Database resource management system and method based on authority control
By building a permission prediction model based on user behavior and database resource characteristics, capturing and determining user operation requests in real time, and triggering hierarchical permission control, the problem that traditional permission control models are difficult to adapt to the popularity of dynamic resource use is solved, and efficient permission management and risk prediction are achieved.
Patent Information
- Application Number
- CN202510457591.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-04-11
AI Technical Summary
The traditional database permission control model is difficult to adapt to the dynamically changing resource usage heat, resulting in increased system performance bottlenecks and data leakage risks, and lacks in-depth analysis of user historical behavior patterns, making it impossible to predict and intercept unconventional access behaviors.
By collecting database resource information and user access operation information, extracting multi-dimensional features and user behavior characteristics, using clustering algorithms and random forest algorithms to build a permission prediction model, capturing user operation requests in real time, combining context information to make permission judgments, and triggering hierarchical permission control.
It realizes dynamic prediction of the risk of users accessing high-frequency resources, improves the real-time and targeted permission management, avoids system performance bottlenecks and data leakage risks, and improves business efficiency and user operation fluency.
Smart Images

Figure CN120011459A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of database resource management, and in particular to a database resource management system and method based on authority control. Background Art
[0002] In today's digital age, databases, as key infrastructure for storing and managing massive amounts of data, are widely used in various fields such as enterprises, governments, and scientific research institutions. In database resource management, permission control is the core link to ensure data security, which determines the access and operation permissions of different users or roles to various resources in the database.
[0003] At present, database permission control mainly relies on role-based access control (RBAC) or attribute-based access control (ABAC) models, and its permission allocation is usually based on static rules. However, in dynamic business scenarios, the access mode of database resources presents high frequency and strong correlation characteristics. Traditional models are difficult to adapt to the dynamic changes in resource usage. For example, some data resources frequently accessed by core businesses lack dynamic adaptability in permission settings. During business peaks, when a large number of users initiate access requests at the same time, it is easy to cause system performance bottlenecks and affect overall business efficiency. At the same time, due to fixed permissions, these high-frequency resources are at the same authorization level for a long time. Once they are attacked maliciously, they lack a layered protection mechanism, which can easily lead to increased data leakage risks. In addition, existing solutions are mostly based on preset role or attribute rules, lack of in-depth analysis of user historical behavior patterns, resulting in a disconnect between permission allocation and real needs, and failure to predict and intercept unconventional access behaviors, such as sudden high-frequency operations, which poses a risk of data leakage or abuse. Summary of the invention
[0004] The purpose of the present invention is to provide a database resource management system and method based on authority control to solve the problems raised in the above background technology.
[0005] In order to solve the above technical problems, the present invention provides the following technical solutions: a database resource management method based on authority control, the method comprising: Step S100: Collect database resource information and extract multi-dimensional features, classify database resources using clustering algorithms, and build a resource category identification system; collect user access operation information from database management system logs and store it in the operation log data warehouse, and filter out high-frequency access resources through statistical analysis; Step S200: extracting user permission access related features from the operation log data warehouse, and building a permission prediction model based on user behavior in combination with the extracted database resource features; Step S300: Capture user operation requests in real time, combine context information, extract and preprocess real-time features related to permissions, and input them into the trained permission prediction model to predict whether the user will access high-frequency resources; at the same time, combine the user role access control list set by the database system to preliminarily determine whether the user's operation is within the user's normal permission range; Step S400: If it is predicted that the user will access high-frequency resources and is initially determined to have permission, hierarchical permission control is triggered. According to the user role and the current usage of data resources, the user's access rights are hierarchically controlled, and a hierarchical permission control notification is sent to the user accessing the high-frequency resources.
[0006] Furthermore, the step S100 includes: Step S101: traverse all resources in the database, including various data tables, views and storage locations; for each resource, extract multidimensional metadata information, including table name, field type, data volume, access user role and corresponding permissions, resource modification time and predefined sensitivity labels; the sensitivity labels include three categories: public, internal and confidential; for each resource, construct a resource feature vector Ri=[ri1, ri2, ri3], where Ri represents the feature vector of the i-th database resource, ri1 represents the data sensitivity of the i-th database resource, ri2 represents the permission association of the i-th database resource, and ri3 represents the data dynamics of the i-th database resource; the data sensitivity is marked according to the set business rules, 0 represents public data, 1 represents internal data, and 2 represents confidential data; the permission association is used to count the number of user roles associated with accessing resources; the data dynamics is used to calculate the number of days between the last modification time of the resource and the current time; Step S102: Use the DBSCAN clustering algorithm to classify database resources, calculate the Euclidean distance between resource feature vectors, determine the nearest neighbor distance dmin of each resource feature vector, summarize the nearest neighbor distances of all resource feature vectors, and draw a distance graph, where the horizontal axis is the data point index and the vertical axis is the nearest neighbor distance of the corresponding point. Connect the points in the order of the data point index to form a curve, and select the distance value corresponding to the first inflection point on the curve as the neighborhood radius e; define the minimum number of neighborhood points Mp, and determine the core points, boundary points, and noise points based on e and Mp; if the resource feature vector Ri If the nearest neighbor distance dmin is less than or equal to e, and the number of points contained in its neighborhood is at least Mp, then Ri is a core point; if Ri is not a core point, but Ri's e neighborhood contains at least one core point, then Ri is a boundary point; if Ri is neither a core point nor a boundary point, then Ri is a noise point; divide the core point and the points in its neighborhood into different clusters, each cluster represents a database resource category; construct a resource category classification system, assign a unique identifier to each category, establish a mapping relationship between resources and classification identifiers, and store the unique identifier of the resource and the corresponding classification identifier in the resource classification table of the database; Step S103: The database management system collects user access information, including operation timestamp, operation type, database resources involved, IP address of the operation initiating terminal, and operation result, and stores the information in the operation log data warehouse; defines an initial statistical period, and divides the total number of resource accesses within the statistical period by the number of time units within the period to obtain the average number of accesses as the initial access frequency F0; uses an exponentially weighted moving average algorithm, and sets the time window to a fixed length T. The calculation formula is F t =α×A t +(1-α)×F t-1 , where F t is the access frequency of the resource at the current moment, A t is the actual number of resource accesses in the current time window T, α is the time decay factor where 0<α<1, F t-1 is the access frequency of the resource at the last moment, and the initial calculation is F t-1 =F0; set an access frequency threshold β, and set F t Resources greater than or equal to β are screened out as high-frequency access resources; by performing statistical analysis on historical access frequency data, the mean and standard deviation are calculated, and the threshold β is set to the mean plus k times the standard deviation, where k is the coefficient for adjusting the threshold.
