Database data tampering-oriented security detection method and device, equipment and medium
By analyzing database network traffic and establishing baselines, accurate detection of database data tampering is achieved, solving the problem of high false alarm rate in existing technologies and improving detection efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NO 15 INST OF CHINA ELECTRONICS TECH GRP
- Filing Date
- 2026-02-26
- Publication Date
- 2026-05-29
AI Technical Summary
Existing technologies are unable to effectively detect database data tampering initiated through legitimate means, resulting in a high false alarm rate and low security detection efficiency.
By analyzing database network traffic and local logs, a baseline of user behavior, data content, and transaction patterns is established. Real-time operational risk assessment and transaction correlation analysis are then performed to generate a security risk level.
Accurately identify covert tampering that conforms to business logic, reduce false alarm rate, and improve the efficiency of security detection for database operations.
Smart Images

Figure CN122113093A_ABST
Abstract
Description
Technical Field
[0001] The embodiments disclosed herein relate to the field of database security and data protection technology, and more specifically, to a security detection method, apparatus, device, and medium for database data tampering. Background Technology
[0002] Databases, as the core of information systems, store a large amount of sensitive and critical business data. Data tampering is a primary means of directly attacking data integrity and can lead to catastrophic consequences such as financial fraud, privacy breaches, and flawed decision-making.
[0003] In related technologies, database operation security detection is mainly achieved through network-side SQL (Structured Query Language) auditing, which involves mirroring database traffic and parsing SQL statements for keyword matching. However, this approach cannot effectively detect data tampering initiated through legitimate means (such as authorized management tools, stored procedures, or application-layer vulnerabilities), resulting in a high false positive rate and low security detection efficiency. Summary of the Invention
[0004] The embodiments described herein provide a security detection method, apparatus, device, and medium for database data tampering, overcoming the aforementioned problems.
[0005] Firstly, based on the content of this disclosure, a security detection method for database data tampering is provided, including: The database network traffic and local database logs are parsed to obtain network operation information and log operation information. The network operation information and the log operation information are standardized and entity enriched to obtain the database audit log. The database audit log is used to describe the database operation information corresponding to multiple business entities. The entity enrichment is used to enrich the database user's operations. For each of the business entities, user behavior learning is performed to establish a user behavior baseline; for each of the business entities, access content learning is performed to establish a data content baseline; for each of the business entities, historical transaction learning is performed to establish a transaction pattern baseline, wherein the transaction pattern baseline is used to describe the transaction execution data of the business entity corresponding to historical operation transactions; Obtain the real-time operation flow of the database corresponding to the target entity; The real-time operation risk assessment of the real-time operation flow is performed using the user behavior baseline and the data content baseline to obtain the operation risk score corresponding to the real-time operation flow. Transaction correlation analysis is performed on the real-time operation flow using the transaction mode baseline to obtain correlation analysis data. Based on the operational risk score corresponding to the real-time operation flow and the correlation analysis data, the security risk level of the database operation corresponding to the real-time operation flow is generated.
[0006] Secondly, according to the content of this disclosure, a security detection device for database data tampering is provided, comprising: The parsing module is used to parse the operation records of database network traffic and local database logs to obtain network operation information and log operation information. The processing module is used to standardize and enrich the network operation information and the log operation information to obtain the database audit log. The database audit log describes the database operation information corresponding to multiple business entities. The entity enrichment is used to enrich the database user's operations. A module is established to perform user behavior learning for each of the business entities and establish a user behavior baseline; to perform access content learning for each of the business entities and establish a data content baseline; and to perform historical transaction learning for each of the business entities and establish a transaction pattern baseline, wherein the transaction pattern baseline is used to describe the transaction execution data of the business entity corresponding to historical operation transactions. The acquisition module is used to acquire the real-time operation flow of the target entity corresponding to the database; The evaluation module is used to perform real-time operation risk assessment on the real-time operation flow based on the user behavior baseline and the data content baseline, and obtain the operation risk score corresponding to the real-time operation flow. The analysis module is used to perform transaction correlation analysis on the real-time operation flow based on the transaction mode baseline to obtain correlation analysis data; The generation module is used to generate the security risk level of the database operation corresponding to the real-time operation flow based on the operation risk score corresponding to the real-time operation flow and the correlation analysis data.
[0007] Thirdly, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the security detection method for database data tampering as described in any of the above embodiments.
