Geophysical computing system protection method and device

Through scripted processing, login protection, system protection and data protection of geophysical high-performance computing systems is solved, and the low-version software of the operating system cannot meet the needs of cluster security management, achieving the effectiveness of cluster security management and reducing operation and maintenance costs.

CN120185828APending Publication Date: 2025-06-20CHINA PETROLEUM & CHEMICAL CORP +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311748575.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-19
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

The low-version software that comes with the operating system cannot meet the security management needs of geophysical computing clusters, resulting in difficulty in security maintenance.

Method used

Through scripting processing, login protection, system protection and data protection of geophysical high-performance computing systems can be achieved, and shell scripts are used to batch update and patch medium and high-risk vulnerabilities in the cluster.

Benefits of technology

It effectively meets the security management needs of geophysical clusters, reduces operation and maintenance costs, and improves the efficiency of security maintenance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120185828A_ABST
    Figure CN120185828A_ABST
Patent Text Reader

Abstract

The invention provides a geophysical computing system protection method and a geophysical computing system protection device, which solve the problem that low-version software of an operating system cannot meet the requirement of cluster security management and brings difficulty to security maintenance of a cluster. The geophysical computing system protection method comprises the steps that when a user logs in a system, a login protection function is started, a risk value of a host is acquired, whether the host is in a high-risk state or not is judged based on the risk value, and if yes, host repair is carried out; after a user logs in the system, a system protection function is started, and the firewall is configured based on policy configuration so as to close unnecessary services; and when the user accesses the system, starting a data protection function, and auditing the user permission to control the access permission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information technology, and in particular to a method and device for protecting a geophysical computing system. Background Art

[0002] For large computer rooms with a large number of nodes and where the operating system version is mainly concentrated on the Linux version, the process of node security protection and vulnerability repair requires a lot of time, manpower and material resources.

[0003] A large number of computing clusters are used to perform computing tasks in the geophysical field. Operation and maintenance personnel need to perform security maintenance on computing clusters and sort out hosts with medium and high risks through regular vulnerability scanning. With the development of security technology and the continuous upgrading of operating systems, the low-version software that comes with the operating system can no longer meet the needs of cluster security management, which brings difficulties to cluster security maintenance. Summary of the invention

[0004] In view of this, an embodiment of the present invention provides a geophysical computing system protection method and device, which solves the problem that the low-version software provided by the operating system can no longer meet the requirements of cluster security management, causing difficulties in cluster security maintenance.

[0005] In a first aspect, a geophysical computing system protection method provided by an embodiment of the present invention includes:

[0006] When a user logs into the system, the login protection function is activated, the host risk value is obtained, and based on the risk value, it is determined whether the host is in a high-risk state. If so, the host is repaired;

[0007] When the user logs into the system, the system protection function is activated and the firewall is configured based on the policy configuration to shut down non-essential services;

[0008] When a user accesses the system, the data protection function is activated and user permissions are audited to control access rights.

[0009] In one embodiment, obtaining a host risk value and determining whether the host is in a high-risk state based on the risk value includes:

[0010] Scan system vulnerabilities to obtain vulnerability data, and obtain a host risk value based on the vulnerability data;

[0011] The host risk level is obtained based on the host risk value and the risk area range, and it is determined whether the host risk level is in a high-risk state.

[0012] In one embodiment, the host repair includes at least one of: deleting or locking irrelevant accounts, deleting passwords that do not conform to the rules, configuring minimum permissions as required, remotely maintaining the IP protocol, configuring timed automatic account logout and automatic screen locking, and patch management.

[0013] In one embodiment, the configuration of the firewall based on policy configuration includes: enabling route forwarding, setting TCP / UDP traffic relay, reloading the configuration file and making it effective to complete the configuration of the firewall.

[0014] In one embodiment, the non-essential services include at least one of: rexec service, rlogin service, and rsh service.

[0015] In one embodiment, the access permissions include at least one of: user permissions, group permissions, and other user permissions.

[0016] In one embodiment, it further includes: recording and saving user operation logs.

[0017] In a second aspect, a geophysical computing system protection device provided by an embodiment of the present invention includes:

[0018] A login protection module, which is used to start the login protection function when a user logs in to the system, obtain the host risk value, and determine whether the host is in a high-risk state based on the risk value. If so, perform host repair;

[0019] A system protection module, which is used to start the system protection function after the user logs in to the system, and configure the firewall based on policy configuration to close non-essential services;

[0020] A data protection module, which is used to start the data protection function when the user accesses the system, and audit the user permissions to control the access permissions.

[0021] In a third aspect, an electronic device provided by an embodiment of the present invention includes a memory and a processor. The memory is used to store one or more computer instructions. Among them, when the one or more computer instructions are executed by the processor, the above-mentioned geophysical computing system protection method is implemented.

[0022] In a fourth aspect, a computer-readable storage medium provided by an embodiment of the present invention stores a computer program. When the computer program is executed by one or more processors, the above-mentioned geophysical computing system protection method is implemented.

[0023] A method and device for protecting a geophysical computing system provided by an embodiment of the present invention. By scripting the operation steps, the present invention batch-upgrades to complete the login protection, system protection, and data protection of the geophysical high-performance computing system, meets the needs of geophysical cluster security and network protection operations, and thus reduces the operation and maintenance costs. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 The figure shows a schematic flowchart of a method for protecting a geophysical computing system provided by an embodiment of the present invention.

