A method and device for monitoring and protecting files

By configuring the security protection policy of files in the security protection system and scanning, the problem of inability to automatically configure the file protection policy and visually displaying the protection results in the prior art is solved, and automated file protection and visual protection results are realized.

CN114021179BActive Publication Date: 2025-06-24GUANGDONG ELECTRIC POWER COMM CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111107998.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-22
Publication Date
2025-06-24
Estimated Expiration
2041-09-22

AI Technical Summary

Technical Problem

In the prior art, the protection of hosts mainly relies on deployment code, and cannot automatically configure the security protection policy of files, and the security protection results cannot be visually displayed.

Method used

In the security protection system, configure the security protection policy of the file, start scanning of relevant files according to the policy, and display the security protection results. The specific steps include selecting the protection file, selecting the security protection strategy corresponding to the file, establishing the correspondence between the policy and the file, scanning the file, and displaying the protection results.

Benefits of technology

It realizes the security protection policy of automatic configuration files in the security protection system installed on the client, and can visually display the security protection results, improving the protection efficiency of the host.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114021179B_ABST
    Figure CN114021179B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention discloses a method and device for file monitoring and protection. The method is applied to a security protection system and includes: configuring corresponding security protection policies for files in the security protection system; starting to scan relevant files according to the security protection policies; and displaying the security protection results of the files, realizing automatic configuration of security protection policies for relevant files in the security protection system installed on the client, and the security protection results can be visually displayed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of network security technology, and particularly to a method and device for file monitoring and protection. Background Art

[0002] With the development of enterprise informatization to a certain extent, the security of application systems has become increasingly important. In the process of Web application system security protection, in addition to the peripheral network security devices, the protection of the host side itself is also worthy of attention, but at the same time it is also the most easily overlooked link.

[0003] In the prior art, the protection of the host mainly deploys code on the host for protection, and cannot automatically configure security protection policies for relevant files, and the security protection results cannot be visually displayed. Summary of the Invention

[0004] The purpose of this application is to overcome the above problems or at least partially solve or mitigate the above problems.

[0005] In a first aspect, this application provides a method for file monitoring and protection. The method is applied to a security protection system, and the method includes:

[0006] Configure corresponding security protection policies for files in the security protection system;

[0007] According to the security protection policies, start scanning relevant files;

[0008] Display the security protection results of files.

[0009] As a preferred embodiment of this application, the configuration of corresponding security protection policies for files includes:

[0010] Select the files to be protected in advance;

[0011] Select the security protection policies corresponding to the files to be protected in advance from multiple security protection policy lists;

[0012] Establish a corresponding relationship between the selected security protection policies and the files to be protected in advance to complete the configuration of the security protection policies for the file directory.

[0013] As a preferred embodiment of this application, the selection of the security protection policies corresponding to the files to be protected in advance from multiple security protection policy lists includes:

[0014] Obtain the type of the file, and the file type includes application files, application cache files, application log files, and application temporary files;

[0015] According to the file type, select the security protection policies corresponding to the files to be protected in advance from multiple security protection policy lists.

[0016] As a preferred embodiment of the present application, the security protection policy list arranges security protection policies according to the file type in order of priority.

[0017] As a preferred embodiment of the present application, after configuring the corresponding security protection policy for the file, it includes,

[0018] According to the pre-set mapping relationship table between files and security protection policies, determine whether the security protection policy selected from multiple security protection policy lists and corresponding to the file to be protected is correct;

[0019] If it is correct, establish a corresponding relationship between the selected security protection policy and the file to be protected to complete the security protection policy configuration of the file;

[0020] If it is incorrect, issue an error prompt.

[0021] As a preferred embodiment of the present application, it further includes, if there are security vulnerabilities in the file, issue an alarm prompt.

[0022] Compared with the prior art, in the security protection system of the present application embodiment, a corresponding security protection policy is configured for the file, and according to the security protection policy, the relevant file is started to be scanned; the security protection result of the file is displayed, realizing the automatic configuration of the security protection policy for the relevant file in the security protection system installed on the client, and the security protection result can be visually displayed.

[0023] In a second aspect, the embodiment of the present application further provides a file monitoring and protection device, which is installed with an application for a security protection system, and the device includes,

[0024] A configuration module, used to configure a corresponding security protection policy for the file in the security protection system;

[0025] A scanning module, used to start scanning relevant files according to the security protection policy;

[0026] A display module, used to display the security protection result of the file.

[0027] As a preferred embodiment of the present application, the device further includes a selection module, used to select the file to be protected, and also used to select the security protection policy corresponding to the file to be protected from multiple security protection policy lists;

[0028] The configuration module is specifically used to establish a corresponding relationship between the selected security protection policy and the file to be protected to complete the security protection policy configuration of the file directory.

