A database security situation assessment and prediction method based on multi-dimensional indexes
By constructing a multi-level indicator system and a dynamic weight allocation situation assessment model, the problem of single and static indicators in existing database security assessment technologies is solved. This enables a comprehensive assessment and trend prediction of database security situation, and provides dynamic adjustment and forward-looking early warning.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-12
- Publication Date
- 2026-04-14
AI Technical Summary
Existing database security assessment methods rely on a single assessment indicator, which fails to reflect the dynamic changes in database security status in real time, lacks predictive capabilities, and has fixed indicator weights that cannot be dynamically adjusted, resulting in lagging security management.
A multi-level indicator system is constructed, and a dynamic weight allocation and situation assessment model are adopted. Combined with threat propagation path analysis, weight adaptive learning, and context-aware adjustment, a comprehensive assessment and trend prediction of database security situation is achieved.
It enables a comprehensive assessment and forward-looking early warning of database security posture, provides dynamically adjustable assessment strategies, improves the accuracy and adaptability of assessment, and provides the ability to predict future security posture.
Smart Images

Figure CN121309231B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a database security posture assessment and prediction method based on multi-dimensional indicators, applicable to database security management and risk assessment scenarios. Background Technology
[0002] With the rapid development of information technology, databases, as critical data storage and processing systems, carry the core data assets of enterprises and organizations, making their security an increasingly paramount concern for information system security. Traditional database security protection mainly relies on static access control, permission management, and encryption technologies, which are insufficient to cope with the increasingly complex security threat environment.
[0003] Existing database security assessment methods suffer from the following problems: First, the assessment indicators are singular, typically focusing only on vulnerability scan results or the compliance of access control policies, lacking a comprehensive assessment of the database security posture; second, the assessment methods are static, failing to reflect the dynamic changes in the database security status in real time, leading to lagging security management; third, they lack predictive capabilities, unable to anticipate the development trend of the security posture and unable to prepare for protection in advance; and finally, the indicator weights are fixed, failing to dynamically adjust the assessment strategy according to different security environments and threat situations.
[0004] In view of the above problems, there is an urgent need for a database security status assessment and prediction method that can comprehensively evaluate the database security status, dynamically adjust the assessment weights, monitor the security situation in real time, and predict future development trends. Summary of the Invention
[0005] The purpose of this invention is to provide a database security situation assessment and prediction method based on multi-dimensional indicators. By constructing a multi-level indicator system, dynamic weight allocation, real-time situation assessment and trend prediction, it can achieve a comprehensive assessment and forward-looking early warning of database security status, and provide decision support for database security management.
[0006] In a first aspect, the embodiments of this disclosure provide a database security posture assessment and prediction method based on multi-dimensional indicators, employing the following technical solution:
[0007] A multi-level indicator system is constructed, including risk indicators, vulnerability indicators, availability indicators, and reliability indicators. Asset data and operational data of the target database are collected. Based on dynamic weighting rules, a first weight for the asset data and a second weight for the operational data are determined. Based on the asset data, the operational data, the first weight, and the second weight, a database security value is calculated using a situation assessment model. Based on the asset data and the operational data, predicted asset data and predicted operational data of the target database are obtained using a situation prediction model. Based on the predicted asset data and the predicted operational data, a predicted database security value is calculated using the situation assessment model. Based on the database security value and the predicted database security value, an early warning is issued according to early warning rules.
[0008] Preferably, the step of collecting asset data and operational data from the target database, and determining a first weight for the asset data and a second weight for the operational data based on dynamic weighting rules, includes: establishing a multi-dimensional weight decision matrix to determine basic weights; outputting weight optimization coefficients through a threat propagation path analysis mechanism and a weight adaptive learning mechanism; determining the current operating status and business load mode of the database based on the asset data and the operational data; acquiring external threat intelligence, and determining the first weight and the second weight based on the basic weights and the weight optimization coefficients through context-aware weight adjustment rules.
[0009] Preferably, the asset data includes at least two of the following: number of vulnerabilities, weak password health, number of secure paths, percentage of sensitive data, memory utilization, CPU utilization, database configuration health, user permission integrity, security policy health, and database service lifespan. The operational data includes at least two of the following: risk events, attack events, request failure rate, sensitive data access volume, traffic, access volume, abnormal access volume, concurrency, latency, device mean time between failures, and response time. The establishment of a multi-dimensional weighted decision matrix to determine the basic weights includes: determining the first-level weight of the asset data and the second-level weight of the operational data based on threat level, business importance, historical attack patterns, and database access characteristics; determining the first and second-level weight reassemblies corresponding to the asset data based on business importance and historical attack patterns; determining the second and second-level weight reassemblies corresponding to the operational data based on threat level, historical attack patterns, and database access characteristics; and determining the basic weights based on the first-level weight, the first and second-level weight reassemblies, the second-level weight, and the second and second-level weight reassemblies.
[0010] Preferably, the step of outputting weight optimization coefficients through the threat propagation path analysis mechanism and the weight adaptive learning mechanism includes: establishing a mapping table between threat attack types and indicators; obtaining threat attack information within a first preset period, and determining a first weight optimization coefficient based on the mapping table between threat attack types and indicators; obtaining a second weight optimization coefficient within a second preset period, wherein the second weight optimization coefficient is generated by the weight adaptive learning mechanism at the end of the previous second preset period; and outputting weight optimization coefficients based on the first weight optimization coefficient and the second weight optimization coefficient.
[0011] Preferably, determining the first weight and the second weight based on the basic weight and the weight optimization coefficient using the context-aware weight adjustment rule includes: acquiring historical data corresponding to historical hazard indicators, historical vulnerability indicators, historical availability indicators, and historical reliability indicators; constructing a context-aware weight adjustment rule; determining the indicator weights corresponding to the hazard indicators, the vulnerability indicators, the availability indicators, and the reliability indicators based on the context-aware weight adjustment rule; and determining the first weight and the second weight based on the indicator weights, the basic weight, and the weight optimization coefficient.
[0012] Preferably, the risk indicators include risk events, attack events, and request failure rates; the vulnerability indicators include the number of vulnerabilities, password health, number of secure paths, proportion of sensitive data, and access volume of sensitive data; the availability indicators include traffic, access volume, abnormal access volume, concurrency, latency, memory utilization, and CPU utilization; and the reliability indicators include database configuration health, user permission integrity, security policy health, database service life, device fault-free time, and response time.
[0013] Preferably, the database security value includes a comprehensive value, a risk index value, a vulnerability index value, an availability index value, and a reliability index value. The step of calculating the database security value using a situation assessment model based on the asset data, the operational data, the first weight, and the second weight includes: performing time alignment and format standardization on the asset data and the operational data to obtain standard asset data and standard operational data; obtaining an initial database security value based on the standard asset data and the standard operational data using the scoring module in the situation assessment model; identifying the transmission influence coefficient of each indicator change on other indicators using the indicator causal dependency graph in the situation assessment model; obtaining an intermediate-level database security value based on the initial database security value and the transmission influence coefficient; determining whether the first confidence level of the intermediate-level database security value reaches a first confidence threshold using an outlier detection and correction mechanism and a cross-validation mechanism; and outputting the intermediate-level database security value as the database security value if it reaches the first confidence threshold.
