An Account Dynamic Monitoring and Management System Based on Data Transmission Protocol

By using an account dynamic monitoring and management system based on data transmission protocols, the system can identify privileged account behavior in the DM database in real time, dynamically detect changes and automatically take protective measures. This solves the problems of the complexity of privileged account management and the lag in anomaly detection in the DM database, and achieves efficient security management.

CN120151031BActive Publication Date: 2025-10-31上海市大数据中心
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510297894.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-10-31
Estimated Expiration
2045-03-13

AI Technical Summary

Technical Problem

The existing general database's privileged account management and security detection tools are difficult to effectively adapt to the problems of dynamic discovery of privileged accounts, lagging detection of abnormal behavior, and complex multi-node management in the DM database.

Method used

The system employs a data transmission protocol-based account dynamic monitoring and management system, which includes a protocol parsing module, a privileged account dynamic discovery module, a behavior anomaly detection module, and a dynamic response module. By deeply analyzing the proprietary communication protocol of the Dameng database, it identifies account behavior in real time, dynamically discovers privileged accounts, and uses AI technology to analyze behavior, automatically adopting protection strategies in conjunction with security configuration items.

Benefits of technology

It enables real-time monitoring and dynamic response to privileged accounts in the DM database, improving the timeliness of abnormal behavior detection and the uniformity of multi-node management, and reducing the impact of threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151031B_ABST
    Figure CN120151031B_ABST
Patent Text Reader

Abstract

This application relates to the technical field of database security and discloses an account dynamic monitoring and management system based on a data transmission protocol. The system includes: a protocol parsing module, which parses a specified communication protocol of a specified database and extracts key information related to privileged accounts; a privileged account dynamic discovery module, which dynamically discovers all privileged accounts in a specified database; a behavior anomaly detection module, which analyzes the behavior of privileged accounts, constructs a behavioral baseline for privileged accounts, and identifies risky operations by privileged accounts; and a dynamic response module, which provides targeted security protection strategies after detecting risky operations. By parsing the specified communication protocol of a specified database, the system extracts and parses the login authentication process of privileged accounts within the communication protocol, identifies account behavior in real time, dynamically discovers changing privileged accounts, uses AI technology to analyze privileged account behavior, and automatically adopts appropriate security protection strategies based on the security configuration items of the specified database after detecting risky operations, thereby reducing the impact of threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of database security, and in particular to an account dynamic monitoring and management system based on a data transmission protocol. Background Technology

[0002] A database is a collection of interconnected data stored in computer memory, organized in a specific format, for users to process data quickly and efficiently. It can be viewed as a large, organized, shareable, and centrally managed collection of data stored permanently in a computer.

[0003] Currently, DM Database, as a representative of domestically produced databases, is widely used in key industries such as finance, government, and energy. In the process of managing and using the database, the primary requirement is to ensure its security. It is necessary to be able to monitor the activity of database accounts to promptly detect unauthorized access or other potential security threats, identify and prevent potential data leakage risks, and for organizations that need to comply with specific data protection regulations, monitoring database account activity helps to ensure compliance and achieve effective management and reliable use of the database.

[0004] Due to its self-developed communication protocol, permission management mechanism, and high-availability architecture, DM Database differs significantly from other mainstream databases. Currently, existing privileged account management and security detection tools for general databases are difficult to effectively adapt to DM Database, resulting in problems such as difficulty in dynamically discovering privileged accounts, lag in abnormal behavior detection, and complexity in multi-node management. Therefore, there is a need to provide a privileged account discovery and security check method based on DM Database protocol parsing and behavior modeling, which can support real-time monitoring, behavior risk assessment, and dynamic response. Summary of the Invention

[0005] To address the challenges of dynamic account monitoring and management in the DM database, including difficulties in discovering privileged accounts, delays in detecting abnormal behavior, and complex multi-node management, this application provides an account dynamic monitoring and management system based on a data transmission protocol, employing the following technical solution:

[0006] An account dynamic monitoring and management system based on a data transmission protocol includes:

[0007] The protocol parsing module is used to parse a specified communication protocol of a specified database and extract key information related to privileged accounts; the key information includes username, IP address, login time, and operation type.

[0008] The privileged account dynamic discovery module is used to dynamically discover all the privileged accounts in a specified database; the privileged accounts include default accounts and user-defined high-privilege accounts.

