Database auditing method and device, equipment, medium and program product
By embedding native audit probes in the distributed database and utilizing global transaction identifiers and directed acyclic graph technology, the problem of cross-node operation tracing in dynamic sharding scenarios is solved, achieving efficient and non-intrusive database operation monitoring and auditing.
Patent Information
- Application Number
- CN202511023461.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-23
- Publication Date
- 2025-11-07
AI Technical Summary
In existing technologies, distributed databases lack the ability to track cross-node operations in dynamic sharding scenarios, resulting in high complexity. Furthermore, traditional solutions require the deployment of third-party proxies, leading to performance degradation and resource waste.
By capturing operation requests in real time through the built-in native audit probe of the target cluster, and using global transaction identifiers to associate the operation logs of each shard, a directed acyclic graph is constructed for auditing, achieving non-intrusive monitoring, reducing resource consumption, and supporting cross-shard operation tracing.
It enables cross-shard operation tracing in dynamic sharding scenarios, reduces the impact on database performance, avoids dependence on third-party proxies, and ensures the integrity and security of operations.
Smart Images

Figure CN120909890A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of computer, and particularly relates to a database auditing method and device, equipment, medium and program product. BACKGROUND
[0002] With the rapid development of information technology, as a core tool for information storage and management, databases play a vital role in various enterprises and organizations. At the same time, the security problem of the database is increasingly prominent. Therefore, how to effectively monitor and audit the operation of the database has become a problem to be solved.
[0003] It should be noted that the information disclosed in the above background section is only used to strengthen the understanding of the background of the present disclosure, and therefore can include information that does not constitute prior art known to those of ordinary skill in the art. SUMMARY
[0004] The purpose of the present disclosure is to provide a database auditing method, device, equipment, medium and program product, which at least solves the problem of monitoring and auditing the operation of the database in the prior art to some extent.
[0005] Other characteristics and advantages of the present disclosure will become apparent from the following detailed description, or will be learned by practice of the present disclosure.
[0006] According to a first aspect of the present disclosure, a database auditing method is provided, the method comprising:
[0007] capturing operation requests in real time through a built-in native auditing probe of a target cluster; the built-in native auditing probe is integrated in a component of the target cluster;
[0008] if the operation log is a cross-shard operation request, associating the operation log of each shard according to a global transaction identifier;
[0009] receiving an auditing request through the built-in native auditing probe;
[0010] auditing the associated operation log.
[0011] In a possible embodiment, the associating the operation log of each shard according to a global transaction identifier comprises:
[0012] determining a hash chain of the operation log of each shard;
[0013] storing the hash chain of each shard and confirming an anchor point;
[0014] constructing a first directed acyclic graph according to the global transaction identifier and the hash chain of each shard;
[0015] store the first directed acyclic graph based on the anchor point.
[0016] In a possible embodiment, the auditing the associated operation log comprises:
[0017] determining, through the anchor point, an update hash chain of the operation log of each shard;
[0018] judging whether each of the update hash chains is consistent with each of the hash chains stored in the first directed acyclic graph;
[0019] if consistent, confirming that the audit verification is passed;
[0020] if inconsistent, alarming.
[0021] In a possible embodiment, the method further comprises:
[0022] constructing a second directed acyclic graph according to the global transaction identifier, the hash chain of each shard, and the version number of each shard;
[0023] receiving a historical state rollback request;
[0024] initiating a historical state rollback according to the second directed acyclic graph.
[0025] In a possible embodiment, the method further comprises:
[0026] if the operation request is a structured query language operation request, parsing a structured query language syntax tree to obtain an original field;
[0027] judging whether the original field includes a sensitive field;
[0028] if yes, replacing the sensitive field with a hash value;
[0029] generating a desensitized operation log according to the hash value.
[0030] In a possible embodiment, the auditing the associated operation log comprises:
[0031] if the operation request is a cross-shard operation request and a structured query language operation request, obtaining a desensitized operation log of each shard;
[0032] auditing the associated desensitized operation log.
[0033] According to still another aspect of the present disclosure, there is provided a database auditing apparatus, comprising:
[0034] The receiving unit is configured to capture, in real time, an operation request through a built-in native audit probe of a target cluster.