[0014] Preferably, the step of obtaining predicted asset data and predicted operational data of the target database based on the asset data and the operational data through a situation prediction model includes: acquiring periodic asset data and periodic operational data within a third preset period; extracting data features from the periodic asset data, the periodic operational data, the asset data, and the operational data to obtain periodic patterns, trend characteristics, and abnormal fluctuation patterns; establishing a hierarchical prediction architecture to perform independent time series predictions on the risk indicators, vulnerability indicators, availability indicators, and reliability indicators; predicting the asset data and operational data of the target database to obtain initial predicted asset data and initial predicted operational data; calculating a second confidence level of the initial predicted asset data and the initial predicted operational data based on data relationship constraints and indicator constraints; determining whether the second confidence level reaches a second confidence level threshold; and if it reaches the second confidence level threshold, outputting the initial predicted asset data and the initial prediction as the predicted asset data and the predicted operational data.
[0015] Preferably, the step of calculating the database predicted safety value based on the predicted asset data and the predicted operation data through the situation assessment model includes: setting a confidence interval for the predicted data; inputting the confidence interval of the predicted data, the predicted asset data, and the predicted operation data into the situation assessment model to obtain the original database predicted safety value and the uncertainty quantification value; obtaining the verification database predicted safety value based on a simple prediction method using trend extrapolation; constructing a prediction result cross-validation mechanism to compare and verify the original database predicted safety value with the verification database predicted safety value; when the verification result meets a preset condition, outputting the original database predicted safety value as the database predicted safety value; when the verification result does not meet the preset condition, determining whether the number of calculations is less than a threshold; if so, then again based on the asset data and the operation data, through the situation prediction model, obtaining the predicted asset data and the predicted operation data of the target database, and again obtaining the original database predicted safety value, until the verification result meets the preset condition; if not, then outputting the original database predicted safety value with the lowest uncertainty quantification value and the last calculated original database predicted safety value as the database predicted safety value.
[0016] Preferably, the step of initiating an early warning based on the database security value and the predicted database security value, according to early warning rules, includes: constructing a multi-level early warning threshold system, setting different early warning trigger values and corresponding strategies based on the database business importance and historical security baseline; the step of initiating an early warning according to the early warning rules includes triggering an early warning when any of the following conditions are met: analyzing the rate of change and / or acceleration of the comprehensive value in the database security value, and triggering an early warning when the frequency and / or acceleration of the change in the database security value exceeds the frequency threshold and / or speed threshold; constructing a correlational early warning mechanism, triggering an early warning when any one of the danger index value, the vulnerability index value, the availability index value, and the reliability index value in the database security value exceeds the corresponding single warning line; and triggering an alarm when the predicted database security value reaches the predicted warning line.
[0017] Secondly, this disclosure also provides a database security posture assessment and prediction system based on multi-dimensional indicators, including,
[0018] A multi-level indicator system construction module is used to construct a multi-level indicator system, which includes risk indicators, vulnerability indicators, availability indicators, and reliability indicators.
[0019] The data acquisition module collects asset data and operational data from the target database, and determines a first weight for the asset data and a second weight for the operational data based on dynamic weighting rules.
[0020] The security assessment module is used to calculate the database security value based on the asset data, the operational data, the first weight, and the second weight, using a situation assessment model.
[0021] The data prediction module is used to obtain the predicted asset data and predicted operational data of the target database based on the asset data and the operational data, through a situation prediction model.
[0022] The security prediction module calculates the database predicted security value based on the predicted asset data and the predicted operation data through the situation assessment model.
[0023] The early warning module is used to initiate an early warning based on the database security value and the database predicted security value, according to the early warning rules.
[0024] Thirdly, this disclosure also provides a computer device, which adopts the following technical solution:
[0025] The computer device includes:
[0026] At least one processor; and,
[0027] A memory communicatively connected to the at least one processor; wherein,
[0028] The memory stores instructions that can be executed by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform any of the above-described database security posture assessment and prediction methods based on multi-dimensional indicators.
[0029] Fourthly, embodiments of this disclosure also provide a computer-readable storage medium storing computer instructions for causing a computer to execute any of the above-described database security posture assessment and prediction methods based on multi-dimensional indicators.
[0030] Fifthly, embodiments of this disclosure also provide a computer program product, including a computer program / instructions that, when executed by a processor, implement the steps of any of the methods described above.
[0031] The beneficial effects of the database security posture assessment and prediction method and system based on multi-dimensional indicators provided in this disclosure are as follows:
[0032] 1. A multi-level indicator system including risk indicators, vulnerability indicators, availability indicators, and reliability indicators has been established, enabling a comprehensive assessment of the database security posture;
[0033] 2. A dynamic weight allocation mechanism has been introduced, which can adaptively adjust the weight of various indicators according to changes in the threat environment, business conditions and historical attack patterns, thereby improving the accuracy and adaptability of the assessment.
[0034] 3. Through the situation prediction model, the future security situation of the database can be predicted, providing a forward-looking security situation awareness capability and providing decision support for security management personnel;
[0035] 4. A multi-level early warning threshold system has been established. Based on the changing trends of database security values and predicted security values, the system automatically triggers security warnings at the corresponding levels, thus achieving early warning of security risks.
[0036] The above description is merely an overview of the technical solution disclosed herein. In order to better understand the technical means of this disclosure and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this disclosure more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0037] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0038] Figure 1 A flowchart illustrating the database security posture assessment and prediction method based on multi-dimensional indicators provided in this embodiment of the disclosure;
[0039] Figure 2 This is a schematic diagram of the structure of a database security posture assessment and prediction system based on multi-dimensional indicators;
[0040] Figure 3 This is a schematic diagram of the structure of a computer device provided in an embodiment of the present disclosure. Detailed Implementation
[0041] The embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.
[0042] It should be understood that the following specific examples illustrate the implementation of this disclosure, and those skilled in the art can easily understand other advantages and effects of this disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of this disclosure, and not all of them. This disclosure can also be implemented or applied through other different specific implementation methods, and the details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of this disclosure. It should be noted that, in the absence of conflict, the following embodiments and features in the embodiments can be combined with each other. Based on the embodiments in this disclosure, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this disclosure.
[0043] It should be noted that various aspects of embodiments within the scope of the appended claims are described below. It will be apparent that the aspects described herein can be embodied in a wide variety of forms, and any particular structure and / or function described herein is merely illustrative. Based on this disclosure, those skilled in the art will understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects set forth herein can be used to implement the device and / or practice the method. Additionally, this device and / or method can be implemented using structures and / or functionalities other than one or more of the aspects set forth herein.
[0044] It should also be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of this disclosure. The drawings only show the components related to this disclosure and are not drawn according to the number, shape and size of the components in actual implementation. In actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.
[0045] Furthermore, specific details are provided in the following description to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.
[0046] like Figure 1 As shown, this embodiment provides a database security posture assessment and prediction method based on multi-dimensional indicators, including the following steps:
[0047] Step S1: Construct a multi-level indicator system, which includes risk indicators, vulnerability indicators, availability indicators, and reliability indicators;
[0048] Step S2: Collect asset data and operational data from the target database, and determine the first weight of the asset data and the second weight of the operational data based on dynamic weighting rules;
[0049] Step S3: Based on the asset data, the operational data, the first weight, and the second weight, calculate the database security value using the situation assessment model;
[0050] Step S4: Based on the asset data and the operational data, obtain the predicted asset data and predicted operational data of the target database through the situation prediction model;
[0051] Step S5: Based on the predicted asset data and the predicted operational data, calculate the database predicted security value using the situation assessment model;
[0052] Step S6: Based on the database security value and the database predicted security value, initiate an early warning according to the early warning rules.
