Service state detection method and device and electronic equipment
By utilizing the LSA interface and named pipe features of the Windows operating system in a low-privilege environment, combined with the RPC and SMB protocols, accurate detection of remote service status is achieved, solving the problem of high user permission requirements for service status detection in a permission-restricted environment, and improving the stealth and efficiency of detection.
Patent Information
- Application Number
- CN202510939584.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-10-14
- Estimated Expiration
- 2045-07-08
AI Technical Summary
In a network environment with restricted permissions, existing technologies require high user permissions when performing remote service status detection, making it difficult to implement.
By utilizing the LSA interface and named pipe features of the Windows operating system in a low-privilege environment, combined with the RPC and SMB protocols, the installation status and running status of remote services can be detected, including querying the service account name and accessing the named pipe.
Accurate detection of remote service status is achieved under low-privilege conditions, reducing dependence on administrator permissions, improving the stealth and efficiency of detection, and reducing the misjudgment rate.
Smart Images

Figure CN120785594A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the technical field of network security, and particularly relates to a service state detection method and device and electronic equipment. BACKGROUND
[0002] In the field of information technology and network security, operation and maintenance personnel, security auditors and penetration testers often need to identify and verify the installation state and running state of some key services on a remote target host. Such requirements exist widely in intrusion detection, antivirus / anti-spyware monitoring, terminal protection system monitoring and penetration testing scenarios.
[0003] When the related technology performs remote service detection by calling a service control manager (SCM) interface, the calling party often needs to have administrator privileges in the target system, which has a high requirement for user privileges and is difficult to apply in most practical environments, especially in network environments with limited privileges and only ordinary user privileges.
[0004] At present, there is no effective technical solution to the problem of high user privilege requirement in service state detection in the related technology. SUMMARY
[0005] The main purpose of the present disclosure is to provide a service state detection method and device and electronic equipment to solve the problem of high user privilege requirement in service state detection in the related technology.
[0006] To achieve the above purpose, the first aspect of the present disclosure provides a service state detection method applied to a low-privilege environment with a privilege lower than an administrator privilege, comprising: loading a configuration file, wherein the configuration file contains a target service name and a target host address; According to the configuration file, calling a local security authority of the target host based on a remote procedure call interface, remotely querying a service account, and detecting a service installation state, wherein the target host is a detected object and has a local security account service interface and a named pipe communication capability; If it is detected that the service has been installed, based on a pre-set mapping relationship between the service name and the named pipe, accessing the named pipe associated with the service according to a server message block protocol, and detecting a service running state; Combining the service installation state and the service running state, outputting a service state detection result, wherein the service state detection result is that the service has been installed and is running, the service has been installed but is not running, or the service has not been installed.
[0007] Optionally, according to the configuration file, a local security mechanism of the target host is invoked based on a remote procedure call interface, a service account is remotely queried, and a service installation state is detected, including: According to a target service name in the configuration file, a service account name conforming to a Windows service account naming specification is constructed, wherein the service account name is used to represent an identification format of the target service when the target service runs in a system account in a local security account manager; An account name query interface of the target host is invoked through a remote procedure call protocol, and an account name query request is submitted to an LSA service of the target host by taking the service account name as a parameter, so as to query a security identifier of the service; A status code returned by the target host is determined, and whether the target service has been installed in the target host is judged through the status code in a low-privilege environment, wherein the low privilege is a privilege lower than an administrator privilege; If the status code returned by the target host is STATUS_SUCCESS, the service has been installed, otherwise, the service has not been installed.
[0008] Optionally, based on a pre-set mapping relationship between a service name and a named pipe, a named pipe associated with the service is accessed according to a server message block protocol, and a service running state is detected, including: In a scenario of not logging in the target host, the target host is accessed in a low-privilege manner, wherein the low privilege is a privilege lower than an administrator privilege; Based on the pre-set mapping relationship between the service name and the named pipe, the named pipe associated with the service is accessed in a low-privilege manner by opening a named pipe handle according to a server message block protocol; The content returned by the target host is determined, and whether the target service is running is judged according to the content returned by the target host; If the target host returns ERROR_FILE_NOT_FOUND, the named pipe does not exist, and the service is not running; If the target host returns ERROR_ACCESS_DENIED, successfully acquires the named pipe handle, or successfully establishes a connection, the named pipe exists, and the service is running.
[0009] Further, the named pipe handle is opened in a low-privilege manner, including any one of the following: A bottom pipe path is connected through a server message block protocol; A communication connection is established by binding the named pipe through RPC; A NetUse command in a Windows native command is used to access the named pipe associated with the service by mounting a remote share.