[0035] The association unit is configured to, if the operation log is a cross-shard operation request, associate the operation logs of each shard according to a global transaction identifier.
[0036] The receiving unit is further configured to receive an audit request through the built-in native audit probe.
[0037] The audit unit is configured to audit the associated operation logs.
[0038] In a possible implementation, the database audit apparatus further includes:
[0039] The desensitization unit is configured to, if the operation request is a structured query language operation request, parse a structured query language syntax tree to obtain an original field.
[0040] Determine whether the original field includes a sensitive field.
[0041] If yes, replace the sensitive field with a hash value.
[0042] Generate a desensitized operation log according to the hash value.
[0043] According to still another aspect of the present disclosure, an electronic device is provided, including: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the method of any one of the first aspect via execution of the executable instructions.
[0044] According to still another aspect of the present disclosure, a computer readable storage medium is provided, having a computer program stored thereon, the computer program being executed by a processor to implement the method of any one of the first aspect.
[0045] According to still another aspect of the present disclosure, a computer program product or computer program is also provided, the computer program product or computer program including computer instructions stored in a computer readable storage medium. A processor of a computer device reads the computer instructions from the computer readable storage medium, and the processor executes the computer instructions to cause the computer device to perform the method of the first aspect.
[0046] The embodiment of the present disclosure provides a database auditing method, device, equipment, medium and program product, and relates to the technical field of computers.
[0047] It should be understood that the foregoing general description and the following detailed description are only exemplary and explanatory and are not restrictive of the present disclosure. BRIEF DESCRIPTION OF DRAWINGS
[0048] The accompanying drawings, which are incorporated into and form part of the specification, illustrate embodiments consistent with the present disclosure and, together with the description, serve to explain the principles of the disclosure. It is apparent that the drawings described below are only some embodiments of the present disclosure, and other drawings can be obtained according to these drawings without creative labor for those skilled in the art.
[0049] Figure 1 A flowchart of a database auditing method in the embodiment of the present disclosure is shown;
[0050] Figure 2 A flowchart of associating operation logs in the embodiment of the present disclosure is shown;
[0051] Figure 3 A flowchart of processing a cross-shard operation request in the embodiment of the present disclosure is shown;
[0052] Figure 4 A flowchart of an auditing process in the embodiment of the present disclosure is shown;
[0053] Figure 5 A flowchart of a desensitization process in the embodiment of the present disclosure is shown;
[0054] Figure 6 A flowchart of another database auditing method in the embodiment of the present disclosure is shown;
[0055] Figure 7 A structural schematic diagram of a database auditing device in the embodiment of the present disclosure is shown;
[0056] Figure 8 A structural schematic diagram of an electronic device in the embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0057] Example implementations will now be described more fully with reference to the accompanying drawings. Example implementations can be implemented in any
[0058] Moreover, the drawings are not necessarily to scale. Like numbers refer to like, similar or analogous items and steps throughout the drawings and text. Some of the diagrams shown in the drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities can be implemented in software, or in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0059] As in the related art, with the rapid development of information technology, databases as the core tool for information storage and management play a vital role in various enterprises and organizations. At the same time, the security problem of the database is increasingly prominent. Therefore, how to effectively monitor and audit the operation of the database has become a problem to be solved.
[0060] In the related art, the audit technology of a distributed database (such as StarDB) has the following problems:
[0061] 1. The operation chain is broken, the native database lacks the ability to track cross-node operations in the dynamic sharding scenario, the complexity is high, and it is easy to miss or misjudge.
[0062] 2. High performance loss: the traditional scheme needs to deploy a third-party agent (such as Fluentd) to collect logs, which is highly invasive, resulting in increased system complexity, performance loss and resource waste.
