An industrial host terminal security protection system

By collecting and analyzing kernel-level particle-sized behavioral data in real time in the terminal system, combining AI intelligent analysis and multi-engine identification technology, the problem that traditional antivirus software cannot defend against APT is solved, real-time detection and rapid response to advanced threats is achieved, and terminal security management capabilities are improved.

CN113901450BActive Publication Date: 2025-07-29CHINA ELECTRONICS CORP 6TH RES INST
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111101942.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-18
Publication Date
2025-07-29
Estimated Expiration
2041-09-18

AI Technical Summary

Technical Problem

Traditional antivirus software cannot effectively defend against advanced persistent threat APT, and terminal security cannot be guaranteed.

Method used

Clients using C/S architecture and servers using B/S architecture can obtain kernel-level particle-sized behavior data in real time through lightweight Agent programs, combine threat behavior detection, threat alerting, threat identification and system management, use AI intelligent analysis components for threat traceability and real-time repair, and integrate multi-engine malicious sample identification platform for full-network linkage defense.

Benefits of technology

Real-time detection and disposal of known and unknown threats is realized, the scope of incident impact is reduced, comprehensive terminal security management capabilities are provided, and defense capabilities are improved against ransomware, mining and fileless attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113901450B_ABST
    Figure CN113901450B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention discloses an industrial host terminal security protection system, which integrates core functions such as behavior monitoring, virus killing, remote investigation and evidence collection, linkage defense, and risk situation display. By adopting leading technologies such as behavior recognition, multi-engine sample identification, neural network, trapping, and immunity, it realizes the real-time detection and disposal of known and unknown threats, and effectively solves threats that cannot be effectively defended by traditional security products such as ransomware, mining, evasion of anti-virus, and fileless attacks. Through the lightweight terminal Agent program, it continuously monitors the terminal system by obtaining full-scale kernel-level fine-grained behavior data in real time, and screens out events that are helpful for customers to trace threats for storage, realizing the rapid analysis and response to threat events (including determining the zero victim terminal, attack scope, etc.), obtaining the maximum protection with the minimum resource overhead, and comprehensively improving the customer's terminal security management ability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of network security technology, and more particularly to an industrial host terminal security protection system. Background Art

[0002] The network has become an incubator for contemporary economic prosperity, technological progress, and social awareness by breaking the boundaries of time and space and transforming social networks and economic driving modes. It has also caused the current society to be unable to stop relying on the network, and the severity of network security issues has gradually become prominent. Many problems such as virus proliferation, system vulnerabilities, and hacker attacks have directly affected network security.

[0003] Boundary protection devices provide security protection at various entrances of the network. However, for the lateral spread of viruses and internal threats such as removable storage media, the security protection at the network boundary becomes helpless. As the core carrier of information assets, the importance of terminal security protection becomes extremely prominent. For a long time, signature-based and heuristic antivirus software has been widely used terminal security products. With the continuous upgrading of attack means, the increasingly serious advanced persistent threat APT can easily bypass traditional antivirus software. When traditional antivirus software can no longer detect and defend against APT, the next-generation terminal security protection technology based on terminal detection and response technology has become a standard configuration for network terminal security protection solutions. Summary of the Invention

[0004] Therefore, the embodiments of the present invention provide an industrial host terminal security protection system to solve the problem that traditional antivirus software can no longer detect and defend against APT and terminal security cannot be guaranteed. [[ID=*]]

[0005] To achieve the above object, the embodiments of the present invention provide the following technical solution: An industrial host terminal security protection system, the system includes a client and a server. The client and the server adopt a C / S architecture. By installing a lightweight Agent program in the terminal operating system, full-scale kernel-level micro-behavior data is obtained in real time and reported. The server management adopts a B / S architecture, and threat behavior detection, threat warning, threat identification, threat analysis, and system management are realized according to the collected data.

[0006] Further, the server specifically includes a terminal asset management module, which is used to deeply visualize terminal activities, intuitively display the threat risks suffered by terminal assets, and the infection range of threat events within the organization; group and batch manage terminals according to the customer's business organization, and at the same time allow customers to view the detailed information of a certain terminal and support self-export of terminal data.

