Account Security Control Method, System, Readable Storage Medium and Computer Device
By recording and analyzing the operation and maintenance trajectory of operation and maintenance personnel, forming a trajectory diagram, and generating alarms or disconnection based on deviation thresholds, the shortcomings of account security control in operation and maintenance operations are solved, and the security and controllability of operation and maintenance operations are achieved.
Patent Information
- Application Number
- CN202111300012.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-04
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2041-11-04
AI Technical Summary
The existing technology cannot effectively control the account security of operation and maintenance personnel during operation and maintenance operations, resulting in an increase in the security risks of information systems.
By recording the operation and maintenance trajectory of operation and maintenance personnel, intelligent statistical analysis is performed to form an operation and maintenance trajectory chart. When the deviation between the current operation and maintenance trajectory and the historical trajectory exceeds the preset threshold, alarm information is generated or disconnected, and account information is automatically modified.
It effectively avoids authentication errors in operation and maintenance operations, improves the security of operation and maintenance personnel accounts, and reduces the security risks of information systems.
Smart Images

Figure CN113961892B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of account security protection, and particularly to an account security control method, system, readable storage medium, and computer device. Background Art
[0002] With the rapid development of technology and the improvement of people's living standards, the scale of the network and the number of devices have expanded rapidly. The increasingly complex systems and the behaviors of operation and maintenance personnel with different backgrounds pose greater risks to the security of information systems.
[0003] Previously, the security of operation and maintenance personnel accounts could only be protected before the operation and maintenance personnel performed operation and maintenance operations. For example, the account or source IP would be locked after continuous use of incorrect passwords. However, there were no restrictions during operation and maintenance operations. Regardless of whether the operation and maintenance operations of the operation and maintenance personnel were abnormal, as long as they had the permission, they could execute all commands, without any control and unable to achieve secure operation and maintenance protection. Summary of the Invention
[0004] Embodiments of this application provide an account security control method, device, readable storage medium, and computer device to at least solve the deficiencies in the above related technologies.
[0005] In a first aspect, embodiments of this application provide an account security control method, including:
[0006] Obtain the historical operation and maintenance trajectories of operation and maintenance personnel recorded by an operation and maintenance audit system within a preset period, and form a historical operation and maintenance trajectory graph based on the historical operation and maintenance trajectories;
[0007] When the data deviation between the current operation and maintenance trajectory of the operation and maintenance personnel and the historical operation and maintenance trajectory graph exceeds a preset first threshold, generate a first warning message;
[0008] When the data deviation between the current operation and maintenance trajectory of the operation and maintenance personnel and the historical operation and maintenance trajectory graph exceeds a preset second threshold, disconnect the connection between the operation and maintenance personnel and the operation and maintenance audit system, generate a second warning message, and modify the account information of the operation and maintenance personnel for logging in to the operation and maintenance audit system, where the preset second threshold is greater than the preset first threshold.
[0009] In some embodiments, the method further includes:
[0010] Preprocess each historical operation and maintenance trajectory of the operation and maintenance personnel through a clustering method, and calculate the mean of the local historical records under each task node in the execution path to form an effective operation and maintenance trajectory graph.
[0011] In some embodiments, the method further includes:
[0012] Decompose the global constraints of the historical operation and maintenance trajectory to form local historical records under multiple task nodes in the execution path;
[0013] Eliminate the local historical records that do not meet the local constraints, and calculate the average value of the candidate local historical records;
[0014] Obtain the utility value of the local historical records under each task node through the average value of the candidate local historical records;
[0015] Set the first threshold and the second threshold according to the utility value of the local historical records under each task node.
[0016] In some embodiments, the method further includes:
[0017] If the historical operation and maintenance trajectory of the operation and maintenance personnel has been deleted, obtain the complete mirror file of the historical operation and maintenance trajectory of the operation and maintenance personnel, and locate the trajectory file from the complete mirror file according to the file magic;
[0018] Locate all data blocks of the trajectory file, and extract the file header of the trajectory file and splice it with each data block to obtain a reconstructed data block;
[0019] Extract the historical trajectory from the reconstructed data block, and search for the deleted operation and maintenance trajectory from the unallocated area on the disk according to the historical trajectory;
[0020] Extract the file header of the deleted operation and maintenance trajectory and reorganize it with the corresponding reconstructed data block, and use the reorganized operation and maintenance trajectory file as the historical operation and maintenance trajectory of the operation and maintenance personnel.
[0021] In some embodiments, the operation and maintenance audit system includes an end-user layer, a secure access layer, and an intranet resource layer. The main body of the operation and maintenance audit system is located in the secure access layer, the operation and maintenance client is located in the end-user layer, and various remote operation and maintenance resource objects are located in the intranet resource layer.
[0022] In some embodiments, the end-user layer includes a browser, a status monitoring client, and an operation and maintenance program. The secure access layer includes a WEB server, a third-party authentication service, a third-party management interface, an HA interface, a status monitoring program, a configuration library, an audit library, and a TS application center management agent. The intranet resource layer includes a graphic service and a character service. The data flow between the proxy server and the client, and between the status monitoring service and the remote operation and maintenance resources is bidirectional. The operation and maintenance audit system is used to perform data parsing and data forwarding between the operation and maintenance client and the operation and maintenance resources.