[0008] Fourthly, a computer-readable storage medium is provided, on which a computer program is stored, and when executed by a processor, the computer program implements the steps of the security detection method for database data tampering as described in any of the above embodiments.
[0009] The security detection method for database data tampering provided in this application includes: parsing operation records of database network traffic and local database logs to obtain network operation information and log operation information; standardizing and enriching the network operation information and log operation information to obtain database audit logs, which describe database operation information corresponding to multiple business entities, and entity enrichment for enriching database user operations; learning user behavior for each business entity to establish a user behavior baseline; learning access content for each business entity to establish a data content baseline; learning historical transactions for each business entity to establish a transaction pattern baseline, which describes the transaction execution data of the business entity corresponding to historical operation transactions; obtaining the real-time operation flow of the target entity corresponding to the database; performing real-time operation risk assessment on the real-time operation flow using the user behavior baseline and data content baseline to obtain the operation risk score corresponding to the real-time operation flow; performing transaction correlation analysis on the real-time operation flow using the transaction pattern baseline to obtain correlation analysis data; and generating a security risk level for the database operation corresponding to the real-time operation flow based on the operation risk score and correlation analysis data. In this way, by integrating the three baselines of behavior, data, and transactions, it can not only detect blatant mass tampering, but also more accurately identify covert tampering that targets specific data and conforms to business logic, greatly reducing the false alarm rate and effectively improving the security detection efficiency of database operations.
[0010] The above description is merely an overview of the technical solutions of the embodiments of this application. In order to better understand the technical means of the embodiments of this application and to implement them in accordance with the contents of the specification, and to make the above and other objects, features and advantages of the embodiments of this application more obvious and understandable, specific implementation methods of this application are described below. Attached Figure Description
[0011] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the accompanying drawings of the embodiments will be briefly described below. It should be understood that the drawings described below only relate to some embodiments of this disclosure and are not intended to limit this disclosure, wherein: Figure 1 This is a flowchart illustrating a security detection method for database data tampering provided in this publication.
[0012] Figure 2 This is a schematic diagram of a security detection device for database data tampering provided in this disclosure.
[0013] Figure 3 This is a schematic diagram of the structure of a computer device provided in this disclosure.
[0014] It should be noted that the elements in the attached diagram are schematic and not drawn to scale. Detailed Implementation
[0015] To make the objectives, technical solutions, and advantages of the embodiments of this disclosure clearer, the technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this disclosure. All other embodiments obtained by those skilled in the art based on the described embodiments of this disclosure without creative effort are also within the scope of protection of this disclosure.
[0016] Unless otherwise defined, all terms used herein (including technical and scientific terms) shall have the same meaning as commonly understood by one of ordinary skill in the art to which this subject matter pertains. It will be further understood that terms such as those defined in commonly used dictionaries shall be interpreted as having the meaning consistent with their meaning in the context of the specification and in the relevant art, and shall not be interpreted in an idealized or overly formal form unless otherwise explicitly defined herein. As used herein, the statement of “connecting” or “coupling” two or more parts together shall mean that these parts are directly joined together or joined through one or more intermediate components.
[0017] The term "embodiment" as used herein means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of the phrase "embodiment" in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0018] In this document, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists, A and B exist simultaneously, or B exists. Additionally, the character " / " generally indicates that the preceding and following related objects have an "or" relationship. Terms such as "first" and "second" are only used to distinguish one component (or part of a component) from another component (or another part of a component).
[0019] In the description of this application, unless otherwise stated, "multiple" means two or more (including two), and similarly, "multiple groups" means two or more (including two groups).
[0020] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.
[0021] Figure 1This is a flowchart illustrating a security detection method for database data tampering provided in an embodiment of this disclosure, as shown below. Figure 1 As shown, the specific process of the security detection method for database data tampering includes: S110. Perform operation record parsing on the database network traffic and database local logs to obtain network operation information and log operation information.
[0022] This allows for the capture of all database modification operations from multiple sources. When parsing database network traffic operation records, all SQL traffic sent by the database front-end application can be captured using splitting or mirroring techniques. A database protocol parsing engine (such as one that parses MySQL or Oracle protocols) can then be used to extract complete SQL statements, execution times, source IPs, database users, and other information as network operation information.