[0053] In this embodiment, in step S1, a multi-level indicator system is constructed, which includes risk indicators, vulnerability indicators, availability indicators, and reliability indicators.
[0054] The risk indicators include risk events, attack events, and request failure rates.
[0055] Risk events refer to events that may threaten database security, such as multiple consecutive failed login attempts for a database account or abnormal access to sensitive tables. Attack events refer to events in which the database is maliciously attacked, such as detecting SQL injection attempts or malicious calls to stored procedures. Request failure rate refers to the number or percentage of database connection failures, such as a database connection failure rate exceeding 5% or a query timeout rate exceeding 10%.
[0056] The vulnerability indicators include the number of vulnerabilities, password health, number of secure paths, proportion of sensitive data, and access volume of sensitive data.
[0057] Vulnerability count refers to the number of unpatched vulnerabilities in the database, such as the number of unpatched CVE-2022-21445 vulnerabilities in the Oracle database; Password health refers to the percentage of complex passwords, such as 15% of accounts whose password complexity does not meet the requirements; Number of secure paths refers to the number or percentage of secure paths in the data access paths of the database, such as 10 paths to access ID card information in the database, of which 9 are secure paths, accounting for 90%; Sensitive data ratio refers to the proportion of sensitive data in the database to the total data volume. Sensitive data includes personal ID card information, iris information, etc., such as personal identity information and payment card data accounting for 35% of the total data volume. Sensitive data can be set according to different application scenarios, and there is no limit here; Sensitive data access volume refers to the number of times, frequency, or proportion exceeding the normal baseline for accessing sensitive data, such as the core transaction table being queried more than 20% of the normal baseline per hour.
[0058] The availability metrics include traffic (e.g., 5,000 database requests per second), access volume (e.g., more than 100,000 queries per hour for the core transaction table), abnormal access volume (e.g., a 200% surge in database access volume outside of working hours), concurrency (e.g., the number of concurrent database connections reaching 85% of the capacity limit during peak periods), latency (e.g., query response time increasing from an average of 50ms to 200ms), memory utilization (e.g., database server memory utilization consistently remaining above 92%), and CPU utilization (e.g., database instance CPU utilization reaching 75% during peak business periods).
[0059] Reliability metrics include database configuration health (e.g., 92% of database parameters conform to security best practices), user permission integrity (e.g., the reasonableness score of privileged account permission allocation is 85 points), security policy health (e.g., audit policy coverage reaches 95%, and backup policy execution success rate is 98%), database service uptime (e.g., continuous uptime of database instances reaches 99.95%), device fault-free time (e.g., no hardware failure record of database server within 30 days), and response time (e.g., the average response time of standard queries remains within 50ms).
[0060] It should be noted that the information corresponding to the above indicators may be obtained directly from the information collected from the database, or it may need to be calculated, such as the number of sensitive data collected and the total amount of data in the database, and the calculation of the proportion of sensitive data.
[0061] By establishing such a multi-level indicator system, the security status of the database system can be comprehensively reflected, covering four dimensions: security threats, system vulnerability, business availability, and system reliability.
[0062] In this embodiment, step S2, which involves collecting asset data and operational data from the target database and determining the first weight of the asset data and the second weight of the operational data based on dynamic weighting rules, includes:
[0063] Step S21: Establish a multi-dimensional weight decision matrix and determine the basic weights.
[0064] In this embodiment, asset and operational data of the target database are collected, including: collecting SQL execution logs and user access records through a database auditing system; collecting database vulnerability information and configuration baseline check results using security scanning tools; deploying a monitoring agent to obtain performance indicators such as CPU utilization, memory usage, and I / O; connecting to the SIEM system to collect security event alarms; and directly obtaining static information such as user permission lists, stored procedure configurations, and backup status from the database management system. The target database refers to the database to be analyzed and predicted.
[0065] In another embodiment, for financial databases, the focus is on collecting the frequency of access to sensitive tables and records of permission changes; for e-commerce systems, the focus is on monitoring the changing trends of concurrent connections, query response time, and transaction throughput.
[0066] In this embodiment, in step S21, the asset data includes at least two of the following: number of vulnerabilities, weak password health, number of secure paths, percentage of sensitive data, memory utilization, CPU utilization, database configuration health, user permission integrity, security policy health, and database service lifespan; the runtime data includes at least two of the following: risk events, attack events, request failure rate, sensitive data access volume, traffic, access volume, abnormal access volume, concurrency, latency, device mean time between failures, and response time.
[0067] The establishment of a multi-dimensional weighted decision matrix and the determination of basic weights include:
[0068] Step S211: Based on threat level, business importance, historical attack patterns, and database access characteristics, determine the first-level weight of the asset data and the second-level weight of the operational data.
[0069] For example, when a high-risk threat originates from a database vulnerability, asset data is of higher importance, so the first-level weight is set to 0.6 and the second-level weight to 0.4. Similarly, for financial databases, the focus is on the frequency of access to sensitive tables and permission change records; for e-commerce systems, the focus is on concurrent connection counts and operational data, which are more important, so the first-level weight is set to 0.7 and the second-level weight to 0.3. These are just examples; the first and second-level weights can be dynamically generated based on a multi-dimensional weight decision matrix according to specific application scenarios and real-time data.
[0070] Step S212: Based on the business importance and the historical attack patterns, determine the first and second-level rights reorganization corresponding to the asset data.
[0071] In this embodiment, asset data includes, for example, four types: number of vulnerabilities, percentage of sensitive data, memory utilization, and user permission integrity. Based on the business focus on sensitive data security and historical attack patterns (vulnerability attacks), first and second level permission groups are set [0.35, 0.35, 0.1, 0.2]. This is only an example; the first and second level weighted reorganizations can be dynamically generated based on a multi-dimensional weighted decision matrix according to specific application scenarios and real-time data.
[0072] Step S213: Based on the threat level, the historical attack pattern, and the database access characteristics, determine the second-level priority reassembly corresponding to the running data.
[0073] For example, the operational data includes five types: risk events, attack events, request failure rate, sensitive data access volume, and concurrency. Based on the focus on external attacks and concurrent access, second and third-level permission groups are set [0.1, 0.25, 0.15, 0.2, 0.3].
[0074] Step S214: Determine the basic weights based on the first primary weight, the first secondary weight reorganization, the second primary weight, and the second secondary weight reorganization.
[0075] For example, if the first level weight is 0.6, the second level weight is 0.4, the first and second level permission groups are [0.35, 0.35, 0.1, 0.2], and the second and second level permission groups are [0.1, 0.25, 0.15, 0.2, 0.3], then the basic weights are [0.21, 0.21, 0.06, 0.12, 0.04, 0.1, 0.06, 0.08, 0.12].
[0076] Step S22: Output weight optimization coefficients through threat propagation path analysis mechanism and weight adaptive learning mechanism.
[0077] In this embodiment, step S22 includes: establishing a threat attack type and indicator association mapping table; obtaining threat attack information within a first preset period; determining a first weight optimization coefficient based on the threat attack type and indicator association mapping table; obtaining a second weight optimization coefficient within a second preset period, wherein the second weight optimization coefficient is generated by a weight adaptive learning mechanism at the end of the previous second preset period; and outputting a weight optimization coefficient based on the first weight optimization coefficient and the second weight optimization coefficient.