[0010] Optionally, the method further includes: According to the multiple sets of target service names in the configuration file, multiple sets of service account names are correspondingly constructed, wherein each set of service account name corresponds to a set of target service names and a set of target host addresses; The multiple service state detection tasks are processed by using a task distribution architecture, the target host addresses corresponding to each set of service account names are combined with the target service names by using Cartesian product, and a detection task queue is generated; According to the hardware device, a thread pool is created, and multiple working threads are configured, and the working threads are independent of each other; The multiple service state detection tasks in the detection task queue are dynamically allocated to the multiple working threads by using a lock-free queue mechanism, the multiple service state detection tasks are concurrently executed in the multiple target host environments, and multiple service state detection results are recorded; The multiple service state detection results are subjected to data aggregation processing according to the target host or the target service name, a structured detection report is generated, and the structured detection report is output in a preset format.
[0011] Further, after the detection task queue is generated, the method further includes: According to the types of the target host and the target service name, all the service state detection tasks are intelligently prioritized.
[0012] Further, the method further includes: A corresponding timeout threshold is set for each service state detection task; When the network delay duration or the target host response duration of the service state detection task is greater than the timeout threshold, the service state detection task is marked as failed and detailed logs are recorded; For the target host whose response duration is greater than the timeout threshold, the frequency of sending a service state detection request to the target host is reduced.
[0013] A second aspect of the present disclosure provides a service state detection device applied to a low-privilege environment with a privilege lower than an administrator privilege, and the device includes: A loading module is configured to load a configuration file, wherein the configuration file contains target service names and target host addresses; A remote query module is configured to remotely query a service account by calling a local security mechanism of a target host based on a remote procedure call interface according to the configuration file, and detect a service installation state, wherein the target host is a detection object and has a local security account service interface and a named pipe communication capability; A named pipe detection module is configured to, if it is detected that the service is installed, access a named pipe associated with the service according to a server message block protocol based on a pre-set mapping relationship between the service name and the named pipe, and detect a service running state; The output module is configured to output a service state detection result in combination with the service installation state and the service running state, wherein the service state detection result is that the service is installed and running, the service is installed but not running, or the service is not installed.
[0014] A third aspect of the present disclosure provides a computer-readable storage medium, which stores computer instructions for causing a computer to execute the service state detection method provided in any one of the first aspect.
[0015] A fourth aspect of the present disclosure provides an electronic device, which comprises at least one processor and a memory connected with the at least one processor in communication; wherein the memory stores computer programs executable by the at least one processor, and the computer programs are executed by the at least one processor to cause the at least one processor to execute the service state detection method provided in any one of the first aspect. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the specific embodiments of the present disclosure or the related art, the drawings needed in the specific embodiments or related art description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present disclosure, and other drawings can be obtained by those skilled in the art without creative labor on the basis of these drawings.
[0017] Figure 1 The service state detection method flowchart provided by the embodiments of the present disclosure; Figure 2 The service state detection device block diagram provided by the embodiments of the present disclosure; Figure 3 The electronic device block diagram provided by the embodiments of the present disclosure. DETAILED DESCRIPTION
[0018] In order to make the person skilled in the art better understand the present disclosure scheme, the technical solutions in the embodiments of the present disclosure will be described clearly and completely below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only some embodiments of the present disclosure, not all. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present disclosure.
[0019] It should be noted that the terms "first", "second", and the like in the description and claims of the present disclosure and the above drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present disclosure described herein can be implemented. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0020] It should be noted that the embodiments in the present disclosure and the features in the embodiments can be combined with each other without conflict. The present disclosure will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0021] In the field of information technology and network security, operation and maintenance personnel, security auditors and penetration testers often need to identify and verify the installation status and running status of some key services on a remote target host. Such requirements exist widely in intrusion detection, antivirus / anti-spyware monitoring, terminal protection system monitoring and penetration testing scenarios.
[0022] The related technology performs remote service detection by calling a service control manager (SCM) interface. The SCM interface allows the calling party to remotely access the service controller of the target host using APIs such as OpenSCManager() and EnumServicesStatusEx(), so as to enumerate all registered services and their state information thereon. However, this calling method often requires the calling party to have administrator privileges or a system service account in the target system, which has a high requirement for user privileges and is difficult to apply in most practical environments, especially in a network environment with limited privileges and only ordinary user privileges, where remote calling such as OpenSCManager() will directly fail.
[0023] In addition, the target host may close the relevant remote service management interface through firewall policy or policy group policy, further limiting the application scope of the SCM interface calling method.
