Vulnerability processing method, device and storage medium based on cloud service
By issuing vulnerability detection instructions and repair patches on the cloud server, and using heartbeat data to transmit configuration information and detection results, the problem of client security in cloud computing scenarios is solved, and vulnerability detection and repair without local security software is achieved, and security and flexibility are improved.
Patent Information
- Application Number
- CN202210736840.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-27
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-06-27
AI Technical Summary
In cloud computing scenarios, a single, universal vulnerability security service cannot meet the growing computing scale, and the security of the client is difficult to guarantee because the existing technology mainly relies on locally installed security software for vulnerability scanning.
The vulnerability handling method based on cloud services is adopted, and vulnerability detection instructions and repair patches are issued by the cloud server, and configuration information and detection results are transmitted by heartbeat data to realize vulnerability detection and repair of the client.
Vulnerability detection and repair can be carried out without installing security software on the client, which improves the security and flexibility of the client and adapts to the growth of computing scale in the cloud computing environment.
Smart Images

Figure CN115146278B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of security technology, and in particular to a vulnerability processing method based on cloud services, an electronic device and a storage medium. Background Art
[0002] A vulnerability is a defect in the specific implementation of hardware, software, protocol, or system security policy, which allows attackers to access or damage the system without authorization.
[0003] At present, the conventional vulnerability detection method is generally to install security software locally and scan for vulnerabilities through security software. However, with the development of cloud computing technology, a single, general vulnerability security service cannot meet the growing computing scale in the cloud computing era. In cloud computing scenarios, cloud servers can connect to multiple clients, each of which can correspond to different configurations. Therefore, by installing security software locally to perform vulnerability scanning, the security of the client is difficult to guarantee. Summary of the invention
[0004] The present invention provides a cloud service-based vulnerability processing method to protect the security of a client.
[0005] Correspondingly, the embodiment of the present application also provides an electronic device and a storage medium to ensure the implementation and application of the above system.
[0006] In order to solve the above problems, the embodiment of the present application discloses a vulnerability processing method based on cloud services, which is applied to the cloud service end. The method includes:
[0007] When the client satisfies the vulnerability detection condition, a vulnerability detection instruction is issued, wherein the vulnerability detection instruction is determined according to the configuration information of the client, and the configuration information is sent through heartbeat data;
[0008] Receive a vulnerability detection result through heartbeat data, where the vulnerability detection result is generated by executing the vulnerability detection on the client according to the vulnerability detection instruction;
[0009] Obtaining at least one vulnerability repair patch according to the vulnerability detection result;
[0010] The at least one vulnerability repair patch is issued to perform vulnerability repair on the client based on the vulnerability repair patch.
[0011] Optionally, also include:
[0012] Use heartbeat data to detect whether the client meets the vulnerability detection conditions.
[0013] Optionally, detecting whether the client satisfies the vulnerability detection condition through heartbeat data includes:
[0014] Determine whether the client is online based on the time information corresponding to the heartbeat data;
[0015] If the client is online, check whether the client supports vulnerability scanning;
[0016] If the client supports vulnerability scanning, determining that the client meets the vulnerability detection condition;
[0017] If the client is offline or does not support vulnerability scanning, it is determined that the client does not meet the vulnerability detection condition.
[0018] Optionally, when the client satisfies the vulnerability detection condition, issuing a vulnerability detection instruction includes:
[0019] When the client meets the vulnerability detection conditions, the configuration information is obtained through the heartbeat data;
[0020] Acquire client information from the configuration information, and determine vulnerability detection instructions based on the client information;
[0021] The vulnerability detection instruction is issued.
[0022] Optionally, obtaining at least one vulnerability repair patch according to the vulnerability detection result includes:
[0023] Obtain at least one vulnerability information from the vulnerability detection result;
[0024] At least one vulnerability repair patch is obtained according to the at least one vulnerability information.
[0025] Optionally, also include:
[0026] Determine risk level information corresponding to the vulnerability information;
[0027] Analyzing the association information between the vulnerability information and the client;
[0028] Generate repair suggestion information according to the risk level and related information, and feed back the repair suggestion information.
[0029] Optionally, the issuing of the vulnerability detection instruction includes:
[0030] The vulnerability detection instruction is transmitted through a dedicated message channel.
[0031] Optionally, the issuing of the at least one vulnerability repair patch includes:
[0032] The at least one vulnerability repair patch is transmitted through a dedicated message channel.
[0033] The embodiment of the present application also discloses a vulnerability processing method based on cloud services, which is applied to a client, and the method includes:
[0034] Upload heartbeat data, wherein the heartbeat data includes configuration information;
[0035] receiving a vulnerability detection instruction, wherein the vulnerability detection instruction is determined by the cloud service end according to the configuration information;
[0036] Execute missed detection processing according to the vulnerability detection instruction to obtain a vulnerability detection result;
[0037] Adding the vulnerability detection result to the heartbeat data, and sending the heartbeat data;
[0038] receiving at least one vulnerability repair patch, where the vulnerability repair patch is determined by the cloud service end according to the vulnerability detection result;
[0039] A vulnerability repair process is performed according to the vulnerability repair patch to determine the vulnerability repair result.
[0040] Optionally, sending the vulnerability repair result includes:
[0041] The vulnerability repair result is sent through a dedicated message channel.
[0042] Optionally, also include:
[0043] Receive repair suggestion information;
[0044] Based on the repair suggestion information, a repair suggestion for the vulnerability to be repaired is displayed, wherein the repair suggestion is determined based on the risk level and related information of the vulnerability to be repaired;
[0045] In response to the triggering of the repair suggestion, the vulnerability to be repaired is determined and fed back to the cloud service end.