[0078] For example, an attack type and indicator mapping table is established, with the week as the first preset period. When an SQL injection attack is detected in the previous week, the weight of sensitive data access volume is increased by 20%, when a vulnerability attack is detected, the weight of the number of vulnerabilities is increased by 30%, and when a privilege escalation attack is detected, the weight of user privilege integrity is increased by 25%, thus obtaining the first weight optimization coefficient [1.3, 1, 1, 1.25, 1, 1, 1, 1.2, 1].
[0079] Using a month as the second preset period, the early warning accuracy and false alarm rate of each weight configuration scheme in the previous month are statistically analyzed. The weight combination with an accuracy higher than 85% and a false alarm rate lower than 10% is selected as the preferred scheme. The weight value of the preferred scheme is used as the second weight optimization coefficient, such as [0.1, 0.1, 0.1, 0.1, 0.1, 0.1, 0.1, 0.1, 0.2].
[0080] Based on the first weight optimization coefficient [1.3, 1, 1, 1.25, 1, 1, 1, 1.2, 1] and the second weight optimization coefficient [0.1, 0.1, 0.1, 0.1, 0.1, 0.1, 0.1, 0.1, 0.2], the weight optimization coefficient [0.13, 0.1, 0.1, 0.125, 0.1, 0.1, 0.1, 0.1, 0.12, 0.2] is obtained.
[0081] An innovative threat propagation path analysis mechanism is introduced. When a specific type of attack is detected, the system can predict the possible direction and scope of attack spread and intelligently adjust the weight allocation of relevant data sources accordingly. A weight adaptive learning mechanism is established. By analyzing the early warning effect of different weight configurations in historical security events, the weight allocation strategy is continuously optimized, enabling the system to learn the optimal weight combination pattern from past experience.
[0082] Step S23: Determine the current operating status and business load mode of the database based on the asset data and the operating data.
[0083] In this embodiment, performance metrics such as CPU utilization, memory utilization, and I / O wait time are analyzed to determine whether the database is under high load (e.g., CPU utilization > 80%), normal load (e.g., CPU utilization 30%-80%), or low load (e.g., CPU utilization < 30%). By analyzing the hourly query volume distribution, peak business periods (e.g., 9:00-11:00 and 14:00-16:00 on weekdays), off-peak periods, and low-peak periods are identified. Combining the number of concurrent connections and transaction processing volume, transaction-intensive (e.g., payment processing periods), query-intensive (e.g., report generation periods), or mixed load patterns are distinguished.
[0084] Step S24: Obtain external threat intelligence, and determine the first weight and the second weight based on the basic weight and the weight optimization coefficient through the context-aware weight adjustment rule.
[0085] In this embodiment, step S24 includes acquiring historical data corresponding to historical hazard indicators, historical vulnerability indicators, historical availability indicators, and historical reliability indicators, and constructing context-aware weight adjustment rules; determining the indicator weights corresponding to the hazard indicators, the vulnerability indicators, the availability indicators, and the reliability indicators based on the context-aware weight adjustment rules; and determining the first weight and the second weight based on the indicator weights, the basic weights, and the weight optimization coefficients.
[0086] For example, analyzing database security incident records over the past 6 months reveals a 30% increase in risk events during peak business periods (such as month-end settlement). Based on this, when similar peak business periods are detected, the risk indicator weight is automatically increased by 15%. By analyzing historical vulnerability exploitation patterns, rules are established to increase the vulnerability indicator weight by 25% within 48 hours of newly released high-risk CVE vulnerabilities. Based on historical performance monitoring data, when the number of concurrent database connections reaches the historical 90th percentile, the availability indicator weight is increased by 20%. According to past system maintenance records, the reliability indicator weight is increased by 10% within 24 hours after planned maintenance to more sensitively monitor post-maintenance stability.
[0087] Based on the context-aware weight adjustment rules, and the current external threats, operating status, and business load patterns faced by the database, determine the corresponding weights of the risk indicators, vulnerability indicators, availability indicators, and reliability indicators, for example, [1, 1, 1, 1.5].
[0088] Based on the indicator weights [1, 1, 1, 1.5] and the basic weights [0.21, 0.21, 0.06, 0.12, 0.04, 0.1, 0.06, 0.08, 0.12], the user permission integrity among the data corresponding to the basic weights is a reliability indicator. Weights are increased according to the indicator weights, and combined with the weight optimization coefficients [0.13, 0.1, 0.1, 0.125, 0.1, 0.1, 0.1, 0.12, 0.2], and normalized to obtain the first weight and the second weight. In this embodiment, the first weight is the first four digits, and the second weight is the last five digits.
[0089] Build a context-aware weight adjustment function to adjust the weight allocation strategy in real time based on the current operating status of the database, business load mode, and external threat intelligence, so as to achieve dynamic matching between weight configuration and security posture.
[0090] In this embodiment, in step S1, a multi-level indicator system is constructed, which includes risk indicators, vulnerability indicators, availability indicators, and reliability indicators.
[0091] Step S3: Based on the asset data, the operational data, the first weight, and the second weight, calculate the database security value using the situation assessment model.
[0092] In this embodiment, the database security values include comprehensive values, risk index values, vulnerability index values, availability index values, and reliability index values.
[0093] Step S3 includes:
[0094] Step S31: Perform time alignment and format standardization on the asset data and the operation data to obtain standard asset data and standard operation data.
[0095] Specifically, the raw data is first standardized by converting the index values of different dimensions into standard scores of 0-100 to obtain standard asset data and standard operation data.
[0096] Step S32: Based on the standard asset data and the standard operation data, obtain the initial database security value through the scoring module in the situation assessment model.
[0097] Specifically, the standardized index values are multiplied by their corresponding weights to obtain a weighted score. Then, the scores are summarized according to the four dimensions of risk, vulnerability, availability, and reliability. The model outputs an initial database security value based on a multi-dimensional index system. This security value includes a comprehensive score and four sub-scores: risk index, vulnerability index, availability index, and reliability index. All scores are based on a 0-100 scale, with higher scores indicating better security in the corresponding dimension.
[0098] Step S33: Identify the transmission influence coefficient of each indicator change on other indicators through the indicator causal dependency graph in the situation assessment model.
[0099] Specifically, the causal dependency graph is a structured model describing the interrelationships between database security indicators. For example, in a core financial transaction database, when a 30% increase in SQL injection attacks is detected, the graph automatically identifies that this will lead to a 25% increase in access to sensitive data and a 15% decrease in database configuration health. In an e-commerce platform database, when CPU utilization consistently exceeds 90%, the graph shows that this will cause a 35% increase in response time and may lead to a 22% decrease in concurrent connections. In a medical system database, when the frequency of user permission changes increases abnormally (e.g., a 200% increase within 24 hours), the graph determines through causal relationships that access to sensitive patient data will increase by 40% within 48 hours and accordingly increases the weight of relevant monitoring indicators.
[0100] Step S34 yields the intermediate database security value based on the initial database security value and the transmission influence coefficient.