[0023] In a second aspect, an embodiment of the present application provides an account security control system, including:
[0024] The first acquisition module is used to acquire the historical operation and maintenance tracks of the operation and maintenance personnel recorded in a preset period of the operation and maintenance audit system, and form a historical operation and maintenance track map according to the historical operation and maintenance tracks;
[0025] A first processing module, configured to generate a first alarm message when a data deviation between the current operation and maintenance trajectory of the operation and maintenance personnel and the historical operation and maintenance trajectory diagram exceeds a preset first threshold;
[0026] The second processing module is used to disconnect the operation and maintenance personnel from the operation and maintenance audit system, generate a second alarm message, and modify the account information of the operation and maintenance personnel for logging into the operation and maintenance audit system when the data deviation between the current operation and maintenance trajectory of the operation and maintenance personnel and the historical operation and maintenance trajectory diagram exceeds a preset second threshold, and the preset second threshold is greater than the preset first threshold.
[0027] In some embodiments, the system further comprises:
[0028] The first calculation module is used to pre-process each historical operation and maintenance trajectory of the operation and maintenance personnel through a clustering method, and calculate the mean of the local historical records under each task node in the execution path to form a valid operation and maintenance trajectory diagram.
[0029] In some embodiments, the system further comprises:
[0030] A decomposition module, used to decompose the global constraints of the historical operation and maintenance trajectory to form local historical records under multiple task nodes in the execution path;
[0031] The second calculation module is used to eliminate local historical records that do not meet the local constraints and calculate the average of the candidate local historical records;
[0032] The third calculation module is used to obtain the utility value of the local historical record under each task node through the average of the candidate local historical records;
[0033] The third processing module is used to set the first threshold and the second threshold according to the utility value of the local historical records under each task node.
[0034] In some embodiments, the system further comprises:
[0035] The second acquisition module acquires the complete image file of the historical operation and maintenance track of the operation and maintenance personnel if the historical operation and maintenance track of the operation and maintenance personnel has been deleted, and locates the track file from the complete image file according to file magic;
[0036] The first extraction module is used to locate all data blocks of the trajectory file, and extract the file header of the trajectory file and splice it with each of the data blocks to obtain a reconstructed data block;
[0037] The search module is used to extract the historical trajectory from the reconstructed data block, and search for the deleted operation and maintenance trajectory from the unallocated area on the disk according to the historical trajectory;
[0038] The second extraction module extracts the file header of the deleted operation and maintenance trajectory and reorganizes it with the corresponding reconstructed data block, and uses the reorganized operation and maintenance trajectory file as the historical operation and maintenance trajectory of the operation and maintenance personnel.
[0039] In a third aspect, an embodiment of the present application provides a readable storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the account security control method as described in the first aspect above.
[0040] In a fourth aspect, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the account security control method as described in the first aspect above.
[0041] Compared with the related art, the account security control method, system, readable storage medium, and computer provided by the embodiments of the present application record the operation and maintenance trajectories of operation and maintenance personnel, perform intelligent statistical analysis on a large number of operation and maintenance records of operation and maintenance personnel to form corresponding operation and maintenance trajectory diagrams. When the deviation between a certain operation and maintenance and the previously statistically analyzed data exceeds a preset first threshold, corresponding warning information is generated to enable the operation and maintenance personnel to confirm their operation and maintenance operations, thereby avoiding information security problems; when the deviation exceeds a preset second threshold, the connection between the operation and maintenance personnel and the operation and maintenance audit system is immediately disconnected, and serious warning information is generated and the account information of the operation and maintenance personnel for logging in to the operation and maintenance audit system is automatically modified; by setting a deviation value for the operation and maintenance trajectories of operation and maintenance personnel, two certifications are performed on the operation and maintenance operations of operation and maintenance personnel, which not only effectively avoids certification errors, but also effectively protects the security of the accounts of operation and maintenance personnel.
[0042] Details of one or more embodiments of the present application are set forth in the following drawings and description, so that other features, objects, and advantages of the present application will become more clearly understood. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The illustrative embodiments and descriptions thereof of the present application are used to explain the present application, and do not constitute an improper limitation of the present application. In the drawings:
[0044] Figure 1Flowchart of the account security control method in the first embodiment of the present invention;
[0045] Figure 2 Flowchart of the account security control method in the second embodiment of the present invention;
[0046] Figure 3 Block diagram of the structure of the account security control system in the third embodiment of the present invention;
[0047] Figure 4 Block diagram of the structure of the computer device in the fourth embodiment of the present invention.
[0048] Description of the main component symbols:
[0049] Memory 10 Partitioning Module 12 Processor 20 Second Creation Module 13 Computer Program 30 Allocation Module 14 First Creation Module 11 Control Module 15
[0050] The following specific embodiments will further illustrate the present invention in conjunction with the above-mentioned drawings. Specific embodiments
[0051] In order to make the objectives, technical solutions and advantages of the present application clearer and more understandable, the following describes and explains the present application in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments provided in the present application without creative efforts fall within the scope of protection of the present application.
[0052] Obviously, the drawings in the following description are only some examples or embodiments of the present application. For those of ordinary skill in the art, the present application can also be applied to other similar scenarios based on these drawings without creative efforts. In addition, it can also be understood that although the efforts made in this development process may be complex and time-consuming, for those of ordinary skill in the art related to the content disclosed in the present application, some design, manufacturing or production changes based on the technical content disclosed in the present application are only conventional technical means and should not be understood as the content disclosed in the present application being insufficient.
[0053] Referring to "embodiments" in the present application means that the specific features, structures or characteristics described in conjunction with the embodiments may be included in at least one embodiment of the present application. The phrase appears in various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those of ordinary skill in the art explicitly and implicitly understand that the embodiments described in the present application can be combined with other embodiments without conflict.