[0046] The embodiment of the present application also discloses a cloud service-based vulnerability processing device, which is applied to a cloud service end, and the device includes:
[0047] A detection and determination module, used to issue a vulnerability detection instruction when the client meets the vulnerability detection conditions, wherein the vulnerability detection instruction is determined based on the configuration information of the client, and the configuration information is sent through heartbeat data;
[0048] A detection result receiving module, used to receive a vulnerability detection result through heartbeat data, wherein the vulnerability detection result is generated by executing the vulnerability detection on the client according to the vulnerability detection instruction;
[0049] The repair determination module is used to obtain at least one vulnerability repair patch according to the vulnerability detection result; and issue the at least one vulnerability repair patch to perform vulnerability repair on the client based on the vulnerability repair patch.
[0050] The embodiment of the present application also discloses a cloud service-based vulnerability processing device, which is applied to a client, and the device includes:
[0051] A heartbeat upload module, used to upload heartbeat data, the heartbeat data including configuration information; and to add vulnerability detection results to the heartbeat data, and send the heartbeat data;
[0052] A script transmission module, configured to receive a vulnerability detection instruction, wherein the vulnerability detection instruction is determined by the cloud service end according to the configuration information; and receive at least one vulnerability repair patch, wherein the vulnerability repair patch is determined by the cloud service end according to the vulnerability detection result;
[0053] A vulnerability detection module is used to perform missed detection processing according to the vulnerability detection instruction to obtain a vulnerability detection result;
[0054] The vulnerability repair module is used to perform vulnerability repair processing according to the vulnerability repair patch and determine the vulnerability repair result.
[0055] An embodiment of the present application further discloses an electronic device, including: a processor; and a memory, on which executable code is stored. When the executable code is executed by the processor, the method described in the embodiment of the present application is executed.
[0056] The embodiments of the present application also disclose one or more machine-readable media on which executable codes are stored. When the executable codes are executed by a processor, the method described in the embodiments of the present application is executed.
[0057] Compared with the prior art, the embodiments of the present application have the following advantages:
[0058] In an embodiment of the present application, when the client satisfies the vulnerability detection conditions, the cloud service end issues a vulnerability detection instruction, and the vulnerability detection instruction is determined based on the configuration information of the client, and the configuration information is sent through the heartbeat data, so that appropriate vulnerability detection instructions can be issued based on the client, and there is no need to install security software on the client. Vulnerability detection can be performed on the client through the vulnerability detection instruction to obtain vulnerability detection results, and at least one vulnerability repair patch can be obtained based on the vulnerability detection results. The at least one vulnerability repair patch is issued, and the vulnerability feedback repair patch can be repaired and the repair result is received, thereby improving the security of the client. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] Figure 1 This is an interactive diagram of a vulnerability handling method based on cloud services in an embodiment of the present application;
[0060] Figure 2 It is a schematic diagram of the architecture of a cloud computing system according to an embodiment of the present application;
[0061] Figure 3 This is a flow chart of steps on the cloud service side in an embodiment of a vulnerability handling method based on cloud services of the present application;
[0062] Figure 4 This is a flowchart of the steps of the client in an embodiment of a vulnerability handling method based on cloud services of the present application;
[0063] Figure 5 It is a schematic diagram of the structure of an exemplary device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0064] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, the present application is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.
[0065] The embodiments of the present application can be applied to cloud computing scenarios, and various cloud services are provided based on cloud computing, including vulnerability detection and repair services. The cloud computing system includes: a cloud server and a client, and the client can be located at the terminal device. The cloud server performs the control and issuance of vulnerability-related tasks to realize vulnerability detection, repair and other functions, and the client is responsible for performing specific vulnerability scanning and vulnerability repair operations. The embodiments of the present application adopt an architecture that emphasizes the server and lightly relies on the client, which provides greater flexibility for vulnerability detection and repair. The decision control is placed on the server, and the instructions after the decision is completed are issued to the client to realize vulnerability detection and repair, and complete the collaborative work of the server and the client.
[0066] Reference Figure 1 , showing a schematic diagram of an example of vulnerability detection based on cloud services in an embodiment of the present application.
[0067] Step 102: The client uploads heartbeat data, which includes configuration information.
[0068] In an embodiment of the present application, there may be a periodic heartbeat signal between the cloud service end and the client, and the heartbeat signal can transmit heartbeat data. The heartbeat signal is used to inform the cloud service end about the survival and configuration of the client, so the heartbeat data includes configuration information. That is, on the one hand, the heartbeat signal can be used to inform the cloud service end that the client is alive and online, and on the other hand, the configuration data can be used to inform the cloud service end about the configuration of the client, so as to perform subsequent vulnerability detection and repair. Therefore, the heartbeat data can be understood as data used to inform the client of survival and configuration. In some other embodiments, the heartbeat data can also transmit other information related to vulnerability processing, such as vulnerability detection results, so the heartbeat data can also be understood as heartbeat data used for vulnerability processing.
[0069] The configuration information is information about the client's configuration, and also includes configurations related to vulnerability scanning and repair. In some examples, the configuration information includes data such as the client identifier, client version, and vulnerability configuration information, where the vulnerability configuration information may include whether the client supports vulnerability scanning, such as whether the client supports script running. Heartbeat data is sent regularly, such as 1, 2, 5 minutes, etc., and is set according to specific needs. Therefore, the cloud server can not only determine the survival status of the client, but also obtain the client's configuration information.