[0007] Furthermore, the step S200 includes: Step S201: extract features related to user permission access from the operation log data warehouse, including operation timestamp, operation type, database resources involved, IP address of the terminal initiating the operation, and operation results; at the same time, extract the feature of "whether it is a high-frequency resource" from the high-frequency access resource information screened out in step S100; extract key features from the collected historical behavior data, and construct a user behavior feature vector U=[operation timestamp, operation type, IP address of the terminal initiating the operation, operation result, access frequency, whether to access high-frequency resources]; perform missing value processing, outlier processing and data normalization processing on the extracted features; construct the target label of the model, if the operation record involves high-frequency resources, the label is set to 1; if not, the label is set to 0; Step S202: Divide the collected user behavior data and the database resource data in step S100 into a training set and a test set in a ratio of 8:2, and use the random forest algorithm to build a dynamic permission prediction model, with the user behavior feature vector U and the resource feature vector Ri as input; set the parameters of the random forest algorithm, including the number of trees and the maximum depth, and use the cross-validation method to evaluate and optimize the model. During the training process, continuously adjust the model parameters; the model outputs the probability of users accessing high-frequency resources, and uses accuracy, recall rate, F1 value, ROC-AUC and logarithmic loss as evaluation indicators.
[0008] The accuracy, recall, F1 value, ROC-AUC and logarithmic loss are all performance evaluation indicators of the dynamic permission prediction model, among which ROC-AUC is used to evaluate the accuracy of the model in predicting the probability of users accessing high-frequency resources; First, the trained dynamic permission model is used to predict the test set to obtain the probability value of each sample belonging to the positive class; the positive class indicates that the user accesses high-frequency resources; A plurality of different thresholds are defined from 0 to 1 by an equal interval selection method, and the probability value predicted by the model is compared with the threshold. If the probability value is greater than the threshold, the sample is predicted as a positive class, otherwise it is a negative class, and the negative class indicates that the user does not access high-frequency resources. Then, according to whether the user in the test set sample actually accesses the high-frequency resources, the true positive rate and the false positive rate are calculated. The true positive rate indicates the proportion of samples that are correctly predicted as positive in all samples that actually access high-frequency resources; the false positive rate indicates the proportion of samples that are incorrectly predicted as positive in all samples that do not actually access high-frequency resources. Taking the false positive rate at different calculated thresholds as the abscissa and the true positive rate as the ordinate, plot each point in the Cartesian coordinate system, and then connect these points to obtain the ROC curve; use the trapezoidal method to calculate the area under the ROC curve, divide the area under the ROC curve into multiple small trapezoids, calculate the area of each small trapezoid and sum them to obtain the value of AUC; the value range of AUC is between 0 and 1, and the larger the value, the better the performance of the model: When AUC = 1, it means that the model can completely distinguish positive and negative class samples, all positive class samples can be correctly predicted, and all negative class samples can also be correctly predicted; When AUC <= 0.5, it means that the model's prediction has no ability to distinguish positive and negative class samples; When AUC is between 0.5 and 1, the closer AUC is to 1, the better the performance of the model, and it can more effectively distinguish positive and negative class samples; set the accuracy rate, recall rate, F1 value, ROC-AUC, and logarithmic loss threshold, and when each index reaches or exceeds the threshold, stop the training of the model.
[0009] Further, the step S300 includes: Step S301: Real-time capture user database operation requests, including the operation initiation time, the unique identity identifier of the initiating user, and the operation instruction, and temporarily store the obtained information in the temporary storage area; read the operation instruction from the temporary storage area, parse the operation instruction through an SQL parsing tool, and extract the operation type, the database target access resource, and the operation condition through parsing; at the same time, collect the context information associated with the user operation, including the user role and permission information, the IP of the terminal device currently used by the user for login, and the network environment information of the terminal device; Step S302: Construct a real-time user behavior feature vector according to step S200, extract key features from the real-time captured operation requests and context information, construct a real-time feature vector and perform preprocessing; input the preprocessed real-time feature vector into the trained permission prediction model, and the model outputs the prediction probability P of whether the user will access high-frequency resources, and set a probability threshold f, f ∈ (0, 1); if P >= f, query the user role access control list pre-set and stored in the database system, find the user's affiliated role according to the unique identifier of the user who initiated the request, and the preset permission information granted to the role for the current requested resource, and initially judge whether the user's current operation conforms to the normal permission range of the user by comparing the preset permission information with the type of the current operation request. If the preset permission includes the current operation type, it is determined that the permission range is met, and the hierarchical permission control process is triggered; if P < f, process the user's operation request according to the default permission configuration of the database system, and allow the user to operate with normal permissions.
