Security audit method for distributed database and related device

By implementing a dynamic downgraded security audit method in distributed databases, the performance overhead problems brought about by security audits are solved, and the system processing efficiency and service experience are improved.

WO2025124273A1PCT designated stage expired Publication Date: 2025-06-19CHINA TELECOM CLOUD TECH CO LTD

Patent Information

Application Number
PCT/CN2024/137086
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-14
Filing Date
2024-12-05
Publication Date
2025-06-19

AI Technical Summary

Technical Problem

Distributed databases will incur additional performance overhead when performing security audits, and local audit logs will become a bottleneck in system performance, affecting request delay and service experience.

Method used

By obtaining the security audit request sent by the user terminal with the audit policy identification, the system database is called to obtain the corresponding security audit policy, obtain the system load status, and determine whether it meets the dynamic downgrade triggering conditions. If compliant, perform adjustment policies for dynamic downgrade operations to reduce the performance overhead of the audit.

Benefits of technology

Through dynamic downgrade operations, the performance impact of security audit on distributed databases is reduced, the system's processing efficiency and service experience are improved, and the performance bottlenecks caused by the audit log falling.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024137086_19062025_PF_FP_ABST
    Figure CN2024137086_19062025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a security audit method for a distributed database and a related device. The method comprises: acquiring a security audit request which is sent by a user terminal and carries an audit strategy identifier; acquiring, from a system database, a security audit strategy corresponding to the audit strategy identifier; acquiring a system load condition; determining whether the system load condition meets a dynamic degradation triggering condition; if the system load condition meets the dynamic degradation triggering condition, executing an adjustment strategy to perform a dynamic degradation operation; and if the system load condition does not meet the dynamic degradation triggering condition, outputting a load normal signal. In the present application, on the basis of the concept of audit dynamic degradation, during audit strategy configuration, a user can set a degradation triggering condition and a degradation operation on the basis of a system load condition, and when the degradation condition is met due to a high system load, dynamic degradation to low-overhead auditing or no auditing is triggered, thereby reducing the impact of auditing on the distributed database and an application.
Need to check novelty before this filing date? Find Prior Art

Description

A security audit method and related equipment applied to distributed database

[0001] Related applications

[0002] This application claims priority to Chinese patent application number 2023117205116, filed on December 14, 2023, entitled “A security audit method and related equipment for distributed databases,” the entire text of which is hereby incorporated by reference. Technical Field

[0003] The present invention relates to the field of IT and software development technology of artificial intelligence, and more specifically, to a security audit method and related equipment applied to a distributed database. Background Art

[0004] Distributed databases provide database auditing capabilities, recording database activity in real time. This provides comprehensive security traceability, diagnosis, and management capabilities for database risk behaviors such as SQL (Structured Query Language) injection and abnormal operations. Security auditing has become a key means for distributed databases to address security threats.

[0005] However, distributed databases incur additional performance overhead when performing security audits. Locally storing audit logs can also become a bottleneck in system performance, ultimately impacting request latency and service experience. This demonstrates the low processing efficiency of traditional distributed databases when performing security audits. Summary of the Invention

[0006] In order to overcome the above-mentioned defects of the prior art, the present invention provides a security audit method and related equipment applied to a distributed database.

[0007] This embodiment of the present application provides a security audit method for a distributed database, which adopts the following technical solutions:

[0008] Obtaining a security audit request carrying an audit policy identifier sent by a user terminal;

[0009] Calling a system database and obtaining a security audit policy corresponding to the audit policy identifier in the system database, wherein the security audit policy includes audit rules set for the operation of the database system and dynamic downgrade trigger conditions and adjustment strategies corresponding to the audit rules;

[0010] Get system load status;

[0011] Determining whether the system load condition meets the dynamic degradation triggering condition;

[0012] If the system load condition meets the dynamic degradation triggering condition, executing the adjustment strategy to perform a dynamic degradation operation;

[0013] If the system load condition does not meet the dynamic degradation triggering condition, a load normal signal is output.

[0014] Furthermore, the system load condition includes basic monitoring.

