Authority hierarchical control method based on dynamic desensitization and real-time monitoring and operation and maintenance bastion host system
By introducing dynamic desensitization and real-time monitoring technologies into the operation and maintenance fortress, the problems of overloading permissions, insufficient static desensitization and lagging violation monitoring are solved, and more efficient data security management and rapid response capabilities are achieved.
Patent Information
- Application Number
- CN202510669834.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2045-05-23
AI Technical Summary
The existing operation and maintenance fortress machines have problems such as overloading of authority, insufficient flexibility in static desensitization and lag in monitoring of illegal operations.
The permission hierarchical control method based on dynamic desensitization and real-time monitoring is adopted, and SQL query requests are intercepted through the database firewall, and SQL statements are dynamically rewritten according to the permission level of the operation and maintenance role for differentiated desensitization, and operation logs are captured in real time, and operation semantic analysis and machine learning models are used for illegal operation detection.
It significantly improves data security and operation compliance in operation and maintenance scenarios, realizes dynamic desensitization, real-time monitoring and rapid response, reduces the risk of data leakage, and improves operation and maintenance efficiency.
Smart Images

Figure CN120197200A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of information security technology, and particularly to a method for hierarchical permission control based on dynamic desensitization and real-time monitoring and an operation and maintenance bastion host system. Background Art
[0002] An operation and maintenance bastion host is a core device in the field of information security, mainly used for centrally controlling the access behaviors of operation and maintenance personnel to key infrastructures such as databases and servers. Its core functions include permission management, access control, operation auditing, and session recording and playback, etc. Identity authentication and authorization are carried out for operation and maintenance operations through a unified entry to ensure that operations are traceable. Traditional operation and maintenance bastion hosts usually adopt a static permission allocation mechanism, that is, a fixed permission range is preset according to roles, and the compliance of operations is audited afterwards through log records. In addition, some systems support basic data desensitization functions, that is, sensitive fields (such as ID numbers, mobile phone numbers) are masked or replaced before data storage to reduce the risk of data leakage.
[0003] Although the existing operation and maintenance bastion hosts have improved operation and maintenance security to a certain extent, there are still the following significant problems:
[0004] 1) The permission control is extensive and prone to permission overload: Operation and maintenance personnel are often granted access permissions that exceed actual needs. For example, ordinary operation and maintenance roles can access sensitive data tables without restriction, increasing the risk of internal data abuse.
[0005] 2) The flexibility of static desensitization is insufficient: Traditional desensitization technologies only process static copies during the data storage stage and cannot dynamically adjust desensitization strategies according to real-time business scenarios (such as different user roles, query requirements). For example, when developers need to access test data, they still need to rely on the static desensitized copy of the production database, and it is difficult to achieve "desensitization on demand".
[0006] 3) The monitoring of illegal operations is lagging: Existing systems rely on manual audit logs or timed scanning rule matching and cannot intercept high-risk operations in real time (such as batch exporting data during non-working hours, abnormal high-frequency queries). Such lag makes it often possible to start security responses only after data leakage occurs, and it is difficult to achieve pre-event defense. Summary of the Invention
[0007] Therefore, the embodiments of the present invention provide a method for hierarchical permission control based on dynamic desensitization and real-time monitoring and an operation and maintenance bastion host system to solve the technical problems of permission overload, insufficient static desensitization, and lagging illegal operation monitoring in the prior art.
[0008] To achieve the above object, the embodiments of the present invention provide the following technical solutions:
[0009] According to a first aspect of an embodiment of the present invention, a method for hierarchical permission control based on dynamic desensitization and real-time monitoring is provided, the method being applied to a database firewall and comprising:
[0010] Obtain all operation and maintenance roles and classify the permissions of the operation and maintenance roles into three levels: primary, advanced, and special.
[0011] After detecting an SQL query request, intercept the SQL query request and obtain the current operation and maintenance role and the corresponding authority level, and use the authority level to dynamically rewrite the SQL statement to perform differential desensitization on sensitive fields. After desensitization, the production database returns the desensitization result to the operation and maintenance personnel terminal;
[0012] Capture operation logs in real time and use operational semantic analysis and machine learning models to detect illegal operations in real time, trigger blocking or alarms based on risk levels, and dynamically update the risk rule base.