[0070] The client sends heartbeat data to the cloud server through a heartbeat signal, and the cloud server records the heartbeat data and uses it when needed. In an embodiment of the present application, vulnerability detection for the client can be executed periodically or when a trigger is received. For the scheme of periodic execution, a timing period can be set in advance on the cloud server, so that vulnerability detection and repair are started when the timing period is reached. Among them, the server provides an API of the console, and the console can be understood as a user-controlled operating console. The operating console can provide interactive pages in the client through browsers, applications, etc., and users interact with the cloud server through the interactive pages and APIs of the console. Users can set the cycle of missed detection in the interactive page, or trigger the execution of vulnerability detection through controls, etc. For example, a vulnerability detection control is provided in the page of the browser, and triggering the vulnerability detection control can send a vulnerability detection request to the cloud server, thereby starting vulnerability detection on the cloud server.
[0071] The cloud service end can receive the vulnerability detection request of the client, and can also automatically trigger the vulnerability detection when the vulnerability detection cycle of the client is reached. Then, based on the heartbeat data of the client, it is detected whether the client meets the vulnerability detection condition. In the embodiment of the present application, the vulnerability detection condition is the condition for executing the vulnerability detection, such as a vulnerability detection condition that the client supports vulnerability detection, such as a vulnerability detection condition that the client allows the running of the vulnerability detection plug-in, etc. Therefore, the vulnerability configuration information can be obtained from the heartbeat data to determine whether the client supports vulnerability scanning, whether the client supports vulnerability detection conditions such as scripts, and whether the client is online. If the client is online and can support vulnerability scanning, it is considered that the client meets the vulnerability detection condition. In one example, the detection of whether the client meets the vulnerability detection condition through the heartbeat data includes: judging whether the client is online through the time information corresponding to the heartbeat data; if the client is online, detecting whether the client supports vulnerability scanning; if the client supports vulnerability scanning, determining that the client meets the vulnerability detection condition; if the client is offline or does not support vulnerability scanning, determining that the client does not meet the vulnerability detection condition.
[0072] Step 104: When the client satisfies the vulnerability detection conditions, the cloud server issues a vulnerability detection instruction.
[0073] When the client meets the vulnerability detection conditions, the cloud server can determine the vulnerability detection instruction based on the client's configuration information, and then send the vulnerability detection instruction to the corresponding client. The vulnerability detection instruction can carry vulnerability detection scripts, vulnerability feature information, vulnerability detection plug-ins, etc., so that vulnerability detection can be performed on the client based on the vulnerability detection instruction.
[0074] In the embodiments of the present application, vulnerability detection instructions and vulnerability repair patches can be configured based on vulnerability features and actual scenarios. The actual scenarios can be based on the version of the client, the device where the client is located, etc. In other examples, the cloud server can also provide an API for the vulnerability operation console, which is provided to the operation user, and interacts with the cloud server through the page to provide the configuration required for operation. Combining vulnerability features and scenario configuration scripts can better adapt to various clients and provide richer functional configurations.
[0075] In an optional embodiment of the present application, when the client satisfies the vulnerability detection condition, issuing the vulnerability detection instruction includes: when the client satisfies the vulnerability detection condition, obtaining configuration information through heartbeat data; determining the vulnerability detection instruction based on the configuration information; issuing the vulnerability detection instruction. When the client satisfies the vulnerability detection condition, the configuration information can be obtained from the heartbeat data of the client, and the configuration information may include configuration information such as the client identifier, the client version, and the vulnerability configuration information, and then the vulnerability detection instruction can be determined based on the configuration information, and the vulnerability detection instruction can be sent to the client.
[0076] In the embodiment of the present application, a dedicated message channel can be established between the client and the cloud server to transmit vulnerability detection instructions and vulnerability repair patches to improve data security. The script's dedicated message channel increases the success rate of script instruction issuance and ensures smooth execution of tasks.
[0077] Step 106: The client performs missed detection processing according to the vulnerability detection instruction to obtain a vulnerability detection result.
[0078] After receiving the vulnerability detection instruction, the client can execute the vulnerability detection instruction and perform vulnerability detection processing in the client. Among them, the vulnerability detection instruction may include parameters such as vulnerability detection rules and vulnerability characteristics. These parameters can be carried in the form of vulnerability detection plug-ins or vulnerability detection scripts, so that the client can scan and detect whether there are vulnerabilities and generate corresponding vulnerability detection results. For example, the client runs a vulnerability detection plug-in or vulnerability detection script based on the vulnerability detection instruction. The plug-in or script can scan the client and match the scan data and vulnerability characteristics according to the vulnerability detection rules to implement vulnerability detection processing. Among them, if a vulnerability is detected, the vulnerability information such as vulnerability identification and characteristics can be recorded in the vulnerability detection result.
[0079] Step 108: The client adds the vulnerability detection result to the heartbeat data and sends the heartbeat data.
[0080] The client adds the vulnerability detection results to the heartbeat data, such as the identification of the detected vulnerability, and then can send the heartbeat data to the cloud client.
[0081] Step 110: The cloud server obtains at least one vulnerability repair patch based on the vulnerability detection result.
[0082] After receiving the heartbeat data, the cloud service end can obtain the vulnerability detection result from the heartbeat data, and then determine at least one vulnerability repair patch based on the vulnerability detection result. In the embodiment of the present application, the vulnerability repair patch is a program package for repairing a vulnerability, and the vulnerability corresponds to the vulnerability repair patch. Therefore, the vulnerability repair patch can be determined based on the vulnerability detected on the client, and a vulnerability repair patch is determined for each detected vulnerability. The vulnerability repair patch can include various forms such as vulnerability repair code, vulnerability repair script, and vulnerability repair plug-in.