[0054] Unless otherwise defined, the technical terms or scientific terms involved in this application shall have the ordinary meanings understood by those with ordinary skills in the technical field to which this application belongs. The words such as "a", "an", "one kind", "the" and the like involved in this application do not indicate a quantity limitation and may represent a singular or plural number. The terms "including", "comprising", "having" and any variations thereof involved in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product or device including a series of steps or modules (units) is not limited to the listed steps or units, but may further include steps or units not listed, or may further include other steps or units inherent to these processes, methods, products or devices. The similar words such as "connected", "linked", "coupled" and the like involved in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The "multiple" involved in this application means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships may exist. For example, "A and / or B" may represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the front and rear associated objects. The terms "first", "second", "third" and the like involved in this application are only used to distinguish similar objects and do not represent a specific order for the objects.
[0055] First of all, it should be noted that:
[0056] The operation and maintenance audit system is a new generation of operation and maintenance security audit product. It can perform fine-grained authorization on the access process of operation and maintenance personnel, record and control the entire operation process, conduct all-round operation audits, and support the function of playing back the operation process after the event, realizing "prevention before the event, control during the event, and audit after the event" in the operation and maintenance process. While simplifying the operation and maintenance operations, it comprehensively solves the operation and maintenance security problems in various complex environments and improves the enterprise's IT operation and maintenance management level.
[0057] The present invention provides an account security control method. By recording the operation and maintenance tracks of operation and maintenance personnel, a large number of operation and maintenance records of operation and maintenance personnel are intelligently statistically analyzed to form corresponding operation and maintenance track diagrams. Each operation and maintenance action of each operation and maintenance personnel is generally the same and there will be no large changes. Once the deviation between a certain operation and maintenance and the previously statistically analyzed data exceeds a preset first threshold, corresponding warning information is generated, and the administrator must immediately find the corresponding operation and maintenance personnel for confirmation. When the deviation exceeds the preset second threshold, all sessions of the current operation and maintenance personnel are immediately disconnected, and serious warning information is generated and the account information of the operation and maintenance personnel is automatically modified. By setting a deviation value for the operation and maintenance tracks of operation and maintenance personnel and performing two authentications on the operation and maintenance personnel, not only is the authentication error effectively avoided, but also the security of the operation and maintenance personnel's accounts is effectively protected.
[0058] Embodiment 1
[0059] Please refer to Figure 1 , which shows the account security control method in the first embodiment of the present invention. The method specifically includes steps S101 to S103:
[0060] S101, obtain the historical operation and maintenance tracks of operation and maintenance personnel recorded within a preset period of the operation and maintenance audit system, and form a historical operation and maintenance track diagram according to the historical operation and maintenance tracks;
[0061] In specific implementation, enable the operation and maintenance track recording configuration in the operation and maintenance audit system, set the recording period to X days, and set the operation and maintenance track deviation value; preprocess each historical operation and maintenance track of the operation and maintenance personnel through a clustering method, and calculate the mean value of the local historical records under each task node in the execution path to form an effective operation and maintenance track diagram.
[0062] In this embodiment, the operation and maintenance audit system includes a terminal user layer, a secure access layer, and an intranet resource layer. The main body of the operation and maintenance audit system is located in the secure access layer, the operation and maintenance client is located in the terminal user layer, and various remote operation and maintenance resource objects are located in the intranet resource layer. The terminal user layer includes a browser, a status monitoring client, and an operation and maintenance program. The secure access layer includes a WEB server, a third-party authentication service, a third-party management interface, an HA interface, a status monitoring program, a configuration library, an audit library, and a TS application center management agent. The intranet resource layer includes a graphic service and a character service. The data flow directions between the proxy server and the client, the status monitoring service, and the remote operation and maintenance resources are all two-way. The operation and maintenance audit system acts as a "middleman" between the operation and maintenance client and the operation and maintenance resources, responsible for parsing and forwarding the data of both parties, and performing permission configuration through role-based minimum authorization. After logging in to the system with an administrator role, this mechanism allows it to configure system security control function points such as operation and maintenance account groups, account information, business objects, asset objects, operation commands, and filtering methods, and can also set the system's own security protection functions, such as backup and recovery of the policy library, complexity of the login system password, and two-factor identity authentication.
[0063] The browser includes operations such as the user logging in to, configuring, and performing operation and maintenance connections with the operation and maintenance audit system through the browser. The status monitoring client monitors the operation of the client operation and maintenance program and plugins. The status monitoring client includes the client tool connecting to the operation and maintenance audit system server to query the operation status of system processes and restart services, control access connections, the audit library proxying different remote operation and maintenance communication protocols, parsing protocols, performing operations, and re-encapsulating and forwarding, proxying various text input information and performing permission control, the configuration library storing accounts, passwords, roles, resources, permissions, and access control policies, the TS application center management agent reading configuration information, providing TS services, configuring user application access permission information for the TS application center, and pushing the configuration information to the application center. The application center is responsible for running third-party applications based on the Windows operating system, including an HA interface supporting load balancing and a third-party authentication service. The graphical service is used for the RDP graphical remote connection service enabled on operation and maintenance resources, and the character service is used for the SSH, Telnet, FTP, and SFTP character remote connection services enabled on operation and maintenance resources. When logging in to the system as an auditor, this mechanism allows access to and advanced applications of various security logs, such as keyword queries, statistical analysis, comprehensive comparison, and report generation, to achieve security auditing and evidence collection. When logging in to the system as an operation and maintenance personnel, this mechanism allows them to perform topology viewing, object designation, remote connection, and execution of authorized operation instructions on operation and maintenance assets within the defined operation and maintenance management scope, and the operation and maintenance control mechanism implements the process.