[0023] When parsing operation records in the local database logs, detailed information for each data change (DML: INSERT, UPDATE, DELETE) can be extracted by reading the database's transaction logs in real time, such as MySQL's binlog and PostgreSQL's WAL. This includes: the before-image and after-image of the data, the transaction ID (XID) of the operation, and the affected table names and primary keys, which serve as log operation information. The parsing steps of the local database logs can also detect operations performed directly through database background tools (such as the MySQL command line).
[0024] S120. Standardize and enrich the network operation information and log operation information to obtain the database audit log.
[0025] Among these features, a unified audit log format can be used to standardize and enrich the entity records of operation records from different sources (i.e., network operation information and log operation information).
[0026] Database audit logs describe database operation information corresponding to multiple business entities. Database audit logs may include: timestamp, operation type, database user, source IP (Internet Protocol) address, client tool, executed SQL, table name, primary key value, value before change, value after change, and transaction ID. Entity enrichment is used to enrich database user information, that is, to associate users with databases in the database audit logs. For example, when calling an asset management system interface, the source IP can be enriched to a specific server, and the database user can be enriched to the actual responsible person.
[0027] S130. Perform user behavior learning for each business entity and establish a user behavior baseline; perform access content learning for each business entity and establish a data content baseline; perform historical transaction learning for each business entity and establish a transaction pattern baseline.
[0028] Among them, the user behavior baseline is used to describe the behavioral profile established for each business entity; the data content baseline is used to describe the content model established for the important fields of the key core tables; and the transaction mode baseline is used to describe the transaction execution data of the business entity corresponding to the historical operation transactions, that is, the business transactions consisting of multiple operations.
[0029] When establishing a user behavior baseline, machine learning can be used to identify the set of tables typically accessed by each business entity, common operation types (e.g., one user is read-only while another can write), common operation times (e.g., working hours), and common client IP ranges. For example, it can be discovered that user dev_user typically only operates on the test_table table on the test machine at 192.168.1.100. Based on this, a behavioral profile can be built for the business entity represented by each database user / application account.
[0030] In some embodiments, access content learning is performed on each business entity to establish a data content baseline, including: obtaining the access core table corresponding to each business entity; performing historical value distribution learning, normal fluctuation range learning, and change frequency learning on the numerical fields in the access core table to obtain a first content baseline; performing state enumeration set learning and state transition path learning on the enumeration fields in the access core table to obtain a second content baseline; performing data format learning and check bit rule learning on the preset sensitive fields in the access core table to obtain a third content baseline; and constructing a data content baseline based on the first content baseline, the second content baseline, and the third content baseline.
[0031] For example, for numerical fields such as account balances or product prices, a first content baseline is obtained by machine learning their historical value distribution, normal fluctuation range (e.g., ±10%), and change frequency (e.g., updated daily). For enumerable fields such as order status, a second content baseline is obtained by machine learning their normal status enumeration set (e.g., pending payment, shipped, completed) and reasonable status transition paths (e.g., pending payment -> shipped, which is an abnormal jump). For sensitive fields such as ID card numbers, a third content baseline is obtained by machine learning their data format (e.g., 18 digits), check digit rules, etc. The first, second, and third content baselines are then combined to form the data content baseline.
[0032] Thus, the first content baseline can quickly identify abnormal fluctuations or changes outside the normal range of numerical fields; the second content baseline can detect abnormal state transitions of enumerated fields; and the third content baseline can effectively verify the format compliance of sensitive fields and the correctness of validation rules. This effectively enables comprehensive monitoring and anomaly detection of data content, thereby efficiently establishing data content baselines.
[0033] In some embodiments, historical transaction learning is performed on each business entity to establish a transaction mode baseline, including: learning transaction operation records for each business entity to obtain a first mode baseline; learning transaction operation status for each business entity to obtain a second mode baseline; learning transaction operation change for each business entity to obtain a third mode baseline; and constructing a transaction mode baseline based on the first mode baseline, the second mode baseline, and the third mode baseline.
[0034] This can be achieved by studying historical transactions and analyzing the multi-step operations of each business entity to establish common transaction templates. For example, a "payment transaction" typically includes: inserting a payment record into the `payment_table` (the transaction operation record), thus obtaining the first pattern baseline; updating the `order_table` to "paid," thus obtaining the transaction operation status, thus obtaining the second pattern baseline; and updating the `account_table` to deduct the balance, thus obtaining the transaction operation change, thus obtaining the third pattern baseline. The order and dependencies of operations within a transaction are fixed. Therefore, abnormal transaction behaviors of business entities can be effectively identified and predicted to efficiently construct transaction pattern baselines.