[0024] To solve the above problems, the embodiments of the present disclosure provide a service state detection method, which can perform concealed detection on the service state of a remote target host in a low-privilege environment. In the low-privilege environment, no administrator privileges are required. The method is applied in a low-privilege environment with lower privileges than administrator privileges, and of course can also be applied in an administrator privilege environment, such as Figure 1 As shown in the figure, the method comprises the following steps S11 to S14: Step S11: loading a configuration file, wherein the configuration file contains a target service name and a target host address; the configuration file can be in JSON format or CSV format, and the configuration file contains target network information such as the target service name and the target host address, and the target service name can be WebClient; Step S12: according to the configuration file, calling a local security authority of the target host based on a remote procedure call interface to remotely query a service account and detect a service installation state, wherein the target host is a detection object, has a local security account service interface and a named pipe communication capability; the remote procedure call (RPC) is a communication protocol that allows programs to call each other's functions or services between different hosts through a network; the local security authority (LSA) is a key component in the Windows operating system, responsible for the execution and management of local security policies; Based on the RPC mechanism of the Windows system, the LSA of the target host can be called to remotely query the service account; in addition, the queried service account information can be cached to reduce the network overhead caused by repeated RPC calls and improve the detection efficiency.
[0025] In an optional embodiment of the present disclosure, step S12 includes: According to the target service name in the configuration file, a service account name conforming to the naming specification of the Windows service account is constructed, wherein the service account name is used to represent the identification format of the target service in the local security account manager when the target service runs in a system account; the format of the service account name is a string "NT SERVICE<target service name>", for example, the target service name is WebClient, and the constructed service account name is NT SERVICE <webclient>; The account name query interface of the target host is called through a remote procedure call protocol, and the service account name is submitted as a parameter to the LSA service of the target host to query the security identifier of the service. The account name query interface can be the LsarLookupNames() function in the LSA component of the Windows system, and the security identifier (Security Identifier, SID) is a structured identifier in the Windows system for uniquely identifying users, groups, and other security principals. The LsarLookupNames() function is used to map account names to SIDs, and the permission requirement is reduced, which can be called in a low-privilege environment (such as normal user permission, anonymous user permission, etc.). The LsarLookupNames() function allows normal users to submit an account name query request to the LSA service of the target host through the RPC protocol, and determines whether the target service has been registered and installed in the target host without administrator permission.
[0026] The client establishes communication with the LSA service of the target host through the RPC protocol. RPC is a core IPC mechanism of Windows, supports cross-network calls, and encapsulates the underlying network transmission details. The protocol series ncacn_ip_tcp (RPC binding based on TCP) or the protocol series ncacn_np (RPC binding based on named pipes) is used as the transmission protocol, which ensures stable execution in various network environments.
[0027] In order to improve compatibility, the LSA interface differences of different Windows versions (such as Windows 7, Windows 10, Windows 11, Server 2012R2+) are automatically adapted when calling LsarLookupNames().
[0028] By using the LsarLookupNames() and other RPC interfaces with lower permission requirements for detection, the service installation state can be detected in a hidden manner, reducing the risk of being monitored or monitored.
[0029] Determine the status code returned by the target host. In a low-privilege environment, determine whether the target service has been installed in the target host by the status code, wherein the low-privilege is a lower permission than the administrator permission. If the status code returned by the target host is STATUS_SUCCESS, the service has been installed, otherwise, the service has not been installed.
[0030] If the LsarLookupNames() function returns a status code STATUS_SUCCESS and the corresponding relative identifier, the target service has been registered and installed; if the query returns a negative result, the output result is: the service is not installed, and in the negative result, the Windows system generally returns the status code STATUS_NONE_MAPPED, and the old version of the Windows system may return the status code STATUS_ACCESS_DENIED instead of the status code STATUS_NONE_MAPPED. In the case of adapting to different Windows versions, the secondary judgment can be combined with the status code and additional information (such as the SID resolution result) to avoid misjudgment.
[0031] Since the LsarLookupNames() function allows non-administrator users to perform single target service name lookup, in the service installation state detection aspect, the embodiment of the disclosure performs single-point query on the specified target service name by using the LsarLookupNames() function exposed by the Windows operating system, so as to determine whether the target service has been registered and installed on the target host. By querying the target service name once, the complete service list does not need to be enumerated, the high privilege requirement of the SCM interface in the related technology is avoided, the permission limit and the monitoring of the audit system are bypassed, the risk of being monitored by the security system is reduced, and the problem that the user permission requirement is high when the service state is detected in the related technology is solved.
[0032] Step S13: If it is detected that the service has been installed, based on the pre-set mapping relationship between the service name and the named pipe, the named pipe associated with the service is accessed according to the server message block protocol, and the service running state is detected; in the Windows operating system, the named pipe serves as an efficient Inter-Process Communication (IPC) mechanism and provides a reliable channel for data exchange between system services and application programs, and the low-privilege access to the named pipe of the remote target host can be realized by using the Server Message Block (SMB) protocol. This access mode not only bypasses the dependence on the administrator permission in the related technology, but also greatly improves the stealth and feasibility of detection. According to the SMB protocol, the service running state is detected by low-privilege access to the named pipe resource of the target host; on the basis of confirming that the service has been installed, the named pipe detection is performed, and the specific named pipe associated with the service is attempted to be accessed.