[0063] Based on this, the embodiments of the present disclosure provide a database audit method, device, equipment, medium and program product, relating to the technical field of computer, the method comprises: capturing operation requests in real time through a built-in native audit probe of a target cluster, the built-in native audit probe is integrated in a component of the target cluster, if the operation log is a cross-sharding operation request, then associating the operation log of each shard according to a global transaction identifier, receiving an audit request, and auditing the associated operation log. Through the above method, the probe integrated in the native component realizes non-intrusive audit, reduces resource occupation, reduces the impact on the performance of the database, avoids the dependence on the third-party agent, and can realize the tracking of cross-sharding operations in the dynamic sharding scenario.
[0064] Embodiments of the present disclosure are described for a database auditing method, which is specifically described as follows.
[0065] Figure 1 A flowchart of a database auditing method in an embodiment of the present disclosure is shown. As shown in Figure 1 , the method comprises the following steps:
[0066] S102: Real-time capture of operation requests through a built-in native auditing probe of a target cluster, the built-in native auditing probe being integrated in a component of the target cluster.
[0067] In a possible embodiment, the target cluster can be a distributed database cluster. The distributed database can be StarDB.
[0068] In a possible embodiment, the built-in native auditing probe is integrated in a component of the distributed database, and the component can be a Proxy or a Tablet. The operation requests are captured through the built-in native auditing probe. The shard routing metadata and the transaction status can also be captured in real time.
[0069] In a possible embodiment, the operation logs are collected through the built-in native auditing probe.
[0070] The operation requests can include at least one of the following: a structured query language (SQL) operation and a cross-shard operation request. The cross-shard operation request means that the operation request is between multiple shards. The cross-shard operation request can be a transfer request, for example, a financial transfer auditing scenario, a transfer deduction in a shard A, and an account entry in a shard B.
[0071] S104: If the operation log is a cross-shard operation request, associate the operation log of each shard according to a global transaction identifier.
[0072] In a possible embodiment, according to the cross-shard operation request, the operation log corresponding to each shard is obtained, and the operation log of each shard is associated according to the global transaction identifier.
[0073] Exemplarily, taking the cross-shard operation request of initiating a transfer from a shard A to a shard B as an example, a global transaction identifier (GTID) is generated through a Proxy component, an instruction for executing a deduction can be sent to the shard A through the Proxy component, an instruction for executing an account entry can be sent to the shard B, the shard A and the shard B respectively generate operation logs, and the operation logs of each shard are associated through the global transaction identifier.
[0074] S106: Receive an auditing request through the built-in native auditing probe.
[0075] S108: Audit the associated operation logs.
[0076] In this way, the probe integrated in the native component realizes non-intrusive auditing, reduces resource occupation, reduces the impact on database performance, avoids dependence on a third-party agent, and can realize tracking of cross-shard operations in a dynamic sharding scenario. When auditing, the global transaction identifier can be used to determine whether the data has been tampered with.
[0077] It should be noted that the operation log collection method can be implemented by a lightweight Sidecar agent, which has better performance than related art, but compared with the built-in native audit probe, part of the performance is sacrificed.
[0078] In S104, the operation logs of each shard are associated according to the global transaction identifier, which can include the following methods. Figure 2 A flowchart for associating operation logs in an embodiment of the present disclosure is shown as follows. Figure 2 As shown, the following steps are included.
[0079] S202: Determine the hash chain of the operation log of each shard.
[0080] In one possible embodiment, the hash chain of the operation log of each shard is independently generated, and the log hash is written. The hash chain can be: (H_i=SM3(H_{i-1}||Log_i)).
[0081] The hash chain of the operation log of shard A is denoted as H_A, and the hash chain of the operation log of shard B is denoted as H_B.
[0082] S204: Store the hash chain of each shard and confirm the anchor point.
[0083] In one possible embodiment, each shard writes the anchor point of the hash chain to a distributed key-value storage system (etcd), and the anchor point storage is confirmed by the Proxy component. It can also be stored in ZooKeeper.
[0084] S206: According to the global transaction identifier and the hash chain of each shard, a first directed acyclic graph is constructed.
[0085] S208: Store the first directed acyclic graph based on the anchor point.
[0086] In one possible embodiment, the global transaction identifier and the hash chain of each shard are associated to construct a first directed acyclic graph (DAG), and the first directed acyclic graph is submitted to etcd based on the anchor point.