[0013] Furthermore, the permissions are divided into three levels: primary, advanced and special, including:
[0014] Primary authority: only has the authority to perform static desensitization; Advanced authority: has the authority to perform dynamic desensitization and auditing; Special authority: has emergency temporary authority.
[0015] Furthermore, the static desensitization includes:
[0016] Pre-generate static desensitized copies and desensitized copy databases of high-risk data tables for direct access by low-privilege users;
[0017] The desensitized copy database is isolated from the production database, and reverse association with the original data is prohibited.
[0018] Furthermore, after detecting the SQL query request, the SQL query request is intercepted and the current operation and maintenance role and the corresponding authority level are obtained, and the SQL statement is dynamically rewritten using the authority level to perform differential desensitization on sensitive fields. After desensitization, the production database returns the desensitization result to the operation and maintenance personnel terminal, including:
[0019] The operation and maintenance personnel terminal initiates an SQL query request to the database firewall. After receiving the SQL query request, the database firewall detects the user authority through the rule engine, and the rule engine returns the desensitization rule to the database firewall;
[0020] After receiving the desensitization rule, the database firewall sends a request to the production database to execute the desensitization rule;
[0021] After the desensitization rules are executed, the desensitization results will be returned to the operation and maintenance personnel terminal.
[0022] Furthermore, the differentiated desensitization is to replace sensitive fields in SQL queries with masks or hash values according to user roles.
[0023] Furthermore, the operational semantic analysis includes:
[0024] Analyze the operation type, execution time and data volume of SQL statements;
[0025] Identify batch exports and high-frequency sensitive field query behaviors during non-working hours.
[0026] Furthermore, the operation logs are captured in real time and the illegal operations are detected in real time using operation semantic analysis and machine learning models. Blocking or alarming is triggered according to the risk level and the risk rule base is dynamically updated, including:
[0027] Capture operation logs and perform rule matching on current operation logs to determine whether the current operation logs match preset rules;
[0028] If the preset rules are matched, an alarm is triggered and blocking is performed;
[0029] If the preset rules are not matched, the machine learning model is used for analysis to obtain an anomaly score and determine whether the anomaly score is greater than a preset threshold;
[0030] If it is greater than the preset threshold, a new rule is dynamically added and the current operation is blocked; if it is a normal operation, it is released.
[0031] Furthermore, the machine learning model is an Attention-GRU-Adaboost model, which introduces the attention mechanism into the GRU network and integrates the Attention-GRU model through the Adaboost algorithm.
[0032] According to a second aspect of an embodiment of the present invention, an operation and maintenance bastion host system based on dynamic desensitization and real-time monitoring is provided, the system consisting of an operation and maintenance bastion host, a database firewall and a rule engine, specifically including:
[0033] The operation and maintenance bastion machine is used to obtain all operation and maintenance roles and classify the permissions of the operation and maintenance roles. The permissions are classified into three levels: primary, advanced, and special.
[0034] The database firewall is used to intercept the SQL query request after detecting it and obtain the current operation and maintenance role and the corresponding authority level;
[0035] The rule engine is used to dynamically rewrite SQL statements using the permission levels to perform differentiated desensitization on sensitive fields. After desensitization, the production database returns the desensitization results to the operation and maintenance personnel terminal.
[0036] Furthermore, the system also includes an audit module, which is used to perform the following steps:
[0037] Capture operation logs in real time and use operational semantic analysis and machine learning models to detect illegal operations in real time, trigger blocking or alarms based on risk levels, and dynamically update the risk rule base.
[0038] The embodiments of the present invention have the following advantages:
[0039] The embodiment of the present invention integrates a database firewall and a dual-mode desensitization engine, combines permission hierarchical control and real-time semantic analysis, and significantly improves data security and operational compliance in operation and maintenance scenarios. Dynamic desensitization rewrites query statements in real time according to user roles to limit exposure of original data; static desensitization pre-generates isolated copies to reduce direct access to production libraries; based on semantic analysis and rule engines, the response time is shortened to within 1 second to achieve "pre-emptive defense"; the static desensitization library supports direct use in development and testing, reducing the permission application process; the rule library is dynamically updated through the Attention-GRU-Adaboost model to improve adaptability to new attack modes. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] In order to more clearly illustrate the implementation methods of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the implementation methods or the description of the prior art. Obviously, the drawings in the following description are only exemplary, and for ordinary technicians in this field, other implementation drawings can be derived from the provided drawings without creative work.
