Audit plug-in installation method and device, equipment, medium and product
By comparing the attribute information of the database server, the risk database server that does not have the audit plug-in installed is automatically identified and installed, which solves the data security problem caused by the failure to install the plug-in in time on the database server, and realizes the timely monitoring and security improvement of the database.
Patent Information
- Application Number
- CN202510826053.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-19
- Publication Date
- 2025-09-26
AI Technical Summary
Since the audit plug-in was not installed in time on the database server, the data security of the relevant database could not be guaranteed.
By determining the candidate database servers in the target data platform, obtaining their attribute information, and comparing it with the attribute information of the compliant database servers with the audit plug-in installed, the risky database servers without the audit plug-in installed are identified, and the plug-in installation operation is automatically executed.
Timely identification and installation of risky database servers without audit plug-ins installed improves database data security, reduces operation and maintenance costs, and improves data security and operation and maintenance efficiency.
Smart Images

Figure CN120704762A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud computing technology, and in particular to an audit plug-in installation method, device, equipment, medium and product. Background Art
[0002] In recent years, data security has become increasingly important. Many database resources on data platforms are exposed outside of control, posing a significant threat to production safety. To ensure database data security, the data platform has introduced a database audit plug-in. By installing the audit plug-in on the database server, the database is monitored 24 / 7.
[0003] However, due to the large number of database servers included in the data platform, some database servers have not installed the audit plug-in in a timely manner, which undoubtedly leads to the inability to guarantee the data security of the relevant databases. Summary of the Invention
[0004] The present invention provides an installation method, device, equipment, medium and product for an audit plug-in, so as to solve the problem that the data security of the relevant database cannot be guaranteed due to the failure to timely install the audit plug-in on the database server.
[0005] According to one aspect of the present invention, a method for installing an audit plug-in is provided, the method comprising:
[0006] Determine at least one candidate database server included in the target data platform, and determine a target database server on which an audit plug-in needs to be installed from the candidate database servers, and obtain target server attribute information corresponding to the target database server;
[0007] Determine a compliance database server in the target data platform that has an audit plug-in installed, and obtain compliance server attribute information corresponding to the compliance database server;
[0008] Comparing the target server attribute information with the compliant server attribute information, and determining a risk database server that does not have an audit plug-in installed from the target database server based on the information comparison result;
[0009] An audit plug-in installation operation is performed on the risk database server.
[0010] According to another aspect of the present invention, a device for installing an audit plug-in is provided, the device comprising:
[0011] An information acquisition module is used to determine at least one candidate database server included in the target data platform, determine a target database server on which an audit plug-in needs to be installed from the candidate database servers, and obtain target server attribute information corresponding to the target database server;
[0012] A compliance database server determination module is used to determine a compliance database server in the target data platform that has an audit plug-in installed, and obtain compliance server attribute information corresponding to the compliance database server;
[0013] a risk database server determination module, configured to compare the target server attribute information with the compliant server attribute information, and determine a risk database server that does not have an audit plug-in installed from the target database server based on the information comparison result;
[0014] The audit plug-in installation module is used to perform an audit plug-in installation operation on the risk database server.
[0015] According to another aspect of the present invention, an electronic device is provided, comprising:
[0016] at least one processor; and
[0017] a memory communicatively connected to the at least one processor; wherein,
[0018] The memory stores a computer program that can be executed by the at least one processor. The computer program is executed by the at least one processor so that the at least one processor can execute the audit plug-in installation method according to any one of the present inventions.
[0019] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the audit plug-in installation method according to any one of the present inventions when executed.
[0020] According to another aspect of the present invention, a computer program product is provided, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements the audit plug-in installation method according to any one of the present inventions.
[0021] The present invention determines at least one candidate database server included in the target data platform, and determines the target database server that needs to install the audit plug-in from the candidate database servers, and obtains the target server attribute information corresponding to the target database server; determines the compliance database server in the target data platform that has the audit plug-in installed, and obtains the compliance server attribute information corresponding to the compliance database server; compares the target server attribute information with the compliance server attribute information, and determines the risk database server that does not have the audit plug-in installed from the target database server based on the information comparison result; and performs the audit plug-in installation operation on the risk database server. The beneficial effect is that: the risk database server that does not have the audit plug-in installed can be identified in time, and the audit plug-in can be automatically installed in the risk database server, which is beneficial to improving the data security of the database in the risk database server.