[0087] The DAG can be represented as: {TX2024_v3: [H_A, H_B]}.
[0088] In this way, the anchor point is generated based on the hash chain, the log association processing is performed based on the global transaction identifier, and when the shard migration is performed, the log can also be tracked to ensure the integrity of the log chain of the cross-shard transaction.
[0089] Figure 3 A processing flow diagram of a cross-shard operation request in an embodiment of the present disclosure is shown, taking a cross-shard operation request of shard A initiating a transfer to shard B as an example, as shown in Figure 3 , including:
[0090] S302: The Proxy component receives a request to initiate a transfer and generates a global transaction identifier.
[0091] S304: The Proxy component sends an instruction to perform a deduction to shard A.
[0092] S306: The Proxy component sends an instruction to perform a deposit to shard B.
[0093] S308: The shard A generates an operation log and writes a hash chain of the operation log to the etcd.
[0094] S310: The shard B generates an operation log and writes a hash chain of the operation log to the etcd.
[0095] S312: The Proxy component confirms the anchor point storage.
[0096] S314: The Proxy component constructs a first directed acyclic graph according to the global transaction identifier and the hash chain of each shard.
[0097] S316: The Proxy component stores the directed acyclic graph based on the anchor point.
[0098] For the above embodiment, the associated operation log can be tracked to verify whether there is a data tampering problem.
[0099] In S108, the auditing process of the associated operation log can include the following ways, Figure 4 A flowchart of an auditing process in an embodiment of the present disclosure is shown, as shown in Figure 4 , including the following steps:
[0100] S402: Determine the updated hash chain of the operation log of each shard through the anchor point;
[0101] S404: Determine whether each updated hash chain is consistent with each hash chain stored in the first directed acyclic graph; if yes, perform S406; if no, perform S408.
[0102] S406: Confirm that the audit verification is passed.
[0103] S408: Alarm.
[0104] In the foregoing manner, transaction tracking of cross-shard operation requests can be completed, and when auditing is performed, correlation auditing can be performed to realize cross-node operation chain tracking in a dynamic sharding scenario.
[0105] In a possible embodiment, in the related art, shard topology changes cannot be recorded, and in the method of the embodiment of the present disclosure, the following method can be performed, which can include: constructing a second directed acyclic graph according to a global transaction identifier, a hash chain of each shard, and a version number of each shard, receiving a historical state backtracking request, and initiating historical state backtracking according to the second directed acyclic graph.
[0106] By constructing a DAG with a shard topology version and storing the DAG based on an anchor point to etcd, the version number of the shard is embedded in the DAG, the topology change of the shard is recorded, historical state backtracking is supported, and shard topology version tracking is supported.
[0107] In a possible embodiment, after shards A and B are re-sharded and expanded, shard A becomes A1 and A2, and shard B becomes B1 and B2, at this time, if shard A is migrated to shard A1 when the data corresponding to the cross-shard operation request is expanded, and shard B is migrated to shard B2 when the data corresponding to the cross-shard operation request is expanded, then backtracking can be performed according to the second directed acyclic graph, and when auditing is performed, accurate auditing and verification of the cross-shard operation request can still be completed.
[0108] Figure 5 A flowchart of a desensitization process in the embodiment of the present disclosure is shown, as shown in FIG. 8, including the following steps: Figure 5
[0109] S502: If the operation request is a structured query language operation request, parse the structured query language syntax tree to obtain an original field.
[0110] S504: Determine whether the original field includes a sensitive field, if yes, perform S506; if no, perform S510.
[0111] S506: Replace the sensitive field with a hash value.
[0112] S508: Generate a desensitization operation log according to the hash value.
[0113] S510: Generate an operation log.
[0114] In a possible embodiment, for any operation request, if it is a structured query language (SQL) operation request, after being captured by the built-in native audit probe, the SQL syntax tree is parsed, it is determined whether the sensitive field is included in the original field, the sensitive field is dynamically replaced according to the user role, and the hash value is recorded in the operation log to generate a desensitization operation log.
[0115] For example, if the user's mobile phone number is included in the original field, the mobile phone number is converted into a hash value through hash processing, and the generated content can be: mask (phone).