[0041] The structures, proportions, sizes, etc. illustrated in this specification are only used to match the contents disclosed in the specification so as to facilitate understanding and reading by persons familiar with the technology. They are not used to limit the conditions under which the present invention can be implemented, and therefore have no substantial technical significance. Any structural modification, change in proportion or adjustment of size shall still fall within the scope of the technical contents disclosed in the present invention without affecting the effects and purposes that can be achieved by the present invention.
[0042] Figure 1 A schematic diagram of the logical structure of an operation and maintenance bastion host system based on dynamic desensitization and real-time monitoring provided by an embodiment of the present invention;
[0043] Figure 2 A flowchart of a permission hierarchical control method based on dynamic desensitization and real-time monitoring provided by an embodiment of the present invention;
[0044] Figure 3 A schematic diagram of a dynamic desensitization process in a permission hierarchical control method based on dynamic desensitization and real-time monitoring provided in an embodiment of the present invention;
[0045] Figure 4 It is a schematic diagram of the violation detection process in a permission hierarchical control method based on dynamic desensitization and real-time monitoring provided by an embodiment of the present invention;
[0046] Figure 5 It is a schematic diagram of related components of an operation and maintenance bastion host system based on dynamic desensitization and real-time monitoring provided by an embodiment of the present invention. Detailed implementation manners
[0047] The following specific embodiments illustrate the implementation manners of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0048] An operation and maintenance bastion host (Operation Bastion Host) is a core device in the field of information security, mainly used for centrally controlling and managing the access behaviors of operation and maintenance personnel to key infrastructure such as databases and servers. Its core functions include permission management, access control, operation auditing, and session recording and playback, etc. Identity authentication and authorization are performed on operation and maintenance operations through a unified entry to ensure that operations are traceable. Traditional operation and maintenance bastion hosts usually adopt a static permission allocation mechanism, that is, a fixed permission range is preset according to roles, and the compliance of operations is audited afterwards through log records. In addition, some systems support basic data desensitization functions, that is, sensitive fields (such as ID numbers, mobile phone numbers) are masked or replaced before data storage to reduce the risk of data leakage.
[0049] Although the existing operation and maintenance bastion hosts have improved operation and maintenance security to a certain extent, there are still the following significant problems:
[0050] 1) The permission control is extensive and prone to permission overload: Operation and maintenance personnel are often granted access permissions that exceed actual needs. For example, ordinary operation and maintenance roles can access sensitive data tables without restriction, increasing the risk of internal data abuse.
[0051] 2) The flexibility of static desensitization is insufficient: Traditional desensitization technologies only process static copies during the data storage stage and cannot dynamically adjust the desensitization strategy according to real-time business scenarios (such as different user roles, query requirements). For example, when developers need to access test data, they still need to rely on the static desensitized copy of the production database, and it is difficult to achieve "desensitization on demand".
[0052] 3) Lag in detecting illegal operations: Existing systems rely on manual auditing of logs or timed scanning for rule matching and cannot intercept high-risk operations in real time (such as batch data exports outside working hours, abnormal high-frequency queries). Such lag makes it difficult to initiate security responses until after a data breach occurs, making it hard to achieve pre-event defense.
[0053] To solve the above technical problems of easy occurrence of permission overload, insufficient static data masking, and lag in illegal operation monitoring in the prior art.
[0054] Refer to Figure 1 , an embodiment of the present invention discloses an operation and maintenance bastion host system based on dynamic data masking and real-time monitoring. The system consists of an operation and maintenance bastion host, a database firewall, and a rule engine, and specifically includes: The operation and maintenance bastion host is used to obtain all operation and maintenance roles and classify the permissions of the operation and maintenance roles. The permission classification is divided into three levels: primary, advanced, and special-level permissions; The database firewall is used to intercept the SQL query request and obtain the current operation and maintenance role and the corresponding permission level after detecting the SQL query request; The rule engine is used to dynamically rewrite the SQL statement using the permission level to perform differential data masking on sensitive fields, and the production database after data masking returns the data masking result to the operation and maintenance personnel terminal.
[0055] Furthermore, the system further includes an audit module for performing the following steps: capturing operation logs in real time and using operation semantic analysis and machine learning models to detect illegal operations in real time, triggering blocking or alarms according to the risk level, and dynamically updating the risk rule library.
