Account dynamic monitoring management system based on data transmission protocol
By adopting an account dynamic monitoring and management system based on data transmission protocol in the Dameng database, the problems of difficulty in dynamic discovery of privileged accounts, lagging detection of abnormal behaviors and complex multi-node management are solved, real-time monitoring and dynamic response to the privileged accounts of Dameng database are realized, and security and management efficiency are improved.
Patent Information
- Application Number
- CN202510297894.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-03-13
AI Technical Summary
The problems of difficulty in dynamic discovery of privileged accounts in Dameng database, lagging detection of abnormal behaviors, and complex multi-node management.
The account dynamic monitoring and management system based on the data transmission protocol is adopted, including the protocol analysis module, the privileged account dynamic discovery module, the behavior abnormality detection module and the dynamic response module. By deeply analyzing the proprietary communication protocol of the Dameng database, the account behavior is identified in real time, the privileged account in dynamic discovery is discovered, and the behavior is analyzed using AI technology to automatically adopt security protection strategies.
Real-time monitoring and dynamic response to the privileged account of Dameng database is realized, timeliness and accuracy of abnormal behavior detection is improved, data leakage risk is reduced, and global privileged account unified discovery and management of distributed environments is supported.
Smart Images

Figure CN120151031A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of database security, and in particular, to an account dynamic monitoring and management system based on a data transmission protocol. Background Art
[0002] A database is a collection of various interrelated data compiled in a certain format and stored in a computer memory for users to quickly and effectively process data. It can be regarded as a collection of a large amount of data that is long-term stored in a computer, organized, shareable, and uniformly managed.
[0003] Currently, as a representative of domestic databases, DM databases are widely used in key industries such as finance, government, and energy. In the process of managing and using databases, it is necessary to ensure their security first. It is necessary to be able to monitor the activities of database accounts in a timely manner to detect unauthorized access or other potential security threats, identify and prevent potential data leakage risks. For organizations that need to comply with specific data protection regulations, monitoring database account activities helps to ensure compliance and achieve effective management and reliable use of databases.
[0004] However, due to its self-developed communication protocol, privilege management mechanism, and high-availability architecture, DM databases are significantly different from other mainstream databases. Currently, the privilege account management and security detection tools of existing general databases are difficult to effectively adapt to DM databases, resulting in problems such as difficult dynamic discovery of privilege accounts in DM databases, lag in abnormal behavior detection, and complex multi-node management. There is a need to provide a method for discovering privilege accounts and security inspection based on DM database protocol parsing and behavior modeling, which has the functions of supporting real-time monitoring, behavior risk assessment, and dynamic response. Summary of the Invention
[0005] In order to solve the problems of difficult dynamic discovery of privilege accounts in DM databases, lag in abnormal behavior detection, and complex multi-node management, the present application provides an account dynamic monitoring and management system based on a data transmission protocol, adopting the following technical solutions:
[0006] An account dynamic monitoring and management system based on a data transmission protocol, comprising:
[0007] A protocol parsing module for parsing a specified communication protocol of a specified database and extracting key information related to privilege accounts; the key information includes username, IP address, login time, and operation type;
[0008] A privilege account dynamic discovery module for dynamically discovering all the privilege accounts in the specified database; the privilege accounts include default accounts and user-defined high-privilege accounts;
[0009] The abnormal behavior detection module is used to analyze the behavior of the privileged account, construct the behavior baseline of the privileged account, and identify the risk operations of the privileged account;
[0010] The dynamic response module is used to provide targeted security protection strategies after detecting risk operations.
[0011] By adopting the above technical solutions, the present invention deeply analyzes the proprietary communication protocol of the DM database, extracts and analyzes the login authentication process of the privileged account in the DM protocol, real-time identifies the account behavior, dynamically discovers the changing privileged accounts, can use AI technology to analyze the behavior of the privileged account, and after detecting risk operations, combines with the security configuration items of the DM database to automatically adopt appropriate security protection strategies to reduce the threat impact.