[0116] The hash processing can use SM3 hash calculation or SHA-256 conforming to the national standard.
[0117] For example, for data processing of medical data, the operation log generation scenario can need to be desensitized, the original field is replaced, and the hash and desensitization strategy are recorded. The desensitization strategy is stored in a role-based access control (RBAC) policy library.
[0118] In a possible embodiment, in S108, the auditing process of the associated operation log can include the following manner: if the operation request is a cross-shard operation request and a structured query language operation request, the desensitization operation log of each shard is obtained, and the associated desensitization operation log is audited.
[0119] In the above manner, in the operation log generation process, the integrity of the operation log is ensured through dynamic desensitization, and the problem of destroying integrity caused by static desensitization is avoided.
[0120] Figure 6 A flowchart of a database auditing method in the embodiment of the present disclosure is shown, taking an operation request as an SQL operation request and a cross-shard operation request as an example. As shown in Figure 6 the following steps are included:
[0121] S602: The operation request is captured in real time through the built-in native audit probe of the target cluster, and the built-in native audit probe is integrated in the component of the target cluster.
[0122] S604: The structured query language syntax tree is parsed to obtain the original field.
[0123] S606: The sensitive field in the original field is replaced by a hash value to generate a desensitization operation log.
[0124] The syntax tree is parsed by the SQL parsing engine to obtain the original field, and desensitization processing is performed to generate a desensitization operation log.
[0125] S608: Obtain the de-sensitization operation log of each shard, and determine the corresponding hash chain.
[0126] S610: Store the hash chain of each shard, and confirm the anchor point.
[0127] S612: According to the global transaction identifier, the hash chain of each shard and the version number of each shard, a directed acyclic graph is constructed.
[0128] S614: Based on the anchor point, the directed acyclic graph is stored.
[0129] S616: Receive an audit request through a built-in native audit probe.
[0130] S618: Query the corresponding anchor point, obtain the de-sensitization operation log of each shard, and recalculate the corresponding update hash chain.
[0131] S620: Determine whether each update hash chain is consistent with each hash chain stored in the directed acyclic graph; if yes, perform S622; if no, perform S624.
[0132] S622: Confirm that the audit verification is passed.
[0133] S624: Alarm.
[0134] The dynamic de-sensitization mechanism and cross-shard transaction tracking can be cooperatively processed. After capturing the operation request, de-sensitization is performed, and then association is performed. A "dynamic de-sensitization strategy-encryption hash-shard anchor point" three-tuple mechanism is adopted to realize the tracking capability of supporting cross-shard operation transactions, to ensure privacy and integrity, and to realize audit and verification, and to support the audit backtracking mechanism.
[0135] In a possible embodiment, the embodiments of the present disclosure further include intelligent analysis and compliance output, for example: risk-driven sampling, full-quantity recording for high-risk operations (such as delete operation DELETE), and reduced sampling (such as 1 / 10 frequency) recording for low-risk operations. For example: automated reporting, generating structured reports conforming to GDPR / China's network security protection level three through NLG technology.
[0136] Based on the same inventive concept as the above method embodiment, the embodiments of the present application also provide a database audit device. Figure 7 A structural schematic diagram of a database audit device provided by the embodiments of the present application is shown.
[0137] The device 70 comprises: a receiving unit 701, configured to capture an operation request by a built-in native audit probe of a target cluster; the built-in native audit probe is integrated into a component of the target cluster; an association unit 702, configured to, if the operation log is a cross-shard operation request, associate operation logs of each shard according to a global transaction identifier; a receiving unit 703, further configured to receive an audit request by the built-in native audit probe; and an auditing unit 704, configured to audit the associated operation logs.
[0138] Those skilled in the art can understand that each aspect of the present application can be implemented as a system, a method or a program product. Therefore, each aspect of the present application can be specifically implemented as follows: a complete hardware embodiment, a complete software embodiment (including firmware, microcode, etc.), or an embodiment combining hardware and software aspects, which can be collectively referred to as "circuitry", "module" or "system" here.