[0083] In an optional embodiment, obtaining at least one vulnerability repair patch based on the vulnerability detection result includes: obtaining at least one vulnerability information from the vulnerability detection result; obtaining at least one vulnerability repair patch based on the at least one vulnerability information. One or more vulnerability information may be detected in the vulnerability detection, so the vulnerability result may carry at least one vulnerability information, and for each vulnerability information, a corresponding vulnerability repair patch can be obtained so as to repair each vulnerability separately. In the embodiment of the present application, the vulnerability repair patch is also related to the configuration of the client, such as the client version, so the corresponding vulnerability repair patch can be determined based on the vulnerability information, the client version, etc.
[0084] Step 112: The cloud server sends the at least one vulnerability repair patch.
[0085] After determining at least one vulnerability repair patch, the cloud service end may send the at least one vulnerability repair patch, and the vulnerability repair patch may be sent through a dedicated channel.
[0086] Step 114: the client performs vulnerability repair processing according to the vulnerability repair patch and determines a vulnerability repair result.
[0087] After receiving at least one vulnerability repair patch, the client can use the vulnerability repair patch to perform vulnerability repair processing and obtain a corresponding vulnerability repair result. For example, the client can start a vulnerability repair process, run the vulnerability repair patch through the vulnerability repair process, perform vulnerability repair processing, perform vulnerability repair on the client, and determine the vulnerability repair result.
[0088] After determining the vulnerability repair result, the client can send the vulnerability repair result to the cloud server, wherein the vulnerability repair result can be sent through a dedicated message channel. The cloud server receives the repair result and records the vulnerability repair result.
[0089] In summary, when the client meets the vulnerability detection conditions, the cloud server issues a vulnerability detection instruction, which is determined based on the client's configuration information. The configuration information is sent through heartbeat data, so that appropriate vulnerability detection instructions can be issued based on the client, and vulnerability detection can be performed without installing security software on the client. The vulnerability detection result is then received through the heartbeat data. The vulnerability detection result is generated by executing vulnerability detection on the client based on the detection instruction, and at least one vulnerability repair patch is obtained based on the vulnerability detection result. The at least one vulnerability repair patch is issued, and the vulnerability feedback repair patch can be repaired, which can improve the security of the client.
[0090] Based on the above embodiments, the present application also provides a vulnerability detection and repair method based on a cloud computing system, the system comprising: a cloud service end and a client end, such as Figure 2 shown.
[0091] The cloud service end includes: user console API, operation console API, vulnerability library, scanning task unit, client management unit, script management unit and vulnerability processing unit. Plug-ins and processes can be run in the client, and vulnerability detection instructions can be executed through plug-ins, and vulnerability repair patches can be run through them.
[0092] Among them, the user console API is used to provide an interactive interface for users (or first users) who use cloud services, supports the creation of vulnerability scanning scheduled tasks based on user requests, so that the cloud server can automatically trigger the vulnerability task when the timing period is reached, supports the creation of vulnerability scanning tasks on the cloud server based on user trigger requests, and supports the determination of vulnerabilities that need to be repaired based on user trigger requests, so as to determine the vulnerability repair patch through the cloud server to perform vulnerability repair, that is, to implement functions that can be triggered by users on the server, and the specific implementation of the function is handled by the cloud server.
[0093] The operation console API is used to provide an interactive interface for operation users (or second users). The script is configured by the operation according to specific scenarios to implement refined vulnerability handling solutions.
[0094] The vulnerability database stores information such as the characteristics of various vulnerabilities, and can also store information such as the configuration and rules for fixing vulnerabilities. The server maintains the vulnerability database and matching rules.
[0095] The scanning task unit is used to determine the vulnerability scanning task, which can be a vulnerability scanning scheduled task, a trigger-based vulnerability scanning task, etc. When the task is triggered by the user or by the scheduled trigger, first check whether the current state of the client meets the vulnerability detection conditions.
[0096] The client management unit is used to manage the client, including heartbeat management, plug-in management, etc. Among them, the server and the client maintain a heartbeat channel, the client regularly reports the keep-alive heartbeat data, receives the client heartbeat and confirms that the client is online, and returns a confirmation message after the heartbeat processing is completed. The heartbeat carries the client configuration and vulnerability detection results. The server checks whether the client configuration meets the vulnerability scanning conditions, marks the client status, and parses the vulnerability detection results. The server is also responsible for controlling other client management, such as installing and uninstalling plug-ins on the client, confirming the plug-in status, etc.
[0097] The script management unit is used to manage vulnerability repair patches and vulnerability detection instructions, as well as manage dedicated message channels. The server and the client maintain a dedicated message channel for vulnerability detection, and transmit vulnerability detection instructions, vulnerability repairs, etc. through the dedicated message channel to ensure that the client receives vulnerability detection instructions and vulnerability repairs.
[0098] The vulnerability processing unit is used to perform vulnerability-related processing, such as vulnerability correlation matching, vulnerability location, etc. The cloud server performs matching operations when extracting vulnerability detection results, and sorts them by score according to the impact of the vulnerability and the closeness of the vulnerability correlation.
[0099] The following processing can be performed on the cloud server, such as Figure 3 As shown:
[0100] Step 302: When the client satisfies the vulnerability detection condition, a vulnerability detection instruction is issued, wherein the vulnerability detection instruction is determined based on the configuration information of the client, and the configuration information is sent via heartbeat data.
