Database access authority intelligent control and security audit optimization method and system
Through timing analysis and dynamic association rules, combined with real-time monitoring of the fusion attention long short-term memory model, the problem of the inability to continuously verify the operator's identity in the existing technology is solved, and the security monitoring and permission adjustment of the database is realized to prevent data tampering and sensitive information leakage.
Patent Information
- Application Number
- CN202510262450.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-06-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, the authentication process only occurs in the initial stage of login, and the identity consistency during the operation cannot be continuously verified, resulting in data tampering and sensitive information leakage when the database is operated by others.
Through time-sequence analysis of operation records, the time points of frequent operations and key operations are extracted, dynamic association rules are established based on preset interval thresholds, the combination that complies with the rules is marked as a trigger operation sequence, and the fusion attention long short-term memory model is used for real-time monitoring to determine whether the current operation is the first sub-operation in the trigger operation sequence, thereby performing permission adjustment.
It realizes verification of the operator's identity before critical operations. Once suspicious or abnormal operations are found, permission degradation or session blocking can be triggered immediately, ensuring data security.
Smart Images

Figure CN120105385A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of database security, and in particular relates to a method for intelligently controlling database access rights and optimizing security audit, and a system for intelligently controlling database access rights and optimizing security audit. Background Art
[0002] As the core of data storage, the security of the database cannot be ignored. To achieve data security, it is necessary to adopt intelligent access control to ensure that only authorized users can access it, improve audit logs, record all operations, implement real-time monitoring and regular audits, promptly detect and respond to security threats, and optimize audit performance to ensure safe and efficient operation of the database.
[0003] In the field of user identity security of database systems, traditional technologies mainly ensure the legitimacy of operators through static identity authentication. However, the authentication process only occurs at the initial login stage, and it is generally impossible to continuously verify the identity consistency during the operation process, making it difficult to effectively identify the operator's identity. Once the database is operated by others, it is easy to cause major security risks such as data tampering and sensitive information leakage. Summary of the invention
[0004] The present application provides a method and system for intelligent control of database access rights and security audit optimization, which effectively solves the problem that in the prior art, the authentication link only occurs in the initial login stage, and generally cannot continuously verify the identity consistency during the operation process. Once the database is operated by others, it is easy to cause major security risks such as data tampering and sensitive information leakage. The application can verify the identity of the operator before key operations, and once suspicious or abnormal operations are found, it can immediately trigger permission downgrade or session blocking, thereby ensuring data security.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] In the first aspect, the present application provides a method for intelligent control of database access rights and security audit optimization, including: obtaining operation records in user database operation logs, identifying frequent operation sequences and pre-marked key operations in the operation records, and recording the start time of frequent operations, the start time and the end time of key operations; successively associating frequent operation sequences with time intervals within a preset interval threshold with key operations, and marking all frequent operations associated with key operations as trigger operation sequences; extracting each current operation of the user from the operation records, comparing the current operation with the trigger operation sequence, and determining whether to execute the monitoring operation step; in the process of executing the monitoring operation step, outputting the monitoring results, and adjusting permissions based on the monitoring results.
[0007] Furthermore, identifying frequent operation sequences and pre-marked key operations in operation records includes: sorting the operation records in chronological order of operation time, and dividing the sorted operation records into continuous operation sequences; for each operation sequence, generating all its subsequences; traversing the operation sequences of all users, and counting the number of times each subsequence appears in all operation sequences; setting a support threshold and a confidence threshold, screening out subsequences whose support is greater than or equal to the support threshold and whose confidence is greater than or equal to the confidence threshold, and marking the screened out subsequences as frequent operation sequences.
[0008] Furthermore, frequent operation sequences whose time intervals are within a preset interval threshold are associated with key operations in sequence, including: for each frequent operation sequence: traverse all key operations, use a time difference calculation function to calculate the time interval between the frequent operation sequence and each key operation, and associate the frequent operation sequences whose time intervals are within the preset interval threshold with the key operations in sequence; after each traversal is completed, check whether there are still key operations that have not been associated with the frequent operation sequence, and if so, increase the interval threshold by a specified value until all key operations are associated or the interval threshold reaches a preset maximum value or the maximum number of traversals is reached.