[0139] The electronic device 800 according to this embodiment of the present application will be described below with reference to Figure 8 Figure 8 The electronic device 800 shown is merely one example and should not be taken as limiting the scope of the present application embodiments.
[0140] As shown in Figure 8 The components of electronic device 800 can include, but are not limited to, at least one processing unit 810, at least one storage unit 820, and a bus 830 connecting the different system components, including the storage unit 820 and the processing unit 810.
[0141] The storage unit stores program codes which can be executed by the processing unit 810, so that the processing unit 810 performs the steps according to various exemplary embodiments of the present application described in the "Exemplary Method" section of the present specification.
[0142] The storage unit 820 can include a readable medium in the form of a volatile storage unit, such as a random access memory (RAM) 8201 and / or a cache memory 8202, and can further include a read-only memory (ROM) 8203.
[0143] The storage unit 820 can further include program / utility 8204 having a set of program modules 8205, including but not limited to, an operating system, one or more application programs, other program modules, and program data, each of which or a combination thereof can include implementation of a network environment.
[0144] Bus 830 can be one or more of several types of bus structure including a storage bus or a memory bus, a peripheral bus, a graphics bus, a processor or local bus using any of a variety of bus architectures including a memory, using a variety of bus architectures including Industry Standard Architecture (ISA), Micro Channel Architecture (MCA), Enhanced ISA (EISA), Video Electronics Standards Association (VESA) local bus, and PCI (peripheral component interconnect) bus.
[0145] Electronic device 800 can also communicate with one or more external devices 840 such as a keyboard or pointing device, a Bluetooth device, etc.; other devices that enable a user to interact with electronic device 800; and / or any devices (e.g., a router, a modem, a printer, etc.) that enable electronic device 800 to communicate with one or more other computing devices. Such communication can occur via Input / Output (I / O) interface 850. Still yet, electronic device 800 can communicate with one or more networks, such as one or more local area networks (LANs), one or more wide area networks (WANs), and / or the Internet, through network adapter 860. As an example, network adapter 860 can include a modem, a router, a switch or other known communication device(s) suitable for communication with a network. As illustrated, network adapter 860 can be communicatively coupled to bus 830 through a bus bridge 870. However, it should be understood that network adapter 860 can be directly coupled to bus 830, as shown in FIG. 1, or it can be coupled to bus 830 through another bus or through some other method of communication.
[0146] Those skilled in the art will readily understand that the example embodiments described herein can be implemented by software and / or by hardware coupled with software, as described above. Thus, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash disk, a mobile hard disk, or the like) or a network, and includes a number of instructions that cause a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to perform the methods according to the embodiments of the present disclosure.
[0147] In the example embodiments of the present disclosure, a computer readable storage medium is also provided, which stores a program product capable of implementing the above-mentioned method of the present disclosure. In some possible embodiments, various aspects of the present disclosure can also be implemented in the form of a program product, which includes program codes for causing a terminal device to perform the steps according to various example embodiments of the present disclosure described in the above-mentioned “example method” section of the present disclosure when the program product is run on the terminal device.
[0148] A program product for implementing the above-described method according to the embodiments of the present application is described, which can take a portable compact disc read-only memory (CD-ROM) and include a program code, and can be run on a terminal device, such as a personal computer. However, the program product of the present application is not limited to this, and in this document, the readable storage medium can be any tangible medium that contains or stores a program, which can be used by or in connection with an instruction execution system, apparatus, or device.
[0149] The program product can take any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium, for example, can be, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include an electrical connection having one or more wires, a portable disc, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0150] The computer readable signal medium can include a data signal propagated in baseband or propagated as a carrier wave, in which the readable program code is embodied. Such propagated data signal can take multiple forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. The readable signal medium can also be any readable medium that is not a readable storage medium, which can send, propagate, or transmit the program for use by or in connection with an instruction execution system, apparatus, or device.
[0151] The program code contained on the readable medium can be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, and the like, or any suitable combination of the above.
