronic device 9600 according to an embodiment of the present application. DETAILED DESCRIPTION
[0072] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0073] Those skilled in the art will appreciate that the embodiments of the present invention may be implemented as a system, device, apparatus, method or computer program product. Therefore, the present disclosure may be specifically implemented in the following forms, namely: complete hardware, complete software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.
[0074] The acquisition, storage, use, and processing of data in the technical solution of the present invention are in compliance with the relevant provisions of national laws and regulations. The user information in the embodiments of this application is obtained through legal and compliant channels, and the acquisition, storage, use, and processing of user information are authorized and agreed by the customer.
[0075] The present invention identifies the risks caused by excessive operation data by designing and applying an analysis method for the operation of the MySQL database system, combined with static judgment of the operation impact; based on the basic functions of the database itself such as logging and synchronization, combined with the actual needs of the business system, a complete risk identification and management system is formed, covering the entire life cycle of business system research and development, operation, and maintenance, with the characteristics of configurability, monitorability, and continuous improvement.
[0076] Figure 2 It is a flow chart of a database risk identification method in an embodiment of the present invention. Fig. 9 FIG. 1 is a flow chart of dynamic vehicle inspection in an embodiment of the present invention. Figure 2 and Fig. 9 As shown, the database risk identification method includes:
[0077] S101: Obtain the number of operation record rows in the database.
[0078] In specific implementation, according to the pre-configured running frequency, query the real-time status of the database engine through show engine innodb status. Parse the transaction information segment, and for each uncommitted transaction, analyze the following transaction-related information:
[0079] 1lock struct(s),heap size 1136,0row lock(s),undo log entries 3245768
[0080] MySQL thread id 13535,OS thread handle 140133376112384,query id227localhost root
[0081] The undo log entries 3245768 represent the number of records that have been inserted / updated / deleted (INSERT / UPDATE / DELETE) but not committed by the transaction.
[0082] Figure 3 It is a flow chart of generating static risk data of a database in an embodiment of the present invention. Fig.10 Flowchart of static inspection in the embodiment of the present invention. Figure 3 and Fig.10 As shown, before executing S101, the process further includes:
[0083] S201: Determine risk statement judgment rules according to database statement types.
[0084] S202: judging the database statements according to the risk statement judgment rule, and generating database static risk data.
[0085] In specific implementation, for delete, update, and replace SQL statements, if any of the following conditions are met, they are identified as risk statements that may cause large transactions, and the corresponding database static risk data is generated at this time:
[0086] There is a limit control, but the number of rows controlled is greater than 100,000;
[0087] There are no filter conditions or limit restrictions in the statement;
[0088] The statement involves filtering conditions, but the filtered field is not a primary key or unique key and has no limit.
[0089] For data import statements, all are considered to be risky statements that may lead to large transactions, and corresponding database static risk data is generated.
[0090] S102: Determine a database dynamic log threshold according to network loans and statement response time.
[0091] In specific implementation, the database dynamic log threshold can be determined based on the transaction response time requirements of the specific transaction system and the bandwidth of the primary and standby networks. For example, if the network bandwidth is 100MB / s and the single SQL response time is required to be no more than 1s, the database dynamic log threshold is no more than 100MB.
[0092] S103: Determine a row number threshold according to the database dynamic log threshold and a single row record capacity.
[0093] For example, if the size of a single row record is 1KB, calculated as 100MB, the row count threshold can be set to no more than 102400.
[0094] S104: Generate first database dynamic risk data according to a comparison result between the number of operation record rows and the row number threshold.
[0095] For example, when the number of operation record rows is greater than the row number threshold, an alarm is issued for the transaction (determined by thread ID 13535) or the transaction is terminated (killed) in real time.
[0096] Figure 4 : is a flow chart of generating dynamic risk data of the second database in an embodiment of the present invention. Figure 4 As shown, the database risk identification method also includes:
[0097] S301: Determine the database dynamic log capacity according to the system information table, the number of operation record rows and the coefficient.
[0098] Figure 5 is a flow chart of S301 in an embodiment of the present invention. Figure 5 As shown, S301 includes:
[0099] S401: Determine table average records according to the system information table.
[0100] During specific implementation, the table information of the transaction operation is obtained through the system information table, AVG_ROW_LENGTH, that is, the average record size of the table.