[0009] Furthermore, the step of comparing the current operation with the trigger operation sequence to determine whether to perform the monitoring operation includes: comparing the current operation with the trigger operation sequence to determine whether the current operation is the first sub-operation in the trigger operation sequence. If the current operation is the first sub-operation in the trigger operation sequence, the fused attention long short-term memory model is used to start monitoring the operation behavior on the database, and the monitoring result is output until the key operation associated with the trigger operation sequence is completed.
[0010] Furthermore, the fused attention long-short-term memory model is used to start monitoring the operation behavior on the database and output the monitoring results, including: extracting operation data from the operation record; organizing the operation data into a feature sequence in tensor form; using the trained fused attention long-short-term memory model to process the feature sequence and output the operation probability value of the person himself.
[0011] Furthermore, the operation data includes: a recent operation time interval sequence, an operation type conversion code sequence, and a periodic sequence of operation time.
[0012] Furthermore, when using a trained fused attention long short-term memory model to process the feature sequence, the fused attention long short-term memory model includes: an input layer, a feature fusion block, an LSTM layer, an attention mechanism layer and a fully connected classification layer; the input layer is used to receive the feature sequence; the feature fusion block is used to perform cross-dimensional weighted fusion of the feature sequence to generate a fused feature sequence; the LSTM layer is used to extract temporal dependencies from the fused feature sequence and output a hidden state sequence; the attention mechanism layer is used to dynamically assign feature weights to the hidden state sequence to generate attention weighted features; the fully connected classification layer is used to map the attention weighted features to the probability values of the user's own operation.
[0013] Furthermore, training the fused attention long short-term memory model includes: preprocessing the feature sequence and marking the real identity label corresponding to each feature sequence; dividing the preprocessed feature sequence into a data set including a training set, a validation set and a test set according to a preset ratio; constructing a fused attention long short-term memory model including an input layer, a feature fusion block, an LSTM layer, an attention block and a fully connected layer, and initializing it; using the data set to perform cyclic training on the fused attention long short-term memory model for a specified number of rounds, evaluating the model performance on the validation set after each training round, adjusting the hyperparameters according to the evaluated model set performance, and stopping the training until the preset stopping condition is met.
[0014] Furthermore, the permissions of the database are adjusted according to the monitoring results, including: setting a first threshold, a second threshold interval, and a third threshold; when the probability value of the personal operation is greater than the first threshold, it is determined to be an operation by the user himself, and full operation permissions are granted; when the probability value of the personal operation belongs to the second threshold, it is determined to be a suspicious operation, and a restricted access mode is triggered; when the probability value of the personal operation is less than the third threshold, it is determined to be an abnormal operation, and the current session is terminated immediately and the login is logged out.
[0015] In the second aspect, the present application provides a database access rights intelligent control and security audit optimization system, including: a log analysis module, a sequence association module, a real-time operation monitoring module and a response processing module.
[0016] The log analysis module is used to obtain operation records in the user database operation log, identify frequent operation sequences and pre-marked key operations in the operation records, and record the start time of frequent operations, the start time of key operations, and the end time; the sequence association module is used to associate the frequent operation sequences with time intervals within a preset interval threshold with the key operations in sequence, and mark all frequent operations associated with the key operations as trigger operation sequences; the real-time operation monitoring module is used to extract each current operation of the user from the operation record, compare the current operation with the trigger operation sequence, and determine whether to execute the monitoring operation steps; the response processing module is used to output the monitoring results in the process of executing the monitoring operation steps, and adjust the permissions according to the monitoring results.
[0017] In a third aspect, the present application provides a device comprising a memory and a processor; the memory is used to store a computer program; the processor is used to implement the steps of the database access rights intelligent control and security audit optimization method as described in the first aspect when executing the computer program.
[0018] In a fourth aspect, the present application provides a readable storage medium, which stores computer program instructions. When the computer program instructions are read and executed by a processor, the steps of the database access rights intelligent control and security audit optimization method as described in the first aspect are executed.
[0019] Beneficial effects of the present invention:
[0020] The present application analyzes operation records through time series, extracts the time points of frequent operations and key operations, establishes dynamic association rules based on preset interval thresholds, marks combinations that meet the rules as trigger operation sequences, and monitors user operations based on current operations and trigger operation sequences. This effectively solves the problem in the prior art that the authentication link only occurs in the initial login stage, and generally cannot continuously verify the identity consistency during the operation process. Once the database is operated by others, it is easy to cause major security risks such as data tampering and sensitive information leakage. The application can verify the identity of the operator before key operations, and once suspicious or abnormal operations are found, it can immediately trigger permission downgrade or session blocking, thereby ensuring data security.