[0012] Optionally, the process of parsing the specified communication protocol of the specified database and extracting the key information related to the privileged account includes:
[0013] Step S1, capturing the network communication traffic of the specified database;
[0014] Step S2, determining whether the network communication traffic conforms to the specified communication protocol specification. If so, enter Step S3; otherwise, enter Step S3X;
[0015] Step S3, parsing the authentication packets, command packets, and response packets of the network communication traffic and then extracting the key information related to the privileged account;
[0016] Step S3X, discarding the network communication traffic and then returning to Step S1;
[0017] Step S4, determining whether it is a new privileged account. If so, enter Step S5; otherwise, enter Step S6;
[0018] Step S5, storing the new privileged account and updating the feature library;
[0019] Step S6, sending the parsing result and extraction result of the network communication traffic to the privileged account dynamic discovery module.
[0020] By adopting the above technical solutions, the network communication traffic of the DM database is captured. The network communication traffic includes authentication packets, SQL command packets, and response packets in the TCP session. A dedicated decoder can be designed for specific fields in the DM protocol (such as user identity identifier, operation type identifier) to extract the login and operation information of the privileged account.
[0021] Optionally, the process of dynamically discovering all the privileged accounts in the specified database includes:
[0022] Step S7: Receive the parsing result and the extraction result, and match them with the feature library of the privileged account;
[0023] Step S8: Determine whether the privileged account exists; if so, proceed to Step S9, otherwise proceed to Step S9X;
[0024] Step S9: Identify whether the type of the privileged account belongs to the default account or the user-defined high-privilege account;
[0025] Step S9X: Ignore and record the normal operation behavior logs;
[0026] Step S10: Determine whether the permissions of the privileged account have changed; if so, proceed to Step S10X, otherwise proceed to Step S11;
[0027] Step S10X: Mark the permission change situation of the privileged account;
[0028] Step S11: Send the operation behavior logs related to the privileged account to the behavior anomaly detection module.
[0029] By adopting the above technical solutions, a DM privileged account feature library can be constructed, including default accounts (such as SYSDBA and SYSAUDITOR) and common high-privilege accounts. Utilizing the unique permission model and default account characteristics of DM, combined with the login and operation data captured by the protocol parsing module, and matching with the feature library, newly added, deleted, or permission-changed privileged accounts can be dynamically identified, making up for the deficiencies of general database security tools in specific permission management; in addition, it can also support the unified discovery of global privileged accounts in a distributed DM database environment, and generate a global privileged account view by integrating the logs and protocol data of multiple nodes.
[0030] Optionally, the process of analyzing the behavior of the privileged account, constructing the behavior baseline of the privileged account, and identifying the risky operations of the privileged account includes:
[0031] Construct a behavior baseline model based on the historical operation behavior logs of the privileged account;
[0032] Step S12: Receive the current operation behavior logs of the privileged account;
[0033] Step S13: Send the operation behavior logs to the behavior baseline model;
[0034] Step S14: Determine whether the current operation behavior logs meet the security requirements through the behavior baseline model; if they meet the requirements, record them as normal operations, otherwise proceed to Step S15;
[0035] Step S15: Process the current operation behavior log and send it to the risk assessment model for risk level assessment; the risk assessment model is obtained by training based on the historical operation behavior logs of privileged accounts.
[0036] Step S16: Send the risk level assessment data to the dynamic response module.
[0037] By adopting the above technical solution, a behavior baseline model constructed based on an unsupervised learning algorithm and a risk assessment model based on AI technology are used to double-monitor and verify the operation behavior of privileged accounts, completing a risk level assessment with a relatively high security level.
[0038] Optionally, the process of providing targeted security protection strategies after discovering a risk operation includes:
[0039] Step S17: Select corresponding response measures according to the results of the risk level assessment;
[0040] If it is a low risk, record the log and send an alarm notification;
[0041] If it is a medium risk, reduce the privileges of the privileged account;
[0042] If it is a high risk, freeze the privileged account and interrupt the current session;
[0043] Step S18: The distributed node synchronously responds and transmits the response instruction to other database nodes to ensure consistent global privilege adjustment;
[0044] Step S19: Generate a security report containing operation suggestions.
[0045] By adopting the above technical solution, after discovering a risk operation, it can deeply combine the security configuration items of the DM database (such as password policy, encrypted communication), automatically take appropriate protection measures, reduce the threat impact, provide targeted risk protection capabilities, and for the DM distributed environment, uniformly implement multi-node responses to ensure consistency.