[0101] S402: Determine the dynamic log capacity of the database according to the average records of the table, the number of operation record rows and the coefficient.
[0102] In specific implementation, the number of operation record rows, the average record size of the table and the coefficient are multiplied in sequence to obtain the dynamic log capacity of the database.
[0103] Figure 6 is a flow chart of determining coefficients in an embodiment of the present invention. Figure 6 As shown, S402 includes:
[0104] S501: Obtain database statement type.
[0105] S502: Determine the coefficient according to the database statement type.
[0106] For example, when the database statement type is an update or delete statement, the coefficient is 2; when the database statement type is an insert or data import statement, the coefficient is 1.
[0107] S302: Generate second database dynamic risk data according to a comparison result of the database dynamic log capacity and the database dynamic log threshold.
[0108] In specific implementation, when the bytes of the database dynamic log capacity are greater than the database dynamic log threshold, second database dynamic risk data is generated, and a corresponding transaction (determined by thread id 13535) is warned or terminated in real time.
[0109] Figure 7 It is a flow chart of generating database verification risk data in an embodiment of the present invention. Fig.11 Schematic diagram of the verification process in the embodiment of the present invention. Figure 7 and Fig.11 As shown, after executing S302, the database risk identification method further includes:
[0110] S601: Parse the incremental log to obtain multiple log data.
[0111] In specific implementation, obtain the current log list and record the corresponding file name (Log_name) and file size (File_size):
[0112] |Log_name |File_size|
[0113] |mysql-bin.000001| 179|
[0114] |mysql-bin.000002| 2036|
[0115] |mysql-bin.000003| 243|
[0116] |mysql-bin.000004| 2230|
[0117] Parse each log file. Take the log file (mysql-bin.000004) as an example. The format after parsing is as follows:
[0118] |Log_name |Pos|Event_type|Server_id|End_log_pos|Info
[0119] |mysql-bin.000004|1246|Gtid |242229| 1325|SET
[0120] @@SESSION.GTID_NEXT='fbf225e5-7215-11ee-89f6-fa163e9e14e8:13'|
[0121] |mysql-bin.000004|1325|Query |242229| 1400|BEGIN|
[0122] |mysql-bin.000004|1400|Rows_query|242229| 1450|#insert into t1values(3,3)|
[0123] |mysql-bin.000004|1450|Table_map|242229|1499|table_id:146(test.t1)|
[0124] |mysql-bin.000004|1499|Write_rows|242229|1543|table_id:146flags:STMT_END_F|
[0125] |mysql-bin.000004|1543|Xid|242229|1574|COMMIT / *xid=241* / |
[0126] |mysql-bin.000004|1574|Gtid|242229|1653|SET
[0127] @@SESSION.GTID_NEXT='fbf225e5-7215-11ee-89f6-fa163e9e14e8:14'|
[0128] |mysql-bin.000004|1653|Query |242229| 1728|BEGIN|
[0129] |mysql-bin.000004|1728|Rows_query|242229| 1778|#insert into t1values(4,4)|
[0130] |mysql-bin.000004|1778|Table_map|242229|1827|table_id:146(test.t1)|
[0131] |mysql-bin.000004|1827|Write_rows|242229|1871|table_id:146flags:STMT_END_F|
[0132] |mysql-bin.000004|1871|Xid|242229|1902|COMMIT / *xid=242* / |
[0133] |mysql-bin.000004|1902|Gtid|242229|1981|SET
[0134] @@SESSION.GTID_NEXT='fbf225e5-7215-11ee-89f6-fa163e9e14e8:15'|
[0135] |mysql-bin.000004|1981|Query |242229| 2056|BEGIN|
[0136] |mysql-bin.000004|2056|Rows_query|242229| 2106|#insert into t1values(5,4)|
[0137] |mysql-bin.000004|2106|Table_map|242229|2155|table_id:146(test.t1)|
[0138] |mysql-bin.000004|2155|Write_rows|242229|2199|table_id:146flags:STMT_END_F|
[0139] |mysql-bin.000004|2199|Xid|242229|2230|COMMIT / *xid=243* /
[0140] S602: Determine the log data capacity according to the plurality of log data.
[0141] Figure 8 is a flow chart of S602 in an embodiment of the present invention. Figure 8 As shown, S602 includes:
[0142] S701: Determine a start position and an end position according to the information type of the plurality of log data.