[0021] Other features and advantages of the present invention will be described in the following description, and partly become obvious from the description, or be understood by implementing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures pointed out in the description and the drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0023] Figure 1 A schematic diagram of a process of intelligent control of database access rights and security audit optimization method in Embodiment 1 of the present invention is shown;
[0024] Figure 2 A module schematic diagram of a database access rights intelligent control and security audit optimization system in Embodiment 2 of the present invention is shown. DETAILED DESCRIPTION
[0025] In order to solve the problems raised by the background technology, the present application analyzes the operation records through time series, extracts the time points of frequent operations and key operations, establishes dynamic association rules based on preset interval thresholds, marks the combinations that meet the rules as trigger operation sequences, and monitors user operations according to the current operations and the trigger operation sequences.
[0026] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0027] Embodiment 1:
[0028] like Figure 1 As shown, this embodiment provides a method for intelligent control of database access rights and security audit optimization, including:
[0029] S100. Obtain operation records in the user database operation log, identify frequent operation sequences and pre-marked key operations in the operation records, and record the start time of the frequent operations, the start time and the end time of the key operations.
[0030] S200. Associating a frequent operation sequence whose time interval is within a preset interval threshold with a key operation in sequence, and marking all frequent operations associated with the key operation as a triggering operation sequence.
[0031] S300. Extract each current operation of the user from the operation record, compare the current operation with the trigger operation sequence, and determine whether to perform the monitoring operation step.
[0032] S400. During the process of executing the monitoring operation step, the monitoring result is output, and the authority is adjusted according to the monitoring result.
[0033] In S100, the operation log should record the time, operation type, operation object, and operation result of each operation in detail; for example, in an e-commerce system, it should include a series of operation records such as users browsing products, adding products to shopping carts, submitting orders, and paying. The collected operation log data is then preprocessed, including removing duplicate records, correcting erroneous data, and processing missing values.
[0034] Critical operations refer to specific operational behaviors that have a high impact on sensitive data in the database or system security, such as batch data export, permission changes, sensitive information processing, high-risk instruction execution, etc.
[0035] In S100, frequent operation sequences and pre-marked key operations in the operation record are identified, including:
[0036] S110. Sort the operation records according to the chronological order of the operations, and divide the sorted operation records into a continuous operation sequence.
[0037] S120. For each operation sequence, generate all its subsequences.
[0038] S130. Traverse the operation sequences of all users and count the number of times each subsequence appears in all operation sequences.
[0039] S140. Set a support threshold S and a confidence threshold C, filter out subsequences whose support is greater than or equal to the support threshold S and whose confidence is greater than or equal to the confidence threshold C, and mark the filtered subsequences as frequent operation sequences.
[0040] Sort the operation records in chronological order, and divide the sorted operation records into continuous operation sequences, each of which contains at least two operations; for example, the operation log of user A can be divided into operation sequences such as [query user mobile phone number, modify user address], [count sales this month, filter TOP10 best-selling products], etc.
[0041] For each operation sequence, generate all possible subsequences. For an operation sequence of length n, its subsequences include all consecutive subsequences of length 2 to n. For example, for the operation sequence [operation 1, operation 2, operation 3], the generated subsequences are [operation 1, operation 2], [operation 2, operation 3], and [operation 1, operation 2, operation 3].
[0042] Traverse the operation sequences of all users and count the number of times each subsequence appears in all operation sequences; for example, if the subsequence [query user mobile number, modify user address] appears 30 times in 100 operation sequences of the user, then its number of occurrences is 30; by counting the number of occurrences of each subsequence, quantify the frequency of occurrence of the subsequence in the overall operation data.
[0043] Set the support threshold S and confidence threshold C; the support represents the frequency of the subsequence in all operation sequences, that is, the ratio of the number of subsequence occurrences to the total number of operation sequences; the confidence is used to measure the probability of the next operation occurring after the previous operation in the subsequence occurs.