[0101] For example, in a core financial transaction database, when the initial security value shows that the number of vulnerabilities increases from 2 to 8 (the initial vulnerability index value decreases from 85 to 72), the propagation impact coefficient calculation shows that this will lead to a decrease of 7 points in the danger index value (from 88 to 81) and a decrease of 5 points in the reliability index value (from 90 to 85). In the evaluation of an e-commerce platform database, when the CPU utilization rate increases from 65% to 92% (the initial availability index value decreases from 83 to 68), the system automatically applies the propagation impact coefficient to calculate that the increased response time leads to a decrease of 8 points in the reliability index value (from 85 to 77). For a government system database, when the frequency of user permission changes increases abnormally by 300% within 24 hours, the system calculates through the propagation relationship that the increased access to sensitive data causes a decrease of 12 points in the danger index value, thus obtaining a more accurate intermediate security value.
[0102] One feasible implementation is to construct a scoring calculation function to calculate the sub-scores across four dimensions, return the complete scoring results, and define a causal relationship matrix between the indicators, such as:
[0103] 'Hazard Index Value': {'Vulnerability Index Value': 0.15, 'Availability Index Value': 0.2}
[0104] Vulnerability Index Value: {Vulnerability Index Value: 0.25, Reliability Index Value: 0.1}
[0105] 'Availability metric value': {'Reliability metric value': 0.3}
[0106] 'Reliability metric value': {'Availability metric value': 0.25}
[0107] By applying causal influences, the overall value and the values of each indicator are recalculated.
[0108] Step S35: Determine whether the first confidence level of the intermediate database security value reaches the first confidence level threshold through the outlier detection and correction mechanism and the cross-validation mechanism.
[0109] Specifically, the mean and standard deviation of historical data are calculated, outliers are detected and corrected, a first confidence threshold is set based on the mean and standard deviation, and it is determined whether the corrected intermediate database security value reaches the first confidence threshold.
[0110] Step S36: If the first confidence threshold is reached, output the intermediate database security value as the database security value.
[0111] If the first confidence threshold is not reached, the intermediate database security value can be output as the database security value and explained. Alternatively, the process can return to S2, reconfirm the first weight and the second weight, and recalculate the database security value.
[0112] The model outputs a database security value based on a multi-dimensional indicator system. This security value includes a comprehensive score and four sub-scores: risk index, vulnerability index, availability index, and reliability index. A cross-validation mechanism is established between the sub-scores. When a logical contradiction occurs between the sub-score and the comprehensive score, a secondary verification is triggered to ensure the consistency and credibility of the evaluation results.
[0113] In this embodiment, step S4, based on the asset data and the operational data, obtains the predicted asset data and predicted operational data of the target database through a situation prediction model. This includes: acquiring periodic asset data and periodic operational data within a third preset period; extracting features from the periodic asset data, the periodic operational data, the asset data, and the operational data to obtain periodic patterns, trend characteristics, and abnormal fluctuation patterns; establishing a hierarchical prediction architecture to perform independent time series predictions on the risk indicators, vulnerability indicators, availability indicators, and reliability indicators; predicting the asset data and operational data of the target database to obtain initial predicted asset data and initial predicted operational data; calculating the second confidence level of the initial predicted asset data and the initial predicted operational data based on data relationship constraints and indicator constraints; determining whether the second confidence level reaches a second confidence level threshold; and if it reaches the second confidence level threshold, outputting the initial predicted asset data and the initial prediction as the predicted asset data and the predicted operational data.
[0114] Specifically, the situation prediction model employs a multimodal data fusion mechanism, performing time-series alignment and feature engineering on historical data at different time granularities to extract periodic patterns, trend characteristics, and abnormal fluctuation patterns of data changes. The prediction model adopts a hierarchical prediction architecture, first performing independent time-series predictions on each secondary indicator, and then performing constraint optimization based on the historical correlation between primary indicators to ensure that the prediction results maintain logical rationality across all dimensions.
[0115] Based on data relationship constraints and indicator constraints, a second confidence level is calculated. For example, in a financial database, when the prediction model outputs that CPU utilization will increase from 65% to 95%, while the response time only increases from 30ms to 35ms, the system identifies this as a violation of the data relationship constraint that "when CPU utilization exceeds 90%, the response time usually increases by at least 50%", and reduces the confidence level of the prediction by 25%. For an e-commerce database, when the prediction shows that the number of vulnerabilities increases from 2 to 8 but the number of risk events remains unchanged, it violates the indicator constraint that "the number of high-risk vulnerabilities is positively correlated with the number of risk events", and reduces the confidence level by 30%. In the evaluation of a medical database, when the prediction results show that the access volume of sensitive data suddenly increases by 200% at night, but the abnormal access volume only increases by 5%, the system determines that this violates historical statistical patterns and reduces the confidence level from 0.85 to 0.62, which is lower than the preset second confidence level threshold of 0.75.
[0116] If the second confidence threshold is not reached, the prediction is recalculated and the constraints are adjusted. Alternatively, the result can be directly output with an explanation.
[0117] In this embodiment, the third preset period can be 6 months or 1 year, and there is no limitation here.
[0118] In this embodiment, step S5 calculates the database prediction safety value based on the predicted asset data and the predicted operation data using the situation assessment model. This includes setting a confidence interval for the predicted data, inputting the confidence interval, the predicted asset data, and the predicted operation data into the situation assessment model to obtain the original database prediction safety value and uncertainty quantification value; obtaining a verification database prediction safety value based on a simple prediction method using trend extrapolation; constructing a prediction result cross-validation mechanism to compare and verify the original database prediction safety value with the verification database prediction safety value; when the verification result meets a preset condition, outputting the original database prediction safety value as the database prediction safety value; when the verification result does not meet the preset condition, determining whether the number of calculations is less than a threshold; if so, then again based on the asset data and the operation data, using the situation prediction model, obtaining the predicted asset data and the predicted operation data of the target database, and obtaining the original database prediction safety value again, until the verification result meets the preset condition; if not, then outputting the original database prediction safety value with the lowest uncertainty quantification value and the last calculated original database prediction safety value as the database prediction safety value.
[0119] For example, in a core financial transaction database, the system sets a 95% confidence interval for the predicted data. The predicted CPU utilization (expected to increase from 65% to 88% ± 5%) and response time (expected to increase from 30ms to 45ms ± 8ms) are input into the situation assessment model, yielding an initial predicted safety value of 72 points and an uncertainty quantification value of 0.15. Simultaneously, a simple linear regression is used to obtain a validation predicted safety value of 75 points. The cross-validation mechanism detects a difference of 4.2%, lower than the preset 5% threshold, therefore the initial predicted safety value of 72 points is accepted as the final output. In e-commerce database prediction, when the difference between the initial predicted safety value (68 points) and the validation predicted safety value (78 points) reaches 14.7%, exceeding the preset threshold, the system automatically performs a second round of prediction calculations until the third round of prediction results meet the validation conditions, ultimately outputting a predicted safety value of 70 points as the decision-making basis.
[0120] In this embodiment, step S6, based on the database security value and the predicted database security value, initiates an early warning according to the early warning rules. This includes constructing a multi-level early warning threshold system and setting different early warning trigger values and corresponding strategies based on the database business importance and historical security baseline. Initiating an early warning according to the early warning rules includes triggering an early warning when any of the following conditions are met: analyzing the rate of change and / or acceleration of the comprehensive value in the database security value; triggering an early warning when the frequency and / or acceleration of the database security value exceeds a frequency threshold and / or a speed threshold; constructing a correlational early warning mechanism; triggering an early warning when any one of the danger index value, vulnerability index value, availability index value, and reliability index value in the database security value exceeds the corresponding single warning line; and triggering an alarm when the predicted database security value reaches the predicted warning line.
