
Editorial
Security Risk Modeling and Protection Resilience Assessment of Smart Tourism Distributed Graph Database Based on Hybrid Random Graph Model
@ARTICLE{10.4108/eetsis.12946, author={Xiang Li and Siying Li}, title={Security Risk Modeling and Protection Resilience Assessment of Smart Tourism Distributed Graph Database Based on Hybrid Random Graph Model}, journal={EAI Endorsed Transactions on Scalable Information Systems}, volume={13}, number={2}, publisher={EAI}, journal_a={SIS}, year={2026}, month={8}, keywords={Smart Tourism Ecosystem, Distributed graph database, Hybrid random graph, Data security risk modeling, Protection resilience assessment, Dynamic access control, Graph traversal attack}, doi={10.4108/eetsis.12946} }- Xiang Li
Siying Li
Year: 2026
Security Risk Modeling and Protection Resilience Assessment of Smart Tourism Distributed Graph Database Based on Hybrid Random Graph Model
SIS
EAI
DOI: 10.4108/eetsis.12946
Abstract
INTRODUCTION: Distributed graph database for smart tourism scenarios is becoming a key target of network attacks because it stores a large amount of sensitive data, such as user trajectories and consumer preferences. The network security and operational resilience of such databases directly determine the stability of the upper application ecosystem. OBJECTIVES: To address the lack of coordination between topology-aware risk modeling, active protection, and resilience assessment, this study develops an HRG–structural framework for distributed graph databases in smart tourism. The framework explicitly defines the threat model, including external attackers with partial graph knowledge and legitimate insiders who may abuse authorized traversal privileges. METHODS: First, a closed-loop mechanism of “risk identification–quantitative assessment–dynamic protection” is constructed. The HRG topology and the structural resilience model are coupled bidirectionally: topology-derived risk is transferred to the resilience evaluator, while quarantine and policy decisions feed back to edge probabilities and access paths. A time-decayed attack-exposure term, dynamic access control, traversal-depth restriction, sensitive-edge masking, node quarantine, and audit logging are integrated. In addition to the controlled security simulations, a real Neo4j Community 5.26.0 property-graph prototype is evaluated at 1,000–25,000 nodes. Fixed seeds, attack schedules, configuration files, raw results, and source code are supplied as Supplementary Material S1. RESULTS: In the original controlled comparison, the HRG–structural model achieved a comprehensive performance score of 92.6±1.5, an attack interception rate of 95.8%±0.8%, and a sensitive-data leakage suppression rate of 68.9%±2.5%. In the separate reproducibility stress test, removing both time decay and topology feedback reduced interception from 87.8% to 51.6% and increased trusted-state restoration time from 1.99 h to 3.54 h. The Neo4j prototype loaded a 25,000-node/100,000-edge graph in 1.51 s with a 60.59 MB store; policy-filtered traversal and quarantine-update mean latencies were 0.038 ms and 0.110 ms, respectively. These prototype values are single-host, in-process measurements rather than distributed-cluster results. CONCLUSION: The combined evidence supports the internal effectiveness of topology–risk–protection feedback and demonstrates technically feasible property-graph integration under the evaluated single-host and short-horizon conditions. The evidence does not constitute production-cluster validation against zero-day exploits, long-term advanced persistent threats, side channels, or multi-node collusion; those scenarios remain deployment-stage priorities.
Copyright © 2026 Xiang Li et al., licensed to EAI. This is an open access article distributed under the terms of the CC BY-NC-SA 4.0, which permits copying, redistributing, remixing, transformation, and building upon the material in any medium so long as the original work is properly cited.