[0010] Furthermore, the step S400 includes: Step S401: The database predefines different user roles, including ordinary users, advanced users and administrators; each role has different responsibilities and authority ranges in the database; if the user is predicted to access high-frequency resources according to step S300 and is initially determined to have authority, hierarchical authority control is triggered; the number of concurrent accesses to data resources is obtained in real time; Step S402: When the number of concurrent accesses to data resources is higher than the set concurrent threshold, set an upper limit on the single duration of access to high-frequency resources by ordinary users; monitor the access time through a built-in timer, and automatically terminate the access connection once it times out, and pop up a window to prompt the user; the single duration of access to high-frequency resources by advanced users is limited to x minutes, and a warning pop-up window is sent to the user in advance to prompt the remaining access time; the database system will record the administrator's long-term operation behavior, and if the continuous access exceeds a hour, an email warning will be sent to the monitoring personnel, prompting them to pay attention to whether the administrator's operation is abnormal; while performing hierarchical control on the user's access rights, a detailed hierarchical permission control notification is generated, and the notification content includes the user's current role, the number of concurrent accesses to the current data resource, the access rights granted to the user, and the validity period of the permission restriction.
[0011] A database resource management system based on authority control, the system comprising a resource management module, a user behavior analysis module, a real-time authority determination module and a hierarchical authority control module; The resource management module is used to collect database resource information and extract multi-dimensional features, classify database resources using a clustering algorithm, and build a resource category identification system; collect user access operation information from the database management system log and store it in the operation log data warehouse, and filter out high-frequency access resources through statistical analysis; The user behavior analysis module extracts user permission access related features from the operation log data warehouse, and builds a permission prediction model based on user behavior in combination with the extracted database resource features; The real-time permission determination module captures user operation requests in real time, combines context information, extracts and preprocesses real-time features related to permissions, and inputs them into the trained permission prediction model to predict whether the user will access high-frequency resources; at the same time, combined with the user role access control list set by the database system, it preliminarily determines whether the user's operation is within the user's normal permission range; If the hierarchical permission control module predicts that the user will access high-frequency resources and preliminarily determines that he has permission, it triggers hierarchical permission control, hierarchically controls user access rights according to the user role and current data resource usage, and sends a hierarchical permission control notification to the user accessing the high-frequency resources.
[0012] Compared with the prior art, the beneficial effects achieved by the present invention are: The present invention uses a clustering algorithm to deeply classify database resources, build a resource category identification system, and divide database resources in an orderly manner according to the multi-dimensional characteristics of the resources themselves; compared with the traditional classification method based on simple directories or single attributes, the classification of the present invention allows administrators to understand the resource architecture more clearly, and is more targeted when allocating permissions and optimizing resource configuration; The present invention can dynamically predict whether a user will access high-frequency resources by capturing user operation requests in real time, combining context information to construct feature vectors, and inputting permission prediction models trained based on user behavior and database resource features. The present invention focuses on risk prevention and control of high-frequency access resources, captures potential high-frequency resource access behaviors based on real-time user behavior trends, and predicts risks in advance, effectively solving the problem of insufficient supervision of high-frequency resource access in traditional permission management systems when facing complex and changeable user operations, and avoiding illegal or excessive access to sensitive high-frequency resources caused by delayed responses. The present invention sends hierarchical permission control notifications to users, informing them in detail of key information such as the current permission status, resource usage, etc., so that users can understand the operation boundaries in real time, avoid erroneous operations caused by unclear permissions, and improve operation fluency; on the other hand, through the permission judgment process, combined with the user role access control list and real-time permission prediction, it ensures that user operations are compliant throughout the process. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings: Figure 1 The invention is a method flow chart of a database resource management method based on authority control. DETAILED DESCRIPTION
[0014] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0015] See also Figure 1 The present invention provides a technical solution: a database resource management method based on authority control, the method comprising: Step S100: Collect database resource information and extract multi-dimensional features, classify database resources using clustering algorithms, and build a resource category identification system; collect user access operation information from database management system logs and store it in the operation log data warehouse, and filter out high-frequency access resources through statistical analysis; Step S200: extracting user permission access related features from the operation log data warehouse, and building a permission prediction model based on user behavior in combination with the extracted database resource features; Step S300: Capture user operation requests in real time, combine context information, extract and preprocess real-time features related to permissions, and input them into the trained permission prediction model to predict whether the user will access high-frequency resources; at the same time, combine the user role access control list set by the database system to preliminarily determine whether the user's operation is within the user's normal permission range; Step S400: If it is predicted that the user will access high-frequency resources and is initially determined to have permission, hierarchical permission control is triggered. According to the user role and the current usage of data resources, the user's access rights are hierarchically controlled, and a hierarchical permission control notification is sent to the user accessing the high-frequency resources.