[0044] Filter out subsequences whose support is greater than or equal to the support threshold S and whose confidence is greater than or equal to the confidence threshold C, and mark the filtered subsequences as frequent operation sequences. For example, if the total number of operation sequences is 1000, the support threshold S is set to 0.05, the confidence threshold C is set to 0.8, the subsequence [query user mobile phone number, modify user address] appears 60 times, its support is 0.06, which is greater than 0.05, and its confidence is calculated to be greater than 0.8, then the subsequence is identified as a frequent operation sequence.
[0045] In S200, the frequent operation sequence with a time interval within a preset interval threshold is associated with the key operation in sequence, including:
[0046] S210. For each frequent operation sequence: traverse all key operations, use the time difference calculation function to calculate the time interval between the frequent operation sequence and each key operation, and associate the frequent operation sequence with a time interval within a preset interval threshold with the key operation.
[0047] S220. After each traversal is completed, check whether there are still key operations that are not associated with the frequent operation sequence. If so, increase the interval threshold by a specified value until all key operations are associated or the interval threshold reaches a preset maximum value or the maximum number of traversals is reached.
[0048] The core of the dynamic threshold iteration algorithm is to achieve accurate association between frequent operation sequences and key operations, which is to solve the problem of association omission or misjudgment caused by traditional fixed time windows. Specifically, first based on the preset initial interval threshold, each frequent operation sequence is traversed and the time interval difference between it and all key operations is calculated. If the difference falls within the threshold, an association is established. In this stage, short-interval association pairs with high confidence are captured first. Then, for the remaining key operations that are not associated, the system increases the threshold in a specified step size and rematches until full coverage association is met, the threshold upper limit or the maximum number of iterations is reached. By gradually relaxing the time constraints, it ensures that operation pairs with close timing dependence are prioritized within a reasonable time range, and avoids the loss of necessary associations due to reasonable scenarios such as business delays.
[0049] The dual constraints of the upper threshold limit and the number of iterations can improve the association coverage while preventing false associations caused by excessive relaxation of the threshold, thereby achieving a balance between risk detection accuracy and system computing load. It is suitable for database monitoring scenarios that need to take into account both real-time and complex business timing characteristics.
[0050] The trigger operation sequence can be stored in a specific table of the associated database, and the table structure includes fields such as the trigger operation sequence identifier, the operation sequence content, and the associated key operation identifier.
[0051] In S300, the step of comparing the current operation with the trigger operation sequence to determine whether to perform the monitoring operation includes:
[0052] S310. Compare the current operation with the trigger operation sequence to determine whether the current operation is the first sub-operation in the trigger operation sequence.
[0053] S320. If the current operation is the first sub-operation in the trigger operation sequence, the fused attention long short-term memory model is used to start monitoring the operation behavior on the database.
[0054] Through the mechanism of first operation matching trigger model monitoring, early identification and continuous tracking of potential risk operation links are achieved. When the user performs the current operation, the operation type, parameters and other features are quickly compared with the first sub-operation in the pre-stored trigger operation sequence library. If the features match, the current operation is determined to be the starting point of the risk link, and the real-time monitoring process of the fusion attention long-term and short-term memory model is triggered immediately. For example, when it is detected that the user abnormally accelerates the execution of key operations after triggering the first operation, the model will generate a risk level in real time and trigger permission intervention based on the time interval deviation and the abnormality of the operation sequence, which not only avoids the burden of real-time analysis of the full amount of operation logs, but also starts monitoring at the initial stage of the attack link, significantly improving detection efficiency and accuracy, and ensuring accurate interception of high-risk behaviors with a low false alarm rate.
[0055] In S400, during the process of executing the monitoring operation step, the monitoring result is output, including: using the fused attention long short-term memory model to start monitoring the operation behavior on the database and outputting the monitoring result until the key operation associated with the trigger operation sequence is completed.
[0056] Use the fused attention long short-term memory model to start monitoring the operation behavior of the database and output the monitoring results, including:
[0057] S410. Extracting operation data from the operation record, including a recent operation time interval sequence, an operation type conversion code sequence, and a periodic sequence of operation time.
[0058] S420. Arrange the operation data into a feature sequence in tensor form.
[0059] S430. Use the trained fusion attention long short-term memory model to process the feature sequence and output the operation probability value of the user.