[0046] Optionally, the risk assessment model includes a risk level identification model, and the training process of the risk level identification model includes:
[0047] Obtain the key information and historical operation behavior logs of the privileged account;
[0048] Convert the key information into a QR code picture in a specified format;
[0049] Extract the data within a complete login and logout cycle from the historical operation behavior logs, organize it in chronological order, and then convert each operation behavior into a corresponding pixel array and load it to the specified position in the QR code picture;
[0050] If there is a change in the permissions of the privileged account, a corresponding change marker pixel array is loaded between the pixel arrays at the corresponding timestamp positions.
[0051] After the QR code image is marked with a risk level, a training sample of the risk level recognition model is obtained.
[0052] After repeating the above loop at least 2 times, a training sample set of the risk level recognition model is obtained.
[0053] The risk level recognition model is trained and obtained according to the training sample set.
[0054] Optionally, the risk level recognition model further includes a risk level assessment model, and the process of risk level assessment includes:
[0055] Obtain the operation behavior and operation behavior log of the privileged account within a specified time length Δt.
[0056] Calculate the current risk valuation Hi during the i-th login / logout cycle of the privileged account.
[0057]
[0058] Among them, SLchi is the traffic occurrence value during the i-th successful login / logout cycle, is the average traffic occurrence value during the historical login / logout cycles, Tchi is the duration of the i-th successful login / logout cycle, is the average login cycle duration during the historical login / logout cycles, N DDLi is the number of DDL operations during the i-th successful login / logout cycle, N DMLi is the number of DML operations during the i-th successful login / logout cycle, ηi is the ratio of the number of operations during non-working hours to the total number of operations during the i-th successful login / logout cycle, li is the distance between the IP address of the i-th successful login and the commonly used IP address of the previous login, Ti is the timestamp of the IP address of the i-th successful login, Tss is the timestamp of the commonly used IP address of the previous login, Sth is a preset threshold, lsi is the distance between the IP address of the i-th successful login and the IP address of the previous login, and Tsi is the timestamp of the previous login for the i-th login;
[0059] Calculate the risk assessment value H(t) of the privileged account within the specified time length Δt.
[0060]
[0061] Among them, t is the current timestamp within the specified time length Δt, N is the number of multi-factor authentication failures, is the variance value of the multi-factor authentication failure time interval length sequence, and n is the number of complete login and logout cycles.
[0062] In summary, the present application includes at least one of the following beneficial technical effects:
[0063] 1. By deeply analyzing the proprietary communication protocol of the DM database, extracting and analyzing the login authentication process of privileged accounts in the DM protocol, identifying account behaviors in real time, dynamically discovering changing privileged accounts, the present invention can use AI technology to analyze the behaviors of privileged accounts. After detecting risky operations, combined with the security configuration items of the DM database, appropriate security protection strategies are automatically adopted to reduce the threat impact.
[0064] 2. The present invention can capture the network communication traffic of the DM database. The network communication traffic includes authentication packets, SQL command packets, and response packets in TCP sessions. A dedicated decoder can be designed for specific fields in the DM protocol (such as user identity identifiers, operation type identifiers) to extract the login and operation information of privileged accounts.
[0065] 3. The present invention uses a behavior baseline model constructed based on unsupervised learning algorithms, a risk level identification model based on AI technology, and a risk level assessment model to double-monitor and verify the operation behaviors of privileged accounts, and complete a risk level assessment with a relatively high security level. BRIEF DESCRIPTION OF THE DRAWINGS
[0066] Figure 1 is a schematic diagram of the architecture of the account dynamic monitoring and management system in the present invention.
[0067] Figure 2 is a schematic diagram of the working principle process of the protocol parsing module in the present invention;
[0068] Figure 3 is a schematic diagram of the working principle process of the privileged account dynamic discovery module in the present invention;
[0069] Figure 4 is a schematic diagram of the working principle process of the behavior anomaly detection module in the present invention;
[0070] Figure 5 is a schematic diagram of the working principle process of the dynamic response module in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0071] The following details the embodiments of the present application. The examples of the embodiments are shown in the drawings.
[0072] In the description of this specification, the descriptions referring to terms such as "certain embodiments", "one embodiment", "some embodiments", "schematic embodiments", "examples", "specific examples", or "some examples" mean that the specific features, structures, materials, or characteristics described in connection with the embodiments or examples are included in at least one embodiment or example of this application. In this specification, the schematic expressions of the above terms do not necessarily refer to the same embodiments or examples. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.