[0064] S102. When the data deviation between the current operation and maintenance track of the operation and maintenance personnel and the data in the historical operation and maintenance track diagram exceeds a preset first threshold, generate a first warning message.
[0065] In specific implementation, each operation and maintenance action of each operation and maintenance personnel is generally the same and there will be no significant changes. Once the data deviation of a certain operation and maintenance or firewall operation and maintenance of the operation and maintenance personnel from the previous statistical analysis data exceeds N%, corresponding warning messages are generated to enable the operation and maintenance personnel to confirm the corresponding operation and maintenance operations.
[0066] S103. When the data deviation between the current operation and maintenance track of the operation and maintenance personnel and the data in the historical operation and maintenance track diagram exceeds a preset second threshold, disconnect the connection between the operation and maintenance personnel and the operation and maintenance audit system, generate a second warning message, and modify the account information of the operation and maintenance personnel for logging in to the operation and maintenance audit system. The preset second threshold is greater than the preset first threshold.
[0067] In specific implementation, when the deviation exceeds M%, all sessions of the current operation and maintenance personnel are immediately disconnected, and serious warning information is generated and the account password of the operation and maintenance personnel is automatically modified. This method sets the deviation value for the operation and maintenance track of the operation and maintenance personnel by the administrator and performs two authentications on the operation and maintenance personnel, which not only effectively avoids authentication errors, but also effectively protects the security of the operation and maintenance personnel's accounts.
[0068] In some alternative embodiments, X days in step S101 are default set to 14 days, and the adjustable range is 7 - 21 days. The setting of the operation and maintenance track deviation value includes the following steps:
[0069] S111, decompose the global constraints of the historical operation and maintenance track to form local historical records under multiple task nodes in the execution path;
[0070] S112, eliminate the local historical records that do not meet the local constraints and calculate the mean value of the candidate local historical records;
[0071] In specific implementation,
[0072] S113, obtain the utility value of the local historical records under each task node through the mean value of the candidate local historical records;
[0073] S114, set the first threshold and the second threshold according to the utility values of the local historical records under each task node.
[0074] In specific implementation, for an execution path with n tasks, each task corresponds to m services, each service has 1 historical operation and maintenance track, the number of clustering partitions is k, the time complexity of the CBSC method is 0, which is lower than that of the traditional global combination recommendation algorithm. Moreover, as the number of historical operation and maintenance tracks (i.e., l) increases, the time complexity of the global method will increase, while the time complexity of the CBSC method will not be significantly affected. By directly applying the global constraints to the combination scheme of the center point records, the accuracy can be guaranteed. The historical operation and maintenance track set is represented by the clustering center points. As the clustering partition value k increases, the accuracy will gradually approach the global method without constraints.
[0075] The operation and maintenance track calculates the execution plan for each historical record of each operation and maintenance personnel, and then aggregates to obtain a service combination plan for recommendation. The execution plan of each historical record of the operation and maintenance personnel is preprocessed by a clustering method. By calculating the mean value of all historical records under each task node in the execution path, the personalized global constraint of the operation and maintenance personnel is decomposed into local task node constraints, and the global constraint is transformed into local constraints of individual task nodes. By introducing a tolerance coefficient, the errors of effective plans are filtered, so as to retain the effective historical operation and maintenance tracks that meet the local constraints, obtain the mean value of effective historical records of each service, and complete the final service combination operation. By adopting a clustering strategy, the clustering center point is used to represent the entire historical record set to participate in the combination plan, simplifying the service combination. The clustering method used effectively prevents the explosion problem of service combination in the processing of large-scale historical records, and significantly improves the performance of the system.
[0076] In some alternative embodiments, the method further includes:
[0077] S121, if the historical operation and maintenance track of the operation and maintenance personnel has been deleted, obtain the complete mirror file of the historical operation and maintenance track of the operation and maintenance personnel, and locate the track file from the complete mirror file according to the file magic;
[0078] S122, locate all data blocks of the track file, and extract the file header of the track file and splice it with each of the data blocks to obtain a reconstructed data block;
[0079] S123, extract the historical track from the reconstructed data block, and search for the deleted operation and maintenance track from the unallocated area on the disk according to the historical track;
[0080] S124, extract the file header of the deleted operation and maintenance track and reorganize it with the corresponding reconstructed data block, and use the reorganized operation and maintenance track file as the historical operation and maintenance track of the operation and maintenance personnel.
[0081] In specific implementation, when restoring the operation and maintenance track, it includes obtaining a complete mirror of the historical track as sample data for analysis, locating the track file from the mirror file according to the file magic, then locating all data blocks of the track according to the random number consistency, extracting the file header and each data block for splicing, extracting the reconstructed data blocks, analyzing the content of the data pages in the data blocks, with the leaf pages as the key analysis points, extracting the historical track from the data blocks according to the recorded storage structure, first looking for the deleted operation and maintenance track in the unallocated area of the disk, extracting the file header and the corresponding data blocks for recombination through the invariant feature of the random number between the data blocks and the file header, extracting each record from the recombined operation and maintenance track file according to the record structure, where the operation and maintenance track includes the file header and the data blocks. In the case of sharded storage, there may be some other unknown data blocks between the data blocks or the file headers. By using the method of locating data blocks through random number matching, the interference area is excluded.