[0060] In the code logic of database operations, when the user performs each database operation (such as insert, delete, update, query, etc.), add code before and after the operation to record the timestamp of the operation. You can use the time-related functions provided in the programming language to obtain the precise time. For example, use the time.time() function in Python to obtain the timestamp of the current time (in seconds), and use System.currentTimeMillis() in Java to obtain the millisecond timestamp of the current time. Store the timestamps of consecutive operations obtained, and then calculate the difference between the timestamps of two adjacent operations to obtain the time interval. Store the timestamps of consecutive operations obtained, and then calculate the difference between the timestamps of two adjacent operations to obtain the time interval. For example, there are three operation timestamps t 1 ,t 2 ,t 3 , then the time intervals are t int1 =t 2 -t 1 , t int2 =t 3 -t 2 ; Find the maximum value t in the time interval sequence max , divide each time interval value by t max Normalize and get the final time interval sequence T int .
[0061] Using normalized time interval sequences can more carefully capture the rhythmic habits of user operations. For example, different users have different operation interval rhythms during normal operations. Some users may be accustomed to rapid and continuous operations, while others may operate at longer intervals. Through this sequence feature, the model can learn each user's unique operation rhythm pattern, and can better identify and adapt to abnormal time interval changes caused by daily behaviors (such as drinking water, going to the toilet, etc.), which is different from the traditional method of simply judging the time range or frequency.
[0062] Mark the type of each operation and define a mapping relationship to map the operation type (such as insert, delete, update, query, etc.) to the corresponding code, such as 1 for insert, 2 for delete, 3 for update, 4 for query, etc. When the operation is executed, record the code of the operation type.
[0063] By calculating the difference between adjacent operation types, the operation type conversion pattern is highlighted. For example, some users may follow a specific operation type conversion logic in daily operations, such as querying first and then updating. When an abnormal operation type conversion occurs (such as suddenly inserting an uncommon operation type conversion), the model can identify the anomaly based on the learned normal conversion pattern. The type codes of consecutive operations are stored and the difference between adjacent operation type codes is calculated. For example, there are three operation type codes o 1 , o 2 , o 3 , then the conversion code differences are o trans1 =o 2 -o 1 , o trans1 =o 3 -o 2 , get the operation type conversion code sequence O trans .
[0064] On the basis of recording the operation timestamp, parse the timestamp to obtain the specific date and time information of the operation. You can use the date and time processing library in the programming language, such as the datetime module in Python, the java.time package in Java, etc. According to the obtained date and time information, calculate the day of the week the operation is (the value range is 1 to 7, 1 represents Monday, 7 represents Sunday) and the time period of the day the operation is in. It can be divided into 0-6 o'clock as 1, 6-12 o'clock as 2, 12-18 o'clock as 3, and 18-24 o'clock as 4.
[0065] The day of the week and time period information obtained from each operation is combined into a two-dimensional feature vector t peri =[t week ,t day ] and store them in the order of operation to form a periodic sequence T of user operation timeperi .
[0066] The operation time is broken down into time periods of the day and days of the week, and input into the model in the form of a two-dimensional feature vector sequence. This approach allows the model to learn the user's operating habits in different time periods. For example, some users may only perform database operations during the day on weekdays. When abnormal time period operations occur, such as operations during non-working hours or infrequent operation time periods, the model can make judgments based on the learned periodic patterns. Compared with existing technologies that do not consider time periodicity or simply divide time periods, it has stronger differentiation and recognition capabilities for abnormal operations.
[0067] For the recent operation time interval sequence T int =[t int1 ,t int2 ,…,t intn1 ], operation type conversion code sequence O trans =[o trans1 ,o trans2 ,…,o transn2 ], the periodic sequence of operation time T peri =[t peri1 ,t peri2 ,…,t perin3 ], and adjust the sequence length by appropriate interpolation or truncation methods so that the final length is n. For each operation position i (i = 1, 2, ..., n), the three features are combined to generate a new feature vector F i =[t inti ,o transi ,t weeki ,t dayi ], all feature sequences F i Combine them in order to form a new feature sequence F = [F 1 ,F 2 ,…,F n ], the new feature sequence integrates the information of operation time interval, operation type conversion and operation time periodicity, which can describe the user's operation behavior more comprehensively.
[0068] Arrange the feature sequence F into a tensor with the following dimensions: (batch size ,n,4); among them, batch size represents the number of data samples input into the model each time, n represents the length of the feature sequence, and 4 represents the dimension of each feature vector.
[0069] The feature sequence F is used as the input model of the fused attention long-short-term memory model and the output is a probability value P, which indicates the possibility that the current operation is the user's operation, and the value range is between 0 and 1.