[0007] Further, the server specifically includes a threat warning management module, and the threat warning management module includes a threat traceability module and a threat warning module;

[0008] The threat traceability module is used to provide visual context association for alarms to restore attack behaviors, utilize the full amount of event storage and the EIS terminal immune system to provide a basis for tracking and obtaining evidence of the attack source, and combine threat intelligence data, terminal threat behavior detection engines, and AI intelligent analysis components to identify threats, accurately intercept threats and give alarms, and can also investigate and obtain evidence of the attack, form threat analysis reports and intelligence data, and the continuously updated and iterated intelligence data provides richer data support for subsequent threat traceability;

[0009] The threat warning module is used to provide real-time threat warning information, automatically repair and process scripts for known and unknown threats, thereby reducing the scope of event impact; support viewing alarm information and its alarm levels generated by all terminals in the entire network; allow customers to handle alarms from terminals to achieve threat response to the security of terminals in the entire network, and at the same time allow viewing of the process tree and process details related to threat events in the system.

[0010] Further, the server specifically includes a network-wide file management module, and the network-wide file management module is used to view and manage newly added files in all current enterprises after installing the terminal Agent program, and the platform manages them uniformly; support viewing the malicious degree of files and the scanning results of AI intelligent analysis components, allow modifying the file types in the network-wide file list, and at the same time support viewing the distribution of the MD5 of a certain file within the enterprise or the entire network, viewing the time, host, file path information entropy, etc. when the file first appears on each terminal, and finally to achieve interception or release by the EIS terminal immune system.

[0011] Further, the server specifically includes a security policy management module, and the security policy management module includes a security policy configuration module, a virus defense policy configuration module, and a terminal immune system policy configuration module;

[0012] The security policy configuration module is used to perform editing, adding, and viewing operations on security policies, and when editing and adding, customize the switch configuration of rules and functions used by the current enterprise, and save the configuration as a security policy and send it to the terminal for security response;

[0013] The virus defense policy configuration module is used to perform custom switch configuration on the currently used rules to intercept all black files in the network; at the same time, turn on the isolation switch to defend against and kill viruses according to the identification results of the AI intelligent analysis component, and can apply this policy to different groups in the current enterprise organizational structure;

[0014] The terminal immune system policy configuration module is used to customize the switch to configure the terminal immune system policy and provide high-level protection policies for critical assets. Based on the establishment of a local file gene information database in local self-learning, it realizes screening local executable files for gene deviation, strictly screening the files that the system attempts to load into memory for execution, and precisely intercepting existing threat events. It can avoid important assets such as servers from being damaged by unknown threats without installing antivirus software or upgrading the operating system patches, reduce unnecessary threat events, and precisely intercept black and white list files to provide reliable security protection and immunity for the terminal.

[0015] Furthermore, the server specifically includes a report management module, and the report management module includes an asset and threat report management module and a custom report management module.

[0016] The asset and threat report management module is used for users to generate report templates by distinguishing different report entrances; select daily, weekly, monthly, custom time periods, and department grouping information to generate asset reports or threat reports; generate report content for customers to understand the distribution of assets in the entire network in real time, and at the same time, customers can download and export asset report or threat report data by themselves.

[0017] The custom report management module is used for customers to select custom report items, report statistical periods, and department groupings to create a what-you-see-is-what-you-get report to generate the security status information of the entire network; and allows downloading reports, and the downloaded file formats are PDF and HTML files; at the same time, it supports automatic sending settings and can add different email sending configurations.

[0018] Furthermore, the server specifically includes a large screen display module. The large screen display module is used to display the comprehensive score value of enterprise terminals according to risk terminals, risk servers, and unprocessed alarms, display the proportion and quantity of alarm levels generated by terminals and servers logged in within the last 24 hours, and the TOP5 data, online quantity, and total quantity calculated from the alarms generated in assets, as well as the quantity of abnormal files and non-abnormal files identified by the AI intelligent analysis component after scanning; and dynamically display in real time through bar charts the trend charts of the alarm volume and processed alarm volume generated by servers and terminals within the last 24 hours, the distribution of ATT&CK metric items, and the data of the total number of alarms, disposed alarms, un-disposed alarms, total EIS interceptions, risk terminals, and risk servers in the currently logged-in enterprise, and also includes the asset information of the assets that generated alarm events and the terminal event alarm situation in the currently logged-in enterprise.