[0143] S702: Determine the log data capacity according to the start position and the end position.
[0144] In specific implementation, the event type field is used as the location of Rows_query (Pos column in the information) as the benchmark, and two consecutive Rows_queries are subtracted to obtain the log size generated by the data of the transaction operation. For the last transaction in the log file, the log file volume, that is, the log end location End_log_pos column 2230 at the end of the information, is calculated by the corresponding previous Rows_query location.
[0145] S603: Generate database verification risk data according to the comparison result between the log data capacity and a preset log data capacity threshold.
[0146] In specific implementation, when the log data capacity is greater than the preset log data capacity threshold, the monitoring alarm module is used to notify the system developers to optimize the program design and eliminate the risk.
[0147] In summary, the database risk identification method provided by the embodiment of the present invention has the following beneficial effects:
[0148] Database synchronization technology solves the need to prevent database disaster recovery data from being lost. However, in strong synchronization mode, the size of transactions directly affects the use of database core resources, causing global business response time issues. The present invention discovers and solves large transaction risks in three stages: before going online, in operation, and after operation. While giving priority to disaster recovery data consistency, it can also ensure the response time of business services and effectively improve user experience.
[0149] Based on the same inventive concept, an embodiment of the present invention further provides a database risk identification device. Since the principle of solving the problem by the device is similar to that of the database risk identification method, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be repeated.
[0150] Fig.12 : is a structural block diagram of a database risk identification device in an embodiment of the present invention. Fig.12 As shown, the database risk identification device includes:
[0151] The acquisition module is used to obtain the number of operation records in the database;
[0152] A database dynamic log threshold module is used to determine the database dynamic log threshold according to network loans and statement response time;
[0153] A row number threshold module, used to determine the row number threshold according to the database dynamic log threshold and the single row record capacity;
[0154] The first dynamic risk data module is used to generate first database dynamic risk data according to a comparison result between the number of operation record rows and the row number threshold.
[0155] In one embodiment, it also includes:
[0156] A database dynamic log capacity module, used to determine the database dynamic log capacity according to the system information table, the number of operation record rows and the coefficient;
[0157] The second dynamic risk data module is used to generate second database dynamic risk data according to the comparison result of the database dynamic log capacity and the database dynamic log threshold.
[0158] In one embodiment, the database dynamic log capacity module includes:
[0159] A table average record unit, used to determine a table average record according to the system information table;
[0160] The database dynamic log capacity unit is used to determine the database dynamic log capacity according to the average record of the table, the number of operation record rows and the coefficient.
[0161] In one embodiment, it also includes:
[0162] Database statement type module, used to obtain database statement type;
[0163] A coefficient module is used to determine the coefficient according to the database statement type.
[0164] In one embodiment, it also includes:
[0165] A risk statement judgment rule module, used to determine a risk statement judgment rule according to the database statement type;
[0166] The database static risk data module is used to judge the database statements according to the risk statement judgment rules and generate database static risk data.
[0167] In one embodiment, it also includes:
[0168] Log parsing module, used to parse incremental logs and obtain multiple log data;
[0169] A log data capacity module, used to determine the log data capacity according to the plurality of log data;
[0170] The database verification risk data module is used to generate database verification risk data according to the comparison result between the log data capacity and a preset log data capacity threshold.
[0171] In one embodiment, the log data capacity module includes:
[0172] A position unit, used to determine a start position and an end position according to information types of the plurality of log data;
[0173] The log data capacity unit is used to determine the log data capacity according to the start position and the end position.
[0174] Fig.13 FIG. 1 is a schematic diagram of a database risk identification device in another embodiment of the present invention. Fig.13As shown, in actual application, the database risk identification device includes: a configuration module, a static pre-check module, a dynamic check and automatic control module, a review and verification module and a monitoring alarm module.
[0175] Configuration module: responsible for the global and refined configuration of the system; including the start and stop control of other modules (such as time, frequency), parameter control of transaction size, alarm level configuration, alarm channel configuration, user configuration, log configuration, etc.
[0176] Static pre-check module: including risk statement judgment rule module and database static risk data module, responsible for static scanning of transaction logic before application goes online, and early warning of possible risk transactions based on SQL syntax;
[0177] The static pre-check module works on the developer's development tools and development environment servers. It scans the static SQL statements and table structures involved in the static code of the server environment and analyzes and discovers possible risks in the statements through preset rules. For example, if the delete / update statement does not contain a where condition and contains keywords such as limit, it may cause a large amount of data to trigger risks after it is actually launched. Through pre-control and feedback, risks can be avoided before the business goes online.