[0073] An embodiment of this application discloses an account dynamic monitoring and management system based on a data transmission protocol. Referring to Figure 1 , it includes:
[0074] A protocol parsing module, configured to parse a specified communication protocol of a specified database and extract key information related to privileged accounts; the key information includes username, IP address, login time, and operation type;
[0075] A privileged account dynamic discovery module, configured to dynamically discover all the privileged accounts in the specified database; the privileged accounts include default accounts and user-defined high-privilege accounts;
[0076] A behavior anomaly detection module, configured to analyze the behaviors of the privileged accounts, construct a behavior baseline of the privileged accounts, and identify risk operations of the privileged accounts;
[0077] A dynamic response module, configured to provide targeted security protection strategies after discovering risk operations.
[0078] In the present invention, by deeply parsing the proprietary communication protocol of the DM database, the login authentication process of privileged accounts in the DM protocol can be extracted, the account behaviors can be identified in real time, and the changing privileged accounts can be dynamically discovered. AI technology can be used to analyze the behaviors of privileged accounts. After discovering risk operations, combined with the security configuration items of the DM database, appropriate security protection strategies can be automatically adopted to reduce the threat impact.
[0079] Optionally, referring to Figure 2 , the process of parsing the specified communication protocol of the specified database and extracting key information related to privileged accounts includes:
[0080] Step S1, capturing the network communication traffic of the specified database;
[0081] Step S2, determining whether the network communication traffic conforms to the specified communication protocol specification. If so, proceed to step S3; otherwise, proceed to step S3X;
[0082] Step S3: After parsing the authentication packets, command packets, and response packets of the network communication traffic, extract the key information related to the privileged accounts.
[0083] Step S3X: Discard the network communication traffic and return to Step S1.
[0084] Step S4: Determine whether it is a new privileged account. If so, go to Step S5; otherwise, go to Step S6.
[0085] Step S5: Store the new privileged account and update the feature library.
[0086] Step S6: Send the parsing result and extraction result of the network communication traffic to the privileged account dynamic discovery module.
[0087] By adopting the above technical solution, capture the network communication traffic of the DM database. The network communication traffic includes authentication packets, SQL command packets, and response packets in TCP sessions. A dedicated decoder can be designed for specific fields in the DM protocol (such as user identity identifier, operation type identifier) to extract the login and operation information of privileged accounts.
[0088] Optionally, refer to Figure 3 , the process of dynamically discovering all the privileged accounts in the specified database includes:
[0089] Step S7: Receive the parsing result and the extraction result, and match them with the feature library of the privileged accounts.
[0090] Step S8: Determine whether the privileged account exists. If so, go to Step S9; otherwise, go to Step S9X.
[0091] Step S9: Identify whether the type of the privileged account belongs to the default account or the user-defined high-privilege account.
[0092] Step S9X: Ignore and record the ordinary operation behavior logs.
[0093] Step S10: Determine whether the privilege of the privileged account has changed. If so, go to Step S10X; otherwise, go to Step S11.
[0094] Step S10X: Mark the privilege change situation of the privileged account.
[0095] Step S11: Send the operation behavior logs related to the privileged account to the behavior anomaly detection module.
[0096] In this embodiment of the present invention, a DM privilege account feature library can be constructed, including default accounts (such as SYSDBA and SYSAUDITOR) and common high-privilege accounts. By leveraging the unique privilege model and default account characteristics of DM, combined with the login and operation data captured by the protocol parsing module, it is matched with the feature library to dynamically identify newly added, deleted, or privilege-changed privilege accounts, making up for the deficiencies of general database security tools in specific privilege management. Additionally, it can also support the unified discovery of global privilege accounts in a distributed DM database environment, generating a global privilege account view by integrating the logs and protocol data of multiple nodes.
[0097] Optionally, referring to Figure 4 , the process of analyzing the behavior of the privilege account, constructing the behavior baseline of the privilege account, and identifying the risk operations of the privilege account includes:
[0098] Construct a behavior baseline model based on the operation behavior logs of historical privilege accounts;
[0099] Step S12, receive the current operation behavior log of the privilege account;
[0100] Step S13, send the operation behavior log to the behavior baseline model;
[0101] Step S14, determine whether the current operation behavior log meets the security requirements through the behavior baseline model. If it meets the requirements, record it as a normal operation; otherwise, proceed to step S15;
[0102] Step S15, send the current operation behavior log to the risk assessment model after processing for risk level assessment; the risk assessment model is obtained through training based on the operation behavior logs of historical privilege accounts;
[0103] Step S16, send the risk level assessment data to the dynamic response module.