[0070] The fused attention long short-term memory model is based on LSTM as a whole, and adds customized feature fusion blocks and attention blocks before and after the LSTM layer for optimization. The input feature sequence F is first processed by the feature fusion block, and then enters the LSTM layer to learn the long-term dependencies in the sequence. The LSTM layer output then passes through the attention block, and finally outputs the final probability value through the fully connected layer and activation function. Compared with the original model, the newly added custom blocks are designed to fuse the input features and allocate attention to the LSTM output features to better explore the relationship between features and highlight key information.
[0071] Specifically, the feature fusion block is located between the input layer and the LSTM layer, which effectively fuses the features of different dimensions in the feature sequence F and mines the potential relationship between them. The feature fusion block learns a set of weights W = [w 1 ,w 2 ,w 3 ,w 4 ], perform weighted summation on each feature dimension, and for each feature vector F at time step i i , the fused eigenvalue f i The calculation is as follows: i =w 1 ×t inti +w 2 ×o transi +w 3 ×t weeki +w 4 ×t dayi ;W represents the trainable parameter, which is adjusted continuously by the back propagation algorithm during the model training process so that the fused features can better reflect the user's operation mode and improve the model's ability to judge whether the user's operation is the user's own operation. After being processed by the feature fusion block, the output feature sequence dimension becomes: (batch size ,n,1), and input it into the subsequent LSTM layer.
[0072] The attention block is located after the LSTM layer and before the fully connected layer. The function of the attention block is to enable the model to pay more attention to the more important part of judging whether the operation is the person's operation when processing the feature sequence output by the LSTM layer. Suppose the feature sequence output by the LSTM layer is: H = [h 1 ,h 2 ,…,h n ], the dimensions are: (batch size ,n,hidden size ), where hidden size Represents the dimension of the LSTM hidden layer.
[0073] Map H to query Q, key K and value V respectively through linear transformation; Q = W Q H; K = W K H; V = W V ·H; where W Q , W K , W V Represents a trainable weight matrix; calculates the similarity score between the query Q and the key K, using the dot product method and scaling: The softmax operation is performed on the score to obtain the attention weight A, and then the value V is weighted and summed according to the attention weight to obtain the output O of the attention block. In this way, the model can automatically assign attention weights and highlight the features of key time steps, thereby better capturing important information related to user operations and improving the model's ability to recognize abnormal operations.
[0074] The feature sequence dimension of the attention block output is still (batch size ,n,hidden size ), and input it into the subsequent fully connected layer for the final classification prediction.
[0075] Assume the probability value predicted by the model is The true label is y, and the loss function L is defined as follows:
[0076]
[0077] The stochastic gradient descent algorithm can be used to update the parameters. In each iteration, a small batch of data is randomly selected from the training data set for calculation. The trainable parameters θ in the model include the weight W of the feature fusion block and the weight matrix W of the attention block. Q , W K , W V As well as the parameters of the LSTM layer and the fully connected layer, according to the gradient of the loss function L with respect to the parameter θ To update: Among them, α represents the learning rate, which controls the step size of each parameter update.
[0078] Training a fused attention long short-term memory model, including:
[0079] S431. Preprocess the feature sequence and mark the corresponding real identity label.
[0080] S432. Divide the preprocessed feature sequence into data sets including training set, validation set and test set according to a preset ratio; construct a fused attention long short-term memory model including an input layer, a feature fusion block, an LSTM layer, an attention block and a fully connected layer, and initialize it.
[0081] S433. Use the dataset to perform cyclic training on the fused attention long short-term memory model for a specified number of rounds.
[0082] S434. After each training round, the model performance is evaluated on the validation set, such as calculating indicators such as accuracy and recall, and hyperparameters such as learning rate are adjusted according to the evaluated model set performance until the preset stopping condition is met and the training is stopped.
[0083] The stopping conditions include: reaching the preset maximum number of training rounds, the fluctuation range of the verification set accuracy within a preset number of training rounds is less than the preset fluctuation threshold, and the decrease range of the training loss function value within a preset number of training rounds is less than the preset decrease threshold.