[0178] Dynamic inspection and automatic control module: including acquisition module, database dynamic log threshold module, row number threshold module, first dynamic risk data module, database dynamic log capacity module, second dynamic risk data module, database statement type module, coefficient module, responsible for the monitoring and control of the running state, and online early warning or automatic and manual intervention of the risk transactions in the running state based on database transaction information;
[0179] The dynamic inspection and automatic control module works in the online operation stage. Based on the database's own capabilities, it monitors the relevant indicators of in-transit transactions (number of rows, table structure, record size, etc.) in real time, analyzes the data volume of in-transit transaction operations in real time, and performs automatic control on the in-transit transactions: such as terminating transactions, temporarily releasing transactions, and issuing alarms.
[0180] Review and verification module: including log analysis module, log data capacity module, database verification risk data module, responsible for analyzing database logs, solving logs that cannot be found by module 2 and module 3, and feeding the model back to the configuration module for continuous improvement.
[0181] The review and verification module analyzes the database transaction log, analyzes the start and end positions of the log transaction according to the transaction log file structure, calculates the transaction size, and analyzes the records and statements involved in the transaction processing. And feeds the information back to the configuration module.
[0182] Monitoring and alarm module: Identify risks and warn about the system's own operation status, and promptly notify operation and maintenance personnel through WeChat, email, SMS, phone and other channels to handle risks as soon as possible;
[0183] The alarm module is the interface between system event processing and alarm channels. It mainly collects risks and event alarms found in each module during operation, and monitors the operation status of each module, whether there is any failure, etc.
[0184] In summary, the database risk identification device of the embodiment of the present invention determines the database dynamic log threshold according to the network loan and statement response time to further determine the row number threshold, and then generates the first database dynamic risk data according to the comparison result of the operation record row number and the row number threshold, which can solve the risk of large transactions, ensure the response time of business services, and effectively improve the user experience.
[0185] Fig.14 FIG. 9 is a schematic block diagram of the system structure of the electronic device 9600 according to an embodiment of the present application. Fig.14 As shown, the electronic device 9600 may include a central processor 9100 and a memory 9140; the memory 9140 is coupled to the central processor 9100. It is worth noting that Fig.14 is exemplary; other types of structures may also be used to supplement or replace this structure to implement telecommunication functions or other functions.
[0186] In one embodiment, the database risk identification method function may be integrated into the central processing unit 9100. The central processing unit 9100 may be configured to perform the following control:
[0187] Get the number of rows of operation records in the database;
[0188] Determine database dynamic log thresholds based on network loans and statement response time;
[0189] Determine the row number threshold according to the database dynamic log threshold and the single row record capacity;
[0190] Generate first database dynamic risk data according to a comparison result of the operation record row number and the row number threshold.
[0191] From the above description, it can be seen that the database risk identification method provided in the present application determines the database dynamic log threshold based on the network loan and statement response time to further determine the row number threshold, and then generates the first database dynamic risk data based on the comparison result of the operation record row number and the row number threshold, which can solve large transaction risks, ensure the response time of business services, and effectively improve user experience.
[0192] In another embodiment, the database risk identification device may be configured separately from the central processor 9100. For example, the database risk identification device may be configured as a chip connected to the central processor 9100, and the functions of the database risk identification method may be implemented under the control of the central processor.
[0193] like Fig.14 As shown, the electronic device 9600 may also include: a communication module 9110, an input unit 9120, an audio processor 9130, a display 9160, and a power supply 9170. It is worth noting that the electronic device 9600 does not necessarily have to include Fig.14 In addition, the electronic device 9600 may also include Fig.14 For components not shown, reference may be made to the prior art.
[0194] like Fig.14 As shown, the central processing unit 9100 is sometimes also referred to as a controller or an operation control, and may include a microprocessor or other processor device and / or logic device. The central processing unit 9100 receives input and controls the operation of various components of the electronic device 9600.
[0195] The memory 9140 may be, for example, one or more of a cache, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory or other suitable devices. The above-mentioned information related to the failure may be stored, and a program for executing the relevant information may also be stored. The CPU 9100 may execute the program stored in the memory 9140 to implement information storage or processing, etc.