[0022] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0024] Figure 1 A flowchart of a method for installing an audit plug-in provided in Example 1 of the present invention;
[0025] Figure 2 A flowchart of a method for installing an audit plug-in provided in the second embodiment of the present invention;
[0026] Figure 3 A schematic diagram of the structure of an installation device for an audit plug-in provided in the third embodiment of the present invention;
[0027] Figure 4 The present invention is a schematic diagram of the structure of an electronic device for implementing the audit plug-in installation method according to an embodiment of the present invention. DETAILED DESCRIPTION
[0028] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0029] It should be noted that the terms "candidate", "target", "first", "second", "third", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0030] Example 1
[0031] Figure 1 This is a flowchart of a method for installing an audit plug-in provided in the first embodiment of the present invention. This embodiment is applicable to the case where the audit plug-in is not installed in the database server in the data platform. The method can be executed by the installation device of the audit plug-in. The installation device of the audit plug-in can be implemented in the form of hardware and / or software, such as using a server with a direct-connected storage architecture. Figure 1 As shown, the method includes:
[0032] S101. Determine at least one candidate database server included in a target data platform, determine a target database server on which an audit plug-in needs to be installed from the candidate database servers, and obtain target server attribute information corresponding to the target database server.
[0033] The target data platform refers to any data platform that relies on audit plug-ins to monitor database data. A data platform is a systematic technical architecture that integrates data collection, storage, processing, analysis, and application. An audit plug-in is a security-enhancing plug-in specifically designed to record and monitor database operations. By capturing events such as user logins, queries, and data modifications, it generates detailed operation logs to meet security compliance, threat detection, and incident tracing requirements.
[0034] The target data platform is equipped with at least one candidate database server. A candidate database server is a hardware and software integrated system specifically designed to run a database. Its core mission is to efficiently store, manage, process, and provide access services to structured or unstructured data.
[0035] The target database server refers to the candidate database server on which the audit plug-in needs to be installed. The target server attribute information refers to the server attribute information of the target database server. The server attribute information is a set of core parameters that describe the server hardware configuration, software features, operating status, and management policies, including but not limited to fields such as server IP, application name, maintenance department, and production status.
[0036] In one embodiment, a system information table of a target data platform is periodically obtained, such as daily. The system information table records all types of servers included in the target data platform. Furthermore, information is searched in the system information table according to preset search criteria to identify at least one candidate database server included in the target data platform.
[0037] Among them, the preset search conditions include but are not limited to "node system online, not the enterprise control center operation and maintenance operation terminal, centralized document machine, computer room environment monitoring environment, non-special network segment, entered as database node", etc., that is, "node system online, not the enterprise control center operation and maintenance operation terminal, centralized document machine, computer room environment monitoring environment, non-special network segment, entered as database node" is used as the search condition to search information in the system information table, and determine the server that meets the above search conditions from the system information table as a candidate database server.
[0038] Furthermore, an application information table of the target data platform is obtained, wherein the application information table records application information of applications used to access the target data platform, and the application information includes but is not limited to application status, application name, server IP of the server used, and the like.
[0039] A search is performed in the application information table based on the server IP of each candidate database server to determine the candidate application to which each candidate database server belongs, and to determine the application status of each candidate application. The candidate database server corresponding to the candidate application with an online application status is then used as the target database server for which the audit plug-in needs to be installed.
[0040] Furthermore, the server attribute information corresponding to each target database server is searched in the system information table as the target server attribute information corresponding to each target database server, for example, the server IP, application name, maintenance department, production status, etc. corresponding to each target database server.
[0041] Optionally, after obtaining the target server attribute information corresponding to the target database server, the following steps are also included:
[0042] Get the exception server list; the exception server list records the server IP of the exception server, the exception reason, the exception start time, the exception end time, etc.; the exception server refers to the candidate database server that is not identified by the audit plug-in through the exception application.
[0043] The server IP of each exception server is compared with the server IP of each target database server to determine the exception server from each target database server as the first database server to be eliminated; the target server attribute information corresponding to each first database server to be eliminated is eliminated.
[0044] S102: Determine the compliance database server in the target data platform that has the audit plug-in installed, and obtain compliance server attribute information corresponding to the compliance database server.
[0045] Among them, the compliant database server refers to the candidate database server with the audit plug-in installed, and the compliant server attribute information refers to the server attribute information of the compliant database server, including but not limited to fields such as server IP, application name, maintenance department, and production status.
[0046] In one embodiment, an audit plug-in installation list is periodically obtained from the background server of the audit plug-in, such as obtaining the audit plug-in installation list daily, wherein the audit plug-in installation list records the audit plug-in information, the database servers on which the audit plug-in has been installed in the target data platform, and the server attribute information of these database servers.