[0084] In the cyclic training of the fused attention long short-term memory model for specified rounds using the data set, for each training round, it includes: randomly extracting batch data of specified size from the training set; inputting the batch data into the fused attention long short-term memory model, forward propagating to calculate the predicted value; calculating the loss function value based on the predicted value and the true label; back propagating to calculate the gradient of the loss function with respect to the model parameters; and updating the model parameters according to the gradient descent algorithm.
[0085] After training is completed, the final performance of the model is evaluated on the test set to determine whether the model can accurately distinguish whether it is the user's own operation.
[0086] In S400, the permissions of the database are adjusted according to the monitoring result, including:
[0087] S440. Set a first threshold, a second threshold interval, and a third threshold.
[0088] S450. When the probability value P of the user's operation is greater than the first threshold, it is determined to be the user's own operation and full operation permissions are granted; when the probability value P of the user's operation is within the second threshold, it is determined to be a suspicious operation and the restricted access mode is triggered. When the probability value P of the user's operation is less than the third threshold, it is determined to be an abnormal operation, and the current session is terminated immediately and the user logs out.
[0089] Specifically, the first threshold may be 0.6, the second threshold interval may be [0.4, 0.6], and the third threshold may be 0.4.
[0090] Restricted access mode, for example, prohibits UPDATE, DELETE, and DROP operations on predefined key data tables.
[0091] After logging out, the user can log in again to re-operate the database, ensuring the security of the data.
[0092] Embodiment 2:
[0093] This embodiment provides a database access rights intelligent control and security audit optimization system, including: a log analysis module, a sequence association module, a real-time operation monitoring module and a response processing module.
[0094] The log analysis module is used to obtain operation records in the user database operation log, identify frequent operation sequences and pre-marked key operations in the operation records, and record the start time of frequent operations, the start time of key operations, and the end time; the sequence association module is used to associate the frequent operation sequences with time intervals within a preset interval threshold with the key operations in sequence, and mark all frequent operations associated with the key operations as trigger operation sequences; the real-time operation monitoring module is used to extract each current operation of the user from the operation record, compare the current operation with the trigger operation sequence, and determine whether to execute the monitoring operation steps; the response processing module is used to output the monitoring results in the process of executing the monitoring operation steps, and adjust the permissions according to the monitoring results.
[0095] This embodiment has all the advantages of the method for intelligent control of database access rights and security audit optimization in Embodiment 1, and can automatically implement all steps of the method for intelligent control of database access rights and security audit optimization.
[0096] Embodiment three:
[0097] This embodiment provides a device, which includes a memory and a processor; the memory is used to store a computer program; the processor is used to implement the steps of the database access rights intelligent control and security audit optimization method in Embodiment 1 when executing the computer program.
[0098] Embodiment 4:
[0099] This embodiment provides a readable storage medium, in which computer program instructions are stored. When the computer program instructions are read and executed by a processor, the steps of the method for intelligent control of database access rights and security audit optimization in Embodiment 1 are executed.
[0100] Among them, any reference to memory, storage, database or other media used in the embodiments provided by the present invention may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory.
[0101] It should be noted that, in this article, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
[0102] Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent substitutions for some of the technical features therein; and these modifications or substitutions do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for intelligent control of database access rights and security audit optimization, characterized in that: include: Obtain operation records in the user database operation log, identify frequent operation sequences and pre-marked key operations in the operation records, and record the start time of the frequent operations, the start time and the end time of the key operations; The frequent operation sequences with time intervals within a preset interval threshold are successively associated with the key operation, and all the frequent operations associated with the key operation are marked as triggering operation sequences; Extract each current operation of the user from the operation record, compare the current operation with the trigger operation sequence, and determine whether to execute the monitoring operation step; In the process of executing the steps of performing the monitoring operation, the monitoring results are output and the authority is adjusted according to the monitoring results.
2. The method for intelligent control of database access rights and security audit optimization according to claim 1 is characterized in that: Identify frequent operation sequences and pre-marked critical operations in operation logs, including: Sorting the operation records according to the chronological order of the operations, and dividing the sorted operation records into a continuous operation sequence; For each operation sequence, generate all its subsequences; Traverse the operation sequences of all users and count the number of times each subsequence appears in all operation sequences; The support threshold and the confidence threshold are set, and subsequences whose support is greater than or equal to the support threshold and whose confidence is greater than or equal to the confidence threshold are screened out, and the screened subsequences are marked as frequent operation sequences.