[0033] When the service is running, a specific named pipe is created for inter-process communication, for example, after the WebClient service is started, a named pipe named \\ <ip>The named pipe is \pipe\davsvc; therefore, the target host can be accessed in a low-privilege manner by pre-setting a mapping relationship between a service name and a named pipe path in combination with the SMB protocol.
[0034] In an optional embodiment of the present disclosure, step S13 comprises: In a scenario without logging into the target host, the target host is accessed in a low-privilege manner, wherein the low privilege is a privilege lower than the administrator privilege; Based on the pre-set mapping relationship between the service name and the named pipe, the named pipe handle is opened in a low-privilege manner according to the server message block protocol, and the named pipe associated with the service is accessed; The content returned by the target host is determined, and it is judged whether the target service is running according to the content returned by the target host; If the target host returns ERROR_FILE_NOT_FOUND, the named pipe does not exist, and the service is not running; when the named pipe does not exist, the service is not currently running; If the target host returns ERROR_ACCESS_DENIED, successfully acquires the named pipe handle, or successfully establishes a connection, the named pipe exists, and the service is running. When the named pipe exists, it is confirmed that the service is in an active state, and the service is currently running.
[0035] In order to ensure the accuracy and comprehensiveness of the detection result, a service name-named pipe mapping knowledge base can be pre-built, which stores the mapping relationship between the service name and the named pipe. The service name-named pipe mapping knowledge base not only includes the standard pipe naming specification of common Windows services such as WebClient, Spooler, and Dnscache, but also adopts an extensible design architecture, allowing users to add custom mapping relationships according to actual needs, which is particularly important for detecting third-party services or customized system services. In addition, in terms of reliability, in order to implement an intelligent retry mechanism, a "3 attempts + exponential backoff" strategy is adopted to deal with temporary network fluctuations. The interval time of each retry increases according to an exponential law, which not only gives the network time to recover, but also avoids resource waste caused by blind retries. At the same time, historical detection data is continuously recorded, and through comparative analysis of these data, occasional false positives can be identified, further improving the accuracy of the judgment.
[0036] In the service running state detection aspect, the present embodiment is based on the fact that a service usually creates a specific named pipe to communicate with external modules during running, and detects whether these known named pipe identifiers exist on the target host. By the mapping relationship between the service name and the named pipe path, whether the service is running can be judged in a low-privilege condition in combination with whether the named pipe exists; the inherent characteristics of the named pipe are fully utilized, the limitation of the SCM interface in the related art on the higher requirement for the privilege is avoided, and the operation is extremely good in concealment, thereby solving the problem of the higher requirement for the user privilege when the service state is detected in the related art.
[0037] In a preferred embodiment of the present disclosure, the named pipe handle is opened in a low-privilege mode, including any one of the following: The underlying pipe path is connected through the server message block protocol; A communication connection is established through the RPC binding of the named pipe; The NetUse command in the Windows native command is used to access the named pipe associated with the service in a manner of mounting a remote shared manner. The NetUse command is a native command of Windows, which is used to manage and operate network connections, map network shared drives or connect network shared folders.
[0038] The embodiment of the present disclosure adopts a multi-level pipe detection strategy to adapt to different network environments. The most basic detection method is to directly access the named pipe through the SMB protocol to construct a standard UNC path ( <ip>The pipe (\\.\pipe\davsvc) initiates a connection request, and then analyzes the returned error code carefully: when ERROR_ACCESS_DENIED is returned, although the current user has insufficient permissions, this response proves the existence of the named pipe; and when ERROR_FILE_NOT_FOUND is returned, it is explicitly indicated that the named pipe has not been created, and the corresponding service is naturally not running. Considering the firewall restrictions that exist in enterprise networks, the embodiment of the present disclosure also designs a backup detection scheme, which indirectly detects through the RPC over Named Pipe mode. This mode uses the system's inherent pipe (such as \pipe\lsarpc) as a communication channel, and even if the SMB port is blocked, the detection task can still be completed. For some special environments that implement strict security policies, the embodiment of the present disclosure can also intelligently switch to the Windows native command NetUse simulation mode, and access the target pipe through the mounting of remote shares. This flexible adaptability ensures that the detection work can be carried out smoothly in various complex scenarios.