[0015] Furthermore, the system load condition includes distributed database monitoring.

[0016] In order to solve the above technical problems, the embodiment of the present application further provides a security audit device for a distributed database, which adopts the following technical solution:

[0017] A request acquisition module is used to acquire a security audit request carrying an audit policy identifier sent by a user terminal;

[0018] a policy acquisition module, configured to call a system database and acquire a security audit policy corresponding to the audit policy identifier in the system database, wherein the security audit policy includes audit rules set for the operation of the database system and dynamic downgrade trigger conditions and adjustment policies corresponding to the audit rules;

[0019] Load acquisition module, used to obtain system load conditions;

[0020] A condition judgment module, used to judge whether the system load condition meets the dynamic degradation triggering condition;

[0021] A first result module is configured to execute the adjustment strategy to perform a dynamic degradation operation if the system load condition meets the dynamic degradation triggering condition;

[0022] The second result module is configured to output a load normal signal if the system load condition does not meet the dynamic degradation triggering condition.

[0023] Furthermore, the system load condition includes basic monitoring.

[0024] Furthermore, the basic monitoring includes the load condition of the central processing unit.

[0025] Furthermore, the basic monitoring includes memory load conditions.

[0026] Furthermore, the basic monitoring includes the load condition of the disk.

[0027] Furthermore, the basic monitoring includes the load condition of the network.

[0028] Furthermore, the system load condition includes distributed database monitoring.

[0029] In order to solve the above technical problems, the embodiment of the present application further provides a computer device, which adopts the following technical solution:

[0030] The system comprises a memory and a processor, wherein the memory stores computer-readable instructions, and the processor implements the steps of the security audit method applied to a distributed database as described above when executing the computer-readable instructions.

[0031] In order to solve the above technical problems, the embodiment of the present application further provides a computer-readable storage medium, which adopts the following technical solution:

[0032] The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the security audit method applied to a distributed database as described above. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the conventional technology, the following briefly introduces the drawings required for use in the embodiments or the conventional technology descriptions. Obviously, the drawings described below are merely embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the disclosed drawings without any creative work.

[0034] FIG1 is a diagram of an exemplary system architecture in which the present application may be applied;

[0035] FIG2 is a flowchart of a security audit method for a distributed database according to an embodiment of the present invention;

[0036] 3 is a schematic diagram of the structure of a security audit device applied to a distributed database provided in Example 2 of the present application;

[0037] FIG4 is a schematic structural diagram of a computer device according to an embodiment of the present application. DETAILED DESCRIPTION

[0038] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0039] Unless otherwise defined, all technical and scientific terms used herein have the same meanings as commonly understood by those skilled in the art to which this application belongs. The terms used in the specification of the application are for the purpose of describing specific embodiments only and are not intended to limit this application. The terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned drawings are intended to cover non-exclusive inclusions. The terms "first", "second", etc. in the specification and claims of this application or the above-mentioned drawings are used to distinguish different objects, not to describe a specific order.

[0040] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0041] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.

[0042] As shown in Figure 1, system architecture 100 may include terminal devices 101, 102, and 103, a network 104, and a server 105. Network 104 is a medium for providing communication links between terminal devices 101, 102, and 103 and server 105. Network 104 may include various connection types, such as wired or wireless communication links or fiber optic cables.

[0043] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.

[0044] Terminal devices 101, 102, and 103 can be various electronic devices with display screens and support web browsing, including but not limited to smartphones, tablet computers, e-book readers, MP3 players (Moving Picture Experts Group Audio Layer III), MP4 (Moving Picture Experts Group Audio Layer IV), laptop computers, desktop computers, etc.

[0045] The server 105 may be a server that provides various services, such as a background server that provides support for web pages displayed on the terminal devices 101 , 102 , and 103 .

[0046] It should be noted that the security audit method applied to a distributed database provided in the embodiment of the present application is generally executed by a server / terminal device. Accordingly, the security audit device applied to a distributed database is generally set in the server / terminal device.

[0047] It should be understood that the number of terminal devices, networks, and servers in Figure 1 is merely illustrative and any number of terminal devices, networks, and servers may be provided as required.