[0121] Specifically, the early warning rule engine constructs a multi-level early warning threshold system. Based on the importance of the database business and historical security baselines, it sets early warning trigger conditions of varying severity, including four levels: green (normal), yellow (attention), orange (warning), and red (severe). Each level corresponds to a different security value range and response strategy. The early warning system not only monitors whether the current security value crosses the threshold, but more importantly, it analyzes the rate and acceleration of change of the security value. When a rapidly deteriorating security situation is detected, an early warning is triggered in advance, avoiding the lag problem of responding only after the threshold is actually crossed. When the security value falls below the preset threshold or a prediction indicates that the security situation will deteriorate, the system automatically triggers the corresponding level of security warning and initiates corresponding security response measures based on the warning type. These measures include a tiered response mechanism such as automatically adjusting security policy configurations, increasing monitoring frequency, initiating emergency response procedures, and notifying relevant security management personnel, ensuring timely and effective responses to various security threats.
[0122] For example, for a core financial transaction database, green (normal) corresponds to a security score of 90-100, requiring no special handling; yellow (attention) corresponds to 75-89, requiring increased monitoring frequency; orange (warning) corresponds to 60-74, requiring security strategy optimization; and red (severe) corresponds to 0-59, requiring immediate execution of the emergency response plan. The early warning system not only monitors whether the current security value crosses the threshold, but more importantly, it analyzes the rate and acceleration of change in the security value. When a rapidly deteriorating security situation is detected, an early warning is triggered, avoiding the lag problem of responding only after the threshold is actually crossed. For example, when the security value of an e-commerce platform's database drops from 85 to 78 within 24 hours, although still within the yellow range, the rate of decline exceeds the preset threshold, and the system will automatically upgrade the warning level to orange (warning). When the security value falls below the preset threshold or the security situation is predicted to deteriorate, the system automatically triggers the corresponding level of security warning and initiates corresponding security response measures based on the warning type. These measures include automatically adjusting security policy configurations (such as restricting sensitive operations during unusual periods), increasing monitoring frequency (from once per hour to once every 5 minutes), initiating emergency response procedures (such as automatically switching to the backup system when a medical database is attacked), and notifying relevant security management personnel (notifying different levels of management personnel according to the warning level). These tiered response mechanisms ensure that various security threats can be addressed in a timely and effective manner.
[0123] The implementation process of the method of the present invention will be illustrated below through specific examples:
[0124] Example 1: Security posture assessment and prediction of a critical business database in the financial industry.
[0125] Step S1: Construct a multi-level indicator system. Targeting the characteristics of the financial industry, the following indicators were set: risk indicators (including risk events, attack events, and request failure rates), vulnerability indicators (including the number of vulnerabilities, password health, number of secure paths, proportion of sensitive data, and access volume of sensitive data), availability indicators (including traffic, access volume, abnormal access volume, concurrency, latency, memory utilization, and CPU utilization), and reliability indicators (including database configuration health, user permission integrity, security policy health, database service uptime, device mean time between failures, and response time).
[0126] Step S2: Collect asset and operational data from the target database. Using a database auditing system, security scanning tools, and monitoring agents, collect asset data (including configuration information, user permission information, security policy configurations, etc.) and operational data (including access logs, performance metrics, abnormal events, etc.) from the target financial database. Determine the weights of each piece of asset and operational data based on dynamic weighting rules.
[0127] For databases in the financial industry, the dynamic weighting rules specifically consider business importance, setting the weight coefficient for business importance to 0.3. Given the sensitivity of financial data, the weights for the proportion of sensitive data and the volume of access to sensitive data are increased by 25% and 30%, respectively. Threat propagation path analysis reveals that the main threats facing the financial industry recently are data breaches and identity theft; therefore, the weights for user permission integrity and security policy health are increased by 20% and 15%, respectively.
[0128] Step S3: Calculate the database security value using the situation assessment model. The collected asset data and operational data are weighted according to determined weights and input into the situation assessment model for calculation to obtain the database security value. The calculated security value of this financial database is: a comprehensive score of 78 out of 100, with a risk index of 82, a vulnerability index of 75, an availability index of 85, and a reliability index of 70. This indicates that the overall security status of the database is good, but there is still room for improvement in terms of vulnerability and reliability.
[0129] Step S4: Predict future asset and operational data using the situation prediction model. Input historical and current asset and operational data into the situation prediction model to predict the changing trends of various indicators over the next week. The prediction model considers the cyclical changes in database access volume and potential security risks following recent system updates.
[0130] Step S5: Calculate the predicted security value of the database. Input the predicted asset data and operational data into the situation assessment model to calculate the predicted security value for the next week. The prediction results show that without taking any action, the overall security value of the database will drop to 72 points after one week, with the vulnerability index value potentially dropping to 68 points. This is mainly due to the anticipated disclosure and exploitation of new vulnerabilities by attackers.
[0131] Step S6: Issue an alert. Based on the current and predicted database security values, the system triggered a yellow alert (level of concern). On one hand, the current reliability index value of 70 points is close to the alert threshold (a score below 70 triggers an alert); on the other hand, the prediction shows that the vulnerability index value will drop to 68 points within a week, below the alert threshold (a score below 70 triggers an alert). The system automatically sent an alert notification to security administrators, recommending vulnerability remediation and security policy optimization during the system maintenance window next week.
[0132] Example 2: Database security posture assessment and prediction of an e-commerce platform.
[0133] Step S1: Construct a multi-level indicator system. Based on the characteristics of e-commerce platforms, risk indicators, vulnerability indicators, availability indicators, and reliability indicators are set. The secondary indicators for each indicator are similar to those in Example 1, but according to the characteristics of e-commerce platforms, the three secondary indicators of availability—concurrency, traffic, and access volume—are particularly strengthened.
[0134] Step S2: Collect asset and operational data from the target database. Asset and operational data from the e-commerce platform's database are collected using monitoring agents and security scanning tools. The weights of each data item are determined based on dynamic weighting rules.
[0135] For e-commerce platform databases, the dynamic weighting rules take access characteristics into special consideration, setting the weight coefficient of database access characteristics to 0.35; considering the business characteristics of e-commerce platforms, the overall weight of availability indicators is increased by 20%, especially during promotional activities, the weights of traffic, access volume and concurrency are increased by 30%, 25% and 35% respectively.
[0136] Step S3: Calculate the database security value using the situation assessment model. The collected asset data and operational data are weighted according to determined weights and input into the situation assessment model for calculation to obtain the database security value. The calculated security value for the e-commerce platform's database is: a comprehensive score of 76, with a risk index of 80, a vulnerability index of 78, an availability index of 70, and a reliability index of 76. This indicates that the overall security status of the database is good, but there are certain risks in terms of availability.
[0137] Step S4: Using a situational prediction model, forecast future asset and operational data. Considering the upcoming large-scale promotional event, historical promotional data is used as an important reference to predict the trends of various indicators over the next week. The prediction model pays particular attention to three key indicators: peak traffic, concurrency, and system response time.