[0082] In summary, for the account security control method in the above embodiments of the present invention, by recording the operation and maintenance tracks of operation and maintenance personnel, a large number of operation and maintenance records of operation and maintenance personnel are intelligently statistically analyzed to form corresponding operation and maintenance track diagrams. When the deviation between a certain operation and maintenance and the previously statistically analyzed data exceeds a preset first threshold, corresponding warning information is generated to enable operation and maintenance personnel to confirm their operation and maintenance operations, thereby avoiding information security problems; when the deviation exceeds a preset second threshold, the connection between the operation and maintenance personnel and the operation and maintenance audit system is immediately disconnected, and serious warning information is generated and the account information of the operation and maintenance personnel for logging in to the operation and maintenance audit system is automatically modified; by setting a deviation value for the operation and maintenance tracks of operation and maintenance personnel, two-factor authentication is performed on the operation and maintenance operations of operation and maintenance personnel, which not only effectively avoids authentication errors but also effectively protects the security of the operation and maintenance personnel's accounts.
[0083] Embodiment 2
[0084] Please refer to Figure 2 , which shows the account security control method in the second embodiment of the present invention. The method specifically includes steps S201 to S205:
[0085] S201: The administrator logs in to the system
[0086] The administrator logs in to the operation and maintenance audit system;
[0087] Further, in step S201, the operation and maintenance audit system includes an end-user layer, a secure access layer, and an intranet resource layer. The main body of the operation and maintenance audit system is located in the secure access layer, the operation and maintenance client is located in the end-user layer, and various remote operation and maintenance resource objects are located in the intranet resource layer. The end-user layer includes a browser, a status monitoring client, and an operation and maintenance program. The secure access layer includes a WEB server, a third-party authentication service, a third-party management interface, an HA interface, a status monitoring program, a configuration library, an audit library, and a TS application center management agent. The intranet resource layer includes a graphics service and a character service. The data flow between the proxy server and the client, the status monitoring service, and the remote operation and maintenance resources is bidirectional. The operation and maintenance audit system, as the "middleman" between the operation and maintenance client and the operation and maintenance resources, is responsible for parsing and forwarding the data of both parties, and performing permission configuration through role-based minimum authorization. After logging in to the system with an administrator role, this mechanism allows it to configure system security control function points such as operation and maintenance account groups, account information, business objects, asset objects, operation commands, and filtering methods. At the same time, it can also set the system's own security protection functions, such as backup and recovery of the policy library, complexity of the login system password, and two-factor identity authentication.
[0088] Further, the browser allows users to perform login, configuration, and operation and maintenance connection operations on the operation and maintenance audit system through the browser. The status monitoring client monitors the running status of the client operation and maintenance program and plugins. The status monitoring client includes client tools to connect to the operation and maintenance audit system server, query the running status of system processes, restart services, and control access connections. The audit library proxies different remote operation and maintenance communication protocols, parses the protocols, executes operations, and repackages and forwards them, and also proxies and controls various text input information. The configuration library stores accounts, passwords, roles, resources, permissions, and access control policies. The TS application center management agent reads the configuration information, provides TS services, configures the access permission information of TS application center users, and pushes the configuration information to the application center. The application center is responsible for running third-party applications based on the Windows operating system, including an HA interface that supports load balancing and a third-party authentication service. The graphics service is used for the RDP graphical remote connection service enabled on the operation and maintenance resources, and the character service is used for the SSH, Telnet, FTP, and SFTP character remote connection services enabled on the operation and maintenance resources. After logging in to the system with an auditor role, this mechanism allows it to access and perform advanced applications on various security logs, such as keyword query, statistical analysis, comprehensive comparison, and report generation, to achieve security auditing and evidence collection. After logging in to the system with an operation and maintenance personnel role, this mechanism allows it to view the topology of operation and maintenance assets, specify objects, make remote connections, and execute authorized operation instructions within the defined operation and maintenance management scope, and implement the operation and maintenance control mechanism process.
[0089] S202: Set the operation and maintenance track
[0090] The administrator enables the operation and maintenance track record configuration in the operation and maintenance audit system, sets the record period to X days, and sets the operation and maintenance track deviation value;
[0091] S203: The operation and maintenance personnel log in to the system
[0092] The operation and maintenance personnel log in to the operation and maintenance audit system to perform server operation and maintenance;
[0093] S204: System recording
[0094] The operation and maintenance audit system records the operation and maintenance tracks of the operation and maintenance personnel for consecutive N days, and forms an operation and maintenance track diagram from the operation and maintenance tracks within the period;
[0095] S205: Data verification
[0096] In specific implementation, step S205 specifically includes the following steps:
[0097] (1). After the period, the operation and maintenance personnel log in for operation and maintenance. If the data deviation of a certain operation and maintenance of the operation and maintenance personnel from the previous operation and maintenance track diagram exceeds N%, corresponding alarm information is generated, and the administrator must immediately find the corresponding operation and maintenance personnel for confirmation;
[0098] (2). When the deviation exceeds M%, immediately disconnect all sessions of the current operation and maintenance personnel, and generate serious alarm information and automatically modify the account password of the operation and maintenance personnel. The value of M is greater than the value of N.