[0025] Figure 2 The figure shows a schematic diagram of a setting page for access control permissions provided by an embodiment of the present invention.

[0026] Figure 3 The figure shows a schematic structural diagram of a device for protecting a geophysical computing system provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present invention.

[0028] Example 1:

[0029] This embodiment provides a method for protecting a geophysical computing system. This method for protecting a geophysical computing system scripts the operation steps, thereby batch-upgrading to complete the login protection, system protection, and data protection of the geophysical high-performance computing system, meets the needs of geophysical cluster security and network protection operations, and thus reduces the operation and maintenance costs.

[0030] The method for protecting a geophysical computing system provided in this embodiment is mainly an upgrade step organized based on login protection, system protection, and data protection, and uses shell scripts to batch-update and upgrade the high-performance computing cluster to repair medium and high-risk vulnerabilities in the cluster.

[0031] A Shell script is a program with special functions. It is an interface between the user and the kernel of the UNIX / Linux operating system. Shell scripts are most commonly used for system administration tasks or for combining existing programs to complete small, specific tasks. Once you figure out how to complete a task, you can string together the commands you used and put them into a separate program or script. Then, you can simply execute that program to complete the task in the future.

[0032] Example 2:

[0033] This embodiment provides a method for protecting a geophysical computing system, as Figure 1 shown. The method for protecting a geophysical computing system includes:

[0034] Step 01: When a user logs in to the system, start the login protection function, obtain the host risk value, and determine whether the host is in a high-risk state based on the risk value. If so, perform host repair.

[0035] Further, the obtaining the host risk value and determining whether the host is in a high-risk state based on the risk value includes:

[0036] Step 011: Scan for system vulnerabilities to obtain vulnerability data, and obtain the host risk value based on the vulnerability data.

[0037] Among them, the host risk value is obtained according to the SGRI-CVE calculation formula:

[0038] SGRI-CVE = number of vulnerabilities X severity of vulnerabilities X scope of impact of vulnerabilities.

[0039] Among them, SGRI-CVE is the host risk value.

[0040] Number of vulnerabilities: The number of security vulnerabilities in the system (the system will regularly maintain the vulnerability database).

[0041] Severity of vulnerabilities: Determine the severity of each vulnerability according to the analysis label of each vulnerability in the vulnerability database.

[0042] Scope of impact of vulnerabilities: The scope of the system affected by the vulnerability, such as servers, clients, networks, storage, databases, etc.

[0043] Step 012: Obtain the host risk level based on the host risk value and the risk area range, and determine whether the host risk level is in a high-risk state.

[0044] Specifically, the risk level assessment criteria are shown in the following table:

[0045] Host risk level Host risk value range Very dangerous 7.0 <= Host risk value <= 10.0 Relatively dangerous 5.0 <= Host risk value < 7.0 Relatively safe 2.0 <= Host risk value < 5.0 Very safe 0.0 <= Host risk value < 2.0

[0046] It can be known that the machine is in a high-risk state. The host is automatically repaired according to the analysis program of this tool. The host repair includes at least one of the following: deleting or locking irrelevant accounts, deleting passwords that do not conform to the rules, configuring the minimum permissions as required, remotely maintaining the IP protocol, configuring timed automatic account logout and automatic screen locking, and patch management.

[0047] Optionally, the repair content is reported as follows:

[0048] 1) Accounts: Accounts that are irrelevant to device operation, maintenance, etc. should be deleted or locked. There are built-in accounts in the system that cannot be deleted, including root, bin, etc.; restrict remote login of users with super administrator privileges. For remote execution of administrator privilege operations, first remotely log in as a normal privilege user, and then switch to the super administrator privilege account to perform the corresponding operations.

[0049] 2) Passwords: For devices using static password authentication technology, the password length should be at least 6 digits and include at least 2 of the 4 categories of numbers, lowercase letters, uppercase letters, and special symbols; for devices using static password authentication technology, the lifespan of the account password should not exceed 90 days.

[0050] 3) Authorization: Configure the minimum permissions required according to the user's business needs within the device permission configuration capabilities.

[0051] 4) IP protocol security configuration: The device should support listing the correspondence table between the IP service ports open to the outside world and the internal processes of the device; for devices using the IP protocol for remote maintenance, the device should be configured to use encrypted protocols such as SSH.

[0052] 5) Timeout protection: For devices with a character interaction interface, configure timed automatic account logout; for devices with a graphical interface (including WEB interface), configure timed automatic screen locking.

[0053] 6) Patch management: It is recommended to only install the basic OS part during system installation, and for the remaining software packages, install them on a need-to-have basis, and do not install non-essential packages.

[0054] Step 02: After the user logs in to the system, start the system protection function and configure the firewall based on the policy configuration to turn off unnecessary services.

[0055] In the Linux system, the firewall is a very powerful function. firewall-cmd provides a dynamic firewall management tool that supports network / firewall zone definitions, network link, and interface security levels. It supports IPv4 and IPv6 firewall settings, as well as Ethernet bridging, and has runtime configuration and permanent configuration options. It also supports an interface that allows services or applications to directly add firewall rules.

[0056] Furthermore, configuring the firewall based on the policy configuration includes: enabling routing forwarding, setting TCP / UDP traffic forwarding, reloading the configuration file and making it effective to complete the configuration of the firewall.