[0138] Step S5: Calculate the predicted security value of the database. Input the predicted asset data and operational data into the situation assessment model to calculate the predicted security value during the promotional activity. The prediction results show that during the peak promotional period, the overall security value of the database may drop to 65 points, with the availability index value potentially dropping to 58 points, mainly due to the anticipated high concurrency access leading to a decline in system performance.
[0139] Step S6: Issue an alert. Based on the current and predicted database security values, the system triggered an orange-level alert. The alert message indicated that the database system may face severe performance challenges during the promotional period, and availability metrics are expected to drop significantly. The system automatically sent an alert notification to the technical team, recommending that they expand the database server capacity in advance, optimize query statements, adjust caching strategies, and prepare elastic scaling solutions to cope with traffic peaks during the promotion.
[0140] like Figure 2 As shown, this embodiment also provides a database security posture assessment and prediction system based on multi-dimensional indicators, including:
[0141] The hierarchical indicator system construction module is used to construct a multi-level indicator system, which includes risk indicators, vulnerability indicators, availability indicators, and reliability indicators.
[0142] The data acquisition module collects asset data and operational data from the target database, and determines a first weight for the asset data and a second weight for the operational data based on dynamic weighting rules.
[0143] The security assessment module is used to calculate the database security value based on the asset data, the operational data, the first weight, and the second weight, using a situation assessment model.
[0144] The data prediction module is used to obtain the predicted asset data and predicted operational data of the target database based on the asset data and the operational data, through a situation prediction model.
[0145] The security prediction module calculates the database predicted security value based on the predicted asset data and the predicted operation data through the situation assessment model.
[0146] The early warning module is used to initiate an early warning based on the database security value and the database predicted security value, according to the early warning rules.
[0147] The functions and implementation methods of the above modules are the same as the corresponding steps in the aforementioned method embodiments, and will not be repeated here.
[0148] This invention provides a database security posture assessment and prediction method and system based on multi-dimensional indicators. It establishes a multi-level indicator system including risk indicators, vulnerability indicators, availability indicators, and reliability indicators, enabling a comprehensive assessment of database security posture. A dynamic weight allocation mechanism is introduced, which adaptively adjusts the weights of various indicators based on changes in the threat environment, business conditions, and historical attack patterns, improving the accuracy and adaptability of the assessment. Through a posture prediction model, it predicts the future security posture of the database, providing forward-looking security posture awareness capabilities and decision support for security management personnel. A multi-level early warning threshold system is established, automatically triggering corresponding levels of security warnings based on the changing trends of database security values and predicted security values, achieving early warning of security risks.
[0149] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
[0150] Furthermore, it should be understood that although this specification describes embodiments, not every embodiment contains only one independent technical solution. This narrative style is merely for clarity. Those skilled in the art should consider the specification as a whole, and the technical solutions in each embodiment can also be appropriately combined to form other embodiments that can be understood by those skilled in the art.
[0151] like Figure 3 This is a schematic diagram of a computer device provided for an embodiment of the present disclosure. It illustrates a structural schematic diagram suitable for implementing the computer device in the embodiments of the present disclosure. Figure 3 The computer device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.
[0152] A computer device according to embodiments of the present disclosure includes a memory and a processor. The memory is used to store non-transitory computer-readable instructions. Specifically, the memory may include one or more computer program products, which may include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory may, for example, include random access memory (RAM) and / or cache memory. The non-volatile memory may, for example, include read-only memory (ROM), hard disk, flash memory, etc.
[0153] The processor may be a central processing unit (CPU) or other form of processing unit with data processing capabilities and / or instruction execution capabilities, and may control other components in the computer device to perform desired functions. In one embodiment of this disclosure, the processor is used to execute computer-readable instructions stored in the memory, causing the computer device to perform all or part of the steps of the multi-source data fusion database security situation awareness method of the foregoing embodiments of this disclosure.
[0154] Those skilled in the art will understand that, in order to solve the technical problem of how to achieve a good user experience, this embodiment may also include well-known structures such as communication buses and interfaces, and these well-known structures should also be included within the protection scope of this disclosure.
[0155] like Figure 3 As shown, a computer device may include a processor (such as a central processing unit, graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) or programs loaded from storage devices into random access memory (RAM). The RAM also stores various programs and data required for the operation of the computer device. The processor, ROM, and RAM are interconnected via a bus. Input / output (I / O) interfaces are also connected to the bus.
[0156] Typically, the following devices can be connected to the I / O interface: input devices, such as sensors or visual information acquisition devices; output devices, such as displays; storage devices, such as magnetic tapes or hard drives; and communication devices. Communication devices allow the computer device to communicate wirelessly or wiredly with other devices (such as edge computing devices) to exchange data. Although Figure 3 A computer apparatus with various devices is shown, but it should be understood that it is not required to implement or have all of the devices shown. More or fewer devices may be implemented or included alternatively.
[0157] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device, or installed from a ROM. When the computer program is executed by a processor, all or part of the steps of the multi-source data fusion database security situation awareness method of embodiments of this disclosure are performed.
[0158] For a detailed description of this embodiment, please refer to the corresponding descriptions in the foregoing embodiments, which will not be repeated here.
[0159] A computer-readable storage medium according to embodiments of the present disclosure stores non-transitory computer-readable instructions. When these non-transitory computer-readable instructions are executed by a processor, all or part of the steps of the multi-source data fusion database security situation awareness method described in the foregoing embodiments of the present disclosure are performed.
[0160] The aforementioned computer-readable storage media include, but are not limited to: optical storage media (e.g., CD-ROM and DVD), magneto-optical storage media (e.g., MO), magnetic storage media (e.g., magnetic tape or portable hard drive), media with built-in rewritable non-volatile memory (e.g., memory card), and media with built-in ROM (e.g., ROM cartridge).
[0161] For a detailed description of this embodiment, please refer to the corresponding descriptions in the foregoing embodiments, which will not be repeated here.
[0162] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.
[0163] In this disclosure, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The block diagrams of devices, apparatuses, devices, and systems involved in this disclosure are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as "comprising," "including," "having," etc., are open-ended terms meaning "including but not limited to," and are used interchangeably with them. The terms "or" and "and" as used herein refer to the terms "and / or," and are used interchangeably with them unless the context clearly indicates otherwise. The term "such as" as used herein refers to the phrase "such as but not limited to," and is used interchangeably with it.
[0164] Additionally, as used herein, the "or" used in a list of items beginning with "at least one" indicates a separate list, such that a list of, for example, "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the word "exemplary" does not imply that the described example is preferred or better than other examples.
[0165] It should also be noted that in the systems and methods of this disclosure, the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered as equivalent solutions to this disclosure.
[0166] Various changes, substitutions, and modifications can be made to the technology described herein without departing from the teachings defined by the appended claims. Furthermore, the scope of the claims of this disclosure is not limited to the specific aspects of the processes, machines, manufactures, events, means, methods, and actions described above. Currently existing or later-developed processes, machines, manufactures, events, means, methods, or actions that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Therefore, the appended claims include such processes, machines, manufactures, events, means, methods, or actions within their scope.
[0167] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.
[0168] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations therein.