[0047] Furthermore, information is extracted from the audit plug-in installation list to determine the database servers in the target data platform that have installed the audit plug-in as compliant database servers, and the server attribute information corresponding to each compliant database server is extracted as compliant server attribute information.
[0048] Optionally, after obtaining the compliance server attribute information corresponding to the compliance database server, the following is further included:
[0049] Get the exception server list; the exception server list records the server IP of the exception server, the exception reason, the exception start time, the exception end time, etc.; the exception server refers to the candidate database server that is not identified by the audit plug-in through the exception application.
[0050] The server IP of each exception server is compared with the server IP of each compliance database server to determine the exception server from the compliance database servers as the second database server to be eliminated; the compliance server attribute information corresponding to each second database server to be eliminated is eliminated.
[0051] S103: Compare the target server attribute information with the compliant server attribute information, and determine the risk database server that does not have the audit plug-in installed from the target database server according to the information comparison result.
[0052] The risky database server refers to a candidate database server that does not have an audit plug-in installed.
[0053] In one embodiment, target server attribute information corresponding to each target database server is compared with compliance server attribute information corresponding to each compliance database server.
[0054] If the target server attribute information corresponding to any target database server matches the compliance server attribute information corresponding to any compliance database server, it means that the target database server and the compliance database server are the same database server, that is, the target database server has an audit plug-in installed.
[0055] If the target server attribute information corresponding to any target database server does not match the compliance server attribute information corresponding to each compliance database server, it means that the target database server and each compliance database server are not the same database server, which means that the target database server does not have the audit plug-in installed, and thus the target database server is regarded as a risk database server without the audit plug-in installed.
[0056] Optionally, after comparing the target server attribute information with the compliant server attribute information, the following steps are also included:
[0057] If the compliance server attribute information of any compliance database server does not match the target server attribute information of each target database server, it means that the compliance server attribute information of the compliance database server is not entered into the system information table of the target data platform or is entered incorrectly. Therefore, the compliance server attribute information of the compliance database server is re-entered into the system information table, and the compliance server attribute information of the compliance database server is updated to the target server attribute information.
[0058] S104: Execute the installation operation of the audit plug-in on the risk database server.
[0059] In one embodiment, a plug-in installation package required by the audit plug-in is obtained, and the audit plug-in is installed in the risk database server according to the plug-in installation package through an automated script.
[0060] An embodiment of the present invention determines at least one candidate database server included in a target data platform, and determines a target database server on which an audit plug-in needs to be installed from the candidate database servers, and obtains target server attribute information corresponding to the target database server; determines a compliance database server on which an audit plug-in has been installed in the target data platform, and obtains compliance server attribute information corresponding to the compliance database server; compares the target server attribute information with the compliance server attribute information, and determines a risk database server on which an audit plug-in is not installed from the target database server based on the information comparison result; and performs an audit plug-in installation operation on the risk database server. The beneficial effect is that the risk database server on which the audit plug-in is not installed can be identified in a timely manner, and the audit plug-in can be automatically installed in the risk database server, which is beneficial to improving the data security of the database in the risk database server.
[0061] Example 2
[0062] Figure 2 This is a flowchart of a method for installing an audit plug-in provided in the second embodiment of the present invention. This embodiment further optimizes and expands the above embodiment and can be combined with the above optional implementation methods. Figure 2 As shown, the method includes:
[0063] S201: Determine at least one candidate database server included in a target data platform.
[0064] S202: Determine the candidate applications to which each candidate database server belongs, and determine the application status of each candidate application.
[0065] The application status can be either online or offline. If the application status is online, it means the application has been deployed to the production environment and has started providing services. If the application status is offline, it means the application service has been terminated and removed from the running environment.
[0066] In one embodiment, the target data platform's application information table is obtained, and the server IP addresses corresponding to the candidate database servers are matched against the information in the application information table to determine the candidate applications to which each candidate database server belongs. Furthermore, the real-time application status of each candidate application maintained in the application information table is obtained.
[0067] S203: Taking a candidate application whose application status is online as a target application, and taking a candidate database server corresponding to the target application as a first-category database server; and determining a target database server from the first-category database servers.
[0068] In one embodiment, candidate applications with an online status are selected as target applications, and information is matched in the application information table based on the application name of the target application to determine the candidate database servers corresponding to each target application as the first-category database server. Further, the target database server is determined from the first-category database servers.
