Database security protection method and device, medium and product
By connecting access requests to a pre-built obfuscated database, storing fake user data, and recording operation history, the problem of low database security is solved, and confusion about illegal users and security protection of real databases is achieved.
Patent Information
- Application Number
- CN202510264926.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-06
- Publication Date
- 2025-06-06
AI Technical Summary
How to improve the security of the database and prevent illegal access and data breaches.
By detecting the access request of the database, it is determined whether it is illegal access. If so, connect the access request to the pre-built obfuscated database, and the obfuscated database stores fake user data. At the same time, the access log and operation history are recorded, and if the preset threshold is reached, the deletion permission is encrypted or disabled.
Effectively confuse illegal users and make them operate in obfuscated databases rather than real data, thereby reducing attacks on real databases and improving database security.
Smart Images

Figure CN120105481A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of database technology, and in particular to a database security protection method, equipment, medium and product. Background Art
[0002] As the most effective means of data management, database technology has become the core technology and important foundation of information infrastructure, and is widely used in various scenarios such as enterprise information management, e-shopping, financial services, medical care, and education. With the widespread application of databases, more and more important information will be stored in databases. In order to prevent the information stored in the database from being illegally obtained, database security protection is one of the essential tasks in the process of database use. How to improve the security of the database is a major issue in the development of database technology. Summary of the invention
[0003] An object of the present invention is to provide a database security protection method, device, medium and product that help improve the security of the database.
[0004] In particular, the present invention provides a database security protection method, comprising:
[0005] An access request to a real database is detected, where the real database is a database storing real user data;
[0006] Determine whether the access request is an illegal access. If so, connect the access request to a pre-built obfuscation database, where the obfuscation database is a database configured with fake user data.
[0007] Optionally, the obfuscated database is configured to synchronize the table definition of the real database according to a preset period, thereby generating a data table in the obfuscated database having the same table structure and table attributes as the real database, and the obfuscated database is configured to generate the fake user data in the generated data table.
[0008] Optionally, after the step of connecting the access request to a pre-built obfuscation database, the step further includes:
[0009] The accessed table of the obfuscated database is recorded.
[0010] Optionally, the step of recording the accessed table of the obfuscated database includes:
[0011] If it is detected that the number of accesses to a data table in the obfuscated database reaches a preset threshold;
[0012] Encrypting the table with the same name in the real database; or,
[0013] Output a warning prompt, the warning prompt including the table name and the number of accesses of the data table whose number of accesses reaches the preset threshold.
[0014] Optionally, after the step of connecting the access request to a pre-built obfuscation database, the step further includes:
[0015] An operation history for the obfuscated database is recorded, wherein the operation history includes insert, modify, and delete operations on a table.
[0016] Optionally, the step of recording the operation history for the obfuscated database includes:
[0017] If it is detected that the number of deletion operations on the obfuscated database reaches a set threshold;
[0018] Disable the delete permission for the real database.
[0019] Optionally, the step of determining whether the access request is an illegal access includes:
[0020] If it is detected that the number of password errors in the access request reaches a preset value, the access request is determined to be an illegal access; or,
[0021] If it is detected that the access request is an illegal user name and the number of attempts of the illegal user name from the same address reaches a set value, the access request is determined to be an illegal access.
[0022] According to another aspect of the present invention, a computer device is also provided, comprising a memory, a processor, and a computer executable program stored in the memory and running on the processor, and the processor can implement the database security protection method according to any one of the above items when executing the computer executable program.
[0023] According to another aspect of the present invention, there is further provided a computer-readable storage medium on which a computer executable program is stored. When the computer executable program is executed by a processor, the database security protection method according to any one of the above items is implemented.
[0024] According to another aspect of the present invention, a computer program product is provided, including a computer executable program, and when the computer executable program is executed by a processor, the database security protection method according to any one of the above items is implemented.
[0025] The database security protection method of the present invention determines whether the access request is an illegal access after detecting the access request to the real database. If the access request is an illegal access, the access request is connected to a pre-built obfuscated database, and the obfuscated database stores fake user data. Therefore, illegal users can also successfully connect to the obfuscated database and access and operate in the obfuscated database, that is, illegal users can also be displayed as successfully connected to the database, but the data they access and operate are not the data actually used by the legitimate users, so that the illegal users can be confused, thereby reducing the continuous attacks of the illegal users on the real database, which helps to improve the security of the real database storing the real user data.