[0035] S140. Obtain the real-time operation flow corresponding to the target entity in the database; conduct a real-time operation risk assessment on the real-time operation flow through the user behavior baseline and data content baseline, and obtain the operation risk score corresponding to the real-time operation flow.
[0036] The real-time operation flow refers to a sequence of database operations captured within a specific time period. This sequence may include, but is not limited to, actions such as insert, update, and delete. When performing real-time operation risk scoring, each incoming DML operation can be scored in real-time from multiple dimensions, including behavioral deviation, data anomaly, and semantic violation.
[0037] In some embodiments, a real-time operational risk assessment is performed on the real-time operational flow using a user behavior baseline and a data content baseline to obtain an operational risk score corresponding to the real-time operational flow. This includes: assessing the behavioral deviation of the real-time operational flow using the user behavior baseline to obtain a user behavior score; assessing the data anomaly and semantic violation of the real-time operational flow using the data content baseline to obtain a data content score; and obtaining an operational risk score corresponding to the real-time operational flow based on the user behavior score and the data content score.
[0038] In the behavioral deviation assessment, the system evaluates whether the operation deviates from the user behavior baseline. For example, if the operation is "financial staff logging in from an unknown IP late at night and modifying data," then the operation is determined to deviate from the user behavior baseline. In the semantic violation assessment, the system evaluates whether the modified value deviates from the data content baseline. For example, changing the unit price of a product from 100 yuan to 0.01 yuan, or directly changing the order status from "pending payment" to "completed," is determined to deviate from the data content baseline. In the semantic violation assessment, the SQL's WHERE condition is analyzed to determine whether the modification targets a large amount of data or lacks constraints. For example, `UPDATE users SET balance = 0` determines that it does not target a large amount of data. Therefore, by performing multi-dimensional real-time scoring on the real-time operation flow, the comprehensiveness and accuracy of the assessment results are effectively guaranteed.
[0039] When determining the operational risk score corresponding to a real-time operational flow based on user behavior scores and data content scores, the accuracy of the score can be further improved by weighting the user behavior scores and data content scores.
[0040] S150. Perform transaction correlation analysis on the real-time operation flow through the transaction mode baseline to obtain correlation analysis data; generate the security risk level of the database operation corresponding to the real-time operation flow based on the operation risk score and correlation analysis data.
[0041] Transaction correlation analysis involves grouping operations with the same transaction ID together for unified analysis. When generating security risk levels, the comprehensive risk value of a transaction is calculated using the operation risk score corresponding to the real-time operation flow and the correlation analysis data. This comprehensive risk value is then compared with a risk threshold to classify the security risk level. If the comprehensive risk value is less than or equal to the risk threshold, the security risk level of the database operation corresponding to the real-time operation flow is determined to be low risk; if the comprehensive risk value is greater than the risk threshold, the security risk level of the database operation corresponding to the real-time operation flow is determined to be high risk.
[0042] In some embodiments, transaction correlation analysis is performed on the real-time operation flow using a transaction mode baseline to obtain correlation analysis data. This includes: associating operations with the same transaction identifier in the real-time operation flow as a transaction unit; and performing operation sequence analysis and atomicity violation analysis on each transaction unit to obtain correlation analysis data.
[0043] Operation sequence analysis checks whether the order of operations within a transaction conforms to the learnt transaction template; atomicity violation analysis checks whether the atomicity of a transaction has been violated. For example, if only the deduction operation is performed but no order record is generated, it constitutes a business logic vulnerability.
[0044] Performing operation sequence analysis and atomicity violation analysis on each transaction unit yields correlation analysis data that can be used to describe potential risks and anomalies during the execution of a particular transaction unit. This reflects whether transaction operations follow the predetermined logical order and whether there are any abnormal behaviors that could lead to data inconsistencies or business logic errors. For example, correlation analysis data can reveal whether certain operations are skipped, repeated, or executed at the wrong time. Therefore, performing transaction correlation analysis on real-time operation flows can promptly identify potential problems in the transaction processing process.