[0039] Step S14: combining the service installation state and the service running state, outputting the service state detection result, wherein the service state detection result is that the service has been installed and is running, the service has been installed but is not running, or the service has not been installed. By initiating the RPC query and the SMB pipe detection request, and combining the return results of the RPC query and the named pipe detection, the complete state of the service can be accurately determined, and the dual detection of the service installation state and the service running state is realized.
[0040] If it is confirmed that the service has been installed and the named pipe exists, the service state detection result is that the service has been installed and is running; if the service has been installed but the named pipe does not exist, the service state detection result is that the service has been installed but is not running; if the RPC query returns that the service is not registered for installation after excluding the named conflict or false alarm, regardless of whether the named pipe exists or not, the service state detection result is that the service has not been installed.
[0041] The present disclosure combines the security account management mechanism and the named pipe characteristics of the Windows operating system, realizes the dual detection of the service installation state and the service running state, and this dual detection mechanism significantly reduces the misjudgment rate, and covers the detection requirements of the installation and running dimensions; through logical judgment and multi-dimensional information integration, the accurate, low-privilege and concealed detection of the service state of the target host is realized, and the problem of high user permission requirement in the related art is solved.
[0042] The technical solutions of the present disclosure will be further explained and described below in combination with the first embodiment.
[0043] [First embodiment] This embodiment is based on the remote target host detection task in Windows network environment, the goal is to determine whether the remote target host installed and running WebClient service, and the results are classified output. This embodiment to detect the status of the remote target host WebClient service as the goal, complete the whole process from the initialization configuration to the final result output of the work process.
[0044] When running, the client will first generate a special configuration file, which contains the standardized service account name "NT SERVICE\WebClient", this specific format of string is the standard naming rules set by Windows system for service account. After the configuration is completed, the client initiates LsarLookupNames() function call request to the target host through RPC protocol, this key step uses the characteristics of Windows local security authentication mechanism, can complete the service registration state verification under normal user permission.
[0045] When the remote target host returns the status code STATUS_SUCCESS, it indicates that the corresponding service account has been registered in the target host system, thus it can be determined that WebClient service has been installed on the target host. In order to further confirm the real-time running state of the service, the second stage of detection process is started, the client tries to establish a named pipe connection with the target host, the specific access path is constructed as \\ <ip>\pipe\davsvc, which has a fixed correspondence with the WebClient service. The return result of the connection attempt is intelligently parsed: if the system returns the error code ERROR_FILE_NOT_FOUND, this explicit negative response indicates that the named pipe does not exist, and it can be determined that the WebClient service is not currently running; conversely, if the error code ERROR_ACCESS_DENIED or a successful connection is returned, it is strong evidence that the named pipe exists, indicating that the service is active.
[0046] After the entire detection process is completed, clear and explicit detection results are generated, which use standardized expression methods such as "WebClient service is installed and running", "WebClient service is installed but not running", or "WebClient service is not installed". This structured output is not only convenient for manual reading and understanding, but also conducive to subsequent automated processing and analysis.
[0047] In an optional embodiment of the present disclosure, the method further comprises: According to the multiple sets of target service names in the configuration file, multiple sets of service account names are constructed, wherein each set of service account names corresponds to a set of target service names and a set of target host addresses; the multiple sets of target service names (such as WebClient, W32Time, Dnscache, etc.) form a list of services to be detected, and the list of target host addresses can be an IP address segment or a host name. According to the multiple sets of target service names, multiple sets of service account names can be constructed in batches. Each set of service account names, the corresponding set of target service names, and the set of target host addresses form a service state detection task, and the target service names, service account names, and target host addresses are maintained in groups; An intelligent task scheduling mechanism is used to dynamically load target network information from a preset configuration file at startup, including IP address segments (such as CIDR representation method such as 192.168.1.0 / 24) and service lists (such as WebClient, W32Time, and other key system services) to be detected. These raw data are converted into standardized service state detection tasks after parsing, and each service state detection task contains the correspondence between the target IP address and the service name; A task distribution architecture is used to process multiple service state detection tasks, and the target host addresses corresponding to each set of service account names are combined with the target service names to generate a detection task queue; According to the hardware device, a thread pool is created, a plurality of working threads are configured, and each working thread is independent of each other; the thread pool is used to optimize resource utilization, and a thread pool of a proper size is automatically created according to the performance of the hardware device in the initialization stage, and the default configuration is 10 working threads, and the specific number of working threads supports flexible adjustment by a user according to an actual network environment and device performance; each working thread maintains complete independence and can orderly execute respective detection tasks, including core operations such as RPC interface calling and named pipe detection; A plurality of service state detection tasks in the detection task queue are dynamically allocated to a plurality of working threads by using a lock-free queue mechanism, a plurality of service state detection tasks are concurrently executed in a plurality of target host environments, and a plurality of service state detection results are recorded; a multi-thread concurrent and task queue combined architecture design is used, a plurality of target hosts are batched for service state detection in a multi-thread concurrent or thread pool manner through parallel processing, and the overall scanning efficiency is improved; and in order to maximize the concurrent efficiency, an efficient lock-free queue mechanism is used for task allocation between threads, a lock mechanism such as a mutex or a read-write lock is not used for thread safety, performance loss and potential deadlock risk caused by a traditional lock mechanism are effectively avoided, and the task distribution process almost does not generate additional system overhead; A plurality of service state detection results are subjected to data aggregation processing according to target hosts or target service names, a structured detection report is generated, and the structured detection report is output in a preset format. After all the service state detection tasks are executed, the service state detection results of the working threads are collected, an aggregation algorithm is used for de-duplication, verification and classification processing of the original results, a structured report is generated, and various abnormal states such as "the service is installed but not running" and other special conditions are clearly marked in the report, and detailed error codes and possible cause analysis are attached, thereby providing a comprehensive basis for subsequent fault troubleshooting and security analysis. In addition, the finally generated structured report supports multiple output formats, including a CSV format and a JSON format convenient for machine processing, and an HTML format more suitable for manual reading.