[0056] In the embodiment of the present invention, taking Figure 5 as an example, the operation and maintenance bastion host establishes communication with the database firewall, and the database firewall controls the data masking processing module, the dynamic access control unit, the real-time monitoring module, and the audit tracking module respectively.
[0057] Among them, the data masking processing module and the dynamic access control unit are used to protect sensitive data in the sensitive database and implement a dual-mode data masking engine.
[0058] The real-time monitoring module monitors the operations of users in real time through an AI anomaly detection model and discovers illegal behaviors in real time through the audit tracking module and the audit log library.
[0059] Corresponding to the above-disclosed operation and maintenance bastion host system based on dynamic data masking and real-time monitoring, an embodiment of the present invention also discloses a permission classification control method based on dynamic data masking and real-time monitoring. The following details the permission classification control method based on dynamic data masking and real-time monitoring disclosed in the embodiment of the present invention in combination with the above-described operation and maintenance bastion host system based on dynamic data masking and real-time monitoring.
[0060] Refer to Figure 2The present invention discloses a permission hierarchical control method based on dynamic desensitization and real-time monitoring. The method is applied to a database firewall, and comprises: obtaining all operation and maintenance roles and grading the permissions of the operation and maintenance roles, wherein the permission grading is divided into three levels: primary, advanced and special permissions; after detecting an SQL query request, intercepting the SQL query request and obtaining the current operation and maintenance role and the corresponding permission level, dynamically rewriting the SQL statement using the permission level to perform differentiated desensitization on sensitive fields, and after desensitization, the production database returns the desensitization result to the operation and maintenance personnel terminal; capturing operation logs in real time and using operation semantic analysis and machine learning models to perform real-time detection of illegal operations, triggering blocking or alarming according to the risk level and dynamically updating the risk rule library.
[0061] Furthermore, the authority classification is divided into three levels: primary, advanced and special, including: primary authority: only has the authority to perform static desensitization, advanced authority: has dynamic desensitization authority and audit authority, and privileged: has emergency temporary authority.
[0062] Furthermore, the static desensitization includes: pre-generating a static desensitized copy of the high-risk data table and a desensitized copy database for direct access by low-authority users.
[0063] The desensitized copy database is isolated from the production database, and reverse association with the original data is prohibited.
[0064] Further, refer to Figure 3 , after detecting an SQL query request, intercept the SQL query request and obtain the current operation and maintenance role and the corresponding authority level, use the authority level to dynamically rewrite the SQL statement to perform differentiated desensitization on the sensitive field, and after desensitization, the production database returns the desensitization result to the operation and maintenance personnel terminal, including: the operation and maintenance personnel terminal initiates an SQL query request to the database firewall, and the database firewall detects the user authority through the rule engine after receiving the SQL query request, and the rule engine returns the desensitization rule to the database firewall; after receiving the desensitization rule, the database firewall sends a request to the production database to execute the desensitization rule; after the desensitization rule is executed, the desensitization result is returned to the operation and maintenance personnel terminal.
[0065] Example of violation rule base:
[0066] Rule 1: The number of rows returned by a single query > 1000 → triggers manual review.
[0067] Rule 2: Execute data export between 1am and 5am → Automatically block.
[0068] Furthermore, the differentiated desensitization is to replace sensitive fields in SQL queries with masks or hash values according to user roles.
[0069] Desensitization rule configuration example:
[0070] -- Original SQL
[0071] SELECT * FROM user_table WHERE id=1001;
[0072] -- After dynamic rewriting (junior role)
[0073] SELECT name, CONCAT('***', RIGHT(phone,4)) FROM user_table WHERE id=1001;
[0074] Furthermore, the operation semantic analysis includes: parsing the operation type, execution time, and data volume of the SQL statement; identifying batch export and high-frequency sensitive field query behaviors during non-working hours.
[0075] Furthermore, referring to Figure 4 , real-time capture of operation logs and use of operation semantic analysis and machine learning models to perform real-time detection of illegal operations, trigger blocking or alarms according to the risk level, and dynamically update the risk rule library, including: capturing operation logs and performing rule matching on the current operation logs to determine whether the current operation logs match the preset rules; if they match the preset rules, trigger an alarm and block; if they do not match the preset rules, use the machine learning model for analysis to obtain an anomaly score, and determine whether the anomaly score is greater than the preset threshold; if it is greater than the preset threshold, dynamically add new rules and block the current operation; if it is a normal operation, let it pass.