[0026] Based on the following detailed description of specific embodiments of the present invention in conjunction with the accompanying drawings, those skilled in the art will become more aware of the above and other objects, advantages and features of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] Hereinafter, some specific embodiments of the present invention will be described in detail in an exemplary and non-limiting manner with reference to the accompanying drawings. The same reference numerals in the accompanying drawings indicate the same or similar components or parts. It should be understood by those skilled in the art that these drawings are not necessarily drawn to scale. In the accompanying drawings:
[0028] Figure 1 is a schematic flow chart of a database security protection method according to an embodiment of the present invention;
[0029] Figure 2 is a schematic flow chart of a database security protection method according to another embodiment of the present invention;
[0030] Figure 3 is a schematic flow chart of a database security protection method according to yet another embodiment of the present invention;
[0031] Figure 4 is a schematic block diagram of a database structure according to an embodiment of the present invention;
[0032] Figure 5 is a schematic diagram of a computer device according to an embodiment of the present invention;
[0033] Figure 6 is a schematic diagram of a computer-readable storage medium according to an embodiment of the present invention;
[0034] Figure 7 is a schematic diagram of a computer program product according to an embodiment of the present invention. DETAILED DESCRIPTION
[0035] It should be understood by those skilled in the art that the embodiments described below are only some embodiments of the present invention, rather than all embodiments of the present invention, and these embodiments are intended to explain the technical principles of the present invention, rather than to limit the protection scope of the present invention. Based on the embodiments provided by the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should still fall within the protection scope of the present invention.
[0036] It should be noted that the logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, device or equipment (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or equipment and execute instructions), or used in combination with these instruction execution systems, devices or equipment.
[0037] The flow chart provided by the present invention is not intended to indicate that the operation of the method will be performed in any particular order, or all operations of the method are included in all every case. In addition, the method may include additional operations. Within the scope of the technical thinking provided by the present embodiment method, additional changes can be made to the above method.
[0038] like Figure 1 As shown, in one embodiment, the database security protection method generally includes:
[0039] Step S101, detecting an access request to a real database. A real database is a database storing real user data, that is, a database storing user data actually used by a legitimate user. Detecting an access request to a real database means detecting a request to attempt to establish a connection with the database.
[0040] Step S102, determine whether the access request is an illegal access, if so, execute step S103, if not, execute step S104.
[0041] Specifically, that is, to detect whether the access request comes from an illegal user, in some embodiments, this step may include: if it is detected that the number of password errors in the access request reaches a preset value, the access request is determined to be an illegal access. Exemplarily, the preset value may be once, twice, etc.
[0042] In some embodiments, if it is detected that the access request is an illegal username and the number of attempts of the illegal username from the same address reaches a set value, the access request is determined to be an illegal access. Exemplarily, the set value can be two, three, etc.
[0043] Alternatively, after detecting that the access request is an illegal user name, it is directly determined to be an illegal access.
[0044] Step S103, connect the access request to a pre-built obfuscation database. The obfuscation database is a database configured with fake user data. Specifically, the data stored in the obfuscation database is not the real data used by legitimate users. Even if the data in the obfuscation database is obtained by an illegal user, the illegal user will not know the user data used by the legitimate user. Therefore, after detecting that the access request is an illegal access, regardless of whether the user name and password are correct, the access request will be connected to the obfuscation database, so that the illegal access can access and operate in the obfuscation database.
[0045] Furthermore, in one embodiment, the obfuscated database is configured to synchronize the table definition of the real database according to a preset period, thereby generating a data table in the obfuscated database having the same table structure and table attributes as the real database, and the obfuscated database is configured to generate fake user data in the generated data table.
[0046] Specifically, the obfuscated database has the same table names, column names, data types, primary keys, and other definition content required to create a data table as the real database, but the specific data in each table is different, that is, it stores fake user data.
[0047] Step S104, connecting the access request to the real database. After detecting that the access request is a legitimate access, the access request is connected to the real database.