[0057] Optionally, configure the firewall as follows:

[0058] Enable routing forwarding

[0059] Add the code net.ipv4.ip_forward=1 at the end of the file / etc / sysctl.conf and execute the following command:

[0060] echo 'net.ipv4.ip_forward=1' >> / etc / sysctl.conf

[0061] Then execute the following command in the command line to make it effective:

[0062] sysctl - p

[0063] Finally, enable the traffic masquerading function of the firewall and execute the following command:

[0064] firewall-cmd --zone=public --permanent --add-masquerade

[0065] Thus, routing forwarding is successfully enabled.

[0066] Set TCP / UDP forwarding

[0067] First, you need to open the port. For example, to open a port 25021, execute the following command

[0068] # Open the TCP traffic port

[0069] firewall-cmd --add-port=25021 / tcp --permanent

[0070] # At the same time, open the TCP traffic forwarding for multiple ports

[0071] firewall-cmd --add-port=25021-25030 / tcp --permanent

[0072] # Open the UDP traffic port

[0073] firewall-cmd --add-port=25021 / udp --permanent

[0074] In this way, TCP and UDP traffic can enter through port 25021.

[0075] # Forward the remote port

[0076] This is traffic forwarding. For example, if you want to forward the traffic received on port 8080 of the server with IP address 10.225.62.xx to port 666 of the server with IP address 192.168.102.xx, execute the following command on the server with IP address 10.225.62.xx:

[0077] # Enable TCP traffic forwarding

[0078] firewall-cmd

[0079] --add-forward-port=port=8080:proto=tcp:toaddr=192.168.102.xx:toport=666 --permanent

[0080] # Enable UDP traffic forwarding

[0081] firewall-cmd

[0082] --add-forward-port=port=8080:proto=udp:toaddr=192.168.102.xx:toport=666 --permanent

[0083] Reload the configuration file

[0084] After setting the rules, you need to reload the configuration file to take effect. Execute the following command:

[0085] firewall-cmd --reload

[0086] After configuring the firewall, turn off unnecessary services. Among them, the unnecessary services include at least one of the rexec service, the rlogin service, and the rsh service.

[0087] When the alarms scanned by the firewall include: detecting that the remote rexec service is running; detecting that the remote rlogin service is running; detecting that the remote rsh service is running.

[0088] The above three services are brought in by the network request daemon process xinetd.d. Since these three services do not provide good authentication methods and the authentication system is quite simple and vulnerable to attacks, it may be used by attackers to scan third-party hosts. Attackers can use this service to remotely brute-force guess usernames and passwords, or listen to the communication processes of other authorized users to obtain the plaintext passwords, such as the X-scan tool.

[0089] Therefore, it is necessary to turn off the corresponding services in the configuration files / etc / xinetd.d / rexec, / etc / xinetd.d / rlogin, and / etc / xinetd.d / rsh.

[0090] Step 03: When a user accesses the system, start the data protection function and audit the user permissions to control the access permissions.

[0091] Optionally, the access permissions include at least one of user permissions, group permissions, and other user permissions.

[0092] The permissions of the Linux file system are divided into three main types:

[0093] User permissions: The owner of a file and directory has specific access permissions to the file and directory, including read, write, and execute permissions.

[0094] Group permissions: The group to which a file and directory belong also has specific access permissions to the file and directory, including read, write, and execute permissions. A user can belong to multiple groups.

[0095] Other user permissions: All other users except the owner and the group to which the file belongs are classified as other users and also have a set of specific access permissions, including read, write, and execute permissions.

[0096] In the Linux file system, each file and directory has an owner and a group to which it belongs, and a set of basic permissions is set. These permissions control who can access the file or directory and what operations they can perform. The basic permissions of files and directories are usually represented by three numbers, each number representing a different user group: the owner, the group to which the file belongs, and other users. The basic permissions include read, write, and execute permissions, which are represented by the numbers 4, 2, and 1 respectively. Each user group can use these numbers to specify their access permissions to the file or directory. For example, if a file is set with permissions of 644, then its owner has read and write permissions, while the group to which the file belongs and other users only have read permissions.

[0097] Reference Figure 2 As shown, taking storage as an example: Log in to the storage management interface and set the file access control permissions for the directory on the file directory.

[0098] In this geophysical computing system protection method, it further includes step 04: Record and save the user operation logs.

[0099] Linux usually uses history to record, but the defect of history is that it defaults to 1000 lines. Although it can be modified from 1000 to 1000000 lines in / etc / profile, this is just a general approach, and history can be cleared, making it impossible to see the detailed user sources and operation records, such as source IP addresses, operation times, operating users, etc. Therefore, the following script is written to record the user's login IP, operation time, and operation commands. Then, the log file is saved in the / var / log / history / directory.

[0100] Optionally, its program expression is as follows:

[0101] #! / usr / bin / env bash

[0102] # / / Get the user IP

[0103] USER_IP=`who -u am i 2> / dev / null|awk '{print$NF}'|sed -e's / [()] / / g'`

[0104] # / / Get the current date

[0105] DT=`date +"%Y%m%d"`

[0106] # / / Set the history record file

[0107] export HISTORY_FILE=" / var / log / history / ${LOGNAME} / ${DT} / ${USER_IP}.log"

[0108] dir=`dirname$HISTORY_FILE`

[0109] if [! -d$dir];then

[0110] mkdir -p$dir

[0111] chmod 300$dir

[0112] fi

[0113] export PROMPT_COMMAND='{date "+%Y-%m-%d%T$(history 1)";}>>

[0114] $HISTORY_FILE'

[0115] export HISTCONTROL=ignoredups.