[0048] 2, a flow chart of an embodiment of a security audit method for a distributed database according to the present application is shown. The security audit method for a distributed database includes: steps S201, S202, S203, S204, and S205.

[0049] In step S201, a security audit request carrying an audit policy identifier sent by a user terminal is obtained.

[0050] In the embodiments of the present application, the user terminal refers to a terminal device used to execute the image processing method for preventing document abuse provided by the present application. The user terminal can be a mobile terminal such as a mobile phone, a smart phone, a laptop computer, a digital broadcast receiver, a PDA (personal digital assistant), a PAD (tablet computer), a PMP (portable multimedia player), a navigation device, etc., as well as a fixed terminal such as a digital TV, a desktop computer, etc. It should be understood that the examples of user terminals here are only for convenience of understanding and are not used to limit the present application.

[0051] In step S202, the system database is called, and the security audit policy corresponding to the audit policy identifier is obtained in the system database, wherein the security audit policy includes a number of audit rules set for the operation of the database system and dynamic downgrade trigger conditions and adjustment strategies corresponding to the audit rules.

[0052] In an embodiment of the present application, the security audit policy is dynamically modified by the user through an interface during the operation of the database cluster. The security audit policy can include any number of audit rules set for the operation of the database system, as well as dynamic downgrade trigger conditions and policies corresponding to the audit rules. For example, for query events of specific database tables, an audit rule is created to monitor whether the client has abnormal queries, and a corresponding dynamic downgrade policy is created: no audit is performed when the node CPU utilization rate exceeds 80%.

[0053] In the embodiments of the present application, audit rules include auditable events and their processing rules. Auditable events refer to events such as connections that meet certain conditions (e.g., Connected, Disconnected, etc.), system variable modifications, and queries. The corresponding processing rules include operations such as analysis, recording audit logs, and / or passing information to downstream processing systems.

[0054] In the embodiment of this application, the execution process of the "audit rules" mainly includes the following steps:

[0055] 1. Occurrence of an audit event: When a user or application uses a database, various events such as connection, system variable modification, or query may be triggered. The event consists of information such as the event type, the possible libraries, tables, fields, and types involved. For example, an event occurs when the value of the col1 field in test_db.test_table is updated.

[0056] 2. Audit Processing: The database system processes audit events according to predefined audit rules, including analysis, logging, and / or passing information to downstream processing systems. For example, the processing rule might include logging in the audit log any updates to the col1 field in the test_db.test_table that occur more than 10 times within a minute.

[0057] In this embodiment, the primary purpose of downgrading is to reduce audit performance overhead and performance bottlenecks when the system load is high. Downgrading trigger conditions primarily describe system load conditions for downgrading, such as node CPU utilization >= 80% or database cluster QPS > 10,000.

[0058] In the embodiment of the present application, the adjustment strategy includes operations such as analyzing and recording audit logs and / or transmitting information to downstream processing systems. Since the main purpose of downgrading is to reduce audit performance overhead and performance bottlenecks when the system load is high, the downgrading strategy can include low-overhead auditing (sampling auditing or aggregated auditing), no auditing (ignoring events to be audited), etc., in order to reduce the impact of auditing on system performance.

[0059] In step S203, the system load condition is obtained.

[0060] In the embodiment of the present application, the system load condition includes but is not limited to the following operating status information:

[0061] 1. Basic monitoring, such as CPU, memory, disk, network and other hardware load conditions;

[0062] 2. Distributed database monitoring, such as database operation status, request TPS, QPS, number of connections, etc.

[0063] In step S204, it is determined whether the system load condition meets the dynamic degradation triggering condition.

[0064] In step S205 , if the system load condition meets the dynamic degradation triggering condition, the adjustment strategy is executed to perform the dynamic degradation operation.

[0065] In step S206 , if the system load condition does not meet the dynamic degradation triggering condition, a load normal signal is output.

[0066] In the embodiment of the present application, the security audit behavior is adjusted in real time according to the system load and the security audit policy. For example, when the system load is high, some unimportant or low-priority security audit rules are turned off according to the dynamic degradation policy configured by the user.