[0016] Furthermore, the step S100 includes: Step S101: traverse all resources in the database, including various data tables, views and storage locations; for each resource, extract multidimensional metadata information, including table name, field type, data volume, access user role and corresponding permissions, resource modification time and predefined sensitivity labels; the sensitivity labels include three categories: public, internal and confidential; for each resource, construct a resource feature vector Ri=[ri1, ri2, ri3], where Ri represents the feature vector of the i-th database resource, ri1 represents the data sensitivity of the i-th database resource, ri2 represents the permission association of the i-th database resource, and ri3 represents the data dynamics of the i-th database resource; the data sensitivity is marked according to the set business rules, 0 represents public data, 1 represents internal data, and 2 represents confidential data; the permission association is used to count the number of user roles associated with accessing resources; the data dynamics is used to calculate the number of days between the last modification time of the resource and the current time; Step S102: Use the DBSCAN clustering algorithm to classify database resources, calculate the Euclidean distance between resource feature vectors, determine the nearest neighbor distance dmin of each resource feature vector, summarize the nearest neighbor distances of all resource feature vectors, and draw a distance graph, where the horizontal axis is the data point index and the vertical axis is the nearest neighbor distance of the corresponding point. Connect the points in the order of the data point index to form a curve, and select the distance value corresponding to the first inflection point on the curve as the neighborhood radius e; define the minimum number of neighborhood points Mp, and determine the core points, boundary points, and noise points based on e and Mp; if the resource feature vector Ri If the nearest neighbor distance dmin is less than or equal to e, and the number of points contained in its neighborhood is at least Mp, then Ri is a core point; if Ri is not a core point, but Ri's e neighborhood contains at least one core point, then Ri is a boundary point; if Ri is neither a core point nor a boundary point, then Ri is a noise point; divide the core point and the points in its neighborhood into different clusters, each cluster represents a database resource category; construct a resource category classification system, assign a unique identifier to each category, establish a mapping relationship between resources and classification identifiers, and store the unique identifier of the resource and the corresponding classification identifier in the resource classification table of the database; Step S103: The database management system collects user access information, including operation timestamp, operation type, database resources involved, IP address of the operation initiating terminal, and operation result, and stores the information in the operation log data warehouse; defines an initial statistical period, and divides the total number of resource accesses within the statistical period by the number of time units within the period to obtain the average number of accesses as the initial access frequency F0; uses an exponentially weighted moving average algorithm, and sets the time window to a fixed length T. The calculation formula is F t =α×A t +(1-α)×F t-1 , where F t is the access frequency of the resource at the current moment, A t is the actual number of resource accesses in the current time window T, α is the time decay factor where 0<α<1, F t-1 is the access frequency of the resource at the last moment, and the initial calculation is F t-1 =F0; set an access frequency threshold β, and set F t Resources greater than or equal to β are screened out as high-frequency access resources; by performing statistical analysis on historical access frequency data, the mean and standard deviation are calculated, and the threshold β is set to the mean plus k times the standard deviation, where k is the coefficient for adjusting the threshold.
[0017] Furthermore, the step S200 includes: Step S201: extract features related to user permission access from the operation log data warehouse, including operation timestamp, operation type, database resources involved, IP address of the terminal initiating the operation, and operation results; at the same time, extract the feature of "whether it is a high-frequency resource" from the high-frequency access resource information screened out in step S100; extract key features from the collected historical behavior data, and construct a user behavior feature vector U=[operation timestamp, operation type, IP address of the terminal initiating the operation, operation result, access frequency, whether to access high-frequency resources]; perform missing value processing, outlier processing and data normalization processing on the extracted features; construct the target label of the model, if the operation record involves high-frequency resources, the label is set to 1; if not, the label is set to 0; Step S202: Divide the collected user behavior data and the database resource data in step S100 into a training set and a test set in a ratio of 8:2, and use the random forest algorithm to build a dynamic permission prediction model, with the user behavior feature vector U and the resource feature vector Ri as input; set the parameters of the random forest algorithm, including the number of trees and the maximum depth, and use the cross-validation method to evaluate and optimize the model. During the training process, continuously adjust the model parameters; the model outputs the probability of users accessing high-frequency resources, and uses accuracy, recall rate, F1 value, ROC-AUC and logarithmic loss as evaluation indicators.