[0076] GRU (Gate Recurrent Unit): It is a type of recurrent neural network (RNN). Similar to LSTM (Long-Short Term Memory neural network), it is also proposed to solve problems such as long-term memory dependence and gradient disappearance in backpropagation. Compared with LSTM, using GRU can achieve comparable results and is easier to train.
[0077] The attention mechanism is a neural network technology that allows the network to focus on the most important parts of the input sequence. In the GRU network based on the attention mechanism, attention weights are introduced into the GRU unit to measure the importance of each element in the input sequence. Through the attention weights, the network can pay more attention to the features crucial for the classification task, thereby improving the classification accuracy.
[0078] The Adaboost algorithm is an ensemble learning algorithm that generates a strong classifier by weighted combination of multiple weak classifiers. In the Adaboost algorithm, each weak classifier is assigned a different weight in the training set, and the weak classifier with a larger weight has a greater influence in the final decision. Through the Adaboost algorithm, the overall performance and robustness of the classifier can be effectively improved.
[0079] Further, the machine learning model is an Attention-GRU-Adaboost model, which introduces the attention mechanism into the GRU network and integrates the Attention-GRU model through the Adaboost algorithm.
[0080] Introducing the attention mechanism into the GRU network and integrating the Attention-GRU model through the Adaboost algorithm includes:
[0081] 1) Data preprocessing:
[0082] Normalize and standardize the input data to ensure that the data is distributed within a similar range.
[0083] 2) Attention-GRU model training:
[0084] Introduce the attention mechanism into the GRU network and train the Attention-GRU model. During the training process, update the model parameters through the backpropagation algorithm so that the model can learn the attention weights of important features in the input sequence;
[0085] Weak classifier generation: Train multiple Attention-GRU models, each model is trained on a different subset of the training set. These Attention-GRU models serve as weak classifiers.
[0086] 3) Adaboost integration:
[0087] According to the Adaboost algorithm, perform weighted combination on the weak classifiers to generate a strong classifier. The weak classifier with a larger weight has a greater influence in the final decision.
[0088] 4) Classification:
[0089] Use the strong classifier to classify new data.
[0090] The core innovation of the embodiments of the present invention is database firewall integration: before the operation and maintenance request reaches the database, intercept and dynamically desensitize through the firewall; dual-mode desensitization engine: dynamic desensitization: rewrite the query statement in real time according to the user role (such as replacing sensitive fields with hash values); static desensitization: pre-generate desensitized copies of high-risk assets (such as user tables) for low-privilege users to access; real-time discovery of illegal operations: based on operation semantic analysis, identify abnormal behaviors (such as batch exports during non-working hours); combine with machine learning models to dynamically update the risk rule library.
[0091] The embodiments of the present invention have the following advantages:
[0092] 1) Limit the exposure of raw data through dynamic desensitization, reducing the risk of data leakage by 80%;
[0093] 2) Use a real-time rule engine and semantic analysis algorithm to achieve a response time for illegal operations < 1 second;
[0094] 3) The static desensitization library supports direct use in development / testing without the need to apply for production permissions, effectively improving the operation and maintenance efficiency.
[0095] Although the present invention has been described in detail with general descriptions and specific embodiments above, based on the present invention, some modifications or improvements can be made, which are obvious to those skilled in the art. Therefore, these modifications or improvements made without departing from the spirit of the present invention all fall within the scope of protection required by the present invention.
Claims
1. A method for hierarchical control of permissions based on dynamic desensitization and real-time monitoring, characterized in that, The method is applied to a database firewall and comprises: Obtain all operation and maintenance roles and classify the permissions of the operation and maintenance roles into three levels: primary, advanced, and special. After detecting an SQL query request, intercept the SQL query request and obtain the current operation and maintenance role and the corresponding authority level, and use the authority level to dynamically rewrite the SQL statement to perform differentiated desensitization on sensitive fields. After desensitization, the production database returns the desensitization result to the operation and maintenance personnel terminal; Capture operation logs in real time and use operational semantic analysis and machine learning models to detect illegal operations in real time, trigger blocking or alarms based on risk levels, and dynamically update the risk rule base.