[0019] Further, the server specifically includes a virus defense module, which is used to combine the terminal immune system, AI intelligent analysis component, and security event correlation technology to implement a network-wide linkage mechanism, support comprehensive real-time detection and protection of terminals, scan and detect important target files on the terminals, effectively intercept and isolate files at risk; enable customers to manually set the scanning department, file path, file type, etc., and support selecting whether to isolate abnormal files, as well as restoring and deleting files.

[0020] Further, multiple virus scanning engines are centralized to form scanning nodes, and the scanning nodes are networked to implement a distributed multi-engine malicious sample identification platform; the standard SDK interface provided by the platform provides support for later integration of new virus scanning engines to achieve horizontal expansion, and at the same time, it also realizes the dynamic adjustment of the number of scanning nodes without downtime, and the function of adding and deleting any number of scanning engines in real time in the same scanning node.

[0021] The embodiments of the present invention have the following advantages:

[0022] An industrial host terminal security protection system proposed by an embodiment of the present invention is applicable to terminal systems such as servers, terminal PCs, and virtualized hosts. It integrates core functions such as behavior monitoring, virus killing, remote investigation and evidence collection, linkage defense, and risk situation display. It adopts leading technologies such as behavior recognition, multi-engine sample identification, neural network, trapping, and immunity to achieve real-time detection and disposal of known and unknown threats, and effectively solves threats that cannot be effectively defended by traditional security products such as ransomware, mining, evasion of anti-virus, and fileless attacks. Through the lightweight terminal Agent program, it continuously monitors the terminal system by obtaining all kernel-level fine-grained behavior data in real time, and screens out events that are helpful for customers to trace threats and stores them, realizing rapid analysis and response to threat events (including determining the zero victim terminal, attack scope, etc.), obtaining the maximum protection with the smallest resource overhead, and comprehensively improving the customer's terminal security management ability. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only exemplary, and for those of ordinary skill in the art, other implementation drawings can be obtained by extension based on the provided drawings without creative efforts.

[0024] Figure 1 It is a schematic diagram of an industrial host terminal security protection system provided for Embodiment 1 of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0025] The following specific embodiments illustrate the implementation manners of the present invention. Those skilled in this technology can easily understand other advantages and effects of the present invention from the content disclosed in this specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present invention.

[0026] Embodiment 1

[0027] As Figure 1 shown, this embodiment proposes an industrial host terminal security protection system, which is a three-dimensional terminal security protection solution applicable to terminal systems such as servers, terminal PCs, and virtualized hosts. This system uses a combined C / S and B / S mode to provide services such as detection, response, and traceability of terminal threats for customers.

[0028] The system includes a client and a server. The client and the server adopt a C / S architecture. By installing a lightweight Agent program in the terminal operating system, it can obtain all kernel-level fine-grained behavior data in real time and report it. The server management adopts a B / S architecture to implement threat analysis and system management. It uses a distributed deployment method and big data storage to meet high scalability, high availability, and high concurrency, providing a data source for threat analysis and traceability.

[0029] Specifically, the server includes a terminal asset management module, which is used to deeply visualize terminal activities, intuitively display the threat risks suffered by terminal assets, and the infection range of threat events within the organization; group and batch manage terminals according to the customer's business organization, and at the same time allow the customer to view the detailed information of a certain terminal and support self-export of terminal data.

[0030] Specifically, the server includes a threat warning management module, and the threat warning management module includes a threat traceability module and a threat warning module;

[0031] The threat traceability module is used to provide visual context correlation for alarms to restore attack behaviors, use all event storage and the EIS terminal immune system to provide evidence for tracking and obtaining evidence of the attack source, combine threat intelligence data, terminal threat behavior detection engines, and AI intelligent analysis components for threat identification, accurately intercept threats and give alarms, and can also investigate and obtain evidence of attacks, form threat analysis reports and intelligence data. The continuously updated and iterated intelligence data provides further rich data support for post-event threat traceability;

[0032] The threat alert module is used to provide real-time threat alert information, automatically repair and process scripts for known and unknown threats, so as to reduce the scope of event impact; support viewing the alert information generated by all terminals in the whole network and their alert levels; allow customers to handle alerts from terminals to achieve threat response for the security of terminals in the whole network, and at the same time allow viewing the process tree and process details related to threat events of the system, including: file operations, registry activities, network activities, module loading, etc.