[0009] The abnormal behavior detection module is used to analyze the behavior of the privileged account, construct the behavior baseline of the privileged account, and identify the risky operations of the privileged account;

[0010] The dynamic response module is used to provide targeted security protection strategies after a risky operation is detected.

[0011] By adopting the above technical solution, this invention deeply analyzes the proprietary communication protocol of the DM database, extracts and analyzes the login authentication process of privileged accounts in the DM protocol, identifies account behavior in real time, dynamically discovers changing privileged accounts, and can use AI technology to analyze privileged account behavior. After discovering risky operations, it automatically adopts appropriate security protection strategies in combination with the security configuration items of the DM database to reduce the impact of threats.

[0012] Optionally, the process of parsing a specified communication protocol of a specified database and extracting key information related to privileged accounts includes:

[0013] Step S1: Capture network communication traffic for the specified database;

[0014] Step S2: Determine whether the network communication traffic conforms to the specified communication protocol specification. If yes, proceed to step S3; otherwise, proceed to step S3X.

[0015] Step S3: After parsing the authentication packet, command packet, and response packet of the network communication traffic, extract the key information related to the privileged account;

[0016] Step S3X: After discarding the network communication traffic, return to step S1;

[0017] Step S4: Determine if it is a new privileged account. If yes, proceed to step S5; otherwise, proceed to step S6.

[0018] Step S5: Store the new privileged account and update the feature database;

[0019] Step S6: Send the parsing and extraction results of the network communication traffic to the privileged account dynamic discovery module.

[0020] By adopting the above technical solution, the network communication traffic of the DM database can be captured. The network communication traffic includes authentication packets, SQL command packets and response packets in the TCP session. A dedicated decoder can be designed for specific fields in the DM protocol (such as user identity identifier and operation type identifier) ​​to extract the login and operation information of privileged accounts.

[0021] Optionally, the process of dynamically discovering all privileged accounts in the specified database includes:

[0022] Step S7: Receive the parsing result and the extraction result, and match them with the feature library of the privileged account;

[0023] Step S8: Determine if the privileged account exists; if yes, proceed to step S9; otherwise, proceed to step S9X.

[0024] Step S9: Identify whether the privileged account is a default account or a user-defined high-privilege account;

[0025] Step S9X: Ignore and record normal operation behavior logs;

[0026] Step S10: Determine whether the privileged account has undergone a change in permissions. If yes, proceed to step S10X; otherwise, proceed to step S11.

[0027] Step S10X: Mark the changes in permissions of the privileged account;

[0028] Step S11: Send the operation behavior logs related to the privileged account to the behavior anomaly detection module.

[0029] By adopting the above technical solution, a privileged account feature library for DM can be constructed, including default accounts (such as SYSDBA and SYSAUDITOR) and common high-privilege accounts. Utilizing DM's unique permission model and the characteristics of default accounts, combined with login and operation data captured by the protocol parsing module, the feature library is matched to dynamically identify newly added, deleted, or privileged accounts with changed permissions, thus compensating for the shortcomings of general database security tools in specific permission management. In addition, it can also support the unified discovery of global privileged accounts in a distributed DM database environment by integrating logs and protocol data from multiple nodes to generate a global privileged account view.

[0030] Optionally, the process of analyzing the behavior of the privileged account, constructing a behavioral baseline for the privileged account, and identifying risky operations of the privileged account includes:

[0031] A behavioral baseline model is constructed based on the historical operation logs of privileged accounts;

[0032] Step S12: Receive the current operation behavior log of the privileged account;

[0033] Step S13: Send the operation behavior log to the behavior baseline model;

[0034] Step S14: Determine whether the current operation behavior log meets the security requirements through the behavior baseline model. If it does, record it as a normal operation; otherwise, proceed to step S15.

[0035] Step S15: The current operation behavior log is processed and sent to the risk assessment model for risk level assessment; the risk assessment model is trained based on the historical operation behavior logs of privileged accounts.

[0036] Step S16: Send the risk level assessment data to the dynamic response module.

[0037] By adopting the above technical solution, a behavioral baseline model based on unsupervised learning algorithm and a risk assessment model based on AI technology are used to dual monitor and verify the operation behavior of privileged accounts, thereby completing a risk level assessment with a high level of security.