[0101] Upon receiving triggers related to vulnerability detection, such as client requests, reaching the vulnerability detection cycle, etc., the heartbeat data is used to detect whether the client meets the vulnerability detection conditions. Users can trigger vulnerability detection on the client, generate a vulnerability detection request, and send it to the cloud server. Vulnerability detection can also be a timed trigger task, which can trigger vulnerability detection when the timer is reached. The vulnerability detection cycle can be set by the user or by default. Among them, detecting whether the client meets the vulnerability detection conditions through heartbeat data includes: judging whether the client is online through the time information corresponding to the heartbeat data; if the client is online, detecting whether the client supports vulnerability scanning; if the client supports vulnerability scanning, determining that the client meets the vulnerability detection conditions; if the client is offline or does not support vulnerability scanning, determining that the client does not meet the vulnerability detection conditions.
[0102] The server and the client maintain a dedicated message channel and issue vulnerability detection instructions through the dedicated message channel.
[0103] Step 304: receiving vulnerability detection results through heartbeat data, wherein the vulnerability detection results are generated by executing vulnerability detection on the client according to the detection instruction.
[0104] Step 306: Obtain at least one vulnerability repair patch according to the vulnerability detection result.
[0105] Obtain at least one vulnerability information from the vulnerability detection result; and obtain at least one vulnerability repair patch based on the at least one vulnerability information.
[0106] It is also possible to determine the risk level information corresponding to the vulnerability information; analyze the association information between the vulnerability information and the client; generate repair suggestion information based on the risk level and the association information, and feed back the repair suggestion information. The risk level information corresponding to the vulnerability information can be determined, such as high risk, medium risk, low risk, or other level classification methods, and the risk level information is used to indicate the risk information of the vulnerability. By analyzing the association information between the vulnerability information and the client, the processes, applications, etc. running in the client can be determined, and the processes, applications, etc. affected by the vulnerability can be analyzed based on the vulnerability information, so as to determine the association information based on the analysis results, and the association information indicates the extent to which the vulnerability affects the client, and then the vulnerability information can be sorted according to the risk level and / or the association information, and the repair suggestion information can be generated using the risk level and the association information, such as sorting according to the risk level first, and sorting according to the association information for the same risk level, and weighted calculation of the risk level and the association information, and sorting the weighted results, etc. The repair suggestion information may also include vulnerability description information, so that the client can choose whether to repair the vulnerability, which vulnerabilities to repair, and send a corresponding request to the cloud server. The cloud server can determine the vulnerability that needs to be repaired based on the client's request and obtain the corresponding vulnerability repair patch for the vulnerability that needs to be repaired.
[0107] Step 308: issue the at least one vulnerability repair patch, so as to perform vulnerability repair on the client according to the vulnerability repair patch.
[0108] At least one vulnerability repair patch is sent through a dedicated message channel. After the client performs vulnerability repair based on the vulnerability repair patch and obtains the vulnerability repair result, the cloud server can receive and record the repair result.
[0109] The following processing can be performed on the client side, such as Figure 4 As shown:
[0110] Step 402: Upload heartbeat data, where the heartbeat data includes configuration information.
[0111] Step 404: receiving a vulnerability detection instruction, wherein the vulnerability detection instruction is determined by the cloud service end according to the configuration information.
[0112] Receive vulnerability detection instructions through a dedicated message channel.
[0113] Step 406, performing missed detection processing according to the vulnerability detection instruction to obtain a vulnerability detection result.
[0114] The vulnerability detection rules, vulnerability features and other parameters in the vulnerability detection instructions can be carried in the form of vulnerability detection plug-ins or vulnerability detection scripts. Scan and detect whether there are vulnerabilities in the client, and generate corresponding vulnerability detection results. For example, the client runs a vulnerability detection plug-in or vulnerability detection script based on the vulnerability detection instruction. The plug-in or script can scan the client, and match the scan data and vulnerability features according to the vulnerability detection rules to implement vulnerability detection processing. If a vulnerability is detected, the vulnerability information such as vulnerability identification and features can be recorded in the vulnerability detection result.
[0115] Step 408: Add the vulnerability detection result to the heartbeat data, and send the heartbeat data.
[0116] Step 410: Receive at least one vulnerability repair patch, where the vulnerability repair patch is determined by the cloud service end according to the vulnerability detection result.
[0117] In an optional embodiment, the client can select the vulnerability to be repaired. The client receives the repair suggestion information, and based on the repair suggestion information, displays the repair suggestion of the vulnerability to be repaired, and the repair suggestion is determined based on the risk level and associated information of the vulnerability to be repaired, such as displaying the sorting results of each vulnerability according to the risk level in the client, displaying the associated information that characterizes the close association between the vulnerability and the client, the description information of the vulnerability, etc., so that the user can know the situation of each vulnerability, the degree of impact on the client, etc., and can select the vulnerability to be repaired accordingly, and in response to the triggering of the repair suggestion, determine the vulnerability to be repaired, and then feedback to the cloud server. In some other examples, it can also be preset or set by default that all vulnerabilities are repaired, or vulnerabilities that meet certain conditions need to be repaired, such as being ranked in the top N, and the risk level is a specified level such as high security risk. After the cloud server determines at least one vulnerability repair patch based on the client's selection, the at least one vulnerability repair patch can be transmitted through a dedicated message channel.
[0118] Step 412, performing vulnerability repair processing according to the vulnerability repair patch to determine the vulnerability repair result.
[0119] After receiving at least one vulnerability repair patch, the client can create and start a vulnerability repair process, execute at least one vulnerability repair patch, repair the vulnerability based on instructions and parameters, and obtain a vulnerability repair result.
[0120] The embodiment of the present application adopts an architecture that is heavy on the server and light on the client, which provides greater flexibility for vulnerability detection and repair. Decision control is placed on the server, and the vulnerability detection instructions and vulnerability repair patches after the decision is completed are sent to the client to perform vulnerability detection and repair, completing the collaborative work of the server and the client to realize the detection and repair process.