[0029] As a preferred embodiment of the present application, the device further includes an acquisition module for acquiring the type of the file, where the file type includes application files, application cache files, application log files, and application temporary files;

[0030] A selection module for selecting a security protection policy corresponding to the file to be protected from a plurality of security protection policy lists according to the file type.

[0031] As a preferred embodiment of the present application, the device further includes a judgment module for judging whether the security protection policy corresponding to the file to be protected selected from a plurality of security protection policy lists is correct according to a pre-set mapping relation table between files and security protection policies;

[0032] A configuration module is further configured to, if it is correct, establish a corresponding relationship between the selected security protection policy and the file to be protected to complete the security protection policy configuration of the file, and if it is wrong, issue an error prompt.

[0033] As a preferred embodiment of the present application, the device further includes a judgment module for judging whether the security protection policy corresponding to the file to be protected selected from a plurality of security protection policy lists is correct according to a pre-set mapping relation table between files and security protection policies;

[0034] A configuration module is further configured to, if it is correct, establish a corresponding relationship between the selected security protection policy and the file to be protected to complete the security protection policy configuration of the file, and if it is wrong, issue an error prompt.

[0035] In a third aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, where when the program is executed by a processor, it implements the method for monitoring and protecting files described in any one of the above. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] The drawings described herein are used to provide a further understanding of the present application, and constitute a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. Some specific embodiments of the present application will be described in detail hereinafter with reference to the drawings in an exemplary rather than restrictive manner. The same reference numerals in the drawings denote the same or similar components or parts. Those skilled in the art should understand that these drawings are not necessarily drawn to scale. In the drawings:

[0037] Figure 1 It is a flowchart of a method for monitoring and protecting files disclosed in an embodiment of the present invention;

[0038] Figure 2 It is a flowchart of a method for monitoring and protecting files disclosed in another embodiment of the present invention;

[0039] Figure 3 This is a schematic diagram of the structure of a file monitoring and protection device disclosed in an embodiment of the present invention. Detailed implementation manners

[0040] In order to enable those skilled in the art to better understand the solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.

[0041] As Figure 1 shown, an embodiment of this application provides a method for file monitoring and protection. The method is applied to a security protection system. The method includes:

[0042] Step S01, configuring corresponding security protection policies for files in the security protection system;

[0043] It should be noted that since the security protection system is deployed on a relevant host, an application program corresponding to the security protection system can be installed on the terminal device, and relevant staff complete Step S01 by logging in to the application program;

[0044] Specifically, Step S01 includes:

[0045] Step S011, selecting files to be pre-protected;

[0046] It should be noted that relevant staff select the files to be configured in the list of files to be pre-protected.

[0047] Step S012, selecting a security protection policy corresponding to the file to be pre-protected from multiple security protection policy lists;

[0048] It should be noted that the security protection policy lists arrange the security protection policies in order of priority according to the file type. In Step S012, first obtain the type of the file. The file types include application files, application cache files, application log files, and application temporary files;

[0049] Then, according to the file type, select a security protection policy corresponding to the file to be pre-protected from multiple security protection policy lists.

[0050] In the embodiment of this application, the security protection for application files is as follows:

[0051] Set corresponding permissions for the file through the security protection system to restrict the creation and execution operations of the file;

[0052] Protect the application file directory through a tamper-proof device and perform operations such as automatic synchronization;

[0053] Restrict the generation of files that are not normally generated by business under the application file directory through a security protection system.

[0054] In the embodiment of the present application, the security protection of the application cache file is as follows:

[0055] Restrict the file types of the files under this type of file directory;

[0056] Prohibit the creation of files of non-this type;

[0057] Implement the minimum privilege control for the file permissions of this type of file under reasonable circumstances.

[0058] In the embodiment of the present application, the security protection of the application log file is as follows:

[0059] Restrict the file types of the files under this type of file directory;

[0060] Restrict non-files of this type and prohibit the creation of non-files of this type;

[0061] Implement the minimum privilege control for the file permissions of this type of file under reasonable circumstances.

[0062] In the embodiment of the present application, the security protection of the application temporary file is as follows:

[0063] Restrict illegal file types under this directory;

[0064] Implement the minimum privilege control for the file permissions of this type of file under reasonable circumstances and prohibit the execution permission.

[0065] Step S013, establish a correspondence between the selected security protection policy and the file to be protected to complete the configuration of the security protection policy for the file directory.

[0066] Step S02, start scanning the relevant files according to the security protection policy;

[0067] Step S03, display the security protection result of the file.

[0068] Configuring the corresponding security protection policy for the file includes,

[0069] As Figure 2 shown, after step S01, it includes,

[0070] Step S04: Determine whether the security protection policy corresponding to the file to be pre-protected selected from multiple security protection policy lists is correct according to the pre-set mapping relationship table between files and security protection policies.