[0033] The server specifically includes a network-wide file management module, which is used to view and manage all newly added files in the current enterprise after installing the terminal Agent program, and is uniformly managed by the platform; support viewing the malicious degree of files and the scanning results of the AI intelligent analysis component, allow modifying the file types in the network-wide file list, and at the same time support viewing the distribution of the MD5 of a certain file within the enterprise or the whole network, viewing the time when the file first appears on each terminal (the time when the file is first uploaded to the cloud for scanning), host, file path information entropy, etc., and finally achieve the interception or release of the EIS terminal immune system.

[0034] The server specifically includes a security policy management module, which includes a security policy configuration module, a virus defense policy configuration module, and a terminal immune system policy configuration module;

[0035] The security policy configuration module is used to edit, add, and view security policies, and when editing and adding, customize the switch configuration of the rules and functions used by the current enterprise, and save the configuration as a security policy and send it to the terminal for security response;

[0036] The virus defense policy configuration module is used to customize the switch configuration of the current rules to intercept all black files in the network; at the same time, turn on the isolation switch to defend and kill viruses according to the identification results of the AI intelligent analysis component, and can apply this policy to different groups in the current enterprise organizational structure;

[0037] The terminal immune system policy configuration module is used to customize the switch configuration of the terminal immune system policy to provide high-level protection policies for key assets; based on establishing a local file gene information database in local self-learning, realize screening local executable files for gene deviation, strictly screen the files that the system attempts to load into memory for execution for gene deviation, and accurately intercept existing threat events; realize avoiding the harm of unknown threats to important assets such as servers without installing anti-virus software and without patching the operating system, so as to reduce unnecessary threat events, and realize accurately intercepting black and white list files to provide reliable security protection and immunity for the terminal.

[0038] The server specifically includes a report management module, which includes an asset and threat report management module and a custom report management module;

[0039] The asset and threat report management module is used for users to generate report templates by distinguishing different report entrances; select daily, weekly, monthly, custom time periods, and department grouping information to generate asset reports or threat reports; generate report content for customers to understand the distribution of assets in the current entire network in a timely manner, and at the same time, customers can download and export asset report or threat report data by themselves;

[0040] The custom report management module is used for customers to select custom report items, report statistical periods, and department groupings to create a what-you-see-is-what-you-get report to generate the security status information of the entire network; and allows downloading of reports, and the downloaded file format is PDF or HTML files; at the same time, it supports automatic sending settings and can add different email sending configurations.

[0041] The server specifically includes a large-screen display module, which observes and analyzes threat attacks from a macroscopic perspective, and displays core functions such as comprehensive scores, threat alert levels, trends of high-risk assets, and asset situations, and can quickly locate terminal risks to control the situation. The large-screen display module is used to display the comprehensive score value of enterprise terminals according to risk terminals, risk servers, and unprocessed alerts, display the proportion and quantity of alert levels generated by terminals and servers logged in within the last 24 hours, and the TOP5 data calculated from alerts generated in assets, as well as the online quantity and total quantity, and the number of abnormal files and non-abnormal files identified and scanned by the AI intelligent analysis component; and dynamically display in real time through bar charts the trend charts of the number of alerts generated by servers and terminals within the last 24 hours, the number of processed alerts, the distribution of ATT&CK metric items, and the data of the total number of alerts, the number of disposed alerts, the number of un-disposed alerts, the total number of EIS interceptions, risk terminals, and risk servers in the currently logged-in enterprise, and also includes the asset information of the assets that generated alert events and the terminal event alert situations in the currently logged-in enterprise.

[0042] The server specifically includes a virus defense module, which is used to combine the terminal immune system, AI intelligent analysis component, and security event correlation technology to implement a full-network linkage mechanism, support comprehensive real-time detection and protection of terminals, scan and detect important target files on the terminals, effectively intercept and isolate files at risk; allow customers to manually set the scanned departments, file paths, file types, etc., and support selecting whether to isolate abnormal files, as well as restoring and deleting files.

[0043] An industrial host terminal security protection system according to an embodiment of the present invention specifically includes the following core technologies:

[0044] (1) Kernel-level fine-grained behavior data collection

[0045] Use multiple drivers such as Minifilter, NIDS, and WFP to collect data from the kernel in the operating system, which can not only ensure complete visibility of all activities within the system but also provide a reliable data source for continuous detection and recording of terminal activities.