[0048] In a preferred embodiment of the present disclosure, after the detection task queue is generated, the method further includes: According to the types of target hosts and target service names, the service state detection tasks are intelligently prioritized. According to the importance of services and target hosts, the service state detection tasks are intelligently prioritized, and detection of key services and important hosts can be preferentially executed.
[0049] In a preferred embodiment of the present disclosure, the method further includes: A corresponding timeout threshold is set for each service state detection task; for example, the timeout threshold can be 5 seconds; When the network delay duration or the target host response duration of a service state detection task is greater than the timeout threshold, the service state detection task is marked as failed and detailed logs are recorded; when the network delay or the slow target host response causes timeout, the service state detection task is marked as failed and detailed logs are recorded, without waiting indefinitely to affect the overall progress; For the target host with a response duration greater than the timeout threshold, the frequency of sending service state detection requests to the target host is reduced. For the host with high response delay, the dynamic frequency adjustment function is automatically enabled, and the sending frequency of the probe request is appropriately reduced.
[0050] This adaptive timeout control and fault tolerance processing mechanism can not only ensure the continuity of detection, but also effectively avoid triggering the security protection strategy of the target host, such as the anti-brute-force cracking mechanism or the alarm threshold of the intrusion detection system, due to frequent requests.
[0051] The technical solutions of the present disclosure will be further explained and described below in combination with the second embodiment.
[0052] [Second embodiment] The present disclosure is applicable to concurrent execution of service state detection tasks in a plurality of target host environments. In this embodiment, the client can batch construct a plurality of service account names according to a plurality of target service names (such as WebClient, W32Time, Dnscache, etc.), and perform batch service state detection on a plurality of hosts in a multi-threaded concurrent or thread pool manner by pre-maintaining a list of target host addresses (such as IP addresses or host names) and a list of services to be detected, thereby improving the overall scanning efficiency and being suitable for tasks such as horizontal penetration testing and enterprise compliance scanning.
[0053] An advanced task distribution architecture is used to process these detection requirements. An intelligent algorithm is used to combine target host addresses and service names in Cartesian product to generate a complete detection task queue. Each task unit accurately corresponds to a specific detection target and contains explicit host address and service name information. In order to maximize the parallel processing capability of modern computing devices, an optimized thread pool technology is introduced to dynamically allocate detection tasks to multiple worker threads for concurrent execution. Each worker thread follows a standardized detection process: first, the LsarLookupNames() interface is used to query the registration status of the service account to the specified target host, which can accurately determine whether the target service has been installed in the system; then, a probe request is immediately initiated to the service-associated named pipe, and the existence of the named pipe is analyzed to confirm the real-time running state of the service.
[0054] During the task execution, each detection result is monitored and recorded in real time, and a standardized state description (such as "installed and running", "installed but not running", or "not installed") is used to accurately reflect the specific situation of each service. After all the work threads complete the detection task, a comprehensive data aggregation process is performed to systematically organize the scattered detection results according to the target host, service, and other dimensions, and finally generate a structured detection report. The report supports multiple output formats, and users can select different formats such as CSV, JSON, or HTML according to subsequent processing needs, which greatly facilitates the integration and application of detection results in enterprise security management systems.
[0055] The present disclosure can detect the service state of a remote target host under low-privilege conditions, while considering both the installation and running of the service, and minimizing the dependence on the target host's privileges, configuration, and response behavior.