[0067] In an embodiment of the present application, a security audit method for a distributed database is provided, comprising: obtaining a security audit request carrying an audit policy identifier sent by a user terminal; calling a system database and obtaining a security audit policy corresponding to the audit policy identifier in the system database, wherein the security audit policy includes audit rules set for the operation of the database system and dynamic downgrade trigger conditions and adjustment policies corresponding to the audit rules; obtaining system load conditions; determining whether the system load conditions meet the dynamic downgrade trigger conditions; if the system load conditions meet the dynamic downgrade trigger conditions, executing the adjustment policy to perform a dynamic downgrade operation; if the system load conditions do not meet the dynamic downgrade trigger conditions, outputting a load normal signal. Compared with the prior art, the present application addresses the overhead and performance issues brought about by security audits of distributed databases by adopting the concept of dynamic downgrade of audits. When configuring the audit policy, the user can set the downgrade trigger conditions and downgrade operations according to the system load conditions. When the system load is high and the downgrade conditions are met, dynamic downgrade to low-overhead audit or no audit is triggered, thereby reducing the impact of the audit on the distributed database and applications. When the system load returns to normal, normal audit behavior is automatically restored.

[0068] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Artificial Intelligence (AI) is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to achieve optimal results.

[0069] Basic artificial intelligence technologies generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, big data processing technology, operation / interaction systems, and mechatronics. Artificial intelligence software technology mainly includes several major directions, such as computer vision technology, robotics technology, biometrics technology, speech processing technology, natural language processing technology, and machine learning / deep learning. Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing related hardware through computer-readable instructions. The computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, the aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).

[0070] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.

[0071] Example 2

[0072] Further referring to Figure 3, as an implementation of the method shown in Figure 2 above, the present application provides an embodiment of a security audit device applied to a distributed database. The device embodiment corresponds to the method embodiment shown in Figure 2, and the device can be specifically applied to various electronic devices.

[0073] As shown in FIG3 , the security audit device 200 applied to a distributed database in this embodiment includes:

[0074] The request acquisition module 210 is used to acquire a security audit request carrying an audit policy identifier sent by a user terminal;

[0075] The policy acquisition module 220 is used to call the system database and obtain the security audit policy corresponding to the audit policy identifier in the system database, wherein the security audit policy includes a number of audit rules set according to the operation of the database system and the dynamic downgrade trigger conditions and adjustment policies corresponding to the audit rules;

[0076] The load acquisition module 230 is used to obtain the system load condition;

[0077] Condition determination module 240, used to determine whether the system load condition meets the dynamic degradation triggering condition;

[0078] The first result module 250 is configured to execute an adjustment strategy to perform a dynamic degradation operation if the system load condition meets the dynamic degradation triggering condition;

[0079] The second result module 260 is configured to output a load normal signal if the system load condition does not meet the dynamic degradation triggering condition.

[0080] In the embodiments of the present application, the user terminal refers to a terminal device used to execute the image processing method for preventing document abuse provided by the present application. The user terminal can be a mobile terminal such as a mobile phone, a smart phone, a laptop computer, a digital broadcast receiver, a PDA (personal digital assistant), a PAD (tablet computer), a PMP (portable multimedia player), a navigation device, etc., as well as a fixed terminal such as a digital TV, a desktop computer, etc. It should be understood that the examples of user terminals here are only for convenience of understanding and are not used to limit the present application.

[0081] In an embodiment of the present application, the security audit policy is dynamically modified by the user through an interface during the operation of the database cluster. The security audit policy can include any number of audit rules set for the operation of the database system, as well as dynamic downgrade trigger conditions and policies corresponding to the audit rules. For example, for query events of specific database tables, an audit rule is created to monitor whether the client has abnormal queries, and a corresponding dynamic downgrade policy is created: no audit is performed when the node CPU utilization rate exceeds 80%.

[0082] In the embodiment of the present application, the system load condition includes but is not limited to the following operating status information:

[0083] 1. Basic monitoring, such as CPU, memory, disk, network and other hardware load conditions;

[0084] 2. Distributed database monitoring, such as database operation status, request TPS, QPS, number of connections, etc.