[0121] Combined with the client heartbeat keep-alive mechanism to transmit configuration information, the configuration related to vulnerability handling can be transmitted while ensuring the client is online, and a heartbeat message channel and a dedicated message channel are opened separately to realize the classified processing of different messages. The heartbeat message channel and the dedicated message channel improve the success rate of vulnerability detection and repair, making the vulnerability handling task smoothly executed.
[0122] Vulnerability detection scripts and vulnerability repair scripts can be used to perform vulnerability detection and repair processing. Scripts can be introduced to achieve collaborative work between the server and the client. The scripts can be configured based on the client, and the scripts can control the start and end of vulnerability detection and repair tasks. The server can control the detection or repair tasks through the scripts, configure appropriate tasks for specific scenarios, and avoid the greater impact of uncertain client defects.
[0123] In each embodiment of the present application, user information is collected, used and stored only after obtaining the user's authorization, and various operations based on user information are also performed only after obtaining the user's authorization.
[0124] It should be noted that, for the method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the embodiments of the present application are not limited by the described order of actions, because according to the embodiments of the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by the embodiments of the present application.
[0125] On the basis of the above-mentioned embodiment, this embodiment further provides a vulnerability processing device based on cloud service, which is applied to an electronic device on the server side.
[0126] A detection and determination module, used to issue a vulnerability detection instruction when the client meets the vulnerability detection conditions, wherein the vulnerability detection instruction is determined based on the configuration information of the client, and the configuration information is sent through heartbeat data;
[0127] A detection result receiving module, used to receive a vulnerability detection result through heartbeat data, wherein the vulnerability detection result is generated by executing the vulnerability detection on the client according to the vulnerability detection instruction;
[0128] The repair determination module is used to obtain at least one vulnerability repair patch according to the vulnerability detection result; and issue the at least one vulnerability repair patch to perform vulnerability repair on the client based on the vulnerability repair patch.
[0129] The repair result receiving module is used to receive the repair result, and the repair result is generated by executing the vulnerability repair on the client according to the repair patch.
[0130] In summary, when the client meets the vulnerability detection conditions, the cloud server issues a vulnerability detection instruction, which is determined based on the client's configuration information. The configuration information is sent through heartbeat data, so that appropriate vulnerability detection instructions can be issued based on the client, without the need to install security software on the client. The vulnerability detection result is then received through the heartbeat data, and the vulnerability detection result is generated by executing vulnerability detection on the client based on the detection instruction. At least one vulnerability repair patch is obtained based on the vulnerability detection result, and the at least one vulnerability repair patch is issued, so that the vulnerability feedback repair patch can be repaired to improve the security of the client.
[0131] The detection and determination module is also used to detect whether the client meets the vulnerability detection conditions through heartbeat data.
[0132] The detection and determination module is used to determine whether the client is online through the time information corresponding to the heartbeat data; if the client is online, detect whether the client supports vulnerability scanning; if the client supports vulnerability scanning, determine that the client meets the vulnerability detection conditions; if the client is offline or does not support vulnerability scanning, determine that the client does not meet the vulnerability detection conditions.
[0133] The detection and determination module is used to obtain configuration information through heartbeat data when the client meets the vulnerability detection conditions; obtain client information from the configuration information, determine the vulnerability detection instruction according to the client information; and issue the vulnerability detection instruction.
[0134] The repair determination module is used to obtain at least one vulnerability information from the vulnerability detection result; and obtain at least one vulnerability repair patch according to the at least one vulnerability information.
[0135] The repair determination module is also used to determine the risk level information corresponding to the vulnerability information; analyze the association information between the vulnerability information and the client; generate repair suggestion information based on the risk level and the association information, and feed back the repair suggestion information.
[0136] The detection and determination module is used to transmit the vulnerability detection instruction through a dedicated message channel.
[0137] The repair determination module is used to transmit the at least one vulnerability repair patch through a dedicated message channel.
[0138] On the basis of the above embodiments, this embodiment further provides a cloud service-based vulnerability processing device, which is applied to an electronic device of a client.
[0139] A heartbeat upload module, used to upload heartbeat data, the heartbeat data including configuration information; and to add vulnerability detection results to the heartbeat data, and send the heartbeat data;
[0140] A script transmission module, configured to receive a vulnerability detection instruction, the vulnerability detection instruction being determined by the cloud server according to the configuration information; receive at least one vulnerability repair patch, the vulnerability repair patch being determined by the cloud server according to the vulnerability detection result; and send the vulnerability repair result;
[0141] A vulnerability detection module is used to perform missed detection processing according to the vulnerability detection instruction to obtain a vulnerability detection result;
[0142] The vulnerability repair module is used to perform vulnerability repair processing according to the vulnerability repair patch and determine the vulnerability repair result.
[0143] The script transmission module is used to send the vulnerability repair result through a dedicated message channel.
[0144] The vulnerability repair module is also used to receive repair suggestion information; based on the repair suggestion information, display repair suggestions for the vulnerabilities to be repaired, and the repair suggestions are determined based on the risk level and related information of the vulnerabilities to be repaired; in response to the triggering of the repair suggestions, determine the vulnerabilities to be repaired and feed back to the cloud service end.
[0145] The embodiment of the present application adopts an architecture that is heavy on the server and light on the client, which provides greater flexibility for vulnerability detection and repair. Decision control is placed on the server, and the vulnerability detection instructions and vulnerability repair patches after the decision is completed are sent to the client to perform vulnerability detection and repair, completing the collaborative work of the server and the client to realize the detection and repair process.