[0045] In this embodiment, operation records of database network traffic and local database logs are parsed to obtain network operation information and log operation information. The network operation information and log operation information are then standardized and enriched to obtain database audit logs. These audit logs describe database operation information corresponding to multiple business entities, and entity enrichment is used to enrich the database user's operations. User behavior learning is performed on each business entity to establish a user behavior baseline. Access content learning is performed on each business entity to establish a data content baseline. Historical transaction learning is performed on each business entity to establish a transaction pattern baseline, which describes the transaction execution data of the business entity corresponding to historical operation transactions. The real-time operation flow corresponding to the target entity in the database is obtained. Real-time operation risk assessment is performed on the real-time operation flow using the user behavior baseline and data content baseline to obtain the corresponding operation risk score. Transaction correlation analysis is performed on the real-time operation flow using the transaction pattern baseline to obtain correlation analysis data. Based on the operation risk score and correlation analysis data corresponding to the real-time operation flow, a security risk level for the database operation corresponding to the real-time operation flow is generated. In this way, by integrating the three baselines of behavior, data, and transactions, it can not only detect blatant mass tampering, but also more accurately identify covert tampering that targets specific data and conforms to business logic, greatly reducing the false alarm rate and effectively improving the security detection efficiency of database operations.
[0046] In some embodiments, the method further includes: performing aggregate analysis on database operations targeting the same business entity within a preset time period to obtain aggregate analysis results; and generating operation warning information corresponding to the database operations based on the aggregate analysis results.
[0047] This feature allows for the aggregation and analysis of continuous, low-intensity modifications (i.e., "low-speed, low-frequency" attacks) targeting the same data entity (such as the same account) within a short period. A single operation may not pose a high risk, but if the overall change after aggregation is abnormal, such as an increase of 1 yuan each time in 100 separate transactions, resulting in an abnormal increase of 100 yuan in the account balance, an alarm can be generated to facilitate timely warnings and ensure the security of database operations.
[0048] In some embodiments, the method further includes: for target transaction operations whose operation risk score exceeds a preset threshold, determining the cryptographic hash value corresponding to the target transaction operation as the unique digital fingerprint corresponding to the target transaction operation; storing the target transaction operation on the blockchain based on the unique digital fingerprint corresponding to the target transaction operation; and retrieving the relevant operation record corresponding to the target transaction operation from the blockchain in response to an access request for the target transaction operation in the blockchain.
[0049] For operation records whose risk scores exceed a threshold or are deemed suspicious, a cryptographic hash value (such as SHA-256) of their details is calculated as a unique digital fingerprint for that operation. A batch of operation fingerprints, timestamps, and the hash value of the previous block are packaged into a single block, which is then broadcast to a consortium or private blockchain network for consensus and storage. Once on-chain, all audit evidence is immutably solidified. Furthermore, when an investigation is needed, all relevant operation records can be quickly retrieved from the blockchain and local storage based on criteria such as primary key and time range. Due to the correspondence between on-chain fingerprints and local details, a legally credible audit report can be generated, clearly showing the complete change history and operational context of any data. This facilitates the traceability of transactions and effectively solves the problem of the credibility of audit evidence.
[0050] In addition, this embodiment also provides a practical scenario example for detecting balance tampering in the financial system. Attack Scenario: An internal malicious user, using authorized management tools, slowly and repeatedly adds small amounts to the balance of their associated accounts at night, attempting to commit fraud through a "small accumulation" method. Implementation Process: The system captures all UPDATE operations on the account_table by parsing the database binlog, including the operator db_admin, the primary key (account ID) for each change, the balance before the change, and the balance after the change. The system has learned: User behavior baseline: User db_admin typically only performs batch queries and maintenance operations from a fixed management terminal IP during working hours, and rarely directly modifies account balances; Data content baseline: The single change range of the balance field is usually within ±$10,000, and usually appears in pairs with transaction records. Balance changes are rare at night; Transaction pattern baseline: A normal balance change transaction is always accompanied by an INSERT record in the transaction_table. The real-time analysis engine detected a series of abnormal operations: Behavioral deviation: db_admin performed operations between 1 AM and 3 AM, with the source IP being its home computer IP; Data anomaly: 10 UPDATE operations were performed on the balance of account ID 12345, each increasing the balance by $0.5 to $1.0. Although the individual changes were small, aggregate analysis revealed an abnormal increase of $8.5 in the account's total balance within a short period; Semantic violation: These UPDATE operations were committed independently without any accompanying INSERT operations in the transaction_table, violating the transaction template. The overall risk was assessed as high-risk, and the system immediately generated an alert. Furthermore, the fingerprints of these suspicious operations were instantly recorded on the blockchain for evidence. After receiving the alert, security personnel used the system's tracing function to generate a complete audit report containing details of all 10 operations, their context, and blockchain credentials, completing the discovery and evidence collection of this internal tampering.