[0116] In this embodiment, by scripting the operation steps, the login protection, system protection, and data protection of the geophysical high-performance computing system are batch-updated and completed. The shell script is used to batch-update and upgrade the high-performance computing cluster and repair the medium and high-risk vulnerabilities in the cluster, meeting the needs of the geophysical cluster security and network protection operations, thereby reducing the operation and maintenance costs.

[0117] Example 3:

[0118] This embodiment provides a protection device 100 for a geophysical computing system. As Figure 3 shown, the protection device 100 for the geophysical computing system includes a login protection module 10, a system protection module 20, and a data protection module 30. Among them, the functions of each module are as follows:

[0119] The login protection module 10 is used to start the login protection function when a user logs in to the system, obtain the host risk value, and determine whether the host is in a high-risk state based on the risk value. If so, host repair is performed. The host repair includes at least one of: deleting or locking irrelevant accounts, deleting passwords that do not conform to the rules, configuring the minimum permissions as required, remotely maintaining the IP protocol, configuring timed automatic logout of accounts and automatic screen locking, and patch management.

[0120] The system protection module 20 is used to start the system protection function after the user logs in to the system, and configure the firewall based on the policy configuration to turn off unnecessary services. The unnecessary services include at least one of: the rexec service, the rlogin service, and the rsh service.

[0121] The data protection module 30 is used to start the data protection function when the user accesses the system, and audit the user permissions to control the access permissions. The access permissions include at least one of: user permissions, group permissions, and other user permissions.

[0122] Furthermore, the login protection module 10 is also used to scan system vulnerabilities to obtain vulnerability data, and obtain the host risk value based on the vulnerability data; obtain the host risk level based on the host risk value and the risk area range, and determine whether the host risk level is in a high-risk state.

[0123] Further, the system protection module 20 is also used to configure the firewall based on the policy configuration, including: enabling routing forwarding, setting TCP / UDP traffic relay, reloading the configuration file and making it effective, so as to complete the configuration of the firewall.

[0124] The geophysical computing system protection device 100 further includes a storage module 40, which is used to record and save user operation logs.

[0125] Example 4:

[0126] This embodiment provides an electronic device, which can be a mobile phone, a computer, a tablet computer, etc., including a memory and a processor. A computer program is stored on the memory, and when the computer program is executed by the processor, it implements the geophysical computing system protection method as described in Embodiment 1. It can be understood that the electronic device may further include an input / output (I / O) interface and a communication component.

[0127] Among them, the processor is used to execute all or part of the steps in the geophysical computing system protection method in Embodiment 1. Specifically, it includes:

[0128] Step 01: When the user logs in to the system, start the login protection function, obtain the host risk value, and judge whether the host is in a high-risk state based on the risk value. If so, perform host repair.

[0129] Further, the obtaining the host risk value and judging whether the host is in a high-risk state based on the risk value includes:

[0130] Step 011: Scan system vulnerabilities to obtain vulnerability data, and obtain the host risk value based on the vulnerability data.

[0131] Among them, the host risk value is obtained according to the SGRI-CVE calculation formula:

[0132] SGRI-CVE = number of vulnerabilities × severity of vulnerabilities × scope of vulnerability impact.

[0133] Among them, SGRI-CVE is the host risk value.

[0134] Number of vulnerabilities: The number of security vulnerabilities in the system (the system will regularly maintain the vulnerability database).

[0135] Severity of vulnerabilities: Judge the severity of each vulnerability according to the analysis label of each vulnerability in the vulnerability database.

[0136] Scope of vulnerability impact: The scope of the system affected by the vulnerability, such as servers, clients, networks, storage, databases, etc.

[0137] Step 012: Obtain the host risk level based on the host risk value and the risk area range, and determine whether the host risk level is in a high-risk state.

[0138] Specifically, the risk level assessment criteria are shown in the following table:

[0139] Host risk level Host risk value range Very dangerous 7.0 <= Host risk value <= 10.0 Relatively dangerous 5.0 <= Host risk value < 7.0 Relatively safe 2.0 <= Host risk value < 5.0 Very safe 0.0 <= Host risk value < 2.0

[0140] It can be seen that the machine is in a high-risk state. Perform automatic host repair according to the analysis program of this tool. The host repair includes at least one of the following: deleting or locking irrelevant accounts, deleting passwords that do not conform to the rules, configuring the minimum permissions as required, remotely maintaining the IP protocol, configuring timed automatic account logout and automatic screen locking, and patch management.

[0141] Optionally, the repair content report is as follows:

[0142] 1) Accounts: Accounts that are irrelevant to device operation, maintenance, etc. should be deleted or locked. There are built-in accounts in the system that cannot be deleted, including root, bin, etc.; restrict remote login of users with super administrator privileges. For remote execution of administrator privilege operations, first remotely log in as a regular privilege user, and then switch to the super administrator privilege account to perform the corresponding operations.

[0143] 2) Passwords: For devices using static password authentication technology, the password length should be at least 6 digits and include at least 2 of the 4 categories of numbers, lowercase letters, uppercase letters, and special symbols; for devices using static password authentication technology, the lifespan of the account password should not be longer than 90 days.

[0144] 3) Authorization: Configure the minimum permissions required according to the user's business needs within the device permission configuration capabilities.

[0145] 4) IP protocol security configuration: The device should support listing the corresponding table of IP service ports open to the outside world and internal processes of the device; for devices using the IP protocol for remote maintenance, the device should be configured to use encrypted protocols such as SSH.