[0069] By determining the candidate applications to which each candidate database server belongs and determining the application status of each candidate application, wherein the application status is an online state or an offline state; taking the candidate application with the application status being an online state as the target application, and taking the candidate database server corresponding to the target application as the first-category database server; and determining the target database server from the first-category database server, the beneficial effects are:
[0070] First, the audit plug-in is only installed on the database server corresponding to the online application (the first type of database server) to avoid invalid audit resource consumption.
[0071] Secondly, offline applications have lower security risks because there is no real-time data interaction, and excluding audits can reduce interference noise.
[0072] Third, the audit plug-in is only deployed on active business servers (first-class database servers) to avoid occupying memory or CPU resources of offline servers and achieve on-demand allocation of hardware resources.
[0073] Optionally, determining a target database server from the first category of database servers includes:
[0074] S2031: Determine the current database type corresponding to each first-category database server, and match each current database type with at least one adapted database type.
[0075] The "Current Database Type" refers to the database type corresponding to each first-class database server. Database types refer to the data storage architecture and management model designed to meet different data processing requirements. Key differences lie in data structure, scalability, transaction support, and application scenarios. The "Adaptive Database Type" refers to the database type that is compatible with the audit plug-in. This can be set based on experience or business needs.
[0076] S2032: Use the current database type that matches any of the adapted database types as the target database type, and use the first type of database server corresponding to the target database type as the target database server.
[0077] For example, assuming that the compatible database types include "Database Type 1," "Database Type 2," "Database Type 3," and "Database Type 4," and assuming that the current database types include "Database Type 1," "Database Type 2," "Database Type 5," and "Database Type 6," "Database Type 1" and "Database Type 2" are determined as target database types. Assuming that the first-class database server corresponding to "Database Type 1" is "Database Server A," and the first-class database server corresponding to "Database Type 2" is "Database Server B," "Database Server A" and "Database Server B" are selected as target database servers.
[0078] By determining the current database type corresponding to each first-category database server, and matching each current database type with at least one adapted database type, the current database type that matches any adapted database type is used as the target database type, and the first-category database server corresponding to the target database type is used as the target database server that needs to install the audit plug-in. The beneficial effects are:
[0079] First, the database type is marked as the target database server only when it is compatible with the audit plug-in, avoiding resource waste or security blind spots caused by invalid installation of the audit plug-in.
[0080] Secondly, the definition of adaptive database types can be dynamically expanded without modifying the core logic, thereby improving the ecological compatibility of the audit plug-in.
[0081] Thirdly, the traditional solution requires manual verification of the database type, which results in a high error rate. The embodiment of the present invention can reduce the error rate by automatically matching the database type.
[0082] S204: Obtain target server attribute information corresponding to the target database server, determine the compliance database server in which the audit plug-in has been installed in the target data platform, and obtain compliance server attribute information corresponding to the compliance database server.
[0083] S205. Compare the target server attribute information with the compliant server attribute information to determine at least one target server attribute information that does not match any compliant server attribute information as risk server attribute information; and determine the target database server corresponding to each risk server attribute information as the risk database server.
[0084] In one embodiment, the attribute information of each target server is compared with the attribute information of each compliant server. If any target server attribute information does not match any compliant server attribute information, the target server attribute information is deemed risky server attribute information. Furthermore, the target database server corresponding to each risky server attribute information is determined as the risky database server by matching the risky server attribute information against the system information table.
[0085] For example, assuming that the compliant server attribute information includes "aaa," "bbb," and "ccc," and the target server attribute information includes "aaa," "bbb," "ccc," and "ddd," and since the target server attribute information "ddd" does not match any compliant server attribute information, the target server attribute information "ddd" is considered the risky server attribute information. Assuming that the target database server corresponding to the target server attribute information "ddd" is "database server D," "database server D" is considered the risky database server.
[0086] By determining at least one target server attribute information that does not match any compliant server attribute information as risky server attribute information, and determining the target database server corresponding to each risky server attribute information as the risky database server, the beneficial effects are:
[0087] First, it automatically identifies risky database servers that do not have audit plug-ins installed, reduces unmonitored access entries, prevents malicious code injection, unauthorized operations, and other behaviors from bypassing audits, and improves data security.
[0088] Secondly, it replaces manual traversal detection and can quickly locate risk database servers without plug-ins installed through server attribute information comparison, reducing operation and maintenance costs and improving the efficiency of risk database server positioning.
[0089] S206: Determine the busy time for executing the task corresponding to the risk database server, and determine the plug-in installation time corresponding to the risk database server according to the busy time for executing the task.