[0048] In the solution of this embodiment, after detecting the access request to the real database, it is determined whether the access request is an illegal access. If the access request is an illegal access, the access request is connected to the pre-built obfuscated database, and the obfuscated database stores fake user data. Therefore, illegal users can also successfully connect to the obfuscated database and access and operate in the obfuscated database. In other words, illegal users can also be displayed as successfully connected to the database, but the data they access and operate are not the data actually used by legitimate users, so that illegal users can be confused, thereby reducing the continuous attacks of illegal users on the real database, which helps to improve the security of the real database storing real user data.
[0049] Furthermore, by configuring the obfuscated database to synchronize the table definition of the real database according to a preset period, a data table with the same table structure and table attributes as the real database is generated in the obfuscated database, and the obfuscated database is configured to generate false user data in the generated data table, so that the obfuscated database and the real database structure are more similar, and only the data in the table is different, which can achieve a better obfuscation effect and further improve the security of the real database.
[0050] like Figure 2 As shown, in one embodiment, the database security protection method generally includes:
[0051] Step S201: An access request to a real database is detected.
[0052] Step S202, determine whether the access request is an illegal access, if so, execute step S203, if not, execute step S207.
[0053] Step S203, connecting the access request to a pre-built obfuscation database.
[0054] Step S204, record the accessed table of the obfuscated database, specifically, record the table name of the data table accessed illegally in the obfuscated database.
[0055] Step S205, it is detected that the number of accesses to a data table in the obfuscated database reaches a preset threshold. Specifically, by recording the accessed tables of the obfuscated database, the number of accesses to each data table in the obfuscated database can be counted, so as to detect in real time whether the number of accesses to a certain data table in the obfuscated database by an illegal user reaches a preset threshold. Exemplarily, the preset threshold can be two, three, four or more times.
[0056] Step S206, encrypt the table with the same name in the real database. Specifically, when the number of times a certain data table in the obfuscated database is accessed by an illegal user reaches a preset threshold, the data table with the same table name in the real database is encrypted, for example, adding a desensitization rule, adding a mandatory access rule, etc. Because the obfuscated database synchronizes the table definition of the real database, the data table with the same name as the obfuscated database can be found in the real database.
[0057] Step S207: Connect the access request to the real database.
[0058] In the solution of this embodiment, by recording the accessed tables of the obfuscated database, the number of accesses of each data table in the obfuscated database can be obtained using the recorded information, that is, the degree of attention paid by illegal users to the data tables in the obfuscated database can be obtained. Because the obfuscated database and the real database have the same table definition, the degree of attention paid to the data table with the same table name in the real database can be obtained based on the degree of attention paid to the data table in the obfuscated database, so that corresponding response processing can be performed according to the degree of attention paid by illegal users to the data table.
[0059] Furthermore, after detecting that the number of accesses to a data table in the obfuscated database reaches a preset threshold, the table with the same name in the real database is encrypted. That is, based on the data table in the obfuscated database whose number of accesses reaches the preset threshold, the data table with the same table name in the real database is enhanced and encrypted, thereby improving the security of real user data that is highly concerned by illegal users.
[0060] It should be noted that, in some other embodiments, after detecting that the number of accesses to a data table in the obfuscated database reaches a preset threshold, an early warning prompt may also be output, and the early warning prompt includes the table name and the number of accesses of the data table whose number of accesses reaches the preset threshold, thereby prompting the database administrator, which helps the database administrator to promptly obtain the attention of illegal users to the data tables in the real database.
[0061] It should be noted that the steps with the same name in this embodiment refer to the above description.
[0062] like Figure 3 As shown, in one embodiment, the database security protection method generally includes:
[0063] Step S301: An access request to a real database is detected.
[0064] Step S302, determine whether the access request is an illegal access, if so, execute step S303, if not, execute step S307.
[0065] Step S303, connecting the access request to a pre-built obfuscation database.
[0066] Step S304, recording the operation history for the obfuscated database, where the operation history includes insert, modify and delete operations on the table.
[0067] Step S305: It is detected that the number of deletion operations on the obfuscated database reaches a set threshold. Specifically, by recording the operation history of the obfuscated database, the number of various operations performed by the illegal user on the obfuscated database can be learned, so that it can be detected whether the number of deletion operations reaches a set threshold, for example, the set threshold can be five times, ten times, twenty times, etc.