[0104] In this embodiment of the present invention, constructing the behavior baseline of the privilege account supports the following data dimensions:
[0105] A. Based on the operation characteristics of DM privilege accounts (such as common operation types of default accounts), construct a behavior baseline model, supporting the following data dimensions:
[0106] Operation time distribution (for example, the common operation time of SYSDBA is working hours);
[0107] Operation category distribution (such as DDL operations, DML operations, backup operations).
[0108] B. Use unsupervised learning algorithms (such as isolation forest, time series analysis) to identify the following high-risk behaviors:
[0109] Log in or operate during unauthorized time periods;
[0110] Mass data export or modification of sensitive table structures;
[0111] Login behavior of the abnormal source IP.
[0112] C. Combine the audit logs (SYSAUDITOR logs) of DM database to verify operation risks.
[0113] The privileged accounts screened by the behavior baseline model are double-monitored and verified by the risk assessment model, and a risk level assessment with a relatively high security level can be completed.
[0114] Optionally, the risk assessment model includes a risk level identification model, which can be trained based on a convolutional neural network (CNN, Convolutional Neural Network) and is mainly used in fields such as image recognition and image classification. Its design inspiration comes from the response of neurons in the biological visual system to visual stimuli, especially the concept of "receptive field". CNN extracts features in images through convolutional operations, reduces the dimension of the feature map through pooling operations, and finally performs classification or other tasks through fully connected layers.
[0115] The training process of the risk level identification model includes:
[0116] Obtain the key information and historical operation behavior logs of the privileged accounts;
[0117] Convert the key information into a QR code picture of a specified specification; for example, construct a description statement in the order of "username, IP address, login time, operation type" and convert it into a corresponding 50*50 QR code picture;
[0118] Extract the data within a complete login and logout cycle from the historical operation behavior log, organize it in chronological order, and then convert each operation behavior into a corresponding pixel array and load it into the specified position in the QR code image. The "behavior timestamp, specific behavior, and behavior content" can be converted in sequence. For example, the behavior timestamp - 20250101 is converted into a one-dimensional pixel matrix Q1 of "black, white, black, black, white, white, black, black" from left to right, the specific behavior - delete the object in area A is converted into a one-dimensional pixel matrix Q2 of "white, white, black, black, white, black, white, black, black, black, white, black" from left to right, and the behavior content - modify the object in area A is converted into a one-dimensional pixel matrix Q3 of "black, black, white, white, white, black, white, black, white, black, white, white, black" from left to right. Then, arrange Q1, Q2, and Q3 in sequence from left to right to obtain the pixel array 1Q. The docking position can be distinguished by pixels of other colors. And so on, arrange the obtained pixel arrays 1Q, 2Q... mQ in chronological order from top to bottom and load them directly below the QR code to complete the construction of the QR code image.
[0119] If there is a change in the permissions of the privileged account, load the corresponding change marker pixel array between the pixel arrays at the corresponding timestamp positions, such as the pixel arrangement combination representing permission upgrade and upgrade level.
[0120] After that, the QR code image can be marked with a risk level to obtain the training sample of the risk level recognition model.
[0121] Repeat the above loop at least 2 times to obtain the training sample set of the risk level recognition model.
[0122] Train and obtain the risk level recognition model according to the training sample set.
[0123] By adopting the above technical solution, the corresponding QR code image can be obtained as a detection sample during the actual operation process, and the preliminary evaluation result ACC can be obtained after inputting it into the risk level recognition model.
[0124] Optionally, the risk level recognition model further includes a risk level evaluation model. The process of risk level evaluation includes:
[0125] Obtain the operation behaviors and operation behavior logs of the privileged account within the specified time length Δt.
[0126] Calculate the current risk estimate Hi of the privileged account during the i-th login and logout cycle.