[0018] The accuracy, recall, F1 value, ROC-AUC and logarithmic loss are all performance evaluation indicators of the dynamic permission prediction model, among which ROC-AUC is used to evaluate the accuracy of the model in predicting the probability of users accessing high-frequency resources; First, the trained dynamic permission model is used to predict the test set to obtain the probability value of each sample belonging to the positive class; the positive class indicates that the user accesses high-frequency resources; A plurality of different thresholds are defined from 0 to 1 by an equal interval selection method, and the probability value predicted by the model is compared with the threshold. If the probability value is greater than the threshold, the sample is predicted as a positive class, otherwise it is a negative class, and the negative class indicates that the user does not access high-frequency resources. Then, according to whether the user in the test set sample actually accesses the high-frequency resources, the true positive rate and the false positive rate are calculated. The true positive rate indicates the proportion of samples that are correctly predicted as positive in all samples that actually access high-frequency resources; the false positive rate indicates the proportion of samples that are incorrectly predicted as positive in all samples that do not actually access high-frequency resources. Taking the false positive rate at different calculated thresholds as the abscissa and the true positive rate as the ordinate, plot each point in the rectangular coordinate system, and then connect these points to obtain the ROC curve; use the trapezoidal method to calculate the area under the ROC curve, divide the area under the ROC curve into multiple small trapezoids, calculate the area of each small trapezoid and sum them to obtain the value of AUC; the value range of AUC is between 0 and 1, and the larger the value, the better the performance of the model: When AUC = 1, it means that the model can completely distinguish positive and negative class samples, all positive class samples can be correctly predicted, and all negative class samples can also be correctly predicted; When AUC <= 0.5, it means that the model's prediction has no ability to distinguish positive and negative class samples; When AUC is between 0.5 and 1, the closer AUC is to 1, the better the performance of the model, and it can more effectively distinguish positive and negative class samples; set the accuracy rate, recall rate, F1 value, ROC-AUC, and logarithmic loss threshold, and when each index reaches or exceeds the threshold, stop the training of the model.
[0019] Further, the step S300 includes: Step S301: Real-time capture user database operation requests, including the operation initiation time, the unique identity identifier of the initiating user, and the operation instruction, and temporarily store the obtained information in the temporary storage area; read the operation instruction from the temporary storage area, parse the operation instruction through the SQL parsing tool, and extract the operation type, the database target access resource, and the operation conditions through the parsing; at the same time, collect the context information associated with the user operation, including the user role and permission information, the IP of the terminal device currently used by the user for login, and the network environment information of the terminal device; Step S302: Construct a real-time user behavior feature vector according to step S200, extract key features from the real-time captured operation requests and context information, construct a real-time feature vector and perform preprocessing; input the preprocessed real-time feature vector into the trained permission prediction model, and the model outputs the prediction probability P of whether the user will access high-frequency resources, and set the probability threshold f, f ∈ (0, 1); if P >= f, then query the user role access control list pre-set and stored in the database system, find the user's affiliated role according to the unique identifier of the user who发起 the request, and the preset permission information assigned to the role for the current requested resource, and initially judge whether the user's current operation conforms to the normal permission range of the user by comparing the preset permission information with the type of the current operation request. If the preset permission includes the current operation type, it is determined that the permission range is met, and the hierarchical permission control process is triggered; if P < f, then process the user's operation request according to the default permission configuration of the database system, and allow the user to operate with regular permissions.
[0020] Furthermore, the step S400 includes: Step S401: The database predefines different user roles, including ordinary users, advanced users and administrators; each role has different responsibilities and authority ranges in the database; if the user is predicted to access high-frequency resources according to step S300 and is initially determined to have authority, hierarchical authority control is triggered; the number of concurrent accesses to data resources is obtained in real time; Step S402: When the number of concurrent accesses to data resources is higher than the set concurrent threshold, set an upper limit on the single duration of access to high-frequency resources by ordinary users; monitor the access time through a built-in timer, and automatically terminate the access connection once it times out, and pop up a window to prompt the user; the single duration of access to high-frequency resources by advanced users is limited to x minutes, and a warning pop-up window is sent to the user in advance to prompt the remaining access time; the database system will record the administrator's long-term operation behavior, and if the continuous access exceeds a hour, an email warning will be sent to the monitoring personnel, prompting them to pay attention to whether the administrator's operation is abnormal; while performing hierarchical control on the user's access rights, a detailed hierarchical permission control notification is generated, and the notification content includes the user's current role, the number of concurrent accesses to the current data resource, the access rights granted to the user, and the validity period of the permission restriction.
[0021] A database resource management system based on authority control, the system comprising a resource management module, a user behavior analysis module, a real-time authority determination module and a hierarchical authority control module; The resource management module is used to collect database resource information and extract multi-dimensional features, classify database resources using a clustering algorithm, and build a resource category identification system; collect user access operation information from the database management system log and store it in the operation log data warehouse, and filter out high-frequency access resources through statistical analysis; The user behavior analysis module extracts user permission access related features from the operation log data warehouse, and builds a permission prediction model based on user behavior in combination with the extracted database resource features; The real-time permission determination module captures user operation requests in real time, combines context information, extracts and preprocesses real-time features related to permissions, and inputs them into the trained permission prediction model to predict whether the user will access high-frequency resources; at the same time, combined with the user role access control list set by the database system, it preliminarily determines whether the user's operation is within the user's normal permission range; If the hierarchical permission control module predicts that the user will access high-frequency resources and preliminarily determines that he has permission, it triggers hierarchical permission control, hierarchically controls user access rights according to the user role and current data resource usage, and sends a hierarchical permission control notification to the user accessing the high-frequency resources.