[0068] Step S306, prohibiting the deletion permission of the real database. Specifically, when the deletion operation of the obfuscated database reaches the set threshold, it means that the illegal user mainly wants to delete some data in the database. Therefore, by prohibiting the deletion permission of the real database, even if the illegal user invades the real database, it cannot delete, thereby improving the security of the real database.
[0069] Step S307: Connect the access request to the real database.
[0070] In the scheme of this embodiment, by recording the operation history of the obfuscated database, the recorded information can be used to obtain the number of times the illegal user performs various operations in the obfuscated database, that is, it can reflect how the illegal user mainly wants to tamper with the real database, so that corresponding response processing can be performed in the real database according to the operation history of the illegal user in the obfuscated database, thereby improving the security of the real database.
[0071] Furthermore, by prohibiting the deletion permission of the real database after detecting that the number of deletion operations on the obfuscated database reaches a set threshold, that is, revoking the deletion permission of the real database when the illegal user mainly wants to delete the data in the database, even if the illegal user breaks into the real database, the deletion cannot be achieved, thereby improving the security of the real database.
[0072] like Figure 4 FIG. 2 is a schematic diagram of a database structure of an embodiment, in which an obfuscated database 200 is pre-built outside the real database 100. The real database 100 stores real user data. The obfuscated database 200 periodically synchronizes the table definition of the real database 100 and fills the table with fake user data, so that the obfuscated database 200 has the same table structure as the real database 100, but the data in the table is different.
[0073] After detecting the user's access request, the legitimate user 300 is connected to the real database 100 so that the real user data can be accessed and operated. The illegal user 400 is connected to the obfuscated database 200 so that the user can get feedback that the connection is successful, but the data accessed and operated is fake user data. At the same time, the illegal operations of the illegal user 400 in the obfuscated database 200 are recorded, that is, the operations such as access and modification of the table, so that the illegal user 400 wants to tamper with the real database 200 according to the operation of the illegal user 400 in the obfuscated database 200, and the corresponding response processing is carried out in the real database 100, so as to improve the security of the real database 100 in a targeted manner.
[0074] This embodiment also provides a computer device and a computer-readable storage medium. Figure 5 is a schematic diagram of a computer device 10 according to one embodiment of the present invention. Figure 6 is a schematic diagram of a computer-readable storage medium 20 according to one embodiment of the present invention.
[0075] The computer device 10 may include a memory 110, a processor 120, and a computer executable program 11 stored in the memory 110 and running on the processor 120, and the processor 120 implements the database security protection method of any of the above embodiments when executing the computer executable program 11.
[0076] The computer-readable storage medium 20 stores a computer-executable program 11 thereon. When the computer-executable program 11 is executed by a processor, the database security protection method of any of the above-mentioned embodiments can be implemented.
[0077] This embodiment also provides a computer program product. Figure 7 1 is a schematic diagram of a computer program product 30 according to an embodiment of the present invention. The computer program product 30 includes a computer executable program 11, and when the computer executable program 11 is executed by a processor 120, any of the database security protection methods described above can be implemented.
[0078] Specifically, the computer executable program 11 for performing the operations of the present invention may be assembly instructions, instruction set architecture (ISA) instructions, computer instructions, computer-related instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages.
[0079] For the purpose of the description of the present embodiment, the computer-readable storage medium 20 can be any device that can contain, store, communicate, propagate or transmit a program for use with an instruction execution system, device or equipment or in conjunction with these instruction execution systems, devices or equipment. More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection portion (electronic device) with one or more wirings, a portable computer disk box (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and editable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable storage medium 20 can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpreting or processing in other suitable ways as necessary, and then stored in a computer memory.
[0080] It should be understood that each part of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system.
[0081] The computer device 10 may be, for example, a server, a desktop computer, a notebook computer, a tablet computer, or a smart phone. In some examples, the computer device 10 may be a cloud acquisition node. The computer device 10 may be described in the general context of computer system executable instructions (such as program modules) executed by a computer system. Typically, a program module may include routines, programs, object programs, components, logic, data structures, etc. that perform specific tasks or implement specific abstract data types. The computer device 10 may be implemented in a distributed cloud acquisition environment where remote processing devices linked via a communication network perform tasks. In a distributed cloud acquisition environment, program modules may be located on a local or remote acquisition system storage medium including a storage device.