[0085] In the embodiment of the present application, the security audit behavior is adjusted in real time according to the system load and the security audit policy. For example, when the system load is high, some unimportant or low-priority security audit rules are turned off according to the dynamic degradation policy configured by the user.

[0086] In this embodiment, a security audit device 200 applied to a distributed database is provided, including: a request acquisition module 210, used to obtain a security audit request carrying an audit policy identifier sent by a user terminal; a policy acquisition module 220, used to call a system database and obtain a security audit policy corresponding to the audit policy identifier in the system database, wherein the security audit policy includes individual audit rules set for the operation of the database system and dynamic degradation trigger conditions and adjustment policies corresponding to the audit rules; a load acquisition module 230, used to obtain the system load situation; a condition judgment module 240, used to judge whether the system load situation meets the dynamic degradation trigger condition; a first result module 250, used to execute the adjustment policy to perform a dynamic degradation operation if the system load situation meets the dynamic degradation trigger condition; a second result module 260, used to output a load normal signal if the system load situation does not meet the dynamic degradation trigger condition. Compared to existing technologies, this application addresses the overhead and performance issues associated with security audits of distributed databases by adopting the concept of dynamic audit downgrade. When configuring audit policies, users can set downgrade trigger conditions and downgrade actions based on system load. When the system load is high and the downgrade conditions are met, dynamic downgrade to low-overhead auditing or no auditing is triggered, thereby reducing the impact of audits on distributed databases and applications. When the system load returns to normal, normal auditing behavior is automatically restored.

[0087] To solve the above technical problems, the present application also provides a computer device. Specifically, please refer to FIG4 , which is a basic structural block diagram of the computer device of this embodiment.

[0088] The computer device 300 includes a memory 310, a processor 320, and a network interface 330 that are interconnected through a system bus. It should be noted that the figure only shows the computer device 300 having components 310-330, but it should be understood that it is not required to implement all the components shown, and more or fewer components can be implemented instead. Among them, those skilled in the art can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0089] The computer device may be a desktop computer, notebook computer, PDA, cloud server, etc. The computer device may interact with the user via a keyboard, mouse, remote control, touchpad, or voice control device.

[0090] The memory 310 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic storage, magnetic disk, optical disk, etc. In some embodiments, the memory 310 may be an internal storage unit of the computer device 300, such as a hard disk or memory of the computer device 300. In other embodiments, the memory 310 may also be an external storage device of the computer device 300, such as a plug-in hard disk equipped on the computer device 300, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. Of course, the memory 310 may also include both the internal storage unit of the computer device 300 and its external storage device. In this embodiment, the memory 310 is generally used to store an operating system and various application software installed on the computer device 300, such as computer-readable instructions for a security audit method for a distributed database. In addition, the memory 310 can also be used to temporarily store various data that has been output or is about to be output.

[0091] In some embodiments, the processor 320 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 320 is generally used to control the overall operation of the computer device 300. In this embodiment, the processor 320 is used to execute computer-readable instructions stored in the memory 310 or process data, such as executing computer-readable instructions for the security audit method applied to a distributed database.

[0092] The network interface 330 may include a wireless network interface or a wired network interface. The network interface 330 is generally used to establish a communication connection between the computer device 300 and other electronic devices.

[0093] The computer device provided in this application addresses the overhead and performance issues associated with security audits of distributed databases by adopting the concept of dynamic audit downgrade. When configuring audit policies, users can set downgrade trigger conditions and downgrade actions based on system load. When the downgrade conditions are met due to high system load, dynamic downgrade to low-overhead auditing or no auditing is triggered, thereby reducing the impact of audits on distributed databases and applications. When the system load returns to normal, normal auditing behavior is automatically restored.

[0094] The present application also provides another embodiment, namely, providing a computer-readable storage medium, which stores computer-readable instructions, and the computer-readable instructions can be executed by at least one processor to enable the at least one processor to perform the steps of the security audit method applied to a distributed database as described above.