[0038] Optionally, the process of providing targeted security protection strategies after detecting risky operations includes:

[0039] Step S17: Select appropriate response measures based on the results of the risk level assessment;

[0040] If the risk is low, log the information and send an alert notification;

[0041] If the risk level is medium, then the privileges of the privileged account will be reduced.

[0042] If the risk is high, the privileged account will be frozen and the current session will be terminated;

[0043] Step S18: Distributed nodes synchronize responses and transmit response instructions to other database nodes to ensure consistent global permission adjustments;

[0044] Step S19: Generate a safety report containing operational recommendations.

[0045] By adopting the above technical solutions, after a risky operation is detected, appropriate protective measures can be automatically taken by deeply integrating the security configuration items of the DM database (such as password policies and encrypted communication), reducing the impact of threats, providing targeted risk protection capabilities, and implementing unified multi-node response for the DM distributed environment to ensure consistency.

[0046] Optionally, the risk assessment model includes a risk level identification model, and the training process of the risk level identification model includes:

[0047] Obtain the key information and historical operation logs of the privileged account;

[0048] The key information is converted into a QR code image of a specified size;

[0049] Extract data from the historical operation behavior logs for a complete login and logout cycle, organize the data in chronological order, and then convert each operation behavior into a corresponding pixel array and load it into a specified position in the QR code image.

[0050] If the privileged account has changed permissions, then a corresponding change marker pixel array is loaded between the pixel arrays at the corresponding timestamp positions;

[0051] After labeling the QR code image with risk levels, training samples for the risk level recognition model are obtained.

[0052] After repeating the above loop at least twice, the training sample set of the risk level identification model is obtained;

[0053] The risk level identification model is obtained by training the training sample set.

[0054] Optionally, the risk level identification model further includes a risk level assessment model, wherein the risk level assessment process includes:

[0055] Obtain the operation behavior and operation behavior log of the privileged account within a specified time length Δt;

[0056] Calculate the risk assessment Hi for the current instance within the i-th login / logout period of the privileged account;

[0057]

[0058] Wherein, SLchi represents the traffic generation value during the i-th successful login / logout cycle. Tchi represents the average traffic volume over historical login / logout cycles, where Tchi is the duration of the i-th successful login / logout cycle. N represents the average login cycle duration over historical login / logout periods. DDLi N represents the number of DDL operations performed during the i-th successful login / logout cycle. DMLi Let ηi be the number of DML operations within the i-th successful login / logout period, ηi be the percentage of non-working time operations within the i-th successful login / logout period, li be the distance between the i-th successful login IP address and the previously used login IP address, Ti be the timestamp of the i-th successful login IP address, Tss be the timestamp of the previously used login IP address, Sth be the preset threshold, lsi be the distance between the i-th successful login IP address and the previously logged-in IP address, and Tsi be the timestamp of the previously logged-in IP address for the i-th login.

[0059] Calculate the risk assessment value H(t) of the privileged account over a specified time period Δt;

[0060]

[0061] Where t is the current timestamp within the specified time length Δt, and N is the number of multi-factor authentication failures. is the variance of the sequence of time intervals between multi-factor authentication failures, where n is the number of complete login / logout cycles.

[0062] In summary, this application includes at least one of the following beneficial technical effects:

[0063] 1. This invention deeply analyzes the proprietary communication protocol of the DM database, extracts and analyzes the login authentication process of privileged accounts in the DM protocol, identifies account behavior in real time, dynamically discovers changing privileged accounts, and can use AI technology to analyze privileged account behavior. After discovering risky operations, it combines the security configuration items of the DM database to automatically take appropriate security protection strategies to reduce the impact of threats.

[0064] 2. This invention can capture the network communication traffic of the DM database, including authentication packets, SQL command packets, and response packets in TCP sessions. A dedicated decoder can be designed for specific fields in the DM protocol (such as user identity identifier and operation type identifier) ​​to extract the login and operation information of privileged accounts.

[0065] 3. This invention employs a behavioral baseline model built on an unsupervised learning algorithm, a risk level identification model based on AI technology, and a risk level assessment model to perform dual monitoring and verification of the operational behavior of privileged accounts, thereby completing a risk level assessment with a high level of security. Attached Figure Description

[0066] Figure 1 This is a schematic diagram of the account dynamic monitoring and management system in this invention.