[0056] From the above description, it can be seen that the present disclosure achieves the following technical effects: The present disclosure avoids the high-privilege requirement of the SCM interface in related technologies by querying the target service name only once without enumerating the complete service list, bypasses the privilege restrictions and monitoring of the audit system, reduces the risk of being monitored by the security system, and solves the problem of high user privilege requirement in related technologies when detecting the service state. The present disclosure makes full use of the inherent characteristics of the named pipe, avoids the high-privilege requirement of the SCM interface in related technologies, and has excellent operational concealment. The present disclosure combines the security account management mechanism of the Windows operating system and the named pipe characteristics to achieve dual detection of the service installation state and the service running state, which significantly reduces the false positive rate and covers the detection requirements of both installation and running dimensions.
[0057] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0058] The present disclosure also provides a service state detection device for implementing the above-mentioned method embodiments, which is applied to a low-privilege environment with a privilege lower than that of an administrator, such as Figure 2 As shown in the figure, the service state detection device 20 includes: The loading module 21 is configured to load a configuration file, wherein the configuration file contains a target service name and a target host address; The remote query module 22 is configured to remotely query the service account based on a remote procedure call interface to invoke the local security mechanism of the target host according to the configuration file, and detect the service installation state, wherein the target host is a detection object, and has a local security account service interface and a named pipe communication capability. The named pipe detection module 23 is configured to, if it is detected that the service has been installed, access the named pipe associated with the service according to the server message block protocol based on a pre-set mapping relationship between the service name and the named pipe, and detect the service running state. The output module 24 is configured to output the service state detection result in combination with the service installation state and the service running state, wherein the service state detection result is that the service has been installed and is running, the service has been installed but is not running, or the service has not been installed.
[0059] The specific manners in which the units in the above apparatus embodiments perform operations have been described in detail in the embodiments of the method, and will not be described here in detail.
[0060] The present disclosure also provides an electronic device, as shown in the figure. Figure 3 The electronic device includes one or more processors 31 and a memory 32. Figure 3 In the following, the processor 31 will be taken as an example.
[0061] The controller can also include an input device 33 and an output device 34.
[0062] The processor 31, the memory 32, the input device 33 and the output device 34 can be connected through a bus or other means, Figure 3 In the following, the connection through the bus will be taken as an example.
[0063] The processor 31 can be a central processing unit (CPU), and the processor 31 can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or combinations of the above-mentioned chips, and the general-purpose processor can be a microprocessor or any conventional processor.
[0064] The memory 32, as a non-transitory computer readable storage medium, can be configured to store non-transitory software programs, non-transitory computer executable programs and modules, such as program instructions / modules corresponding to the control method in the embodiments of the present disclosure. The processor 31 can execute various functions of the server and data processing by running the non-transitory software programs, instructions and modules stored in the memory 32, that is, implement the service state detection method of the above method embodiments.
[0065] The memory 32 can include a program storage area and a data storage area, wherein the program storage area can store an operating system and application programs required by at least one function; and the data storage area can store data created according to the use of the processing device of the server operation, etc. In addition, the memory 32 can include a high-speed random access memory, and can also include a non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state memory device. In some embodiments, the memory 32 can optionally include a memory remotely arranged with respect to the processor 31, and these remote memories can be connected to the network connection device through a network. Examples of the above network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0066] The input device 33 can receive input digital or character information, and generate key signal inputs related to user settings and function controls of the processing device of the server. The output device 34 can include a display device such as a display screen.
[0067] One or more modules are stored in the memory 32, and when executed by the one or more processors 31, perform the method as shown in Figure 1 .
[0068] Those skilled in the art can understand that the implementation of all or part of the processes in the above method embodiments can be completed by instructing the relevant hardware through a computer program. The program can be stored in a computer readable storage medium, and when the program is executed, the processes of the above method embodiments can be included. The storage medium can be a magnetic disc, an optical disc, a read-only memory (ROM), a random access memory (RAM), a flash memory (FM), a hard disk drive (HDD) or a solid state drive (SSD), etc. The storage medium can also include a combination of the above types of memories.
[0069] While embodiments of the present disclosure have been described in conjunction with the accompanying drawings, various modifications and changes can be suggested by those skilled in the art, and it is intended that the present disclosure encompass such modifications and changes as fall within the scope of the appended claims.< / ip> < / ip> < / ip> < / webclient>
Claims
1. A service status detection method, characterized in that: Applicable to low-privilege environments with permissions lower than administrator privileges, including: Loading a configuration file, wherein the configuration file includes a target service name and a target host address; According to the configuration file, the local security mechanism of the target host is called based on the remote procedure call interface to remotely query the service account and detect the service installation status, wherein the target host is the detected object and has a local security account service interface and named pipe communication capabilities; If it is detected that the service has been installed, based on the pre-set mapping relationship between the service name and the named pipe, the named pipe associated with the service is accessed according to the server message block protocol to detect the service running status; In combination with the service installation status and the service running status, a service status detection result is output, wherein the service status detection result is: the service is installed and running, the service is installed but not running, or the service is not installed.