[0152] The program code may, through the use of any of a variety of programming languages, be implemented in any combination of machine, firmware, or software languages, including object oriented programming languages, such as Java, C++, etc., conventional procedural programming languages, such as the "C" programming language, or similar programming languages. The program code may execute entirely on the user's computing device, partly on the user's computing device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device or entirely on the remote computing device or server. In the latter scenario, the remote computing device can be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computing device, such as through the Internet using an Internet Service Provider (ISP).
[0153] It should be noted that, although several modules or units of the device for action execution are mentioned in the above detailed description, such a division is not mandatory. Indeed, according to embodiments of the present disclosure, features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, features and functions of one module or unit described above can be further divided into a plurality of modules or units.
[0154] Furthermore, although the various steps of the methods of the present disclosure are described in a particular order in the figures, this is not required or implied, nor is it required that all of the steps shown be performed in order to achieve the desired result. Additionally or alternatively, certain steps can be omitted, multiple steps can be combined into a single step, a single step can be broken into multiple steps, etc.
[0155] From the above description of the embodiments, those skilled in the art will readily perceive that the example embodiments described herein can be implemented by software and / or by hardware and / or by a combination of software and hardware. Accordingly, the technical solutions according to the embodiments of the present disclosure can be embodied in the form of a software product. The software product can be stored in a non-volatile storage medium, such as a CD-ROM, a USB flash drive, a mobile hard disk, etc., or a network, and includes a number of instructions for causing a computing device (such as a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the methods according to the embodiments of the present disclosure.
[0156] Other embodiments of the disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the features disclosed herein. It is intended that the specification and examples be considered as exemplary only, with a true scope and spirit of the disclosure being indicated by the following claims.
Claims
1. A database auditing method, characterized by, The method comprises: capturing operation requests in real time through an in-built native audit probe of a target cluster; the in-built native audit probe is integrated into a component of the target cluster; if the operation log is a cross-shard operation request, associating the operation log of each shard according to a global transaction identifier; receiving an audit request through the in-built native audit probe; auditing the associated operation log.
2. The method of claim 1, wherein, The associating the operation log of each shard according to a global transaction identifier comprises: determining a hash chain of the operation log of each shard; storing the hash chain of each shard and confirming an anchor point; constructing a first directed acyclic graph according to the global transaction identifier and the hash chain of each shard; storing the first directed acyclic graph based on the anchor point.
3. The method of claim 2, wherein, The auditing the associated operation log comprises: determining an updated hash chain of the operation log of each shard through the anchor point; judging whether each updated hash chain is consistent with each hash chain stored in the first directed acyclic graph; if consistent, confirming that the audit verification is passed; if inconsistent, alarming.
4. The method of claim 2, wherein, The method further comprises: constructing a second directed acyclic graph according to the global transaction identifier, the hash chain of each shard and a version number of each shard; receiving a historical state backtracking request; initiating historical state backtracking according to the second directed acyclic graph.
5. The method of claim 1, wherein, The method further comprises: if the operation request is a structured query language operation request, parsing a structured query language syntax tree to obtain an original field; judging whether the original field includes a sensitive field; if yes, replacing the sensitive field with a hash value; generating a desensitized operation log according to the hash value.
6. The method of claim 5, wherein, The auditing the associated operation log comprises: if the operation request is a cross-shard operation request and a structured query language operation request, obtaining a desensitized operation log of each shard; auditing the associated desensitized operation log.
7. A database auditing apparatus characterized by comprising: It comprises: a receiving unit configured to capture operation requests in real time through an in-built native audit probe of a target cluster; the in-built native audit probe is integrated into a component of the target cluster; an associating unit configured to, if the operation log is a cross-shard operation request, associate the operation log of each shard according to a global transaction identifier; the receiving unit is further configured to receive an audit request through the in-built native audit probe; an auditing unit configured to audit the associated operation log.
8. An electronic device, comprising: It comprises: a processor; and a memory for storing executable instructions of the processor; wherein the processor is configured to execute the method of any one of claims 1-6 via execution of the executable instructions.
9. A computer-readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the method of any one of claims 1-6.
10. A computer program product, comprising: Computer program or instructions, characterized in that the computer program or instructions are executed by the processor to implement the method of any one of claims 1-6.