[0090] Busy task execution hours refer to periods of time each day when the database server experiences a surge in task requests, leading to response delays. These busy task execution hours can be determined by analyzing and summarizing historical log data from each database server, such as 9:00 AM to 12:00 PM and 7:00 PM to 9:00 PM daily. It's understandable that to ensure smooth audit plug-in installation, the plug-in should be installed during busy task execution hours on the database server. Therefore, any time of day, excluding busy task execution hours, is designated as the plug-in installation time.
[0091] For example, if 9:00-12:00 and 19:00-21:00 are the busy hours for task execution every day, then any time except 9:00-12:00 and 19:00-21:00 every day can be set as the plug-in installation time.
[0092] S207. When the plug-in installation time is met, obtain the available resource amount corresponding to the risk database server and compare the available resource amount with the resource amount threshold; if the available resource amount is greater than or equal to the resource amount threshold, perform the audit plug-in installation operation on the risk database server.
[0093] Available resources refer to the total amount of unused hardware resources on the risk database server that can be immediately allocated to new tasks or applications, including but not limited to available CPU resources, available memory resources, available storage resources, and available network resources. A resource threshold can be set based on experience to determine whether available resources are sufficient for audit plug-in installation.
[0094] In one embodiment, when the plug-in installation time is met, the available resources and resource threshold corresponding to the risk database server are obtained. Furthermore, the available resources are numerically compared with the resource threshold. If it is determined that the available resources are less than the resource threshold, it indicates that the available resources of the risk database server are insufficient for installing the audit plug-in, and the audit plug-in installation operation is not triggered. If it is determined that the available resources are greater than or equal to the resource threshold, it indicates that the available resources of the risk database server are sufficient for installing the audit plug-in, and the audit plug-in installation operation is triggered for the risk database server.
[0095] By determining the busy time of task execution corresponding to the risk database server, and determining the plug-in installation time corresponding to the risk database server based on the busy time of task execution; when the plug-in installation time is met, obtaining the available resources corresponding to the risk database server, and comparing the available resources with the resource threshold; when the available resources are greater than or equal to the resource threshold, performing the audit plug-in installation operation on the risk database server, the beneficial effects are:
[0096] First, by identifying the busy times when the risk database server is performing tasks, the audit plug-in installation operation is scheduled to a low-load period to avoid interfering with the core business of the risk database server and achieve precise staggered installation of the audit plug-in.
[0097] Secondly, compared with the solution of installing the audit plug-in at a fixed time, this solution predicts the plug-in installation time based on real-time load and adapts to business fluctuation scenarios.
[0098] Third, audit the amount of available resources before installing the plug-in to ensure that the server has sufficient redundancy to support the operation of the plug-in.
[0099] Optionally, after determining the risk database server that does not have the audit plug-in installed from the target database server based on the information comparison result, the method further includes:
[0100] A1. Obtain a continuous risk record sheet.
[0101] Among them, the continuous risk record table records risk statistical information corresponding to the continuous risk database server, and the continuous risk database server is a candidate database server that has been identified as not having an audit plug-in installed at least twice in a row; wherein the risk statistical information includes at least one of the number of consecutive records, the last record time, and the first record time.
[0102] For example, if a database server is identified as not having an audit plug-in installed three times in a row, it can be considered a continuously risky database server. The continuous risk record table records the risk statistics of the database server, such as the number of consecutive records "3", the time of the last record T1, and the time of the first record T0.
[0103] B1. Determine whether the continuous risk record table contains a risk database server. If so, update the risk statistical information corresponding to the risk database server in the continuous risk record table.
[0104] In one embodiment, the risk database server's IP address is matched against the continuous risk record table to determine whether the risk database server is included in the continuous risk record table. If so, the number of consecutive records and the last record time corresponding to the risk database server are updated in the continuous risk record table. For example, the number of consecutive records is incremented by 1, and the last record time is updated to the current time.
[0105] By obtaining a continuous risk record table; wherein the continuous risk record table records risk statistical information corresponding to a continuous risk database server, the continuous risk database server being a candidate database server that has been identified as not having an audit plug-in installed at least twice in a row; wherein the risk statistical information includes at least one of the number of consecutive records, the time of the last record, and the time of the first record; determining whether the continuous risk record table includes the risk database server, and if so, updating the risk statistical information corresponding to the risk database server in the continuous risk record table, the beneficial effect is:
[0106] First, by recording the number of consecutive times the audit plug-in has not been installed, systemic management vulnerabilities can be identified, thereby improving the accuracy of risk positioning compared to single detection.