[0127]
[0128] Among them, SLchi is the traffic occurrence value during the i-th successful login and logout cycle. is the average traffic occurrence value within the historical login and logout cycles, and Tchi is the duration of the i-th successful login and logout cycle. is the average login cycle duration within the historical login and logout cycles, N DDLi is the number of DDL operations within the i-th successful login and logout cycle, N DMLi is the number of DML operations within the i-th successful login and logout cycle, ηi is the proportion of non-working time operations to the total number of operations within the i-th successful login and logout cycle, li is the distance between the IP address of the i-th successful login and the frequently used IP address of the previous login, Ti is the timestamp of the IP address of the i-th successful login, Tss is the timestamp of the frequently used IP address of the previous login, Sth is the preset threshold, lsi is the distance between the IP address of the i-th successful login and the IP address of the previous login, and Tsi is the timestamp of the previous login for the i-th login;
[0129] Calculate the risk assessment value H(t) of the privileged account within the specified time length Δt;
[0130]
[0131] where t is the current timestamp within the specified time length Δt, N is the number of multi-factor authentication failures, is the variance value of the multi-factor authentication failure time interval length sequence, and n is the number of complete login and logout cycles.
[0132] After the calculation, add the preliminary evaluation result ACC and the risk assessment value H(t) to obtain the final evaluation value of the risk operation corresponding to the privileged account, and compare the final evaluation value with the preset threshold to obtain the corresponding risk judgment result; the risk judgment results include low risk, medium risk, and high risk.
[0133] Optionally, referring to Figure 5 , the process of providing targeted security protection strategies after discovering risk operations includes:
[0134] Step S17, select corresponding response measures according to the results of the risk level assessment;
[0135] If it is low risk, record the log and send an alarm notification;
[0136] If it is medium risk, reduce the privileges of the privileged account;
[0137] If it is high risk, freeze the privileged account and interrupt the current session;
[0138] Step S18, the distributed node synchronously responds and transmits the response instruction to other database nodes to ensure consistent global privilege adjustment;
[0139] Step S19, generate a security report containing operation suggestions.
[0140] By adopting the above technical solution, after detecting a risky operation, it can deeply combine with the security configuration items of the DM database (such as password policies, encrypted communication), automatically take appropriate protection measures, reduce the threat impact, and provide targeted risk protection capabilities.
[0141] In addition, in a distributed DM database environment, when the system detects that the behavior of a privileged account on a node is abnormal, it automatically implements permission restrictions on other nodes, and at the same time generates a global risk report to uniformly implement multi-node responses to ensure consistency.
[0142] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present application. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present application.
Claims
1. An account dynamic monitoring and management system based on a data transmission protocol, characterized in that: include: The protocol parsing module is used to parse the specified communication protocol of the specified database and extract key information related to the privileged account; The key information includes user name, IP address, login time, and operation type; A privileged account dynamic discovery module, used to dynamically discover all privileged accounts in a specified database; the privileged accounts include default accounts and user-defined high-authority accounts; A behavior anomaly detection module, used to analyze the behavior of the privileged account, build a behavior baseline of the privileged account, and identify risky operations of the privileged account; The dynamic response module is used to provide targeted security protection strategies after risky operations are discovered.
2. The account dynamic monitoring and management system based on the data transmission protocol according to claim 1 is characterized in that: The process of parsing the specified communication protocol of the specified database and extracting key information related to the privileged account includes: Step S1, capturing the network communication traffic of a specified database; Step S2, determining whether the network communication flow complies with the specified communication protocol specification, if so, proceeding to step S3, otherwise proceeding to step S3X; Step S3, parsing the authentication packet, command packet and response packet of the network communication traffic to extract key information related to the privileged account; Step S3X, discarding the network communication traffic and returning to step S1; Step S4, determine whether it is a new privileged account, if so, proceed to step S5, otherwise proceed to step S6; Step S5, storing the new privileged account and updating the feature library; Step S6: Send the parsing result and extraction result of the network communication traffic to the privileged account dynamic discovery module.
3. The account dynamic monitoring and management system based on the data transmission protocol according to claim 1 is characterized in that: The process of dynamically discovering all the privileged accounts in the specified database includes: Step S7, receiving the parsing result and the extraction result, and matching them with the feature library of the privileged account; Step S8, determine whether the privileged account exists; if so, proceed to step S9, otherwise proceed to step S9X; Step S9, identifying whether the privileged account type is a default account or a user-defined high-authority account; Step S9X, ignoring and recording normal operation behavior logs; Step S10, determining whether the privileged account has any permission change, if so, proceeding to step S10X, otherwise proceeding to step S11; Step S10X, marking the permission changes of the privileged account; Step S11, sending the operation behavior log related to the privileged account to the behavior anomaly detection module.