[0046] (2) File scanning ability based on neural network (AI)

[0047] As a next-generation terminal security product, the application of AI is indispensable. The antivirus engine (Onesargus) is trained based on more than 2,000,000 samples using technologies such as transfer learning, interpretability analysis, and generative adversarial networks, achieving in-depth analysis of samples and extraction of high-dimensional complex features / patterns. It can quickly use relevant metric information such as sample Hash, features, and IOCs as the retrieval source for compromised terminals for active and real-time rapid positioning, helping customers more efficiently discover known / unknown threats to terminals, grade threats, and give early warnings.

[0048] (3) Terminal immune protection

[0049] Through local learning, a local file gene information database is generated, and strict screening of gene deviation items is carried out on PE files that the system attempts to load into memory for execution. Through this technology, high-level security protection can be provided in special application environments (such as long-running servers, servers that cannot install patches, terminal environments used by financial personnel, etc.), reducing unnecessary threat events and accurately intercepting black and white list files. Through linkage with the whole network file list and the AI file scanning ability, reliable security protection and immunization effects are provided for the terminal.

[0050] (4) Terminal threat behavior recognition

[0051] Use user entity behavior analysis technology (UEBA, User and Entity Behavior Analytics) to achieve automated modeling, which can solve difficult security problems. By correlating multiple abnormal activities, various advanced threats can be analyzed and detected to achieve the detection of known and unknown threats.

[0052] (5) Terminal threat trapping

[0053] In response to the attack of ransomware, this system is based on the deception defense method to lure attackers through attacks, confuse attackers, perceive attacks, and analyze the behavior of attackers. And trace the source for evidence collection, effectively making up for the problem that traditional terminal security protection products cannot defend against unknown ransomware viruses.

[0054] (6) Multi-engine malicious sample identification

[0055] Multiple virus scanning engines are centralized to form scanning nodes, and the scanning nodes are networked, realizing a distributed multi-engine malicious sample identification platform. The standard SDK interface provided by the platform supports the later integration of new virus scanning engines for horizontal expansion. At the same time, it also realizes the dynamic adjustment of the number of scanning nodes without downtime, and the function of adding and deleting any number of scanning engines in real time in the same scanning node.

[0056] An industrial host terminal security protection system according to an embodiment of the present invention specifically has the following characteristics:

[0057] (1) Terminal Agent program with low resource occupancy

[0058] The lightweight terminal Agent program of this system is imperceptible to customers and has low resource occupancy. It integrates the three functions of threat detection, data collection and response, avoiding the impact on the customer system caused by installing too many terminal security software.

[0059] (2) Threat traceability

[0060] In the traditional security product concept, the basic guiding ideology is EPP, providing unified management functions. However, due to the over-flattening of information such as alarms and logs, what is presented to customers is often a large number of "data" without context association, which does not provide good support for analyzing the entire security event and the security status within the customer network.

[0061] This system adopts full-scale data collection and reporting. The system records the behavior events of terminal assets all the time. The advantage is that even if no alarms are generated in the system, investigations can be carried out at any time according to indicators such as IOC and IOA. At the same time, even when a threat alarm occurs, security analysts can also trace the source according to the associated context and various behavior data provided in the alarm details page, clearly understanding where the hacker or malware comes from, what it has done, and how it has done it, and counting the scope of the currently damaged assets.

[0062] (3) Whole-network linkage defense

[0063] When a file in a certain terminal asset is identified as a "malicious file" by the multi-engine malicious sample identification platform and the anti-virus engine (Onesargus), the gene information of the file will be synchronized throughout the network through the terminal immune system (EIS), enabling all terminals in the network to have immunity to the file, thereby preventing the horizontal spread of malware in the network and achieving the effect of reducing losses and early prevention.

[0064] (4) Remote investigation and evidence collection

[0065] This system can conduct in-depth investigations on the data stored in the server by centrally managing terminal data and performing distributed operations, and analyze the attacker's intentions. Combining with remote investigation and evidence collection commands, it can directly use system SHELL commands to remotely investigate the operating systems of terminal assets within the scope permitted by the permissions.

[0066] (5) High-accuracy virus defense

[0067] This system has the capabilities of virus detection and defense. It comprehensively detects and protects terminals. By using the antivirus engine (Onesargus) and the Scorpio multi-engine malicious sample identification platform (ROBIN), it scans and detects target files using multiple engines simultaneously, effectively intercepts and isolates files at risk, and centrally manages the quarantined files.