[0107] Secondly, combine the "first recording time" and "last recording time" to determine the risk exposure period, and give priority to high-risk database servers that have not been rectified for a long time.
[0108] Third, traditional solutions require manual verification of historical records. This solution reduces manual inspection hours through a real-time matching and updating mechanism.
[0109] Optionally, after determining the compliant database server with the audit plug-in installed in the target data platform, the following steps are also required:
[0110] Determine whether the continuous risk record table contains a compliant database server. If so, delete the risk statistics information corresponding to the compliant database server from the continuous risk record table.
[0111] In one embodiment, information is matched against the continuous risk record table based on the server IP address of the compliance database server to determine whether the continuous risk record table includes the compliance database server. If so, since the compliance database server is identified as having an audit plug-in installed, the risk statistics corresponding to the compliance database server are deleted from the continuous risk record table, such as the number of consecutive records deleted, the time of the last record, and the time of the first record.
[0112] By determining whether the continuous risk record table contains a compliant database server, and if so, deleting the risk statistics information corresponding to the compliant database server from the continuous risk record table, the beneficial effects are:
[0113] First, it automatically identifies compliant database servers that have installed audit plug-ins and immediately removes their risk statistics to ensure that the continuous risk record table only retains real high-risk targets, thereby improving risk focus efficiency.
[0114] Secondly, traditional solutions require manual verification of compliance status, resulting in a high false alarm rate. However, this solution can reduce the false alarm rate through automated matching and avoid interference from false alarms.
[0115] Third, ensure that the continuous risk record sheet only contains unrectified items to enhance the credibility of the audit evidence chain.
[0116] Optionally, the method further includes:
[0117] A2. In response to a data query request implemented by a user, determine the first server number corresponding to the target database server, the second server number corresponding to the compliance database server, and the third server number corresponding to the risk database server.
[0118] B2. Determine the proportion of compliant database servers based on the number of second servers and the number of first servers, and generate data query results based on the number of first servers, the number of second servers, the number of third servers, and the proportion of compliant database servers.
[0119] In one embodiment, a ratio calculation is performed based on the number of the second servers and the number of the first servers, and the ratio of the compliant database servers to the target database servers is determined based on the ratio calculation result, as the compliant database server ratio. Furthermore, a data query result is generated that includes, but is not limited to, the number of the first servers, the number of the second servers, the number of the third servers, and the compliant database server ratio.
[0120] By responding to data query requests implemented by users, the number of first servers corresponding to the target database server, the number of second servers corresponding to the compliance database server, and the number of third servers corresponding to the risk database server are determined; based on the number of second servers and the number of first servers, the proportion of compliance database servers is determined; and based on the number of first servers, the number of second servers, the number of third servers, and the proportion of compliance database servers, data query results are generated, which enables users to perceive in real time the statistical information of three types of database servers: those that need to install audit plug-ins, those that have installed audit plug-ins, and those that do not have audit plug-ins, thereby achieving the effect of data statistical visualization.
[0121] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data comply with relevant laws, regulations and standards in the relevant regions.
[0122] Example 3
[0123] Figure 3 This is a schematic diagram of a structure of an installation device for an audit plug-in provided in the third embodiment of the present invention, which can be applied to automatically identify database servers in a data platform that do not have an audit plug-in installed, such as Figure 3 As shown, the device includes:
[0124] An information acquisition module 31 is configured to determine at least one candidate database server included in a target data platform, determine a target database server on which an audit plug-in needs to be installed from the candidate database servers, and obtain target server attribute information corresponding to the target database server;
[0125] A compliance database server determination module 32 is configured to determine a compliance database server in the target data platform that has an audit plug-in installed thereon, and obtain compliance server attribute information corresponding to the compliance database server;
[0126] a risk database server determining module 33 for comparing the target server attribute information with the compliant server attribute information, and determining a risk database server that does not have an audit plug-in installed from the target database server based on the information comparison result;
[0127] The audit plug-in installation module 34 is used to perform an audit plug-in installation operation on the risk database server.
[0128] Optionally, the information acquisition module 31 is specifically configured to:
[0129] Determine the candidate application to which each candidate database server belongs, and determine the application status of each candidate application; wherein the application status is an online state or an offline state;
[0130] Taking the candidate application whose application status is the online status as a target application, and taking the candidate database server corresponding to the target application as a first-category database server;
[0131] The target database server is determined from the first category of database servers.