4. The account dynamic monitoring and management system based on the data transmission protocol according to claim 1 is characterized in that: The process of analyzing the behavior of the privileged account, building a behavior baseline of the privileged account, and identifying risky operations of the privileged account includes: Build a behavior baseline model based on historical privileged account operation behavior logs; Step S12, receiving the current operation behavior log of the privileged account; Step S13, generating a behavior baseline model for the operation behavior log; Step S14, judging whether the current operation behavior log meets the security requirements through the behavior baseline model, if yes, it is recorded as normal operation, otherwise it goes to step S15; Step S15, sending the current operation behavior log to the risk assessment model after processing to perform risk level assessment; the risk assessment model is trained and acquired based on the operation behavior log of the historical privileged account; Step S16: sending the risk level assessment data to the dynamic response module.
5. The account dynamic monitoring and management system based on the data transmission protocol according to claim 1 is characterized in that: The process of providing targeted security protection strategies after discovering risky operations includes: Step S17, selecting corresponding response measures according to the result of the risk level assessment; If the risk is low, logs are recorded and an alert notification is sent; If the risk is medium, the privileged account's permissions are reduced; If the risk is high, freeze the privileged account and terminate the current session; Step S18, the distributed nodes synchronously respond and transmit the response instructions to other database nodes to ensure that the global authority adjustment is consistent; Step S19: Generate a safety report including operational suggestions.
6. The account dynamic monitoring and management system based on the data transmission protocol according to claim 4 is characterized in that: The risk assessment model includes a risk level identification model, and the training process of the risk level identification model includes: Obtaining the key information and historical operation behavior logs of the privileged account; Convert the key information into a QR code image of specified specifications; Extract data within a complete login and logout cycle from the historical operation behavior log, sort it in chronological order, and convert each operation behavior into a corresponding pixel array and load it into a specified position in the QR code image; If there is a permission change in the privileged account, a corresponding change mark pixel array is loaded between the pixel arrays at the corresponding timestamp position; After labeling the two-dimensional code image with risk level, a training sample of the risk level recognition model is obtained; After repeating the above cycle at least twice, a training sample set of the risk level identification model is obtained; The risk level identification model is obtained by training according to the training sample set.
7. The account dynamic monitoring and management system based on the data transmission protocol according to claim 6 is characterized in that: The risk level identification model also includes a risk level assessment model, and the risk level assessment process includes: Obtaining the operation behavior and operation behavior log of the privileged account within a specified time length Δt; Calculate the current risk valuation Hi of the privileged account during the i-th login and logout cycle; Among them, SLchi is the traffic value during the i-th successful login and logout cycle, is the average traffic value in the historical login and logout cycle, Tchi is the duration of the i-th successful login and logout cycle, is the average login cycle duration in the historical login and logout cycles, N DDLi N is the number of DDL operations in the i-th successful login and logout cycle, DMLi is the number of DML operations in the i-th successful login and logout cycle, ηi is the ratio of non-working time operations to the total number of operations in the i-th successful login and logout cycle, li is the distance between the i-th successful login IP address and the last login common IP address, Ti is the timestamp of the i-th successful login IP address, Tss is the timestamp of the last login common IP address, Sth is the preset threshold, lsi is the distance between the i-th successful login IP address and the last login IP address, and Tsi is the timestamp of the last login for the i-th login; Calculate the risk assessment value H(t) of the privileged account within a specified time length Δt; Wherein, t is the current timestamp within the specified time length Δt, N is the number of multi-factor authentication failures, is the variance of the length sequence of multi-factor authentication failure time intervals, and n is the number of complete login and logout cycles.
Citation Information
Patent Citations
Access control method and device, electronic equipment and medium
CN111935165A
Automatic approval method and system for secure access management
CN117056882A
Monitoring system and method for energy-saving equipment
CN117763294A
Privileged account management method and system
CN118898063A
Creation and verification of behavioral baselines for the detection of cybersecurity anomalies using machine learning techniques
WO2019220363A1
Cited By
Privileged account dynamic management and behavior risk identification blocking method based on AI
CN121547243A