[0095] The computer-readable storage medium provided in this application addresses the overhead and performance issues associated with security audits of distributed databases by adopting the concept of dynamic audit downgrade. When configuring audit policies, users can set downgrade trigger conditions and downgrade actions based on system load. When the downgrade conditions are met due to high system load, dynamic downgrade to low-overhead auditing or no auditing is triggered, thereby reducing the impact of audits on distributed databases and applications. When the system load returns to normal, normal auditing behavior is automatically restored.

[0096] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0097] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the patent application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.

Claims

1. A security audit method applied to a distributed database, wherein: include: Obtaining a security audit request carrying an audit policy identifier sent by a user terminal; Calling a system database, and obtaining a security audit policy corresponding to the audit policy identifier in the system database, wherein the security audit policy includes a number of audit rules set for the operation of the database system and dynamic downgrade trigger conditions and adjustment strategies corresponding to the audit rules; Get system load status; Determining whether the system load condition meets the dynamic degradation triggering condition; If the system load condition meets the dynamic degradation triggering condition, executing the adjustment strategy to perform a dynamic degradation operation; If the system load condition does not meet the dynamic degradation triggering condition, a load normal signal is output.

2. The security audit method applied to a distributed database according to claim 1, wherein: The system load condition includes basic monitoring.

3. The security audit method applied to a distributed database according to claim 2, wherein: The basic monitoring includes the load condition of the central processing unit.

4. The security audit method applied to a distributed database according to claim 2, wherein: The basic monitoring includes the memory load condition.

5. The security audit method applied to a distributed database according to claim 2, wherein: The basic monitoring includes the load condition of the disk.

6. The security audit method applied to a distributed database according to claim 2, wherein: The basic monitoring includes the load condition of the network.

7. The security audit method applied to a distributed database according to claim 2, wherein: The basic monitoring includes the load condition of at least one of a central processing unit, a memory, a disk, and a network.

8. The security audit method applied to a distributed database according to any one of claims 1 to 7, wherein: The system load condition includes distributed database monitoring.

9. A security audit device applied to a distributed database, wherein: include: A request acquisition module, used to acquire a security audit request carrying an audit policy identifier sent by a user terminal; A policy acquisition module, used to call a system database and acquire a security audit policy corresponding to the audit policy identifier in the system database, wherein the security audit policy includes audit rules set for the operation of the database system and dynamic downgrade trigger conditions and adjustment strategies corresponding to the audit rules; Load acquisition module, used to obtain system load conditions; A condition judgment module, used to judge whether the system load condition meets the dynamic degradation triggering condition; A first result module, configured to execute the adjustment strategy to perform a dynamic degradation operation if the system load condition meets the dynamic degradation triggering condition; The second result module is used to output a load normal signal if the system load condition does not meet the dynamic degradation trigger condition.

10. The security audit device applied to a distributed database according to claim 9, wherein: The system load condition includes basic monitoring.

11. The security audit device for distributed database according to claim 10, wherein: The basic monitoring includes the load condition of the central processing unit.

12. The security audit device for distributed database according to claim 2, wherein: The basic monitoring includes the load condition of at least one of a central processing unit, a memory, a disk, and a network.

13. The security audit device applied to a distributed database according to any one of claims 9 to 12, wherein: The system load condition includes distributed database monitoring.

14. A computer device comprising a memory and a processor, wherein the memory stores computer-readable instructions, and when the processor executes the computer-readable instructions, the steps of the security audit method applied to a distributed database as described in any one of claims 1 to 8 are implemented.

15. A computer-readable storage medium, wherein: The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the security audit method applied to a distributed database as claimed in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Service degradation method and apparatus, and distributed task scheduling system

    CN106713028A

  • Transaction degradation method in distributed system and related equipment thereof

    CN113010271A

  • Data processing method and device, computer equipment and storage medium

    CN113778692A

  • Security auditing method applied to distributed database and related equipment

    CN117852024A

  • Session management in distributed storage systems

    US20150280959A1

Cited By

  • Concurrent processing method and device for water conservancy Internet of Things

    CN121217822A