[0132] Optionally, the information acquisition module 31 is further configured to:
[0133] Determine the current database type corresponding to each of the first-category database servers, and match each of the current database types with at least one adapted database type; wherein the adapted database type is a database type adapted to the audit plug-in;
[0134] The current database type that matches any of the adapted database types is used as a target database type, and the first type of database server corresponding to the target database type is used as the target database server.
[0135] Optionally, the risk database server determination module 33 is specifically configured to:
[0136] determining at least one piece of target server attribute information that does not match any of the compliant server attribute information as risky server attribute information;
[0137] The target database servers corresponding to the risk server attribute information are determined as the risk database servers.
[0138] Optionally, the audit plug-in installation module 34 is specifically used to:
[0139] Determining a busy time for executing a task corresponding to the risk database server, and determining a plug-in installation time corresponding to the risk database server according to the busy time for executing the task;
[0140] When the plug-in installation time is met, obtaining the available resource amount corresponding to the risk database server, and comparing the available resource amount with the resource amount threshold;
[0141] When the available resource amount is greater than or equal to the resource amount threshold, an audit plug-in installation operation is performed on the risk database server.
[0142] Optionally, the device further includes a risk statistical information updating module, specifically configured to:
[0143] Obtaining a continuous risk record table; wherein the continuous risk record table records risk statistical information corresponding to a continuous risk database server, wherein the continuous risk database server is the candidate database server that has been identified as not having an audit plug-in installed at least twice in a row; wherein the risk statistical information includes at least one of the number of consecutive records, the time of the last record, and the time of the first record;
[0144] Determine whether the continuous risk record table includes the risk database server, and if so, update the risk statistical information corresponding to the risk database server in the continuous risk record table.
[0145] Optionally, the device further includes a risk statistical information deletion module, specifically configured to:
[0146] Determine whether the continuous risk record table includes the compliance database server, and if so, delete the risk statistical information corresponding to the compliance database server from the continuous risk record table.
[0147] Optionally, the device further includes a data query module, specifically configured to:
[0148] In response to a data query request implemented by a user, determining a first server quantity corresponding to the target database server, a second server quantity corresponding to the compliance database server, and a third server quantity corresponding to the risk database server;
[0149] The proportion of compliant database servers is determined based on the second number of servers and the first number of servers, and a data query result is generated based on the first number of servers, the second number of servers, the third number of servers, and the proportion of compliant database servers.
[0150] The audit plug-in installation device provided by the embodiment of the present invention can execute the audit plug-in installation method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of the execution method.
[0151] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0152] Example 4
[0153] Figure 4 A schematic diagram of the structure of an electronic device 40 that can be used to implement an embodiment of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0154] like Figure 4 As shown, the electronic device 40 includes at least one processor 41 and a memory, such as a read-only memory (ROM) 42, a random access memory (RAM) 43, etc., which is communicatively connected to the at least one processor 41. The memory stores a computer program that can be executed by the at least one processor, and the processor 41 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 42 or the computer program loaded from the storage unit 48 into the random access memory (RAM) 43. Various programs and data required for the operation of the electronic device 40 can also be stored in the RAM 43. The processor 41, ROM 42, and RAM 43 are connected to each other via a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.
[0155] Multiple components in the electronic device 40 are connected to the I / O interface 45, including an input unit 46, such as a keyboard, a mouse, etc.; an output unit 47, such as various types of displays, speakers, etc.; a storage unit 48, such as a magnetic disk, an optical disk, etc.; and a communication unit 49, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 49 allows the electronic device 40 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0156] Processor 41 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. Processor 41 executes the various methods and processes described above, such as the audit plug-in installation method.
[0157] In some embodiments, the method for installing the audit plug-in can be implemented as a computer program that is tangibly contained in a computer-readable storage medium, such as storage unit 48. In some embodiments, part or all of the computer program can be loaded and / or installed on electronic device 40 via ROM 42 and / or communication unit 49. When the computer program is loaded into RAM 43 and executed by processor 41, one or more steps of the method for installing the audit plug-in described above can be performed. Alternatively, in other embodiments, processor 41 can be configured to perform the method for installing the audit plug-in in any other appropriate manner (e.g., by means of firmware).
[0158] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0159] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer program may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0160] In the context of the present invention, computer-readable storage media can be tangible media that can contain or store a computer program for use with an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Computer-readable storage media can include but are not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, computer-readable storage media can be machine-readable signal media. More specific examples of machine-readable storage media can include electrical connections based on one or more lines, portable computer disks, hard disks, random access memories (RAM), read-only memories (ROM), erasable programmable read-only memories (EPROM or flash memory), optical fibers, portable compact disk read-only memories (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0161] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0162] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0163] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.