[0022] Embodiment of the present invention: Taking a database management system of a manufacturing enterprise as an example, this database stores a large amount of product design documents, production orders, supply chain information, employee files and enterprise operation data, etc. The user roles within the enterprise are divided into workshop workers, production supervisors, supply chain specialists, data analysts, IT administrators, etc.; First, we comprehensively traverse all kinds of data tables, views, and document resources in the database to extract multi-dimensional features. Taking the product_designs table as an example, the table stores information related to product design drawings, contains 10 fields, and the data volume reaches 500,000. Since some designs involve core technologies, the sensitive label is set to 2. This table is associated with multiple department roles, and the authority correlation is 4. Based on the historical modification records, we calculate that the data is highly dynamic. We integrate these features and construct a resource feature vector. At the same time, the DBSCAN clustering algorithm is used to classify resources. By calculating the Euclidean distance between resources, the appropriate neighborhood parameters are determined. After clustering analysis, the product_designs table and related resources are classified as category 002 and stored in the resource classification table; the database management system collects employee operation logs in real time, covering the operation initiation time, employee ID, operation instructions, operation objects, operation results, and the IP of the terminal device where the operation is initiated, and stores this information in the operation log data warehouse; the initial statistical period is set to 1 day, and the resource access frequency is calculated using the exponentially weighted moving average algorithm, combined with a 1-hour time window and a time decay factor of 0.3; by performing statistical analysis on historical access frequency data, calculating the mean and standard deviation, and setting the threshold to the mean plus 2 times the standard deviation, high-frequency access resources are screened out. In the new product development stage, the product_designs table is frequently accessed and identified as a high-frequency access resource; Next, key information is extracted from the operation log data warehouse, including operation timestamp, operation type, IP address of the operation initiating terminal, and operation result. The user behavior feature vector is constructed by combining the high-frequency identifier of the resource and historical behavior data. Missing values are processed for the extracted features, and outliers are identified and processed through box plots. The maximum-minimum normalization method is used to normalize the data to the [0,1] interval. The processed user behavior feature vector and resource feature vector are divided into training set and test set in a ratio of 8:2. The random forest algorithm is used to construct a dynamic permission prediction model. During the model construction process, the number of trees is set to 100 and the maximum depth H is set to 8. During model training, the training set is sampled with replacement, and each sub-dataset is used to construct a decision tree. For each node split, some features are randomly selected to find the best split method. The decision tree grows according to the CART algorithm until the depth of the tree reaches the maximum value. Finally, the model integrates the prediction results of multiple decision trees through the majority voting method and outputs the probability of the user accessing high-frequency resources. When the production supervisor initiates an operation to view the design details of a new product in the product_designs table at 2024-03-26 14:30:00, the system captures the operation request, the employee's unique identity, the operation instruction, and the IP address of the terminal device that initiated the operation in real time, and temporarily stores them in a temporary storage area; the operation instruction is read from the temporary storage area, and the SQL parsing tool is used to parse out that the operation type is a query, the database target access resource is the product_designs table, and the operation condition is a screening condition related to the new product design; at the same time, context information is collected, including the IP address of the terminal device currently used by the employee to log in, and the enterprise intranet environment information where the terminal device is located; A real-time feature vector is constructed based on this information. After the same preprocessing steps as before, it is input into the trained permission prediction model, and the predicted probability is 0.6. The probability threshold f is pre-set to 0.5. Since 0.6>0.5, and the user role access control list pre-set and stored in the database system is queried, it is found that the production supervisor role has the viewing permission for the product_designs table, so the hierarchical permission control is triggered; at this time, it is monitored that the number of concurrent accesses to the product_designs table reaches 50, which exceeds the pre-set concurrent threshold of 30. Different roles are controlled hierarchically, and the single upper limit of the duration for ordinary workshop workers to access high-frequency resources is set to 10 minutes. Through the built-in meter The timer monitors the access time. Once the timeout period is reached, the access connection is automatically terminated and a pop-up window is displayed to the user. For advanced users such as senior data analysts, the single access time limit for high-frequency resources is 30 minutes. When the remaining access time is 6 minutes, a warning pop-up window is displayed to the user in advance to remind the remaining access time. For administrators, if the continuous access exceeds 2 hours, the system sends an email warning to the monitoring personnel, prompting them to pay attention to whether the administrator's operation is abnormal. At the same time, the system generates a detailed hierarchical permission control notification, including the user's current role (production supervisor), the number of concurrent accesses to the current data resource (50), the user's granted access rights (view) and the validity period of the permission restriction (during this operation), and sends it to the production supervisor in the form of a pop-up window for reminder.
[0023] It will be apparent to those skilled in the art that the invention is not limited to the details of the exemplary embodiments described above and that the invention can be implemented in other specific forms without departing from the spirit or essential features of the invention. Therefore, the embodiments should be considered exemplary and non-limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description, and it is intended that all variations falling within the meaning and scope of the equivalent elements of the claims be included in the invention. Any reference numeral in a claim should not be considered as limiting the claim to which it relates.
Claims
1. A database resource management method based on authority control, characterized in that: The method comprises: Step S100: Collect database resource information and extract multi-dimensional features, classify database resources using clustering algorithms, and build a resource category identification system; collect user access operation information from database management system logs and store it in the operation log data warehouse, and filter out high-frequency access resources through statistical analysis; Step S200: extracting user permission access related features from the operation log data warehouse, and building a permission prediction model based on user behavior in combination with the extracted database resource features; Step S300: Capture user operation requests in real time, combine context information, extract and preprocess real-time features related to permissions, and input them into the trained permission prediction model to predict whether the user will access high-frequency resources; at the same time, combine the user role access control list set by the database system to preliminarily determine whether the user's operation is within the user's normal permission range; Step S400: If it is predicted that the user will access high-frequency resources and is initially determined to have permission, hierarchical permission control is triggered. According to the user role and the current usage of data resources, the user's access rights are hierarchically controlled, and a hierarchical permission control notification is sent to the user accessing the high-frequency resources.