[0146] 5) Timeout protection: For devices with a character interaction interface, configure timed automatic account logout; for devices with a graphical interface (including WEB interface), configure timed automatic screen locking.

[0147] 6) Patch management: It is recommended to only install the basic OS part during system installation, and for the remaining software packages, install them on a need-to-have basis, and do not install non-essential packages.

[0148] Step 02: When the user logs in to the system, start the system protection function and configure the firewall based on the policy configuration to turn off unnecessary services.

[0149] Firewall is a very powerful feature in Linux system. Firewall-cmd provides a dynamic firewall management tool that supports network / firewall zones to define network links and interface security levels. It supports IPv4, IPv6 firewall settings and Ethernet bridging, and has runtime configuration and permanent configuration options. It also supports interfaces that allow services or applications to add firewall rules directly.

[0150] Furthermore, the configuration of the firewall based on the policy configuration includes: opening routing forwarding, setting TCP / UDP traffic transfer, reloading the configuration file and taking effect, so as to complete the configuration of the firewall.

[0151] Optionally, configure the firewall as follows:

[0152] Enable routing forwarding

[0153] Add the code net.ipv4.ip_forward=1 to the end of the file / etc / sysctl.conf and execute the following commands:

[0154] echo'net.ipv4.ip_forward=1'>> / etc / sysctl.conf

[0155] Then execute the following command on the command line to make it effective:

[0156] sysctl -p

[0157] Finally, enable the traffic masquerade function of the firewall and execute the following command:

[0158] firewall-cmd--zone=public--permanent--add-masquerade

[0159] At this point, routing forwarding is successfully enabled.

[0160] Setting up TCP / UDP forwarding

[0161] First you need to open the port, for example, open a port 25021 and execute the following command

[0162] #Open TCP traffic port

[0163] firewall-cmd--add-port=25021 / tcp--permanent

[0164] #Open multiple ports of TCP traffic forwarding at the same time

[0165] firewall-cmd --add-port=25021-25030 / tcp --permanent

[0166] # Open UDP traffic ports

[0167] firewall-cmd --add-port=25021 / udp --permanent

[0168] In this way, TCP and UDP traffic can enter through port 25021.

[0169] # Forward remote ports

[0170] This is traffic relay. For example, if you want to relay the traffic received on port 8080 of the server with IP address 10.225.62.xx to port 666 of the server with IP address 192.168.102.xx, execute the following command on the server with IP address 10.225.62.xx:

[0171] # Enable TCP traffic forwarding

[0172] firewall-cmd

[0173] --add-forward-port=port=8080:proto=tcp:toaddr=192.168.102.xx:toport=666 --permanent

[0174] # Enable UDP traffic forwarding

[0175] firewall-cmd

[0176] --add-forward-port=port=8080:proto=udp:toaddr=192.168.102.xx:toport=666 --permanent

[0177] Reload the configuration file

[0178] After setting the rules, you need to reload the configuration file to take effect. Execute the following command:

[0179] firewall-cmd --reload.

[0180] After configuring the firewall, turn off unnecessary services. Among them, the unnecessary services include at least one of the rexec service, the rlogin service, and the rsh service.

[0181] When the alarms scanned by the firewall include: detecting that the remote rexec service is running; detecting that the remote rlogin service is running; detecting that the remote rsh service is running.

[0182] The above three services are brought in by the network request daemon process xinetd.d. Since these three services do not provide good authentication methods and the authentication system is quite simple and vulnerable to attacks, it may be used by attackers to scan third-party hosts. Attackers can remotely brute-force guess usernames and passwords through this service, or listen to the communication processes of other authorized users to obtain the clear text of passwords, such as the X-scan tool.

[0183] Therefore, it is necessary to turn off the corresponding services in the configuration files / etc / xinetd.d / rexec, / etc / xinetd.d / rlogin, and / etc / xinetd.d / rsh.

[0184] Step 03: When a user accesses the system, start the data protection function and audit the user permissions to control the access permissions.

[0185] Optionally, the access permissions include at least one of user permissions, group permissions, and other user permissions.

[0186] The permissions of the Linux file system are divided into three main types:

[0187] User permissions: The owner of a file and directory has specific access permissions to the file and directory, including read, write, and execute permissions.

[0188] Group permissions: The group to which a file and directory belong also has specific access permissions to the file and directory, including read, write, and execute permissions. A user can belong to multiple groups.

[0189] Other user permissions: All other users except the owner and the group to which the file or directory belongs are other users and also have a set of specific access permissions, including read, write, and execute permissions.

[0190] In the Linux file system, each file and directory has an owner and a group to which it belongs, and a set of basic permissions is set. These permissions control who can access the file or directory and what operations they can perform. The basic permissions of files and directories are usually represented by three numbers, and each number represents a different user group: the owner, the group to which the file or directory belongs, and other users. The basic permissions include read, write, and execute permissions, which are represented by the numbers 4, 2, and 1 respectively. Each user group can use these numbers to specify their access permissions to the file or directory. For example, if a file is set with permissions of 644, then its owner has read and write permissions, and the group to which the file belongs and other users only have read permissions.

[0191] Taking storage as an example: Log in to the storage management interface and set the file access control permissions for the directory on the file directory.

[0192] In the geophysical computing system protection method, it further includes step 04: Recording and saving the user operation logs.