3. The method for intelligent control of database access rights and security audit optimization according to claim 1 is characterized in that: Frequent operation sequences with time intervals within a preset interval threshold are associated with key operations in sequence, including: For each frequent operation sequence: traverse all key operations, use the time difference calculation function to calculate the time interval between the frequent operation sequence and each key operation, and associate the frequent operation sequence with the key operation in sequence if the time interval is within the preset interval threshold; After each traversal is completed, check whether there are still key operations that are not associated with the frequent operation sequence. If so, increase the specified value for the interval threshold until all key operations are associated or the interval threshold reaches the preset maximum value or the maximum number of traversals is reached.
4. The method for intelligent control of database access rights and security audit optimization according to claim 1 is characterized in that: The step of comparing the current operation with the trigger operation sequence to determine whether to perform the monitoring operation includes: Compare the current operation with the trigger operation sequence to determine whether the current operation is the first sub-operation in the trigger operation sequence; If the current operation is the first sub-operation in the trigger operation sequence, the fused attention long short-term memory model is used to start monitoring the operation behavior on the database and output the monitoring results until the key operation associated with the trigger operation sequence is completed.
5. The method for intelligent control of database access rights and security audit optimization according to claim 4 is characterized in that: Use the fused attention long short-term memory model to start monitoring the operation behavior of the database and output the monitoring results, including: Extracting operation data from operation records; Arrange the operation data into a feature sequence in tensor form; The trained fusion attention long short-term memory model is used to process the feature sequence and output the operation probability value of the user.
6. The method for intelligent control of database access rights and security audit optimization according to claim 5 is characterized in that: The operation data includes: a recent operation time interval sequence, an operation type conversion code sequence, and a periodic sequence of operation time.
7. The method for intelligent control of database access rights and security audit optimization according to claim 5 is characterized in that: When the trained fused attention long short-term memory model is used to process the feature sequence, the fused attention long short-term memory model includes: Input layer, feature fusion block, LSTM layer, attention mechanism layer and fully connected classification layer; The input layer is used to receive a feature sequence; The feature fusion block is used to perform cross-dimensional weighted fusion on the feature sequence to generate a fused feature sequence; The LSTM layer is used to extract temporal dependencies from the fused feature sequence and output a hidden state sequence; The attention mechanism layer is used to dynamically assign feature weights to the hidden state sequence to generate attention weighted features; The fully connected classification layer is used to map the attention weighted features into the probability values of the user's operation.
8. The method for intelligent control of database access rights and security audit optimization according to claim 5 is characterized in that: Training a fused attention long short-term memory model, including: Preprocess the feature sequence and mark the real identity label corresponding to each feature sequence; Divide the preprocessed feature sequence into data sets including training set, validation set and test set according to the preset ratio; construct a fusion attention long short-term memory model including input layer, feature fusion block, LSTM layer, attention block and full connection layer, and initialize it; Use the dataset to perform a specified number of rounds of cyclic training on the fused attention long short-term memory model. After each round of training, evaluate the model performance on the validation set, adjust the hyperparameters based on the evaluated model set performance, and stop training when the preset stopping condition is met.
9. The method for intelligent control of database access rights and security audit optimization according to claim 5 is characterized in that: Adjust the permissions of the database based on the monitoring results, including: Setting a first threshold, a second threshold interval, and a third threshold; When the probability value of the personal operation is greater than the first threshold, it is determined that the operation is performed by the user himself, and full operation authority is granted; When the probability value of the operation performed by the user falls within the second threshold, the operation is determined to be suspicious and the restricted access mode is triggered; When the probability value of the user's operation is less than the third threshold, it is determined to be an abnormal operation, and the current session is terminated immediately and the user logs out.
10. A database access rights intelligent control and security audit optimization system, characterized in that: include: A log analysis module is used to obtain operation records in the user database operation log, identify frequent operation sequences and pre-marked key operations in the operation records, and record the start time of frequent operations, the start time and the end time of key operations; A sequence association module is used to associate a frequent operation sequence whose time interval is within a preset interval threshold with a key operation, and mark all frequent operations associated with the key operation as a triggering operation sequence; A real-time operation monitoring module is used to extract each current operation of the user from the operation record, compare the current operation with the trigger operation sequence, and determine whether to perform the monitoring operation step; The response processing module is used to output the monitoring results and adjust the permissions according to the monitoring results during the execution of the monitoring operation steps.