[0164] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.
[0165] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.
Claims
1. A method for installing an audit plug-in, characterized in that: The method comprises: Determine at least one candidate database server included in the target data platform, and determine a target database server on which an audit plug-in needs to be installed from the candidate database servers, and obtain target server attribute information corresponding to the target database server; Determine a compliance database server in the target data platform that has an audit plug-in installed, and obtain compliance server attribute information corresponding to the compliance database server; Comparing the target server attribute information with the compliant server attribute information, and determining a risk database server that does not have an audit plug-in installed from the target database server based on the information comparison result; An audit plug-in installation operation is performed on the risk database server.
2. The method according to claim 1, characterized in that The step of determining a target database server on which an audit plug-in needs to be installed from the candidate database servers includes: Determine the candidate application to which each candidate database server belongs, and determine the application status of each candidate application; wherein the application status is an online state or an offline state; Taking the candidate application whose application status is the online status as a target application, and taking the candidate database server corresponding to the target application as a first-category database server; The target database server is determined from the first category of database servers.
3. The method according to claim 2, characterized in that The determining the target database server from the first type of database servers includes: Determine the current database type corresponding to each of the first-category database servers, and match each of the current database types with at least one adapted database type; wherein the adapted database type is a database type adapted to the audit plug-in; The current database type that matches any of the adapted database types is used as a target database type, and the first type of database server corresponding to the target database type is used as the target database server.
4. The method according to claim 1, wherein The step of determining a risk database server that does not have an audit plug-in installed from the target database server according to the information comparison result includes: determining at least one piece of target server attribute information that does not match any of the compliant server attribute information as risky server attribute information; The target database servers corresponding to the risk server attribute information are determined as the risk database servers.
5. The method according to claim 1, wherein The performing of the audit plug-in installation operation on the risk database server includes: Determining a busy time for executing a task corresponding to the risk database server, and determining a plug-in installation time corresponding to the risk database server according to the busy time for executing the task; When the plug-in installation time is met, obtaining the available resource amount corresponding to the risk database server, and comparing the available resource amount with the resource amount threshold; When the available resource amount is greater than or equal to the resource amount threshold, an audit plug-in installation operation is performed on the risk database server.
6. The method according to claim 1, after determining the risk database server without the audit plug-in installed from the target database server based on the information comparison result, further comprising: Obtaining a continuous risk record table; wherein the continuous risk record table records risk statistical information corresponding to a continuous risk database server, wherein the continuous risk database server is the candidate database server that has been identified as not having an audit plug-in installed at least twice in a row; wherein the risk statistical information includes at least one of the number of consecutive records, the time of the last record, and the time of the first record; Determine whether the continuous risk record table includes the risk database server, and if so, update the risk statistical information corresponding to the risk database server in the continuous risk record table.
7. The method according to claim 6, after determining the compliance database server in the target data platform that has the audit plug-in installed, further comprising: Determine whether the continuous risk record table includes the compliance database server, and if so, delete the risk statistical information corresponding to the compliance database server from the continuous risk record table.
8. The method according to claim 1, further comprising: In response to a data query request implemented by a user, determining a first server quantity corresponding to the target database server, a second server quantity corresponding to the compliance database server, and a third server quantity corresponding to the risk database server; The proportion of compliant database servers is determined based on the second number of servers and the first number of servers, and a data query result is generated based on the first number of servers, the second number of servers, the third number of servers, and the proportion of compliant database servers.
9. An installation device for an audit plug-in, characterized in that: The device comprises: An information acquisition module is used to determine at least one candidate database server included in the target data platform, determine a target database server on which an audit plug-in needs to be installed from the candidate database servers, and obtain target server attribute information corresponding to the target database server; A compliance database server determination module is used to determine a compliance database server in the target data platform that has an audit plug-in installed, and obtain compliance server attribute information corresponding to the compliance database server; a risk database server determination module, configured to compare the target server attribute information with the compliant server attribute information, and determine a risk database server that does not have an audit plug-in installed from the target database server based on the information comparison result; The audit plug-in installation module is used to perform an audit plug-in installation operation on the risk database server.
10. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor. The computer program is executed by the at least one processor to enable the at least one processor to perform the audit plug-in installation method according to any one of claims 1 to 8.
11. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to execute the audit plug-in installation method according to any one of claims 1 to 8.
12. A computer program product, comprising a computer program, wherein when executed by a processor, the computer program implements the audit plug-in installation method according to any one of claims 1 to 8.