[0051] In summary, this embodiment integrates three baselines: behavior, data, and transactions. It can not only detect blatant mass tampering but also accurately identify covert tampering targeting specific data and conforming to business logic, significantly reducing false alarms. Regardless of whether the tampering operation originates from the application layer, database middleware, or a direct backend connection, as long as it ultimately persists to the database, it can be captured and analyzed, with no detection blind spots. The introduction of transaction templates and state machine concepts allows for judging the rationality of operations from the business logic level, not just the syntax level, resulting in more intelligent detection capabilities. Utilizing blockchain technology to solidify evidence addresses the pain point of traditional database logs being easily tampered with, providing strong technical support for post-event accountability and judicial evidence collection. The baseline model can be dynamically updated along with the normal evolution of the business system, reducing tedious rule maintenance work.
[0052] Figure 2 This is a schematic diagram of a security detection device for database data tampering provided in this embodiment. The security detection device for database data tampering may include: The parsing module 210 is used to parse the database network traffic and database local logs to obtain network operation information and log operation information.
[0053] The processing module 220 is used to standardize and enrich network operation information and log operation information to obtain database audit logs. The database audit logs describe database operation information corresponding to multiple business entities, and entity enrichment is used to enrich the database user's operations.
[0054] Module 230 is established to learn user behavior for each business entity and establish a user behavior baseline; to learn access content for each business entity and establish a data content baseline; and to learn historical transactions for each business entity and establish a transaction pattern baseline. The transaction pattern baseline is used to describe the transaction execution data of the business entity corresponding to historical operation transactions.
[0055] The acquisition module 240 is used to acquire the real-time operation flow of the target entity corresponding to the database.
[0056] The assessment module 250 is used to assess the real-time operational risk of the real-time operation flow based on the user behavior baseline and the data content baseline, and obtain the corresponding operational risk score of the real-time operation flow.
[0057] Analysis module 260 is used to perform transaction correlation analysis on the real-time operation flow through the transaction mode baseline to obtain correlation analysis data.
[0058] The generation module 270 is used to generate the security risk level of the database operation corresponding to the real-time operation flow based on the operation risk score and correlation analysis data corresponding to the real-time operation flow.
[0059] In this embodiment, optionally, the establishment module 230 is specifically used for: Obtain the access core table corresponding to each business entity; perform historical value distribution learning, normal fluctuation range learning, and change frequency learning on the numeric fields in the access core table to obtain the first content baseline; perform state enumeration set learning and state transition path learning on the enumeration fields in the access core table to obtain the second content baseline; perform data format learning and check bit rule learning on the preset sensitive fields in the access core table to obtain the third content baseline; construct the data content baseline based on the first content baseline, the second content baseline, and the third content baseline.
[0060] In this embodiment, optionally, the evaluation module 250 is specifically used for: The user behavior baseline is used to evaluate the behavioral deviation of the real-time operation flow, resulting in a user behavior score; the data content baseline is used to evaluate the data anomaly and semantic violation of the real-time operation flow, resulting in a data content score; and the operation risk score corresponding to the real-time operation flow is obtained based on the user behavior score and the data content score.
[0061] In this embodiment, optionally, the analysis module 260 is specifically used for: Operations with the same transaction identifier in the real-time operation flow are associated as a transaction unit; operation sequence analysis and atomicity violation analysis are performed on each transaction unit to obtain association analysis data.
[0062] In this embodiment, optionally, the establishment module 230 is specifically used for: For each business entity, learn transaction operation records to obtain the first mode baseline; for each business entity, learn transaction operation status to obtain the second mode baseline; for each business entity, learn transaction operation change to obtain the third mode baseline; and construct the transaction mode baseline based on the first mode baseline, the second mode baseline, and the third mode baseline.
[0063] In this embodiment, optionally, the generation module 270 is further configured to perform aggregate analysis on database operations targeting the same business entity within a preset time period to obtain aggregate analysis results; and generate operation warning information corresponding to the database operations based on the aggregate analysis results.