[0067] Figure 2 This is a schematic diagram illustrating the working principle of the protocol parsing module in this invention;

[0068] Figure 3 This is a schematic diagram illustrating the working principle of the privileged account dynamic discovery module in this invention;

[0069] Figure 4 This is a schematic diagram illustrating the working principle of the abnormal behavior detection module in this invention;

[0070] Figure 5 This is a schematic diagram illustrating the working principle of the dynamic response module in this invention. Detailed Implementation

[0071] The embodiments of this application are described in detail below, and examples of the embodiments are shown in the accompanying drawings.

[0072] In the description of this specification, the references to "certain embodiments," "one embodiment," "some embodiments," "illustrative embodiment," "example," "specific example," or "some examples" refer to specific features, structures, materials, or characteristics described in connection with the described embodiment or example, which are included in at least one embodiment or example of this application. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0073] This application discloses an account dynamic monitoring and management system based on a data transmission protocol, referring to... Figure 1 ,include:

[0074] The protocol parsing module is used to parse a specified communication protocol of a specified database and extract key information related to privileged accounts; the key information includes username, IP address, login time, and operation type.

[0075] The privileged account dynamic discovery module is used to dynamically discover all the privileged accounts in a specified database; the privileged accounts include default accounts and user-defined high-privilege accounts.

[0076] The abnormal behavior detection module is used to analyze the behavior of the privileged account, construct the behavior baseline of the privileged account, and identify the risky operations of the privileged account;

[0077] The dynamic response module is used to provide targeted security protection strategies after a risky operation is detected.

[0078] In this invention, the proprietary communication protocol of the DM database can be deeply analyzed to extract and analyze the login authentication process of privileged accounts in the DM protocol, identify account behavior in real time, dynamically discover privileged accounts in change, and use AI technology to analyze privileged account behavior. After discovering risky operations, appropriate security protection strategies can be automatically adopted in combination with the security configuration items of the DM database to reduce the impact of threats.

[0079] Optionally, refer to Figure 2 The process of parsing a specified communication protocol in a specified database and extracting key information related to privileged accounts includes:

[0080] Step S1: Capture network communication traffic for the specified database;

[0081] Step S2: Determine whether the network communication traffic conforms to the specified communication protocol specification. If yes, proceed to step S3; otherwise, proceed to step S3X.

[0082] Step S3: After parsing the authentication packet, command packet, and response packet of the network communication traffic, extract the key information related to the privileged account;

[0083] Step S3X: After discarding the network communication traffic, return to step S1;

[0084] Step S4: Determine if it is a new privileged account. If yes, proceed to step S5; otherwise, proceed to step S6.

[0085] Step S5: Store the new privileged account and update the feature database;

[0086] Step S6: Send the parsing and extraction results of the network communication traffic to the privileged account dynamic discovery module.

[0087] By adopting the above technical solution, the network communication traffic of the DM database can be captured. The network communication traffic includes authentication packets, SQL command packets and response packets in the TCP session. A dedicated decoder can be designed for specific fields in the DM protocol (such as user identity identifier and operation type identifier) ​​to extract the login and operation information of privileged accounts.

[0088] Optionally, refer to Figure 3 The process of dynamically discovering all privileged accounts in the specified database includes:

[0089] Step S7: Receive the parsing result and the extraction result, and match them with the feature library of the privileged account;

[0090] Step S8: Determine if the privileged account exists; if yes, proceed to step S9; otherwise, proceed to step S9X.

[0091] Step S9: Identify whether the privileged account is a default account or a user-defined high-privilege account;

[0092] Step S9X: Ignore and record normal operation behavior logs;

[0093] Step S10: Determine whether the privileged account has undergone a change in permissions. If yes, proceed to step S10X; otherwise, proceed to step S11.

[0094] Step S10X: Mark the changes in permissions of the privileged account;

[0095] Step S11: Send the operation behavior logs related to the privileged account to the behavior anomaly detection module.

[0096] In this embodiment of the invention, a privileged account feature library for DM can be constructed, including default accounts (such as SYSDBA and SYSAUDITOR) and common high-privilege accounts. Utilizing DM's unique permission model and the characteristics of default accounts, combined with login and operation data captured by the protocol parsing module, the feature library is matched to dynamically identify newly added, deleted, or privileged accounts with changed permissions, thus compensating for the shortcomings of general database security tools in specific permission management. In addition, it can also support the unified discovery of global privileged accounts in a distributed DM database environment by integrating logs and protocol data from multiple nodes to generate a global privileged account view.