[0196] The input unit 9120 provides input to the central processing unit 9100. The input unit 9120 is, for example, a key or a touch input device. The power supply 9170 is used to provide power to the electronic device 9600. The display 9160 is used to display display objects such as images and texts. The display may be, for example, an LCD display, but is not limited thereto.
[0197] The memory 9140 may be a solid-state memory, such as a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It may also be a memory that saves information even when the power is off, can be selectively erased, and is provided with more data, examples of which are sometimes referred to as EPROMs, etc. The memory 9140 may also be some other type of device. The memory 9140 includes a buffer 9141 (sometimes referred to as a buffer memory). The memory 9140 may include an application / function storage unit 9142, which is used to store application programs and function programs or processes for executing the operation of the electronic device 9600 through the central processor 9100.
[0198] The memory 9140 may also include a data storage unit 9143 for storing data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 9144 of the memory 9140 may include various drivers for communication functions of the electronic device and / or for executing other functions of the electronic device (such as messaging applications, address book applications, etc.).
[0199] The communication module 9110 is a transmitter / receiver 9110 that sends and receives signals via an antenna 9111. The communication module (transmitter / receiver) 9110 is coupled to the central processor 9100 to provide input signals and receive output signals, which may be the same as the case of a conventional mobile communication terminal.
[0200] Based on different communication technologies, multiple communication modules 9110 may be provided in the same electronic device, such as a cellular network module, a Bluetooth module and / or a wireless LAN module, etc. The communication module (transmitter / receiver) 9110 is also coupled to a speaker 9131 and a microphone 9132 via an audio processor 9130 to provide an audio output via the speaker 9131 and receive an audio input from the microphone 9132, thereby realizing a common telecommunication function. The audio processor 9130 may include any suitable buffer, decoder, amplifier, etc. In addition, the audio processor 9130 is also coupled to the central processor 9100, so that recording can be performed on the local machine through the microphone 9132, and the sound stored on the local machine can be played through the speaker 9131.
[0201] The embodiment of the present invention also provides a computer-readable storage medium capable of implementing all the steps of the database risk identification method in the above embodiment, where the execution subject is a server or a client. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, all the steps of the database risk identification method in the above embodiment are implemented. For example, when the processor executes the computer program, the following steps are implemented:
[0202] Get the number of rows of operation records in the database;
[0203] Determine database dynamic log thresholds based on network loans and statement response time;
[0204] Determine the row number threshold according to the database dynamic log threshold and the single row record capacity;
[0205] Generate first database dynamic risk data according to a comparison result of the operation record row number and the row number threshold.
[0206] In summary, the computer-readable storage medium of the embodiment of the present invention determines the database dynamic log threshold according to the network loan and statement response time to further determine the row number threshold, and then generates the first database dynamic risk data according to the comparison result of the operation record row number and the row number threshold, which can solve the risk of large transactions, ensure the response time of business services, and effectively improve the user experience.
[0207] The embodiment of the present invention also provides a computer program product capable of implementing all the steps of the database risk identification method in the above embodiment, where the execution subject is a server or a client. The computer program product includes a computer program / instruction. When the computer program / instruction is executed by a processor, all the steps of the database risk identification method in the above embodiment are implemented. For example, when the processor executes the computer program, the following steps are implemented:
[0208] Get the number of rows of operation records in the database;
[0209] Determine database dynamic log thresholds based on network loans and statement response time;
[0210] Determine the row number threshold according to the database dynamic log threshold and the single row record capacity;
[0211] Generate first database dynamic risk data according to a comparison result of the operation record row number and the row number threshold.
[0212] In summary, the computer program product of the embodiment of the present invention determines the database dynamic log threshold according to the network loan and statement response time to further determine the row number threshold, and then generates the first database dynamic risk data according to the comparison result of the operation record row number and the row number threshold, which can solve the risk of large transactions, ensure the response time of business services, and effectively improve the user experience.
[0213] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the hardware + program embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0214] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0215] Although the present application provides method operation steps as described in the embodiments or flowcharts, more or fewer operation steps may be included based on conventional or non-creative labor. The order of steps listed in the embodiments is only one way of executing the order of many steps and does not represent the only execution order. When the actual device or client product is executed, it can be executed in the order of the method shown in the embodiments or the drawings or in parallel (for example, in a parallel processor or multi-threaded processing environment).