2. The method for hierarchical permission control based on dynamic desensitization and real-time monitoring according to claim 1, characterized in that, The permissions are divided into three levels: primary, advanced and special, including: Primary authority: only has the authority to perform static desensitization; Advanced authority: has the authority to perform dynamic desensitization and auditing; Special authority: has emergency temporary authority.
3. The method for hierarchical control of permissions based on dynamic desensitization and real-time monitoring according to claim 2, wherein, The static desensitization comprises: Pre-generate static desensitized copies and desensitized copy databases of high-risk data tables for direct access by low-privilege users; The desensitized copy database is isolated from the production database, and reverse association with the original data is prohibited.
4. The method for hierarchical permission control based on dynamic desensitization and real-time monitoring according to claim 1, characterized in that, After detecting the SQL query request, intercept the SQL query request and obtain the current operation and maintenance role and the corresponding authority level, use the authority level to dynamically rewrite the SQL statement to perform differential desensitization on sensitive fields, and after desensitization, the production database returns the desensitization result to the operation and maintenance personnel terminal, including: The operation and maintenance personnel terminal initiates an SQL query request to the database firewall. After receiving the SQL query request, the database firewall detects the user authority through the rule engine, and the rule engine returns the desensitization rule to the database firewall; After receiving the desensitization rule, the database firewall sends a request to the production database to execute the desensitization rule; After the desensitization rules are executed, the desensitization results will be returned to the operation and maintenance personnel terminal.
5. The method for hierarchical permission control based on dynamic desensitization and real-time monitoring according to claim 4, wherein, The differentiated desensitization is to replace sensitive fields in SQL queries with masks or hash values according to user roles.
6. The method for hierarchical control of permissions based on dynamic desensitization and real-time monitoring according to claim 1, wherein The operational semantic analysis includes: Analyze the operation type, execution time and data volume of SQL statements; Identify batch exports and high-frequency sensitive field query behaviors during non-working hours.
7. A method for hierarchical control of permissions based on dynamic desensitization and real-time monitoring according to claim 1, characterized in that, Capture operation logs in real time and use operation semantic analysis and machine learning models to detect illegal operations in real time, trigger blocking or alarming according to risk levels, and dynamically update the risk rule base, including: Capture operation logs and perform rule matching on current operation logs to determine whether the current operation logs match preset rules; If the preset rules are matched, an alarm is triggered and blocking is performed; If the preset rules are not matched, the machine learning model is used for analysis to obtain an anomaly score and determine whether the anomaly score is greater than a preset threshold; If it is greater than the preset threshold, a new rule is dynamically added and the current operation is blocked; if it is a normal operation, it is released.
8. A method for hierarchical control of permissions based on dynamic desensitization and real-time monitoring according to claim 7, characterized in that, The machine learning model is an Attention-GRU-Adaboost model, which introduces the attention mechanism into the GRU network and integrates the Attention-GRU model through the Adaboost algorithm.
9. An operation and maintenance bastion host system based on dynamic desensitization and real-time monitoring, characterized in that, The system consists of an operation and maintenance bastion host, a database firewall, and a rule engine, specifically including: The operation and maintenance bastion machine is used to obtain all operation and maintenance roles and classify the permissions of the operation and maintenance roles. The permissions are classified into three levels: primary, advanced, and special. The database firewall is used to intercept the SQL query request after detecting it and obtain the current operation and maintenance role and the corresponding authority level; The rule engine is used to dynamically rewrite SQL statements using the permission levels to perform differentiated desensitization on sensitive fields. After desensitization, the production database returns the desensitization results to the operation and maintenance personnel terminal.
10. The operation and maintenance bastion host system based on dynamic desensitization and real-time monitoring according to claim 9, characterized in that, The system also includes an audit module for performing the following steps: Capture operation logs in real time and use operational semantic analysis and machine learning models to detect illegal operations in real time, trigger blocking or alarms based on risk levels, and dynamically update the risk rule base.
Citation Information
Patent Citations
Data analysis method and apparatus
CN108268558A
Database protection method and device, firewall and computer readable storage medium
CN112417443A
Database monitoring method and system and server
CN114328119A
Data security hierarchical management and control method and device
CN115062345A
Operation risk assessment method and device for operation and maintenance personnel, electronic equipment and medium
CN115330250A
Cited By
Real-time analysis system based on business data isolation and low-intrusive data synchronization method
CN121037385A
Content generation method, device and equipment based on retrieval enhancement generation
CN121117187A