[0097] Optionally, refer to Figure 4 The process of analyzing the behavior of the privileged account, constructing a behavioral baseline for the privileged account, and identifying risky operations of the privileged account includes:

[0098] A behavioral baseline model is constructed based on the historical operation logs of privileged accounts;

[0099] Step S12: Receive the current operation behavior log of the privileged account;

[0100] Step S13: Send the operation behavior log to the behavior baseline model;

[0101] Step S14: Determine whether the current operation behavior log meets the security requirements through the behavior baseline model. If it does, record it as a normal operation; otherwise, proceed to step S15.

[0102] Step S15: The current operation behavior log is processed and sent to the risk assessment model for risk level assessment; the risk assessment model is trained based on the historical operation behavior logs of privileged accounts.

[0103] Step S16: Send the risk level assessment data to the dynamic response module.

[0104] In this embodiment of the invention, a behavioral baseline for privileged accounts is constructed, supporting the following data dimensions:

[0105] A. Based on the operational characteristics of DM privileged accounts (such as common operational types of default accounts), a behavioral baseline model is constructed, supporting the following data dimensions:

[0106] Operation time distribution (e.g., SYSDBA common operation time is working time);

[0107] Operation category distribution (e.g., DDL operations, DML operations, backup operations).

[0108] B. Use unsupervised learning algorithms (such as Isolation Forest, Time Series Analysis) to identify the following high-risk behaviors:

[0109] Login or operation during unauthorized periods;

[0110] Large-scale data export or sensitive table structure modification;

[0111] Login behavior from an unusual IP address.

[0112] C. Verify operational risks by combining the audit logs (SYSAUDITOR logs) of the DM database.

[0113] Privileged accounts selected through the behavioral baseline model are then subjected to dual monitoring and verification through a risk assessment model, which can achieve a higher level of security risk assessment.

[0114] Optionally, the risk assessment model includes a risk level identification model, which can be trained based on a convolutional neural network (CNN), primarily used in image recognition, image classification, and other fields. Its design is inspired by the response of neurons in the biological visual system to visual stimuli, particularly the concept of the "receptive field." CNNs extract features from images through convolutional operations and reduce the dimensionality of feature maps through pooling operations, finally using fully connected layers for classification or other tasks.

[0115] The training process for this risk level identification model includes:

[0116] Obtain the key information and historical operation logs of the privileged account;

[0117] The key information is converted into a QR code image of a specified size; for example, a description statement is constructed in the order of "username, IP address, login time, operation type" and converted into a corresponding 50*50 QR code image.

[0118] Data from a complete login / logout cycle is extracted from the historical operation logs, organized chronologically, and each operation is converted into a corresponding pixel array and loaded into a designated position in the QR code image. The "action timestamp, specific action, and action content" can be converted sequentially. For example, the action timestamp - 20250101 is converted into a one-dimensional pixel matrix Q1 from left to right ("black black black black black black white black black"), the specific action - deleting area A is converted into a one-dimensional pixel matrix Q2 from left to right ("white white black black black black black black black black black black black black black"), and the action content - modifying area A is converted into a one-dimensional pixel matrix Q3 from left to right ("black black black white white black black black black black black black black black black black black black"). Then, Q1, Q2, and Q3 are arranged and connected from left to right to obtain pixel array 1Q, with the connection points distinguished by pixels of other colors. This process is repeated, and the resulting pixel arrays 1Q, 2Q...mQ are arranged from top to bottom in chronological order and loaded directly below the QR code to complete the construction of the QR code image.

[0119] If the privileged account experiences a change in permissions, a corresponding change marker pixel array is loaded between the pixel arrays at the corresponding timestamp positions, such as a pixel arrangement combination representing permission upgrades and upgrade levels.

[0120] Afterwards, the QR code image can be labeled with risk level to obtain the training samples of the risk level recognition model;

[0121] After repeating the above loop at least twice, the training sample set of the risk level identification model is obtained;

[0122] The risk level identification model is obtained by training the training sample set.

[0123] By adopting the above technical solution, the corresponding QR code image can be obtained as a detection sample in the actual operation process, and after being input into the risk level identification model, the preliminary assessment result ACC can be obtained.