[0068] (6) Real-time monitoring of all data

[0069] As a next-generation terminal security solution, this system can record the system behaviors and related events of all terminal assets, such as events related to users, files, processes, registries, memory, and networks, and can collect and store this information. Combining IOC and IOA and through behavior analysis to retrieve data and identify threats, while using machine learning to continuously analyze this data and quickly respond to security threats (including determining the zero-infected terminal, attack scope, threat control, etc.).

[0070] A terminal protection system proposed in an embodiment of the present invention mainly has two deployment methods: private cloud deployment and public cloud deployment.

[0071] The private cloud deployment method is mainly for physically isolated networks or large enterprise customers with the ability to operate and maintain large-scale network security systems. This deployment method requires deploying systems such as the threat analysis center, the Scorpio multi-engine malicious sample identification platform, and the operation and maintenance support to the customer's intranet environment. It has high requirements for server resources, but is flexible in management. It can utilize the advantages of modular design and distributed systems to flexibly adjust the deployment architecture according to the customer's network topology.

[0072] The public cloud deployment method has the advantages of simplicity, convenient management, and low cost. Customers only need to apply for and obtain authorization, and then download the lightweight terminal Agent program and install it on the terminal assets to be protected to achieve asset protection. This method is suitable for scenarios where the customer's intranet can be directly connected to the Internet, or there are security hosting requirements and no security analysts.

[0073] An industrial host terminal security protection system proposed by an embodiment of the present invention is applicable to terminal systems such as servers, terminal PCs, and virtualized hosts. It integrates core functions such as behavior monitoring, virus killing, remote investigation and evidence collection, linkage defense, and risk situation display. By adopting leading technologies such as behavior recognition, multi-engine sample identification, neural network, entrapment, and immunity, it realizes real-time detection and disposal of known and unknown threats, and effectively solves threats that cannot be effectively defended by traditional security products such as ransomware, mining, evasion of anti-virus, and fileless attacks. Through the lightweight terminal Agent program, it can obtain all kernel-level fine-grained behavior data in real time to continuously monitor the terminal system, and screen out events that are helpful for customers to trace threats for storage, realizing rapid analysis and response to threat events (including determining the zero-th victim terminal, attack scope, etc.), obtaining the maximum protection with the minimum resource overhead, and comprehensively improving the customer's terminal security management ability.

[0074] Although the present invention has been described in detail above with general descriptions and specific embodiments, based on the present invention, some modifications or improvements can be made, which are obvious to those skilled in the art. Therefore, these modifications or improvements made without departing from the spirit of the present invention all fall within the scope of protection required by the present invention.

Claims

1. An industrial host terminal security protection system, characterized in that The system includes a client and a server. The client installs a lightweight Agent program in the terminal operating system to obtain all kernel-level fine-grained behavior data in real time and report it. The server specifically includes a threat alert management module, which includes a threat tracing module and a threat alert module. The threat tracing module is used to provide visual context correlation for alerts to restore attack behaviors, use all event storage and the EIS terminal immune system to provide evidence for tracking and forensics of the attack source, combine threat intelligence data, terminal threat behavior detection engines, and AI intelligent analysis components for threat identification, accurately intercept threats and give alerts, and can also investigate and obtain evidence for attacks, form threat analysis reports and intelligence data, and the continuously updated and iterated intelligence data provides further rich data support for post-event threat tracing. The threat alert module is used to provide real-time threat alert information and automatically repair and process scripts for known and unknown threats. It supports viewing the alert information generated by all terminals in the entire network and their alert levels. It allows customers to handle alerts from terminals and at the same time allows viewing of the process tree and process details related to threat events in the system. The server specifically includes a network-wide file management module, which is used to view and manage all newly added files in the current enterprise after installing the terminal Agent program, and is uniformly managed by the platform; it supports viewing the maliciousness of files and the scanning results of the AI intelligent analysis component, allows modifying the file types in the network-wide file list, and at the same time supports viewing the distribution of the MD5 of a certain file within the enterprise or the entire network, viewing the time, host, file path, and information entropy information when the file first appears on each terminal, and finally realizing the interception or release of the EIS terminal immune system. The server specifically includes a security policy management module, which includes a security policy configuration module, a virus defense policy configuration module, and a terminal immune system policy configuration module. The security policy configuration module is used to edit, add, and view security policies, and when editing and adding, customize the switch configuration of the rules and functions used by the current enterprise, and save the configuration as a security policy and send it to the terminal for security response. The virus defense policy configuration module is used to customize the switch configuration of the current rules to intercept all black files in the network; at the same time, turn on the isolation switch to defend against and kill viruses according to the identification results of the AI intelligent analysis component, and can apply this policy to different groups in the current enterprise organizational structure. The terminal immune system policy configuration module is used to customize the switch configuration of the terminal immune system policy to provide high-level protection policies for key assets. Based on establishing a local file gene information database in local self-learning, it realizes screening local executable files for gene deviation, strictly screens the files that the system attempts to load into memory for execution for gene deviation, and accurately intercepts existing threat events.