[0064] In this embodiment, optionally, the processing module 220 is further configured to: determine the cryptographic hash value corresponding to the target transaction operation as the unique digital fingerprint corresponding to the target transaction operation for the target transaction operation whose operation risk score exceeds a preset threshold; perform blockchain notarization on the target transaction operation based on the unique digital fingerprint corresponding to the target transaction operation; and retrieve the relevant operation record corresponding to the target transaction operation from the blockchain in response to the access request for the target transaction operation in the blockchain.
[0065] The security detection device for database data tampering provided in this disclosure can execute the above-described method embodiments. Its specific implementation principle and technical effects can be found in the above-described method embodiments, and will not be repeated here.
[0066] This application also provides a computer device. Please refer to the following for details. Figure 3 , Figure 3 This is a basic structural block diagram of the computer device in this embodiment.
[0067] The computer device includes a memory 310 and a processor 320 that are interconnected via a system bus. It should be noted that only a computer device with memory 310 and processor 320 is shown in the figure; however, it should be understood that it is not required to implement all the components shown, and more or fewer components may be implemented alternatively. Those skilled in the art will understand that the computer device described herein is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0068] Computer devices can include desktop computers, laptops, handheld computers, and cloud servers. These devices allow for human-computer interaction with users through keyboards, mice, remote controls, touchpads, or voice-activated devices.
[0069] The memory 310 includes at least one type of readable storage medium, including non-volatile memory or volatile memory, such as flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. RAM may include static RAM or dynamic RAM. In some embodiments, the memory 310 may be an internal storage unit of a computer device, such as the hard disk or memory of the computer device. In other embodiments, the memory 310 may also be an external storage device of the computer device, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, or flash card equipped on the computer device. Of course, the memory 310 may include both internal storage units and external storage devices of the computer device. In this embodiment, the memory 310 is typically used to store the operating system and various application software installed on the computer device, such as the program code of the method described above. In addition, the memory 310 can also be used to temporarily store various types of data that have been output or will be output.
[0070] Processor 320 is typically used to perform overall operations of a computer device. In this embodiment, memory 310 is used to store program code or instructions, including computer operation instructions, and processor 320 is used to execute the program code or instructions stored in memory 310 or process data, such as program code that runs the methods described above.
[0071] In this article, the bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. This bus system can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.
[0072] Another embodiment of this application also provides a computer-readable medium, which may be a computer-readable signal medium or a computer-readable medium. A processor in a computer reads computer-readable program code stored in the computer-readable medium, enabling the processor to execute the functional actions specified in each step or combination of steps in the above method; and to generate means for implementing the functional actions specified in each block or combination of blocks in the block diagram.
[0073] Computer-readable media include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared memory or semiconductor systems, devices or apparatuses, or any suitable combination thereof, wherein the memory is used to store program code or instructions, the program code including computer operation instructions, and the processor is used to execute the program code or instructions of the above-described methods stored in the memory.
[0074] The definitions of memory and processor can be found in the description of the foregoing computer device embodiments, and will not be repeated here.
[0075] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0076] In the various embodiments of this application, the functional units or modules can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0077] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0078] In the claims, any reference signs placed between parentheses should not be construed as limiting the claims. The word "comprising" as described in this application does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. This application can be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In the unit claims listing several means, several units of these means may be embodied by the same item of hardware. The use of "first," "second," and "third," etc., does not indicate any order and these words should be interpreted as names. Unless otherwise specified, the steps in the above embodiments should not be construed as limiting the order of execution.
[0079] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A security detection method for database data tampering, characterized in that, include: The database network traffic and local database logs are parsed to obtain network operation information and log operation information. The network operation information and the log operation information are standardized and entity enriched to obtain the database audit log. The database audit log is used to describe the database operation information corresponding to multiple business entities. The entity enrichment is used to enrich the database user's operations. For each of the aforementioned business entities, user behavior learning is performed to establish a user behavior baseline; For each of the aforementioned business entities, access content learning is performed to establish a data content baseline; For each of the business entities, historical transaction learning is performed to establish a transaction pattern baseline, which is used to describe the transaction execution data of the business entity corresponding to historical operation transactions; Obtain the real-time operation flow of the database corresponding to the target entity; The real-time operation risk assessment of the real-time operation flow is performed using the user behavior baseline and the data content baseline to obtain the operation risk score corresponding to the real-time operation flow. Transaction correlation analysis is performed on the real-time operation flow using the transaction mode baseline to obtain correlation analysis data. Based on the operational risk score corresponding to the real-time operation flow and the correlation analysis data, the security risk level of the database operation corresponding to the real-time operation flow is generated.