[0124] Optionally, the risk level identification model further includes a risk level assessment model, wherein the risk level assessment process includes:

[0125] Obtain the operation behavior and operation behavior log of the privileged account within a specified time length Δt;

[0126] Calculate the risk assessment Hi for the current instance within the i-th login / logout period of the privileged account;

[0127]

[0128] Wherein, SLchi represents the traffic generation value during the i-th successful login / logout cycle. Tchi represents the average traffic volume over historical login / logout cycles, where Tchi is the duration of the i-th successful login / logout cycle. N represents the average login cycle duration over historical login / logout periods. DDLi N represents the number of DDL operations performed during the i-th successful login / logout cycle. DMLi Let ηi be the number of DML operations within the i-th successful login / logout period, ηi be the percentage of non-working time operations within the i-th successful login / logout period, li be the distance between the i-th successful login IP address and the previously used login IP address, Ti be the timestamp of the i-th successful login IP address, Tss be the timestamp of the previously used login IP address, Sth be the preset threshold, lsi be the distance between the i-th successful login IP address and the previously logged-in IP address, and Tsi be the timestamp of the previously logged-in IP address for the i-th login.

[0129] Calculate the risk assessment value H(t) of the privileged account over a specified time period Δt;

[0130]

[0131] Where t is the current timestamp within the specified time length Δt, and N is the number of multi-factor authentication failures. is the variance of the sequence of time intervals between multi-factor authentication failures, where n is the number of complete login / logout cycles.

[0132] After the calculation is completed, the preliminary assessment result ACC is added to the risk assessment value H(t) to obtain the final assessment value of the risk operation corresponding to the privileged account. The final assessment value is compared with the preset threshold to obtain the corresponding risk judgment result. The risk judgment result includes low risk, medium risk and high risk.

[0133] Optionally, refer to Figure 5 The process of providing targeted security protection strategies after detecting risky operations includes:

[0134] Step S17: Select appropriate response measures based on the results of the risk level assessment;

[0135] If the risk is low, log the information and send an alert notification;

[0136] If the risk level is medium, then the privileges of the privileged account will be reduced.

[0137] If the risk is high, the privileged account will be frozen and the current session will be terminated;

[0138] Step S18: Distributed nodes synchronize responses and transmit response instructions to other database nodes to ensure consistent global permission adjustments;

[0139] Step S19: Generate a safety report containing operational recommendations.

[0140] By adopting the above technical solutions, after a risky operation is detected, appropriate protective measures can be automatically taken by deeply integrating the security configuration items of the DM database (such as password policies and encrypted communication), reducing the impact of threats and providing targeted risk protection capabilities.

[0141] In addition, in the distributed DM database environment, if the system detects abnormal behavior of a privileged account on one node, it will automatically impose permission restrictions on other nodes and generate a global risk report, and implement a unified multi-node response to ensure consistency.

[0142] Although embodiments of this application have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting this application. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of this application.

Claims

1. An account dynamic monitoring and management system based on a data transmission protocol, characterized in that, include: The protocol parsing module is used to parse a specified communication protocol for a specified database and extract key information related to privileged accounts; The key information includes username, IP address, login time, and operation type; The privileged account dynamic discovery module is used to dynamically discover all the privileged accounts in a specified database; the privileged accounts include default accounts and user-defined high-privilege accounts. The abnormal behavior detection module is used to analyze the behavior of the privileged account, construct the behavior baseline of the privileged account, and identify the risky operations of the privileged account; The dynamic response module is used to provide targeted security protection strategies after a risky operation is detected. The process of analyzing the behavior of the privileged account, constructing a behavioral baseline for the privileged account, and identifying risky operations of the privileged account includes: A behavioral baseline model is constructed based on the historical operation logs of privileged accounts; Step S12: Receive the current operation behavior log of the privileged account; Step S13: Send the operation behavior log to the behavior baseline model; Step S14: Determine whether the current operation behavior log meets the security requirements through the behavior baseline model. If it does, record it as a normal operation; otherwise, proceed to step S15. Step S15: The current operation behavior log is processed and sent to the risk assessment model for risk level assessment; the risk assessment model is trained based on the historical operation behavior logs of privileged accounts. Step S16: Send the risk level assessment data to the dynamic response module; The risk assessment model includes a risk level identification model, and the training process of the risk level identification model includes: Obtain the key information and historical operation logs of the privileged account; The key information is converted into a QR code image of a specified size; Extract data from the historical operation behavior logs for a complete login and logout cycle, organize the data in chronological order, and then convert each operation behavior into a corresponding pixel array and load it into a specified position in the QR code image. If the privileged account has changed permissions, then a corresponding change marker pixel array is loaded between the pixel arrays at the corresponding timestamp positions; After labeling the QR code image with risk levels, training samples for the risk level recognition model are obtained. After training the risk level identification model at least twice, a training sample set for the risk level identification model is obtained. The risk level identification model is obtained by training the training sample set.