2. The industrial host terminal security protection system according to claim 1, characterized in that, The server specifically includes a terminal asset management module, which is used to deeply visualize terminal activities, intuitively display the threat risks to terminal assets, and the infection scope of threat events within the organization; group and batch manage terminals according to the customer's business organization, and at the same time allow the customer to view the detailed information of a certain terminal and support the export of terminal data by themselves.

3. An industrial host terminal security protection system according to claim 1, characterized in that, The server specifically includes a report management module, and the report management module includes an asset and threat report management module and a custom report management module; The asset and threat report management module is used for users to generate report templates by distinguishing different report entrances; select daily reports, weekly reports, monthly reports, custom time periods, and department grouping information to generate asset reports or threat reports; generate report content for customers to understand the distribution of assets in the current entire network in a timely manner, and at the same time, customers can download and export the data of asset reports or threat reports by themselves; The custom report management module is used for customers to select custom report items, report statistical periods, and department groupings to create what-you-see-is-what-you-get reports to generate the overall network security status information; and allows the download of reports, and the downloaded file formats are PDF and HTML files; at the same time, it supports automatic sending settings and can add different email sending configurations.

4. An industrial host terminal security protection system according to claim 1, characterized in that, The server specifically includes a large screen display module, which is used to display the comprehensive score value of enterprise terminals according to risk terminals, risk servers, and unprocessed alarms, display the proportion and quantity of alarm levels generated by terminals and servers logged in within the last 24 hours, and the TOP5 data calculated from the alarms generated in assets, the online quantity and total quantity, as well as the quantity of abnormal files and non-abnormal files identified by the AI intelligent analysis component after scanning; and dynamically display in real time through bar charts the alarm volume, processed alarm volume trend charts, ATT&CK indicator item distribution generated by servers and terminals within the last 24 hours, as well as the total number of alarms, the number of disposed alarms, the number of un-disposed alarms, the total number of EIS interceptions, risk terminals, and risk server data in the currently logged-in enterprise, and also includes the asset information and terminal event alarm situations of the assets that have generated alarm events in the currently logged-in enterprise.

5. An industrial host terminal security protection system according to claim 1, characterized in that, The server specifically includes a virus defense module, which is used to combine the terminal immune system, AI intelligent analysis component, and security event correlation technology to implement a whole-network linkage mechanism, support comprehensive real-time detection and protection of terminals, scan and detect important target files on the terminals, effectively intercept and isolate files at risk; allow customers to manually set the scanning department, file path, and file type, and support the selection of whether to isolate abnormal files, as well as the recovery and deletion of files.

6. The industrial host terminal security protection system according to claim 1, characterized in that, Multiple virus scanning engines are centralized to form scanning nodes, and the scanning nodes are networked to implement a distributed multi-engine malicious sample identification platform; the standard SDK interface provided by the platform provides support for later integration of new virus scanning engines to achieve horizontal expansion, and at the same time, it also realizes the dynamic adjustment of the number of scanning nodes without stopping the machine, and the function of adding and deleting any number of scanning engines in real time in the same scanning node.

7. An industrial host terminal security protection system according to claim 1, characterized in that, The client and the server adopt the C / S architecture.

8. An industrial host terminal security protection system according to claim 1, characterized in that, The server management adopts the B / S architecture, and realizes threat behavior detection, threat warning, threat identification, threat analysis and system management according to the collected data.

Citation Information

Patent Citations

  • Threat early warning and monitoring system and method based on big data analysis and deployment architecture

    CN107196910A

  • Systems and methods for providing an integrated cyber threat defense exchange platform

    US10986117B1