[0216] Although the present specification embodiment provides the method operation steps as described in the embodiment or flow chart, more or less operation steps may be included based on conventional or non-creative means. The order of steps listed in the embodiment is only one way in the order of execution of many steps, and does not represent a unique execution order. When the device or terminal product in practice is executed, it can be executed in sequence or in parallel (such as a parallel processor or a multi-threaded processing environment, or even a distributed data processing environment) according to the method shown in the embodiment or the accompanying drawings. The term "include", "comprise" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, product or equipment including a series of elements not only includes those elements, but also includes other elements not clearly listed, or also includes elements inherent to such process, method, product or equipment. In the absence of more restrictions, it is not excluded that there are other identical or equivalent elements in the process, method, product or equipment including the elements.
[0217] For the convenience of description, the above devices are described in various modules according to their functions. Of course, when implementing the embodiments of this specification, the functions of each module can be implemented in the same or more software and / or hardware, or the module implementing the same function can be implemented by a combination of multiple sub-modules or sub-units. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0218] Those skilled in the art also know that, in addition to implementing the controller in a purely computer-readable program code, the controller can be made to implement the same function in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, such a controller can be considered as a hardware component, and the devices for implementing various functions included therein can also be considered as structures within the hardware component. Or even, the devices for implementing various functions can be considered as both software modules for implementing the method and structures within the hardware component.
[0219] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0220] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0221] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0222] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0223] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0224] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0225] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, the embodiments of this specification may take the form of complete hardware embodiments, complete software embodiments or embodiments combining software and hardware. Moreover, the embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0226] The various embodiments in this specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The embodiments of this specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0227] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the embodiments of this specification. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of the different embodiments or examples, without contradiction.
[0228] The above is only an example of the embodiment of the present specification and is not intended to limit the embodiment of the present specification. For those skilled in the art, the embodiment of the present specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the embodiment of the present specification shall be included in the scope of the claims of the embodiment of the present specification.
Claims
1. A database risk identification method, characterized in that: include: Get the number of rows of operation records in the database; Determine database dynamic log thresholds based on network loans and statement response time; Determine the row number threshold according to the database dynamic log threshold and the single row record capacity; Generate first database dynamic risk data according to a comparison result of the operation record row number and the row number threshold.
2. The database risk identification method according to claim 1, characterized in that: Also includes: Determine the database dynamic log capacity according to the system information table, the number of operation record rows and the coefficient; Second database dynamic risk data is generated according to a comparison result between the database dynamic log capacity and the database dynamic log threshold.
3. The database risk identification method according to claim 2, characterized in that: Determining the database dynamic log capacity according to the system information table, the number of operation record rows and the coefficient includes: Determine the table average record according to the system information table; The dynamic log capacity of the database is determined according to the average records of the table, the number of operation record rows and the coefficient.
4. The database risk identification method according to claim 2, characterized in that: Also includes: Get the database statement type; The coefficient is determined according to the database statement type.
5. The database risk identification method according to claim 4, characterized in that: Also includes: Determining risk statement judgment rules according to the database statement type; The database statements are judged according to the risk statement judgment rules to generate database static risk data.
6. The database risk identification method according to claim 1, characterized in that: Also includes: Parse incremental logs to obtain multiple log data; determining the log data capacity according to the plurality of log data; Database verification risk data is generated according to a comparison result between the log data capacity and a preset log data capacity threshold.
7. The database risk identification method according to claim 6, characterized in that: Determining the log data capacity according to the plurality of log data includes: Determine a start position and an end position according to information types of the plurality of log data; The log data capacity is determined according to the start position and the end position.
8. A database risk identification device, characterized in that: include: The acquisition module is used to obtain the number of operation records in the database; Database dynamic log threshold module, used to determine the database dynamic log threshold according to network loan and statement response time; A row number threshold module, used to determine the row number threshold according to the database dynamic log threshold and the single row record capacity; The first dynamic risk data module is used to generate first database dynamic risk data according to a comparison result between the number of operation record rows and the row number threshold.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the steps of the database risk identification method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the database risk identification method according to any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Risk assessment method and device for long transaction and large transaction of MySQL database and medium
CN122412215A