[0193] Linux usually uses history to record, but the defect of history is that the default is 1000 lines. Although it can be modified from 1000 to 1000000 lines in / etc / profile, this is just a general approach, and history can be cleared, making it impossible to see the detailed user source and operation records, such as the source IP address, operation time, operating user, etc. Therefore, the following script is written to record the user's login IP, operation time, and operation commands. Then, the log file is saved in the / var / log / history / directory.

[0194] Optionally, its program expression is as follows:

[0195] #! / usr / bin / env bash

[0196] # / / Get the user IP

[0197] USER_IP=`who -u am i 2> / dev / null|awk '{print $NF}'|sed -e's / [()] / / g'`

[0198] # / / Get the current date

[0199] DT=`date +"%Y%m%d"`

[0200] # / / Set the history record file

[0201] export HISTORY_FILE=" / var / log / history / ${LOGNAME} / ${DT} / ${USER_IP}.log"

[0202] dir=`dirname $HISTORY_FILE`

[0203] if [! -d $dir ]; then

[0204] mkdir -p $dir

[0205] chmod 300 $dir

[0206] fi

[0207] export PROMPT_COMMAND='{date "+%Y-%m-%d%T$(history 1)";}>>

[0208] $HISTORY_FILE'

[0209] export HISTCONTROL=ignoredups.

[0210] In this embodiment, by scripting the operation steps, the login protection, system protection, and data protection of the geophysical high-performance computing system are completed in batch. The shell script is used to batch update and upgrade the high-performance computing cluster and repair the medium and high-risk vulnerabilities in the cluster, meeting the needs of the geophysical cluster security and network protection operations, thereby reducing the operation and maintenance costs.

[0211] The memory is used to store various types of data, which may include, for example, instructions of any application or method in the electronic device, as well as application-related data.

[0212] The processor may be implemented by an application specific integrated circuit (ASIC), a digital signal processor (DSP), a programmable logic device (PLD), a field programmable gate array (FPGA), a controller, a microcontroller, a microprocessor, or other electronic components, and is used to execute the geophysical computing system protection method in the first embodiment above.

[0213] The memory may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk, or an optical disc.

[0214] Example 5:

[0215] This embodiment also provides a computer-readable storage medium. In each embodiment of the present invention, each functional unit can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium.

[0216] Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention.

[0217] The aforementioned storage medium includes: flash memory, hard disk, multimedia card, card-type memory (such as SD or DX memory, etc.), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, server, APP application mall, and other various media that can store program verification codes. A computer program is stored thereon, and when the computer program is executed by a processor, the following method steps can be implemented:

[0218] Step 01: When the user logs in to the system, start the login protection function, obtain the host risk value, and determine whether the host is in a high-risk state based on the risk value. If so, perform host repair.

[0219] Further, the obtaining of the host risk value and determining whether the host is in a high-risk state based on the risk value includes:

[0220] Step 011: Scan system vulnerabilities to obtain vulnerability data, and obtain the host risk value based on the vulnerability data.

[0221] Among them, the host risk value is obtained according to the SGRI-CVE calculation formula:

[0222] SGRI-CVE = number of vulnerabilities × vulnerability severity × scope of vulnerability impact.

[0223] Among them, SGRI-CVE is the host risk value.

[0224] Number of vulnerabilities: The number of security vulnerabilities existing in the system (the system will regularly maintain the vulnerability library).

[0225] Vulnerability severity: Determine the severity of the vulnerability based on the analysis tags of each vulnerability in the vulnerability database.

[0226] Vulnerability impact scope: The scope of the system affected by the vulnerability, such as servers, clients, networks, storage, databases, etc.

[0227] Step 012: Obtain the host risk level based on the host risk value and the risk area scope, and determine whether the host risk level is in a high-risk state.

[0228] Specifically, the risk level assessment criteria are shown in the following table:

[0229] Host risk level Host risk value range Very dangerous 7.0 <= Host risk value <= 10.0 Relatively dangerous 5.0 <= Host risk value < 7.0 Relatively safe 2.0 <= Host risk value < 5.0 Very safe 0.0 <= Host risk value < 2.0

[0230] It can be known that the machine is in a high-risk state. Automatically repair the host according to the analysis program of this tool. The host repair includes at least one of the following: deleting or locking irrelevant accounts, deleting passwords that do not conform to the rules, configuring the minimum permissions as required, remotely maintaining the IP protocol, configuring timed automatic account logout and automatic screen locking, and patch management.

[0231] Optionally, the repair content report is as follows:

[0232] 1) Accounts: Accounts that are irrelevant to device operation, maintenance, etc. should be deleted or locked. There are built-in accounts in the system that cannot be deleted, including root, bin, etc.; restrict remote login of users with super administrator privileges. When performing remote administrator privilege operations, first remotely log in as a normal privilege user, and then switch to the super administrator privilege account to perform the corresponding operations.

[0233] 2) Passwords: For devices using static password authentication technology, the password length should be at least 6 digits and include at least 2 of the 4 categories of numbers, lowercase letters, uppercase letters, and special symbols; for devices using static password authentication technology, the lifespan of the account password should not exceed 90 days.

[0234] 3) Authorization: Configure the minimum permissions required according to the user's business needs within the device permission configuration capabilities.

[0235] 4) IP protocol security configuration: The device should support listing the corresponding table of the IP service ports open to the outside world and the internal processes of the device; for devices using the IP protocol for remote maintenance, the device should be configured to use encrypted protocols such as SSH.

[0236] 5) Timeout protection: For devices with a character interaction interface, configure timed automatic account logout; for devices with a graphical interface (including WEB interface), configure timed automatic screen locking.