[0099] The above embodiment records the operation and maintenance tracks of the operation and maintenance personnel, makes intelligent statistical analysis of a large number of operation and maintenance records of the operation and maintenance personnel to form corresponding operation and maintenance track diagrams. The operation and maintenance actions of each operation and maintenance personnel are generally the same and there will be no large changes. Once the data deviation of a certain operation and maintenance from the previous statistical analysis data exceeds N%, corresponding alarm information is generated, and the administrator must immediately find the corresponding operation and maintenance personnel for confirmation. When the deviation exceeds M%, immediately disconnect all sessions of the current operation and maintenance personnel, and generate serious alarm information and automatically modify the account password of the operation and maintenance personnel. This method sets the deviation value for the operation and maintenance tracks of the operation and maintenance personnel by the administrator, and conducts two certifications for the operation and maintenance personnel, which not only effectively avoids authentication errors, but also effectively protects the security of the operation and maintenance personnel's accounts.
[0100] In some other alternative embodiments, the operation and maintenance control mechanism is based on the access control privilege management of RBAC. The initialization roles of the security operation and maintenance audit system are divided into system administrators, system auditors, and operation and maintenance operations. System administrators can also be further divided into administrators at different levels and in different businesses according to the actual situation, such as network administrators, database administrators, ERP system administrators, and MIS system administrators. Operation and maintenance personnel can also be divided into different user groups, so as to correspond to the operation and maintenance resources they need. A progressive strategy configuration method is adopted to clearly associate operation and maintenance elements such as people-machine-operation-strategy. A "wizard-style" operation mode is adopted, and return and forward operations can be performed at each step, which conforms to the habits of administrators to issue and modify policies and has good usability. When the administrator completes the issuance and takes effect of the operation and maintenance operation internal control policy through this process, the operation and maintenance personnel can access limited operation and maintenance resources through this policy, perform controlled operation and maintenance operations, and be monitored and audited.
[0101] Further, in the step S201, X days is default set to 14 days, and the adjustable range is 7 - 21 days. The operation and maintenance track calculates the execution plan for each historical record of each operation and maintenance personnel, and then aggregates to obtain a service combination plan for recommendation. The execution plan of each historical record of operation and maintenance personnel is preprocessed by a clustering method. By calculating the mean value of all historical records under each task node in the execution path, the personalized global constraint of the operation and maintenance personnel is decomposed into local task node constraints, and the global constraint is transformed into local constraints of a single task node. By introducing a tolerance coefficient, the errors of effective solutions are filtered, so as to retain the effective historical operation and maintenance tracks that meet the local constraints, obtain the mean value of effective historical records of each service, and complete the final service combination operation. By adopting a clustering strategy, the clustering center point is used to represent the entire historical record set to participate in the combination plan, simplifying the service combination. The clustering method used effectively prevents the explosion problem of service combination in the processing of large-scale historical records, and significantly improves the performance of the system.
[0102] In some other alternative embodiments, for an execution path with n tasks, each task corresponds to m services, each service has 1 historical operation and maintenance track, and the number of clustering partitions is k. The time complexity of the CBSC method is 0, which is lower than that of the traditional global combination recommendation algorithm. Moreover, as the number of historical operation and maintenance tracks (i.e., l) increases, the time complexity of the global method will increase, while the time complexity of the CBSC method will not be significantly affected. By directly applying the global constraint to the combination plan of the center point record, the accuracy can be guaranteed. The historical operation and maintenance track set is represented by the clustering center point. As the clustering partition value k increases, the accuracy will gradually approach the global method without constraints.
[0103] Further, in the step S201, the setting of the operation and maintenance track deviation value includes the following steps:
[0104] A. Statistically maintain the historical operation and maintenance tracks of personnel;
[0105] B. Decompose the global constraints of the operation and maintenance tracks;
[0106] C. Eliminate historical records that do not meet the local constraints;
[0107] D. Calculate the mean value of the historical records of each candidate service;
[0108] E. Calculate the utility value of the execution plan of the mean historical record;
[0109] F. Compare the setting deviations of the utility values of each execution plan.
[0110] Further, when restoring the operation and maintenance track, it includes obtaining a complete mirror of the historical track as sample data for analysis, locating the track file from the mirror file according to the file magic, then locating all data blocks of the track according to the random number consistency, extracting the file header and each data block for splicing, extracting the reconstructed data blocks, analyzing the content of the data pages in the data blocks, with the leaf pages as the key points of analysis, extracting the historical track from the data block according to the recorded storage structure, first looking for the deleted operation and maintenance track on the unallocated area of the disk, extracting the file header and the corresponding data block for recombination through the invariant feature of the random number between the data block and the file header, extracting each record from the recombined operation and maintenance track file according to the record structure. The operation and maintenance track includes the file header and the data block. In the case of sharded storage, there may be some other unknown data blocks between the data blocks or the file headers. By using the method of locating data blocks through random number matching, the interference area is excluded.
[0111] In some other alternative embodiments, through pre-writing operation and maintenance track reconstruction, a pre-written operation and maintenance track from which records can be extracted is obtained. The leaf pages of the data blocks are extracted from the log file. All the operation and maintenance track records of the operation and maintenance personnel are stored in the leaf pages. Through the analysis of the record storage structure, the records can be completely extracted. The positioning and extraction of the data block can locate the first byte of the first data block by offsetting 33 bytes from the file header, and then read the current data block according to the data block size, a total of 32792 bytes. The records are extracted from the data block, and the length and type of each field of the record are calculated. The main steps of record extraction mainly include string matching to locate the position of the record in the data block, the characteristic string, and based on the located position, inversely deriving and calculating the data type and length of each field, and extracting each field of the record to form a complete record.