2. The method according to claim 1, characterized in that, The step of learning the access content for each of the aforementioned business entities and establishing a data content baseline includes: Obtain the access core table corresponding to each of the aforementioned business entities; The first content baseline is obtained by learning the historical value distribution, normal fluctuation range, and change frequency of the numeric fields in the access core table; The second content baseline is obtained by learning the state enumeration set and state transition path of the enumeration type field in the access core table; Data format learning and check bit rule learning are performed on the preset sensitive fields in the access core table to obtain the third content baseline; The data content baseline is constructed based on the first content baseline, the second content baseline, and the third content baseline.
3. The method according to claim 1, characterized in that, The step of performing a real-time operation risk assessment on the real-time operation flow using the user behavior baseline and the data content baseline to obtain an operation risk score corresponding to the real-time operation flow includes: The user behavior score is obtained by evaluating the behavioral deviation of the real-time operation flow based on the user behavior baseline. The real-time operation stream is evaluated for data anomaly and semantic violation based on the data content baseline to obtain a data content score; Based on the user behavior score and the data content score, the operation risk score corresponding to the real-time operation flow is obtained.
4. The method according to claim 1, characterized in that, The step of performing transaction correlation analysis on the real-time operation flow using the transaction mode baseline to obtain correlation analysis data includes: Associate operations with the same transaction identifier in the real-time operation stream into a single transaction unit; The operation sequence analysis and atomicity violation analysis are performed on each of the transaction units to obtain the correlation analysis data.
5. The method according to claim 1, characterized in that, The step of learning historical transactions for each of the business entities and establishing a transaction pattern baseline includes: For each of the aforementioned business entities, transaction operation records are learned to obtain a first mode baseline; For each of the business entities, a transaction operation state learning is performed to obtain a second mode baseline; Transaction operation change learning is performed on each of the aforementioned business entities to obtain the third mode baseline; The transaction mode baseline is constructed based on the first mode baseline, the second mode baseline, and the third mode baseline.
6. The method according to claim 1, characterized in that, Also includes: Aggregate analysis is performed on database operations targeting the same business entity within a preset time period to obtain the aggregation analysis results; Based on the aggregation analysis results, operation warning information corresponding to the database operation is generated.
7. The method according to claim 1, characterized in that, Also includes: For target transaction operations whose operation risk score exceeds a preset threshold, the cryptographic hash value corresponding to the target transaction operation is determined as the unique digital fingerprint of the target transaction operation. Based on the unique digital fingerprint corresponding to the target transaction operation, the target transaction operation is stored on the blockchain. In response to an access request for the target transaction operation in the blockchain, relevant operation records corresponding to the target transaction operation are retrieved from the blockchain.
8. A security detection device for database data tampering, characterized in that, include: The parsing module is used to parse the operation records of database network traffic and local database logs to obtain network operation information and log operation information. The processing module is used to standardize and enrich the network operation information and the log operation information to obtain the database audit log. The database audit log describes the database operation information corresponding to multiple business entities. The entity enrichment is used to enrich the database user's operations. A module is established to perform user behavior learning for each of the business entities and establish a user behavior baseline; and to perform access content learning for each of the business entities and establish a data content baseline. For each of the business entities, historical transaction learning is performed to establish a transaction pattern baseline, which is used to describe the transaction execution data of the business entity corresponding to historical operation transactions; The acquisition module is used to acquire the real-time operation flow of the target entity corresponding to the database; The evaluation module is used to perform real-time operation risk assessment on the real-time operation flow based on the user behavior baseline and the data content baseline, and obtain the operation risk score corresponding to the real-time operation flow. The analysis module is used to perform transaction correlation analysis on the real-time operation flow based on the transaction mode baseline to obtain correlation analysis data; The generation module is used to generate the security risk level of the database operation corresponding to the real-time operation flow based on the operation risk score corresponding to the real-time operation flow and the correlation analysis data.
9. A computer device, characterized in that, It includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the security detection method for database data tampering as described in any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When a computer program is executed by a processor, it implements the security detection method for database data tampering as described in any one of claims 1 to 7.