[0071] Step S05: If it is correct, establish a corresponding relationship between the selected security protection policy and the file to be pre-protected to complete the security protection policy configuration of the file.

[0072] Step S06: If it is incorrect, issue an error prompt.

[0073] Step S07: If there are security vulnerabilities in the file, issue an alarm prompt.

[0074] In a second aspect, an embodiment of the present application further provides a file monitoring and protection device. The device is installed with an application for a security protection system. The device includes:

[0075] A configuration module 21, configured to configure a corresponding security protection policy for a file in the security protection system;

[0076] A scanning module 22, configured to start scanning relevant files according to the security protection policy;

[0077] A display module 23, configured to display the security protection result of the file.

[0078] The device further includes a selection module 24, configured to select a file to be pre-protected and also configured to select a security protection policy corresponding to the file to be pre-protected from multiple security protection policy lists;

[0079] The configuration module 21 is specifically configured to establish a corresponding relationship between the selected security protection policy and the file to be pre-protected to complete the security protection policy configuration of the file directory.

[0080] The device further includes an acquisition module 25, configured to acquire the type of the file. The file types include application files, application cache files, application log files, and application temporary files;

[0081] The selection module 24 is further configured to select a security protection policy corresponding to the file to be pre-protected from multiple security protection policy lists according to the file type.

[0082] The device further includes a judgment module 26, configured to determine whether the security protection policy corresponding to the file to be pre-protected selected from multiple security protection policy lists is correct according to the pre-set mapping relationship table between files and security protection policies;

[0083] The configuration module 21 is further configured to, if it is correct, establish a corresponding relationship between the selected security protection policy and the file to be pre-protected to complete the security protection policy configuration of the file, and if it is incorrect, issue an error prompt.

[0084] It should be noted that the method for executing the file monitoring and protection device provided in the embodiments of the present application is the same as the above, and will not be elaborated here.

[0085] In a third aspect, the embodiments of the present application further provide a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the method for file monitoring and protection described in any one of the above.

[0086] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for monitoring and protecting files, characterized in that, The method is applied to a security protection system, and the method includes: Configuring corresponding security protection policies for files in the security protection system; Starting to scan relevant files according to the security protection policies; Displaying the security protection results of the files; Configuring the corresponding security protection policies for the files includes: Selecting the files to be protected; Selecting the security protection policy corresponding to the files to be protected from multiple security protection policy lists; Establishing a corresponding relationship between the selected security protection policy and the files to be protected to complete the configuration of the security protection policy for the file directory; After configuring the corresponding security protection policies for the files, it includes: Judging whether the security protection policy selected from multiple security protection policy lists and corresponding to the files to be protected is correct according to the pre-set mapping relationship table of files and security protection policies; If it is correct, establishing a corresponding relationship between the selected security protection policy and the files to be protected to complete the configuration of the security protection policy for the files; If it is wrong, an error prompt is issued.

2. The method for monitoring and protecting files according to claim 1, wherein Selecting the security protection policy corresponding to the files to be protected from multiple security protection policy lists includes: Obtaining the type of the file, and the file types include application files, application cache files, application log files, and application temporary files; Selecting the security protection policy corresponding to the files to be protected from multiple security protection policy lists according to the file type.

3. The method for monitoring and protecting files according to claim 1, wherein The security protection policy lists arrange the security protection policies in order of priority according to the file type.

4. The method for monitoring and protecting files according to claim 1, wherein, It also includes that if there are security vulnerabilities in the files, an alarm prompt is issued.

5. A file monitoring and protection device, characterized in that The device is installed with a security protection system, and the device includes: A configuration module for configuring corresponding security protection policies for files in the security protection system; A scanning module for starting to scan relevant files according to the security protection policies; A display module for displaying the security protection results of the files; The device also includes a selection module for selecting the files to be protected and for selecting the security protection policy corresponding to the files to be protected from multiple security protection policy lists; The configuration module is specifically used for establishing a corresponding relationship between the selected security protection policy and the files to be protected to complete the configuration of the security protection policy for the file directory; The device also includes a judgment module for judging whether the security protection policy selected from multiple security protection policy lists and corresponding to the files to be protected is correct according to the pre-set mapping relationship table of files and security protection policies; The configuration module is also used for, if it is correct, establishing a corresponding relationship between the selected security protection policy and the files to be protected to complete the configuration of the security protection policy for the files, and if it is wrong, issuing an error prompt.

6. The file monitoring and protection device according to claim 5, characterized in that, The device also includes an acquisition module for acquiring the type of the file, and the file types include application files, application cache files, application log files, and application temporary files; The selection module is also used for selecting the security protection policy corresponding to the files to be protected from multiple security protection policy lists according to the file type.

Citation Information

Patent Citations

  • File security protection method and device

    CN110807205A