[0112] In summary, the account security control method in the above embodiments of the present invention records the operation and maintenance trajectories of operation and maintenance personnel, makes intelligent statistical analysis on a large number of operation and maintenance records of operation and maintenance personnel to form corresponding operation and maintenance trajectory diagrams. When the deviation between a certain operation and maintenance and the previously made statistical analysis data exceeds a preset first threshold, corresponding alarm information is generated to enable the operation and maintenance personnel to confirm their operation and maintenance operations, thereby avoiding information security problems; when the deviation exceeds a preset second threshold, the connection between the operation and maintenance personnel and the operation and maintenance audit system is immediately disconnected, and serious alarm information is generated and the account information of the operation and maintenance personnel logging in to the operation and maintenance audit system is automatically modified; by setting a deviation value for the operation and maintenance trajectories of operation and maintenance personnel, two certifications are performed on the operation and maintenance operations of operation and maintenance personnel, which not only effectively avoids certification errors, but also effectively protects the security of the accounts of operation and maintenance personnel.
[0113] Embodiment III
[0114] On the other hand, the present invention also proposes an account security control system. Please refer to Figure 3 , which shows the account security control system in the third embodiment of the present invention, including:
[0115] The first acquisition module 11 is used to acquire the historical operation and maintenance trajectories of operation and maintenance personnel recorded by the operation and maintenance audit system within a preset period, and form a historical operation and maintenance trajectory diagram according to the historical operation and maintenance trajectories;
[0116] The first processing module 12 is used to generate first alarm information when the data deviation between the current operation and maintenance trajectory of the operation and maintenance personnel and the historical operation and maintenance trajectory diagram exceeds a preset first threshold;
[0117] The second processing module 13 is used to disconnect the connection between the operation and maintenance personnel and the operation and maintenance audit system, generate second alarm information, and modify the account information of the operation and maintenance personnel logging in to the operation and maintenance audit system when the data deviation between the current operation and maintenance trajectory of the operation and maintenance personnel and the historical operation and maintenance trajectory diagram exceeds a preset second threshold, and the preset second threshold is greater than the preset first threshold.
[0118] In some embodiments, the system further includes:
[0119] The first calculation module is used to preprocess each historical operation and maintenance trajectory of the operation and maintenance personnel by a clustering method, and calculate the mean value of the local historical records under each task node in the execution path to form an effective operation and maintenance trajectory diagram.
[0120] In some embodiments, the system further includes:
[0121] The decomposition module is used to decompose the global constraints of the historical operation and maintenance trajectory to form local historical records under multiple task nodes in the execution path;
[0122] A second calculation module, configured to eliminate local historical records that do not meet local constraints and calculate the average value of candidate local historical records;
[0123] A third calculation module, configured to obtain the utility value of local historical records under each task node based on the average value of candidate local historical records;
[0124] A third processing module, configured to set the first threshold and the second threshold according to the utility value of local historical records under each task node.
[0125] In some embodiments, the system further includes:
[0126] A second acquisition module, if the historical operation and maintenance track of the operation and maintenance personnel has been deleted, acquires a complete mirror file of the historical operation and maintenance track of the operation and maintenance personnel, and locates a track file from the complete mirror file according to the file magic;
[0127] A first extraction module, configured to locate all data blocks of the track file, and extract the file header of the track file and splice it with each of the data blocks to obtain a reconstructed data block;
[0128] A search module, configured to extract a historical track from the reconstructed data block, and search for a deleted operation and maintenance track from an unallocated area on the disk according to the historical track;
[0129] A second extraction module, extracts the file header of the deleted operation and maintenance track and reorganizes it with the corresponding reconstructed data block, and uses the reorganized operation and maintenance track file as the historical operation and maintenance track of the operation and maintenance personnel.
[0130] The functions or operation steps implemented when the above modules are executed are substantially the same as those in the above method embodiments, and will not be described in detail here.
[0131] The account security control system provided by the embodiments of the present invention has the same implementation principle and technical effects as those in the foregoing method embodiments. For the sake of brief description, for the parts not mentioned in the system embodiments, reference may be made to the corresponding parts in the foregoing method embodiments.
[0132] Embodiment 4
[0133] The present invention also provides a computer device. Please refer to Figure 4 , which shows the computer device in the fourth embodiment of the present invention, including a memory 10, a processor 20, and a computer program 30 stored on the memory 10 and executable on the processor 20. When the processor 20 executes the computer program 30, the above-mentioned account security control method is implemented.
[0134] Among them, the memory 10 includes at least one type of readable storage medium, and the readable storage medium includes flash memory, hard disk, multimedia card, card-type memory (such as SD or DX memory, etc.), magnetic memory, magnetic disk, optical disc, etc. The memory 10 can be an internal storage unit of the vehicle in some embodiments, such as the hard disk of the vehicle. The memory 10 can also be an external storage device in other embodiments, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. Further, the memory 10 can also include both the internal storage unit of the vehicle and the external storage device. The memory 10 can be used not only to store application software installed in the vehicle and various types of data, but also to temporarily store data that has been output or will be output.
[0135] Among them, the processor 20 can be an Electronic Control Unit (ECU, also known as the vehicle computer), a Central Processing Unit (CPU), a controller, a microcontroller, a microprocessor or other data processing chips in some embodiments, and is used to run the program code stored in the memory 10 or process data, such as executing an access restriction program, etc.
[0136] It should be noted that Figure 4 The structure shown does not constitute a limitation on the computer. In other embodiments, the computer may include fewer or more components than shown in the figure, or combine certain components, or have a different component arrangement.