[0237] 6) Patch management: When installing the system, it is recommended to install only the basic OS part, and the remaining software packages should be installed based on the principle of necessity. Non-essential packages should not be installed.

[0238] Step 02: When the user logs into the system, start the system protection function and configure the firewall based on the policy configuration to shut down non-essential services.

[0239] Firewall is a very powerful feature in Linux system. Firewall-cmd provides a dynamic firewall management tool that supports network / firewall zones to define network links and interface security levels. It supports IPv4, IPv6 firewall settings and Ethernet bridging, and has runtime configuration and permanent configuration options. It also supports interfaces that allow services or applications to add firewall rules directly.

[0240] Furthermore, the configuration of the firewall based on the policy configuration includes: opening routing forwarding, setting TCP / UDP traffic transfer, reloading the configuration file and taking effect, so as to complete the configuration of the firewall.

[0241] Optionally, configure the firewall as follows:

[0242] Enable routing forwarding

[0243] Add the code net.ipv4.ip_forward=1 to the end of the file / etc / sysctl.conf and execute the following commands:

[0244] echo'net.ipv4.ip_forward=1'>> / etc / sysctl.conf

[0245] Then execute the following command to make it effective:

[0246] sysctl -p

[0247] Finally, enable the traffic masquerade function of the firewall and execute the following command:

[0248] firewall-cmd--zone=public--permanent--add-masquerade

[0249] At this point, routing forwarding is successfully enabled.

[0250] Setting up TCP / UDP forwarding

[0251] First you need to open the port, for example, open a port 25021 and execute the following command

[0252] #Open TCP traffic port

[0253] firewall-cmd --add-port=25021 / tcp --permanent

[0254] # Simultaneously open TCP traffic forwarding for multiple ports

[0255] firewall-cmd --add-port=25021-25030 / tcp --permanent

[0256] # Open UDP traffic port

[0257] firewall-cmd --add-port=25021 / udp --permanent

[0258] In this way, TCP and UDP traffic can enter through port 25021.

[0259] # Forward remote port

[0260] This is traffic relaying. For example, to forward the traffic received on port 8080 of the server with IP address 10.225.62.xx to port 666 of the server with IP address 192.168.102.xx, execute the following command on the server with IP address 10.225.62.xx:

[0261] # Open TCP traffic forwarding

[0262] firewall-cmd

[0263] --add-forward-port=port=8080:proto=tcp:toaddr=192.168.102.xx:toport=666 --permanent

[0264] # Open UDP traffic forwarding

[0265] firewall-cmd

[0266] --add-forward-port=port=8080:proto=udp:toaddr=192.168.102.xx:toport=666 --permanent

[0267] Reload the configuration file

[0268] After setting the rules, you need to reload the configuration file to take effect. Execute the following command:

[0269] firewall-cmd -reload

[0270] After the firewall is configured, turn off unnecessary services. Among them, the unnecessary services include at least one of the rexec service, the rlogin service, and the rsh service.

[0271] When the alarms scanned by the firewall include: detecting that the remote rexec service is running; detecting that the remote rlogin service is running; detecting that the remote rsh service is running.

[0272] The above three services are brought in by the network request daemon xinetd.d. Since these three services do not provide good authentication methods and the authentication system is quite simple and vulnerable to attacks, it may be used by attackers to scan third-party hosts. Attackers can remotely brute-force guess usernames and passwords through this service, or listen to the communication processes of other authorized users to obtain the plaintext passwords, such as the X-scan tool.

[0273] Therefore, it is necessary to turn off the corresponding services in the configuration files / etc / xinetd.d / rexec, / etc / xinetd.d / rlogin, and / etc / xinetd.d / rsh.

[0274] Step 03: When a user accesses the system, start the data protection function and audit the user permissions to control the access permissions.

[0275] Optionally, the access permissions include at least one of user permissions, group permissions, and other user permissions.

[0276] The permissions of the Linux file system are divided into three main types:

[0277] User permissions: The owner of a file and directory has specific access permissions to the file and directory, including read, write, and execute permissions.

[0278] Group permissions: The group to which a file and directory belong also has specific access permissions to the file and directory, including read, write, and execute permissions. A user can belong to multiple groups.

[0279] Other user permissions: All other users except the owner and the group to which the file belongs belong to other users and also have a specific set of access permissions, including read, write, and execute permissions.

[0280] In the Linux file system, each file and directory has an owner and a group, and a set of basic permissions is set. These permissions control who can access the file or directory and the operations they can perform. The basic permissions of files and directories are usually represented by three numbers, each number representing a different user group: the owner, the group, and other users. The basic permissions include read, write, and execute permissions, represented by the numbers 4, 2, and 1 respectively. Each user group can use these numbers to specify their access permissions to the file or directory. For example, if a file has the permissions set to 644, then its owner has read and write permissions, while the group and other users only have read permissions.

[0281] Take storage as an example: Log in to the storage management interface and set the file access control permissions for the directory on the file directory.

[0282] In this geophysical computing system protection method, it further includes step 04: Record and save the user operation logs.

[0283] Linux usually uses history to record, but the drawback of history is that it defaults to 1000 lines. Although it can be modified from 1000 to 1000000 lines in / etc / profile, this is just a general approach, and history can be cleared, making it impossible to see the detailed user source and operation records, such as the source IP address, operation time, operating user, etc. Therefore, write the following script to record the user's login IP, operation time, and operation commands. Then save the log file in the / var / log / history / directory.