Claims
1. A database security posture assessment and prediction method based on multi-dimensional indicators, characterized in that, include: A multi-level indicator system is constructed, which includes risk indicators, vulnerability indicators, availability indicators, and reliability indicators. Asset data and operational data of the target database are collected. Based on dynamic weighting rules, a first weight for the asset data and a second weight for the operational data are determined. The asset data includes at least two of the following: number of vulnerabilities, weak password health, number of secure paths, percentage of sensitive data, memory utilization, CPU utilization, database configuration health, user permission integrity, security policy health, and database service lifespan. The operational data includes at least two of the following: risk events, attack events, request failure rate, sensitive data access volume, traffic, access volume, abnormal access volume, concurrency, latency, device mean time between failures, and response time. Based on the asset data, the operational data, the first weight, and the second weight, a database security value is calculated using a situation assessment model. Based on the asset data and the operational data, the predicted asset data and predicted operational data of the target database are obtained through the situation prediction model. Based on the predicted asset data and the predicted operational data, the database predicted security value is calculated using the situation assessment model. Based on the database security value and the database predicted security value, an early warning is issued according to the early warning rules; The asset data and operational data collected from the target database are used to determine a first weight for the asset data and a second weight for the operational data based on dynamic weighting rules, including: Establish a multi-dimensional weighted decision matrix and determine the basic weights; The weight optimization coefficients are output through a threat propagation path analysis mechanism and a weight adaptive learning mechanism. The current operating status and business load mode of the database are determined based on the asset data and the operating data. Obtain external threat intelligence, and determine the first weight and the second weight based on the basic weight and the weight optimization coefficient through context-aware weight adjustment rules; The step of determining the first weight and the second weight based on the base weight and the weight optimization coefficient using context-aware weight adjustment rules includes: Obtain historical data corresponding to historical risk indicators, historical vulnerability indicators, historical availability indicators, and historical reliability indicators, and construct context-aware weight adjustment rules; Based on the context-aware weight adjustment rule, the corresponding weights of the hazard index, the vulnerability index, the availability index, and the reliability index are determined. The first weight and the second weight are determined based on the indicator weight, the basic weight, and the weight optimization coefficient.
2. The method according to claim 1, characterized in that, The establishment of a multi-dimensional weighted decision matrix and the determination of basic weights include: Based on threat level, business importance, historical attack patterns, and database access characteristics, the first-level weight of the asset data and the second-level weight of the operational data are determined. Based on the aforementioned business importance and the aforementioned historical attack patterns, the first and second-level rights reorganization corresponding to the asset data is determined; Based on the threat level, the historical attack patterns, and the database access characteristics, the second and third level weight reassemblies corresponding to the running data are determined; The basic weights are determined based on the first primary weight, the first secondary weight reorganization, the second primary weight, and the second secondary weight reorganization.
3. The method according to claim 1, characterized in that, The process of using threat propagation path analysis and weight adaptive learning mechanisms to output weight optimization coefficients includes: Establish a mapping table that associates threat attack types with indicators; Obtain threat attack information within the first preset period, and determine the first weight optimization coefficient based on the threat attack type and indicator association mapping table; Obtain the second weight optimization coefficient within the second preset period, wherein the second weight optimization coefficient is generated by the weight adaptive learning mechanism at the end of the previous second preset period; Based on the first weight optimization coefficient and the second weight optimization coefficient, the weight optimization coefficient is output.
4. The method according to any one of claims 1-3, characterized in that, The risk indicators include risk events, attack events, and request failure rates; The vulnerability indicators include the number of vulnerabilities, password health, number of secure paths, proportion of sensitive data, and access volume of sensitive data; The availability metrics include traffic, access volume, abnormal access volume, concurrency, latency, memory utilization, and CPU utilization. The reliability metrics include database configuration health, user permission integrity, security policy health, database service uptime, device fault-free time, and response time.
5. The method according to claim 1, characterized in that, The database security value includes a comprehensive value, a risk index value, a vulnerability index value, an availability index value, and a reliability index value. The calculation of the database security value based on the asset data, the operational data, the first weight, and the second weight, using a situation assessment model, includes: The asset data and the operational data are time-aligned and format-standardized to obtain standard asset data and standard operational data. Based on the standard asset data and the standard operational data, an initial database security value is obtained through the scoring module in the situation assessment model; By using the causal dependency graph of the indicators in the situation assessment model, the transmission influence coefficient of each indicator change on other indicators is identified; Based on the initial database security value and the transmission influence coefficient, the intermediate database security value is obtained; The outlier detection and correction mechanism and the cross-validation mechanism are used to determine whether the first confidence level of the intermediate database security value has reached the first confidence threshold. If the first confidence threshold is reached, the intermediate database security value is output as the database security value.
6. The method according to claim 1, characterized in that, The process of obtaining predicted asset data and predicted operational data for the target database based on the asset data and operational data through a situation prediction model includes: Acquire cyclical asset data and cyclical operation data within a third preset period, extract data features from the cyclical asset data, the cyclical operation data, the asset data, and the operation data to obtain periodic patterns, trend characteristics, and abnormal fluctuation patterns; A hierarchical prediction architecture is established to perform independent time series predictions on the aforementioned risk indicators, vulnerability indicators, availability indicators, and reliability indicators; The asset data and operational data of the target database are predicted to obtain initial predicted asset data and initial predicted operational data; Based on data relationship constraints and indicator constraints, calculate the second confidence level of the initial predicted asset data and the initial predicted running data; Determine whether the second confidence level reaches the second confidence threshold; If the second confidence threshold is reached, the initial predicted asset data and the initial prediction are output as the predicted asset data and the prediction running data.
7. The method according to claim 1, characterized in that, The step of calculating the database predicted security value based on the predicted asset data and the predicted operational data using the situation assessment model includes: Set the confidence interval of the predicted data, input the confidence interval of the predicted data, the predicted asset data and the predicted operation data into the situation assessment model to obtain the original database predicted safety value and uncertainty quantification value; A simple prediction method based on trend extrapolation is used to obtain a safe value for the prediction in the validation database; A cross-validation mechanism for prediction results is constructed, which compares and verifies the original database prediction safety value with the verification database prediction safety value. When the verification result meets the preset conditions, the original database prediction safety value is output as the database prediction safety value. When the verification result does not meet the preset condition, it is determined whether the number of calculations is less than the number of calculations threshold. If so, then based on the asset data and the operational data, the predicted asset data and the predicted operational data of the target database are obtained again through the situation prediction model, and the original database predicted security value is obtained again, until the verification result meets the preset conditions; If not, then the original database prediction safety value with the lowest uncertainty quantification value and the original database prediction safety value obtained in the last calculation are output as the database prediction safety value.
8. The method according to claim 5, characterized in that, The step of initiating an early warning based on the database security value and the database predicted security value, according to the early warning rules, includes: Construct a multi-level early warning threshold system, and set different early warning trigger values and corresponding strategies based on the importance of database business and historical security baseline; The alert is initiated according to the alert rules, including triggering an alert when any of the following conditions are met: Analyze the rate of change and / or acceleration of the comprehensive value in the database security value, and trigger an early warning when the frequency and / or acceleration of the database security value change exceeds the frequency threshold and / or speed threshold; A correlation-based early warning mechanism is established, which triggers an early warning when any one of the risk index value, vulnerability index value, availability index value, and reliability index value in the database security value exceeds the corresponding single warning threshold. An alarm is triggered when the database predicts a safety value that reaches the predicted warning line.
Citation Information
Patent Citations
Security state evaluation method and device of network environment, equipment and storage medium
CN120342697A