2. A database resource management method based on authority control according to claim 1, characterized in that: The step S100 includes: Step S101: traverse all resources in the database, including various data tables, views and storage locations; for each resource, extract multidimensional metadata information, including table name, field type, data volume, access user role and corresponding permissions, resource modification time and predefined sensitivity labels; the sensitivity labels include three categories: public, internal and confidential; for each resource, construct a resource feature vector Ri=[ri1, ri2, ri3], where Ri represents the feature vector of the i-th database resource, ri1 represents the data sensitivity of the i-th database resource, ri2 represents the permission association of the i-th database resource, and ri3 represents the data dynamics of the i-th database resource; the data sensitivity is marked according to the set business rules, 0 represents public data, 1 represents internal data, and 2 represents confidential data; the permission association is used to count the number of user roles associated with accessing resources; the data dynamics is used to calculate the number of days between the last modification time of the resource and the current time; Step S102: Use the DBSCAN clustering algorithm to classify database resources, calculate the Euclidean distance between resource feature vectors, determine the nearest neighbor distance dmin of each resource feature vector, summarize the nearest neighbor distances of all resource feature vectors, and draw a distance graph, where the horizontal axis is the data point index and the vertical axis is the nearest neighbor distance of the corresponding point. Connect the points in the order of the data point index to form a curve, and select the distance value corresponding to the first inflection point on the curve as the neighborhood radius e; define the minimum number of neighborhood points Mp, and determine the core points, boundary points, and noise points based on e and Mp; if the resource feature vector Ri If the nearest neighbor distance dmin is less than or equal to e, and the number of points contained in its neighborhood is at least Mp, then Ri is a core point; if Ri is not a core point, but Ri's e neighborhood contains at least one core point, then Ri is a boundary point; if Ri is neither a core point nor a boundary point, then Ri is a noise point; divide the core point and the points in its neighborhood into different clusters, each cluster represents a database resource category; construct a resource category classification system, assign a unique identifier to each category, establish a mapping relationship between resources and classification identifiers, and store the unique identifier of the resource and the corresponding classification identifier in the resource classification table of the database; Step S103: The database management system collects user access information, including operation timestamp, operation type, database resources involved, IP address of the operation initiating terminal, and operation result, and stores the information in the operation log data warehouse; defines an initial statistical period, and divides the total number of resource accesses within the statistical period by the number of time units within the period to obtain the average number of accesses as the initial access frequency F0; uses an exponentially weighted moving average algorithm, and sets the time window to a fixed length T. The calculation formula is F t =α×A t +(1-α)×F t-1 , where F t is the access frequency of the resource at the current moment, A t is the actual number of resource accesses in the current time window T, α is the time decay factor where 0<α<1, F t-1 is the access frequency of the resource at the last moment, and the initial calculation is F t-1 =F0; set an access frequency threshold β, and set F t Resources greater than or equal to β are screened out as high-frequency access resources; by performing statistical analysis on historical access frequency data, the mean and standard deviation are calculated, and the threshold β is set to the mean plus k times the standard deviation, where k is the coefficient for adjusting the threshold.
3. The method for managing database resources based on authority control according to claim 1, characterized in that: The step S200 includes: Step S201: extract features related to user permission access from the operation log data warehouse, including operation timestamp, operation type, database resources involved, IP address of the terminal initiating the operation, and operation results; at the same time, extract the feature of "whether it is a high-frequency resource" from the high-frequency access resource information screened out in step S100; extract key features from the collected historical behavior data, and construct a user behavior feature vector U=[operation timestamp, operation type, IP address of the terminal initiating the operation, operation result, access frequency, whether to access high-frequency resources]; perform missing value processing, outlier processing and data normalization processing on the extracted features; construct the target label of the model, if the operation record involves high-frequency resources, the label is set to 1; if not, the label is set to 0; Step S202: Divide the collected user behavior data and the database resource data in step S100 into a training set and a test set in a ratio of 8:2, and use the random forest algorithm to build a dynamic permission prediction model, with the user behavior feature vector U and the resource feature vector Ri as input; set the parameters of the random forest algorithm, including the number of trees and the maximum depth, and use the cross-validation method to evaluate and optimize the model. During the training process, continuously adjust the model parameters; the model outputs the probability of users accessing high-frequency resources, and uses accuracy, recall rate, F1 value, ROC-AUC and logarithmic loss as evaluation indicators.
4. The method for managing database resources based on authority control according to claim 1, characterized in that: The step S300 includes: Step S301: Real-time capture user database operation requests, including the operation initiation time, the unique identity identifier of the initiating user, and the operation instruction, and temporarily store the obtained information in a temporary storage area; read the operation instruction from the temporary storage area, parse the operation instruction through an SQL parsing tool, and extract the operation type, the database target access resource, and the operation condition through the parsing; at the same time, collect the context information associated with the user operation, including the user role and permission information, the IP of the terminal device currently used by the user for login, and the network environment information of the terminal device. Step S302: Construct a real-time user behavior feature vector according to Step S200, extract key features from the real-time captured operation requests and context information, construct a real-time feature vector and perform preprocessing; input the preprocessed real-time feature vector into the trained permission prediction model, and the model outputs the prediction probability P of whether the user will access high-frequency resources, and set a probability threshold f, where f ∈ (0, 1); if P >= f, query the user role access control list pre-set and stored in the database system, find the user's affiliated role according to the unique identifier of the user initiating the request, and the preset permission information granted to the role for the current requested resource, and initially judge whether the user's current operation conforms to the normal permission range of the user by comparing the preset permission information with the type of the current operation request. If the preset permission includes the current operation type, it is determined that the permission range is met, and the hierarchical permission control process is triggered; if P < f, process the user's operation request according to the default permission configuration of the database system, and allow the user to operate with regular permissions.