[0284] Optionally, its program expression is as follows:

[0285] #! / usr / bin / env bash

[0286] # / / Get the user IP

[0287] USER_IP=`who -u am i 2> / dev / null|awk '{print $NF}'|sed -e's / [()] / / g'`

[0288] # / / Get the current date

[0289] DT=`date +"%Y%m%d"`

[0290] # / / Set the history file

[0291] export HISTORY_FILE=" / var / log / history / ${LOGNAME} / ${DT} / ${USER_IP}.log"

[0292] dir=`dirname $HISTORY_FILE`

[0293] if [ ! -d $dir ]; then

[0294] mkdir -p $dir

[0295] chmod 300 $dir

[0296] fi

[0297] export PROMPT_COMMAND='{ date "+%Y-%m-%d %T$(history 1)";} >>

[0298] $HISTORY_FILE'

[0299] export HISTCONTROL=ignoredups.

[0300] In this embodiment, by scripting the operation steps, the login protection, system protection, and data protection of the geophysical high-performance computing system are batch-updated. The shell script is used to batch-update and upgrade the high-performance computing cluster and repair the medium and high-risk vulnerabilities in the cluster, meeting the needs of the geophysical cluster security and network protection operations, thereby reducing the operation and maintenance costs.

[0301] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be repeated here.

[0302] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in electrical, mechanical, or other forms. The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0303] The basic principles of the present application have been described above in conjunction with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present application are only examples and not limitations. It cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present application. In addition, the above-disclosed specific details are only for illustrative purposes and for ease of understanding, rather than limitations. These details do not limit the present application to necessarily adopt the above specific details for implementation.

[0304] The block diagrams of the devices, apparatuses, equipment, and systems involved in the present application are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner.

[0305] It should also be noted that in the devices, equipment, and methods of the present application, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present application.

[0306] The above description of the disclosed aspects enables any person skilled in the art to make or use the present application. Various modifications to these aspects are very obvious to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of the present application. Therefore, the present application is not intended to be limited to the aspects shown herein, but rather to the broadest scope consistent with the principles and novel features disclosed herein.

[0307] In the description of this application, the meaning of "a plurality of" is at least two, such as two, three, etc., unless otherwise specifically defined. In the embodiments of this application, all directional indications (such as up, down, left, right, front, back, top, bottom...) are only used to explain the relative positional relationship and movement conditions between components in a specific posture (as shown in the drawings). If the specific posture changes, the directional indications will change accordingly. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not limited to the listed steps or units, but optionally also includes steps or units not listed, or optionally also includes other steps or units inherent to these processes, methods, products or devices.

[0308] In addition, the mention of "embodiment" in this text means that the specific features, structures or characteristics described in connection with the embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.

[0309] As described above, it is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.

[0310] The above is only the preferred embodiment of the present invention and is not used to limit the present invention. Any modifications, equivalent substitutions, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for protecting a geophysical computing system, characterized in that, Including: When a user logs in to the system, start the login protection function, obtain the host risk value, and determine whether the host is in a high-risk state based on the risk value. If so, perform host repair; After the user logs in to the system, start the system protection function, configure the firewall based on the policy configuration to turn off unnecessary services; When the user accesses the system, start the data protection function, audit the user permissions to control the access permissions.

2. The method for protecting a geophysical computing system according to claim 1, characterized in that, The obtaining the host risk value and determining whether the host is in a high-risk state based on the risk value includes: Scan system vulnerabilities to obtain vulnerability data, and obtain the host risk value based on the vulnerability data; Obtain the host risk level based on the host risk value and the risk area range, and determine whether the host risk level is in a high-risk state.

3. The method for protecting a geophysical computing system according to claim 1, characterized in that, The host repair includes at least one of: deleting or locking irrelevant accounts, deleting passwords that do not conform to the rules, configuring the minimum permissions as required, performing remote maintenance for the IP protocol, configuring timed automatic account logout and automatic screen locking, and patch management.

4. The method for protecting a geophysical computing system according to claim 1, characterized in that, The configuring the firewall based on the policy configuration includes: enabling route forwarding, setting TCP / UDP traffic forwarding, reloading the configuration file and making it effective to complete the configuration of the firewall.

5. The method for protecting a geophysical computing system according to claim 1, characterized in that, The unnecessary services include at least one of: rexec service, rlogin service, and rsh service.

6. The method for protecting a geophysical computing system according to claim 1, characterized in that, The access permissions include at least one of: user permissions, group permissions, and other user permissions.

7. The method for protecting a geophysical computing system according to claim 1, characterized in that, Also including: Record and save the user operation logs.

8. A device for protecting a geophysical computing system, characterized in that, Including: A login protection module, used to start the login protection function when a user logs in to the system, obtain the host risk value, and determine whether the host is in a high-risk state based on the risk value. If so, perform host repair; A system protection module, used to start the system protection function after the user logs in to the system, configure the firewall based on the policy configuration to turn off unnecessary services; A data protection module, used to start the data protection function when the user accesses the system, audit the user permissions to control the access permissions.

9. An electronic device, characterized in that, Including a memory and a processor, the memory is used to store one or more computer instructions, wherein when the one or more computer instructions are executed by the processor, the geophysical computing system protection method described in any one of claims 1-7 is implemented.

10. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, and when the computer program is executed by one or more processors, the geophysical computing system protection method described in any one of claims 1-7 is implemented.