[0082] The computer device 10 may include a processor 120 adapted to execute stored instructions, and a memory 110 that provides temporary storage space for the operation of the instructions during operation. The processor 120 may be a single-core processor, a multi-core processor, an acquisition cluster, or any number of other configurations. The memory 110 may include random access memory (RAM), read-only memory, flash memory, or any other suitable storage system.
[0083] The processor 120 may be connected to an I / O interface (input / output interface) suitable for connecting the computer device 10 to one or more I / O devices (input / output devices) via a system interconnect (e.g., PCI, PCI-Express, etc.). The I / O devices may include, for example, a keyboard and a pointing device, wherein the pointing device may include a touch pad or a touch screen, etc. The I / O devices may be built-in components of the computer device 10, or may be devices externally connected to an acquisition device.
[0084] Processor 120 can also be linked to a display interface suitable for connecting computer device 10 to a display device through a system interconnection. Display device can include a display screen as a built-in component of computer device 10. Display device can also include a computer monitor, a television or a projector, etc., which are externally connected to computer device 10. In addition, a network interface controller (NIC) can be suitable for connecting computer device 10 to a network through a system interconnection. In some embodiments, NIC can use any suitable interface or protocol (such as an Internet small computer system interface, etc.) to transmit data. The network can be a cellular network, a radio network, a wide area network (WAN), a local area network (LAN) or the Internet, etc. A remote device can be connected to a computer device through a network.
[0085] At this point, those skilled in the art should recognize that, although multiple exemplary embodiments of the present invention have been shown and described in detail herein, many other variations or modifications that conform to the principles of the present invention can still be directly determined or derived based on the content disclosed in the present invention without departing from the spirit and scope of the present invention. Therefore, the scope of the present invention should be understood and recognized as covering all these other variations or modifications.
Claims
1. A database security protection method, comprising: An access request to a real database is detected, where the real database is a database storing real user data; Determine whether the access request is an illegal access. If so, connect the access request to a pre-built obfuscation database, where the obfuscation database is a database configured with fake user data.
2. The database security protection method according to claim 1, wherein: The obfuscated database is configured to synchronize the table definition of the real database according to a preset period, thereby generating a data table in the obfuscated database having the same table structure and table attributes as the real database, and the obfuscated database is configured to generate the fake user data in the generated data table.
3. The database security protection method according to claim 2, wherein: The step of connecting the access request to a pre-built obfuscation database further includes: The accessed table of the obfuscated database is recorded.
4. The database security protection method according to claim 3, wherein: The step of recording the accessed table of the obfuscated database includes: If it is detected that the number of accesses to a data table in the obfuscated database reaches a preset threshold; Encrypting the table with the same name in the real database; or, Output a warning prompt, the warning prompt including the table name and the number of accesses of the data table whose number of accesses reaches the preset threshold.
5. The database security protection method according to claim 2, wherein: The step of connecting the access request to a pre-built obfuscation database further includes: An operation history for the obfuscated database is recorded, wherein the operation history includes insert, modify, and delete operations on a table.
6. The database security protection method according to claim 5, wherein: The step of recording the operation history for the obfuscated database includes: If it is detected that the number of deletion operations on the obfuscated database reaches a set threshold; Disable the delete permission for the real database.
7. The database security protection method according to claim 1, wherein: The step of determining whether the access request is an illegal access comprises: If it is detected that the number of password errors in the access request reaches a preset value, the access request is determined to be an illegal access; or, If it is detected that the access request is an illegal user name and the number of attempts of the illegal user name from the same address reaches a set value, the access request is determined to be an illegal access.
8. A computer device comprising a memory, a processor, and a computer executable program stored in the memory and running on the processor, wherein the processor implements the database security protection method according to any one of claims 1 to 7 when executing the computer executable program.
9. A computer-readable storage medium having a computer executable program stored thereon, wherein the computer executable program, when executed by a processor, implements the database security protection method according to any one of claims 1 to 7.
10. A computer program product, comprising a computer executable program, wherein when the computer executable program is executed by a processor, the database security protection method according to any one of claims 1 to 7 is implemented.