2. The method according to claim 1, characterized in that The method of calling the local security mechanism of the target host based on the remote procedure call interface according to the configuration file, remotely querying the service account, and detecting the service installation status includes: Constructing a service account name that complies with Windows service account naming specifications based on the target service name in the configuration file, wherein the service account name is used to represent the identification format of the target service in the local security account manager when the target service runs as a system account; Calling the target host's account name query interface through the remote procedure call protocol, and using the service account name as a parameter, submitting an account name query request to the target host's LSA service to query the service's security identifier; Determining a status code returned by the target host, and in a low-privilege environment, determining whether the target service has been installed in the target host based on the status code, wherein the low-privilege is a privilege lower than an administrator privilege; If the status code returned by the target host is STATUS_SUCCESS, the service has been installed; otherwise, the service has not been installed.
3. The method according to claim 1, characterized in that The method of accessing the named pipe associated with the service and detecting the service running status based on the pre-set mapping relationship between the service name and the named pipe according to the server message block protocol includes: Accessing the target host in a low-privilege mode without logging into the target host, wherein the low-privilege is a privilege lower than the administrator privilege; Based on the pre-set mapping relationship between the service name and the named pipe, the named pipe handle is opened in a low-privilege manner according to the Server Message Block protocol to access the named pipe associated with the service; Determine the content returned by the target host, and determine whether the target service is running according to the content returned by the target host; If the target host returns ERROR_FILE_NOT_FOUND, the named pipe does not exist and the service is not running; If the target host returns ERROR_ACCESS_DENIED, successfully obtains the named pipe handle, or successfully establishes the connection, the named pipe exists and the service is running.
4. The method according to claim 3, characterized in that Opening a named pipe handle in a low-privilege manner includes any of the following: Connect to the underlying pipe path via the Server Message Block protocol; Establish a communication connection by binding a named pipe through RPC; Use the NetUse command in the Windows native command to access the named pipe associated with the service by mounting the remote share.
5. The method according to claim 1, wherein The method further comprises: Constructing multiple groups of service account names according to the multiple groups of target service names in the configuration file, wherein each group of service account names corresponds to a group of target service names and a group of target host addresses; A task distribution architecture is used to process multiple service status detection tasks. The target host address corresponding to each group of service account names is combined with the target service name in a Cartesian product to generate a detection task queue. Create a thread pool based on the hardware device and configure multiple worker threads. Each worker thread is independent of each other. Adopting a lock-free queue mechanism, dynamically assigning multiple service status detection tasks in the detection task queue to the multiple worker threads, concurrently executing the multiple service status detection tasks in multiple target host environments, and recording multiple service status detection results; The multiple service status detection results are subjected to data aggregation processing according to the target host or target service name, and a structured detection report is generated and output in a preset format.
6. The method according to claim 5, characterized in that After generating the detection task queue, the method further includes: Intelligently prioritize all service status detection tasks based on the type of target host and target service name.
7. The method according to claim 5, characterized in that The method further comprises: Set a corresponding timeout threshold for each service status detection task; When the network delay duration or the target host response duration of the service status detection task is greater than the timeout threshold, the service status detection task is marked as failed and a detailed log is recorded; For a target host whose response time is longer than the timeout threshold, the frequency of sending the service status detection request to the target host is reduced.
8. A service status detection device, characterized in that: Applicable to low-privilege environments with permissions lower than administrator privileges, including: A loading module, configured to load a configuration file, wherein the configuration file includes a target service name and a target host address; a remote query module, configured to call a local security mechanism of a target host based on the configuration file and a remote procedure call interface, remotely query a service account, and detect a service installation status, wherein the target host is a detected object and has a local security account service interface and named pipe communication capabilities; A named pipe detection module is used to, if it is detected that the service has been installed, access the named pipe associated with the service based on a pre-set mapping relationship between the service name and the named pipe and detect the service running status according to the server message block protocol; The output module is used to output a service status detection result in combination with the service installation status and the service running status, wherein the service status detection result is: the service is installed and running, the service is installed but not running, or the service is not installed.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the service status detection method according to any one of claims 1 to 7.
10. An electronic device, characterized in that: The electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor executes the service status detection method described in any one of claims 1 to 7.
Citation Information
Patent Citations
Identity authentication method and system, server and storage medium
CN109815684A
Business service state detection method and device, electronic equipment and storage medium
CN111506507A
Cloud server data security protection system
CN115604028A
Remote procedure call method based on Netty technology
CN118394544A
Web application access proxy method and device in heterogeneous network environment
CN119382990A