2. The account dynamic monitoring and management system based on data transmission protocol according to claim 1, characterized in that, The process of parsing a specified communication protocol in a specified database and extracting key information related to privileged accounts includes: Step S1: Capture network communication traffic for the specified database; Step S2: Determine whether the network communication traffic conforms to the specified communication protocol specification. If yes, proceed to step S3; otherwise, proceed to step S3X. Step S3: After parsing the authentication packet, command packet, and response packet of the network communication traffic, extract the key information related to the privileged account; Step S3X: After discarding the network communication traffic, return to step S1; Step S4: Determine if it is a new privileged account. If yes, proceed to step S5; otherwise, proceed to step S6. Step S5: Store the new privileged account and update the feature database; Step S6: Send the parsing and extraction results of the network communication traffic to the privileged account dynamic discovery module.

3. The account dynamic monitoring and management system based on data transmission protocol according to claim 2, characterized in that, The process of dynamically discovering all privileged accounts in the specified database includes: Step S7: Receive the parsing result and the extraction result, and match them with the feature library of the privileged account; Step S8: Determine if the privileged account exists; if yes, proceed to step S9; otherwise, proceed to step S9X. Step S9: Identify whether the privileged account is a default account or a user-defined high-privilege account; Step S9X: Ignore and record normal operation behavior logs; Step S10: Determine whether the privileged account has undergone a change in permissions. If yes, proceed to step S10X; otherwise, proceed to step S11. Step S10X: Mark the changes in permissions of the privileged account; Step S11: Send the operation behavior logs related to the privileged account to the behavior anomaly detection module.

4. The account dynamic monitoring and management system based on data transmission protocol according to claim 1, characterized in that, The process of providing targeted security protection strategies after identifying risky operations includes: Step S17: Select appropriate response measures based on the results of the risk level assessment; If the risk is low, log the information and send an alert notification; If the risk level is medium, then the privileges of the privileged account will be reduced. If the risk is high, the privileged account will be frozen and the current session will be terminated; Step S18: Distributed nodes synchronize responses and transmit response instructions to other database nodes to ensure consistent global permission adjustments; Step S19: Generate a safety report containing operational recommendations.

5. The account dynamic monitoring and management system based on data transmission protocol according to claim 1, characterized in that, The risk level identification model also includes a risk level assessment model, the process of which includes: Obtain the privileged account for a specified time period. Internal operation behavior and operation behavior log; Calculate the risk assessment for the privileged account during its i-th login / logout cycle. ; ; in, This represents the traffic volume during the i-th successful login / logout period. This represents the average traffic volume over historical login / logout cycles. The duration of the i-th successful login / logout cycle. This represents the average login cycle duration over historical login / logout periods. This represents the number of DDL operations performed during the i-th successful login / logout cycle. This represents the number of DML operations performed during the i-th successful login / logout cycle. This represents the percentage of non-working-hour operations within the i-th successful login / logout period out of the total number of operations. Let be the distance between the IP address of the i-th successful login and the previously used IP address. Let i be the timestamp of the IP address of the i-th successful login. The timestamp of the last login from the frequently used IP address. For the preset threshold, Let be the distance between the IP address of the i-th successful login and the IP address of the last successful login. This is the timestamp of the previous login for the i-th login; Calculate the privileged account over a specified time period. Risk assessment value within ; ; Where t is the specified time length. The current timestamp within, The number of times multi-factor authentication failed. is the variance of the sequence of time intervals between multi-factor authentication failures, where n is the number of complete login / logout cycles.

Citation Information

Patent Citations

  • Access control method and device, electronic equipment and medium

    CN111935165A

  • Privileged account management method and system

    CN118898063A