5. The database resource management method based on authority control according to claim 1 is characterized in that: The said Step S400 includes: Step S401: The database system pre-defines different user roles, including ordinary users, advanced users, and administrators; if it is predicted according to Step S300 that the user will access high-frequency resources and it is initially determined that the user has permissions, then trigger hierarchical permission control. Step S402: Real-time obtain the concurrent access quantity of data resources. When the concurrent access quantity of data resources is higher than the set concurrent quantity threshold, set the upper limit of the single access duration of ordinary users accessing high-frequency resources to y minutes; monitor the access time through a built-in timer. Once the time is exceeded, automatically terminate the access connection and pop up a prompt window for the user; the single access duration limit of advanced users accessing high-frequency resources is x minutes, and when the remaining access time is 0.2x minutes, an early warning pop-up window is sent to the user in advance to prompt the remaining access time; the database system records the long-time operation behavior of administrators. If the continuous access exceeds a hours, send an email warning to the monitoring personnel to prompt them to pay attention to whether the administrator's operation is abnormal; while performing hierarchical control on the user's access permissions, generate a detailed hierarchical permission control notice, and the notice content includes the user's current role, the concurrent access quantity of the current data resources, the access permissions granted to the user, and the validity period of the permission limit.
6. A database resource management system based on authority control, characterized in that: The said system includes a resource management module, a user behavior analysis module, a real-time permission determination module, and a hierarchical permission control module. The resource management module is used to collect database resource information and extract multi-dimensional features, classify database resources using a clustering algorithm, and build a resource category identification system; collect user access operation information from the database management system log and store it in the operation log data warehouse, and filter out high-frequency access resources through statistical analysis; The user behavior analysis module extracts user permission access related features from the operation log data warehouse, and builds a permission prediction model based on user behavior in combination with the extracted database resource features; The real-time permission determination module captures user operation requests in real time, combines context information, extracts and preprocesses real-time features related to permissions, and inputs them into the trained permission prediction model to predict whether the user will access high-frequency resources; at the same time, combined with the user role access control list set by the database system, it preliminarily determines whether the user's operation is within the user's normal permission range; If the hierarchical permission control module predicts that the user will access high-frequency resources and preliminarily determines that he has permission, it triggers hierarchical permission control, hierarchically controls user access rights according to the user role and current data resource usage, and sends a hierarchical permission control notification to the user accessing the high-frequency resources.
7. A database resource management system based on authority control according to claim 6, characterized in that: The resource management module includes a resource information collection unit and a high-frequency resource screening unit; the resource information collection unit is used to traverse the database and collect multidimensional metadata of various resources; at the same time, user access operation information is collected in the database management system and stored in the operation log data warehouse; the DBSCAN clustering algorithm is used to complete resource classification according to the Euclidean distance of the resource feature vector and construct a resource category identification system; the high-frequency resource screening unit screens out high-frequency access resources based on the designated initial statistical period, combined with the exponentially weighted moving average algorithm, and the comprehensive time window and attenuation factor.
8. A database resource management system based on authority control according to claim 6, characterized in that: The user behavior analysis module includes a behavior data collection unit and a permission model construction unit; the behavior data collection unit extracts permission-related features from the operation log data warehouse, integrates high-frequency resource-related features, constructs a user behavior feature vector, and performs missing value and outlier processing and normalization on the extracted features; The permission model construction unit divides the user behavior data and the database resource data into a training set and a test set in proportion, adopts a random forest algorithm, and inputs the processed feature vector to construct a dynamic permission prediction model.
9. A database resource management system based on authority control according to claim 6, characterized in that: The real-time permission determination module includes an operation behavior analysis unit and a permission determination execution unit; the operation behavior analysis unit captures user database operation requests in real time, analyzes operation instructions, extracts user operation and database resource information, and synchronously collects operation context information; The permission discrimination execution unit constructs and preprocesses the real-time feature vector according to the permission model construction module, inputs the trained model to predict the probability of the user accessing high-frequency resources and compares it with the threshold; Based on the probability comparison results and combined with the user role access control list, determine whether the operation permissions are compliant. If they are compliant, hierarchical permission control is triggered.
10. A database resource management system based on authority control according to claim 6, characterized in that: The hierarchical authority control module monitors the number of concurrent accesses to data resources in real time, limits the access time of each role according to different user roles and authority ranges, and provides hierarchical control prompts.
Citation Information
Patent Citations
Service processing method and device and computer equipment
CN113094611A
Flow control method, device and equipment and computer readable storage medium
CN113364697A
Financial data access authority management method and system
CN119046994A
Permission-based interface current limiting method and device, equipment and storage medium
CN119324898A
Flow control and load balancing method in network communication
CN119383095A
Cited By
Cloud security management system and method thereof
CN120528713A
Database management method and device based on multiple security mechanisms, equipment and medium
CN120632855A
Database management method and device based on multiple security mechanisms, equipment and medium
CN120632855B