[0146] Combined with the client heartbeat keep-alive mechanism to transmit configuration information, the configuration related to vulnerability handling can be transmitted while ensuring the client is online, and a heartbeat message channel and a dedicated message channel are opened separately to realize the classified processing of different messages. The heartbeat message channel and the dedicated message channel improve the success rate of vulnerability detection and repair, making the vulnerability handling task smoothly executed.
[0147] Vulnerability detection scripts and vulnerability repair scripts can be used to perform vulnerability detection and repair processing. Scripts can be introduced to achieve collaborative work between the server and the client. The scripts can be configured based on the client, and the scripts can control the start and end of vulnerability detection and repair tasks. The server can control the detection or repair tasks through the scripts, configure appropriate tasks for specific scenarios, and avoid the greater impact of uncertain client defects.
[0148] In each embodiment of the present application, user information is collected, used and stored only after obtaining the user's authorization, and various operations based on user information are also performed only after obtaining the user's authorization.
[0149] The embodiment of the present application also provides a non-volatile readable storage medium, which stores one or more modules (programs). When the one or more modules are applied to a device, the device can execute instructions (instructions) of each method step in the embodiment of the present application.
[0150] The present application embodiment provides one or more machine-readable media, on which instructions are stored, and when executed by one or more processors, an electronic device executes one or more methods as described in the above embodiments. In the present application embodiment, the electronic device includes a server, a terminal device, and the like.
[0151] The embodiments of the present disclosure may be implemented as a device configured as desired using any appropriate hardware, firmware, software, or any combination thereof, and the device may include electronic devices such as a server (cluster), a terminal, etc. Figure 5 An exemplary apparatus 500 that can be used to implement various embodiments described in this application is schematically shown.
[0152] For one embodiment, Figure 5 An exemplary apparatus 500 is shown having one or more processors 502, a control module (chip set) 504 coupled to at least one of the processor(s) 502, a memory 506 coupled to the control module 504, a non-volatile memory (NVM) / storage device 508 coupled to the control module 504, one or more input / output devices 510 coupled to the control module 504, and a network interface 512 coupled to the control module 504.
[0153] The processor 502 may include one or more single-core or multi-core processors, and the processor 502 may include any combination of general-purpose processors or special-purpose processors (such as graphics processors, application processors, baseband processors, etc.). In some embodiments, the device 500 can be used as a server, terminal, or other device described in the embodiments of the present application.
[0154] In some embodiments, the apparatus 500 may include one or more computer-readable media (e.g., memory 506 or NVM / storage device 508) having instructions 514 and one or more processors 502 configured in conjunction with the one or more computer-readable media to execute the instructions 514 to implement a module to perform the actions described in the present disclosure.
[0155] For one embodiment, control module 504 may include any suitable interface controller to provide any suitable interface to at least one of processor(s) 502 and / or any suitable device or component in communication with control module 504 .
[0156] The control module 504 may include a memory controller module to provide an interface to the memory 506. The memory controller module may be a hardware module, a software module, and / or a firmware module.
[0157] The memory 506 may be used, for example, to load and store data and / or instructions 514 for the device 500. For one embodiment, the memory 506 may include any suitable volatile memory, such as a suitable DRAM. In some embodiments, the memory 506 may include double data rate type four synchronous dynamic random access memory (DDR4 SDRAM).
[0158] For one embodiment, control module 504 may include one or more input / output controllers to provide an interface to NVM / storage device 508 and input / output device(s) 510 .
[0159] For example, NVM / storage 508 may be used to store data and / or instructions 514. NVM / storage 508 may include any suitable non-volatile memory (e.g., flash memory) and / or may include any suitable non-volatile storage device(s) (e.g., one or more hard disk drives (HDDs), one or more compact disk (CD) drives, and / or one or more digital versatile disk (DVD) drives).
[0160] NVM / storage device 508 may include storage resources that are part of the device on which apparatus 500 is installed, or it may be accessible to the device without being part of the device. For example, NVM / storage device 508 may be accessed via (one or more) input / output devices 510 over a network.
[0161] (One or more) input / output devices 510 may provide an interface for the apparatus 500 to communicate with any other appropriate device, and the input / output device 510 may include a communication component, an audio component, a sensor component, etc. The network interface 512 may provide an interface for the apparatus 500 to communicate through one or more networks, and the apparatus 500 may wirelessly communicate with one or more components of a wireless network according to any of one or more wireless network standards and / or protocols, for example, accessing a wireless network based on a communication standard, such as WiFi, 2G, 3G, 4G, 5G, etc., or a combination thereof for wireless communication.
[0162] For one embodiment, at least one of the processor(s) 502 may be packaged together with the logic of one or more controllers (e.g., a memory controller module) of the control module 504. For one embodiment, at least one of the processor(s) 502 may be packaged together with the logic of one or more controllers of the control module 504 to form a system-in-package (SiP). For one embodiment, at least one of the processor(s) 502 may be integrated on the same die with the logic of one or more controllers of the control module 504. For one embodiment, at least one of the processor(s) 502 may be integrated on the same die with the logic of one or more controllers of the control module 504 to form a system-on-chip (SoC).
[0163] In various embodiments, the apparatus 500 may be, but is not limited to, a terminal device such as a server, a desktop computing device, or a mobile computing device (e.g., a laptop computing device, a handheld computing device, a tablet computer, a netbook, etc.). In various embodiments, the apparatus 500 may have more or fewer components and / or a different architecture. For example, in some embodiments, the apparatus 500 includes one or more cameras, a keyboard, a liquid crystal display (LCD) screen (including a touch screen display), a non-volatile memory port, multiple antennas, a graphics chip, an application-specific integrated circuit (ASIC), and a speaker.