[0137] An embodiment of the present invention also proposes a readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the account security control method as described above is implemented.
[0138] Those skilled in the art can understand that the logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, device or equipment (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, device or equipment), or used in combination with these instruction execution systems, devices or equipment. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by or in combination with an instruction execution system, device or equipment.
[0139] More specific examples (nonexhaustive list) of computer-readable media include the following: an electrical connection (electronic device) having one or more wirings, a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable media can even be paper or other suitable media on which the program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or otherwise processing as appropriate, and then storing it in a computer memory.
[0140] It should be understood that various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field programmable gate arrays (FPGAs), etc.
[0141] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as falling within the scope described in this specification.
[0142] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.
Claims
1. An account security control method, characterized in that, Including: Obtain the historical operation and maintenance tracks of operation and maintenance personnel recorded within a preset period of the operation and maintenance audit system, and form a historical operation and maintenance track diagram based on the historical operation and maintenance tracks; When the data deviation between the current operation and maintenance track of the operation and maintenance personnel and the historical operation and maintenance track diagram exceeds a preset first threshold, generate a first warning message; When the data deviation between the current operation and maintenance track of the operation and maintenance personnel and the historical operation and maintenance track diagram exceeds a preset second threshold, disconnect the connection between the operation and maintenance personnel and the operation and maintenance audit system, generate a second warning message, and modify the account information of the operation and maintenance personnel for logging in to the operation and maintenance audit system, where the preset second threshold is greater than the preset first threshold; The method further includes: Decompose the global constraints of the historical operation and maintenance tracks to form local historical records under multiple task nodes in the execution path; Eliminate local historical records that do not meet the local constraints, and calculate the average value of the candidate local historical records; Obtain the utility values of the local historical records under each task node through the average value of the candidate local historical records; Set the first threshold and the second threshold according to the utility values of the local historical records under each task node.
2. The account security control method according to claim 1, wherein The method further includes: Preprocess each historical operation and maintenance track of the operation and maintenance personnel through a clustering method, and calculate the average value of the local historical records under each task node in the execution path to form an effective operation and maintenance track diagram.
3. The account security control method according to claim 1, characterized in that, The method further includes: If the historical operation and maintenance track of the operation and maintenance personnel has been deleted, obtain the complete mirror file of the historical operation and maintenance track of the operation and maintenance personnel, and locate the track file from the complete mirror file according to the file magic; Locate all data blocks of the track file, extract the file header of the track file and splice it with each data block to obtain a reconstructed data block; Extract the historical track from the reconstructed data block, and search for the deleted operation and maintenance track from the unallocated area on the disk according to the historical track; Extract the file header of the deleted operation and maintenance track and reorganize it with the corresponding reconstructed data block, and use the reorganized operation and maintenance track file as the historical operation and maintenance track of the operation and maintenance personnel.
4. The account security control method according to claim 1, wherein, The operation and maintenance audit system includes a terminal user layer, a secure access layer, and an intranet resource layer. The main body of the operation and maintenance audit system is located in the secure access layer, the operation and maintenance client is located in the terminal user layer, and various remote operation and maintenance resource objects are located in the intranet resource layer.
5. The account security control method according to claim 4, wherein The terminal user layer includes a browser, a status monitoring client, and an operation and maintenance program. The secure access layer includes a WEB server, a third-party authentication service, a third-party management interface, an HA interface, a status monitoring program, a configuration library, an audit library, and a TS application center management agent. The intranet resource layer includes a graphic service and a character service. The data flow between the proxy server and the client, and between the status monitoring service and the remote operation and maintenance resources is bidirectional. The operation and maintenance audit system is used for data parsing and data forwarding between the operation and maintenance client and the operation and maintenance resources.
6. An account security control system, characterized in that, Including: The first acquisition module is used to acquire the historical operation and maintenance tracks of the operation and maintenance personnel recorded in a preset period of the operation and maintenance audit system, and form a historical operation and maintenance track map according to the historical operation and maintenance tracks; A first processing module, configured to generate a first alarm message when a data deviation between the current operation and maintenance trajectory of the operation and maintenance personnel and the historical operation and maintenance trajectory diagram exceeds a preset first threshold; A second processing module is used to disconnect the operation and maintenance personnel from the operation and maintenance audit system, generate a second alarm message, and modify the account information of the operation and maintenance personnel for logging into the operation and maintenance audit system when the data deviation between the current operation and maintenance trajectory of the operation and maintenance personnel and the historical operation and maintenance trajectory diagram exceeds a preset second threshold, and the preset second threshold is greater than the preset first threshold; A decomposition module, used to decompose the global constraints of the historical operation and maintenance trajectory to form local historical records under multiple task nodes in the execution path; The second calculation module is used to eliminate local historical records that do not meet the local constraints and calculate the average of the candidate local historical records; The third calculation module is used to obtain the utility value of the local historical record under each task node through the average of the candidate local historical records; The third processing module is used to set the first threshold and the second threshold according to the utility value of the local historical records under each task node.
7. The account security control system according to claim 6, characterized in that, The system further comprises: The first calculation module is used to pre-process each historical operation and maintenance trajectory of the operation and maintenance personnel through a clustering method, and calculate the mean of the local historical records under each task node in the execution path to form a valid operation and maintenance trajectory diagram.
8. A readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, the account security management method as described in any one of claims 1 to 5 is implemented.
9. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, the account security management method according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Data processing method, device and system for operation and maintenance audit
CN105139139A
An abnormal behavior detection method and device
CN109842628A