[0164] Among them, the main control chip can be used as a processor or control module in the detection device, sensor data, location information, etc. are stored in a memory or NVM / storage device, the sensor group can be used as an input / output device, and the communication interface may include a network interface.
[0165] The embodiment of the present application also provides an electronic device, including: a processor; and a memory, on which executable code is stored, and when the executable code is executed, the processor executes one or more methods as described in the embodiment of the present application. In the embodiment of the present application, the memory can store various data, such as target files, file and application association data, and user behavior data, so as to provide a data basis for various processing.
[0166] The embodiments of the present application also provide one or more machine-readable media on which executable codes are stored. When the executable codes are executed, the processor executes one or more methods described in the embodiments of the present application.
[0167] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0168] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0169] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0170] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0171] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0172] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present application.
[0173] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or terminal device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or terminal device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or terminal device including the elements.
[0174] The above is a detailed introduction to a cloud service-based vulnerability handling method, an electronic device and a storage medium provided by the present application. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for general technical personnel in this field, according to the idea of the present application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A vulnerability handling method based on cloud services, It is characterized in that Applied to a cloud server, the method includes: Receiving a heartbeat signal, the heartbeat signal including heartbeat data, the heartbeat signal being used to inform the cloud service end about the survival and configuration of the client; When the client meets the vulnerability detection conditions, a vulnerability detection instruction is issued, wherein the vulnerability detection instruction is determined according to the configuration information of the client, the configuration information is sent through the heartbeat data, and the vulnerability detection instruction carries a vulnerability detection script to perform vulnerability detection on the client without installing security software; Receive a vulnerability detection result through heartbeat data, where the vulnerability detection result is generated by executing the vulnerability detection on the client according to the vulnerability detection instruction; Obtaining at least one vulnerability repair patch according to the vulnerability detection result; The at least one vulnerability repair patch is issued to perform vulnerability repair on the client based on the vulnerability repair patch.
2. The method according to claim 1, It is characterized in that Also includes: Use heartbeat data to detect whether the client meets the vulnerability detection conditions.
3. The method according to claim 2, It is characterized in that The detecting whether the client satisfies the vulnerability detection condition through the heartbeat data includes: Determine whether the client is online based on the time information corresponding to the heartbeat data; If the client is online, check whether the client supports vulnerability scanning; If the client supports vulnerability scanning, determining that the client meets the vulnerability detection condition; If the client is offline or does not support vulnerability scanning, it is determined that the client does not meet the vulnerability detection condition.
4. The method according to claim 1, It is characterized in that When the client satisfies the vulnerability detection condition, issuing a vulnerability detection instruction includes: When the client meets the vulnerability detection conditions, the configuration information is obtained through the heartbeat data; Acquire client information from the configuration information, and determine vulnerability detection instructions based on the client information; The vulnerability detection instruction is issued.
5. The method according to claim 1, It is characterized in that The obtaining at least one vulnerability repair patch according to the vulnerability detection result includes: Obtain at least one vulnerability information from the vulnerability detection result; At least one vulnerability repair patch is obtained according to the at least one vulnerability information.
6. The method according to claim 1 or 5, It is characterized in that Also includes: Determine risk level information corresponding to the vulnerability information; Analyzing the association information between the vulnerability information and the client; Generate repair suggestion information according to the risk level and related information, and feed back the repair suggestion information.
7. The method according to claim 1 or 4, It is characterized in that The issuing of the vulnerability detection instruction comprises: The vulnerability detection instruction is transmitted through a dedicated message channel.
8. The method according to claim 1, It is characterized in that The issuing of the at least one vulnerability repair patch includes: The at least one vulnerability repair patch is transmitted through a dedicated message channel.
9. A vulnerability handling method based on cloud services, It is characterized in that Applied to a client, the method comprises: Upload a heartbeat signal, wherein the heartbeat signal includes heartbeat data, and the heartbeat data includes configuration information. The heartbeat signal is used to inform the cloud service end about the survival and configuration of the client; receiving a vulnerability detection instruction, wherein the vulnerability detection instruction is determined by the cloud server according to the configuration information, and the vulnerability detection instruction carries a vulnerability detection script to perform vulnerability detection on the client without installing security software; Execute missed detection processing according to the vulnerability detection script of the vulnerability detection instruction to obtain a vulnerability detection result; Adding the vulnerability detection result to the heartbeat data, and sending the heartbeat data; receiving at least one vulnerability repair patch, where the vulnerability repair patch is determined by the cloud service end according to the vulnerability detection result; A vulnerability repair process is performed according to the vulnerability repair patch to determine the vulnerability repair result.
10. The method according to claim 9, It is characterized in that Also includes: The vulnerability repair result is sent through a dedicated message channel.
11. The method according to claim 9, It is characterized in that Also includes: Receive repair suggestion information; Based on the repair suggestion information, a repair suggestion for the vulnerability to be repaired is displayed, wherein the repair suggestion is determined based on the risk level and related information of the vulnerability to be repaired; In response to the triggering of the repair suggestion, the vulnerability to be repaired is determined and fed back to the cloud service end.
12. An electronic device, include: processor; and a memory having executable codes stored thereon, wherein when the executable codes are executed by a processor, the method according to any one of claims 1 to 11 is executed.
13. One or more machine-readable media having executable codes stored thereon, and when the executable codes are executed by a processor, the method according to any one of claims 1 to 11 is performed.
Citation Information
Patent Citations
Solution management systems and methods for addressing cybersecurity vulnerabilities
US20200404013A1