Security detection method, apparatus, device, and storage medium

By creating and managing scan records, test records, and system configuration data in the database, setting exemption data, and detecting and sending abnormal data, the problems of missed scans and missed tests are solved, improving the efficiency and effectiveness of security testing.

CN115203705BActive Publication Date: 2026-02-03CHINA PING AN LIFE INSURANCE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210860776.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-21
Publication Date
2026-02-03
Estimated Expiration
2042-07-21

AI Technical Summary

Technical Problem

Existing security detection methods have issues with missed scans and missed tests, leading to security risks.

Method used

Create scan record data, test record data, and system configuration data in the database, set exempt data and non-exempt data, perform detection through data detection commands and security account information, obtain abnormal data, and send security detection data through the service interface.

Benefits of technology

It effectively reduces missed scans and missed tests, improves safety performance, and enables timely detection and handling of safety hazards.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115203705B_ABST
    Figure CN115203705B_ABST
Patent Text Reader

Abstract

The application discloses a kind of security detection method, device, equipment and storage medium, can be widely applied in artificial intelligence technical field;The method of the application comprises: creating scanning record data, test record data and system configuration data in database, wherein, system configuration data is provided with exemption data, non-exempt data and security account information;Data detection instruction is obtained, according to data detection instruction, scanning record data, test record data and exemption data, non-exempt data in system configuration data, detect target to be detected, and obtain abnormal data;According to the security account information in system configuration data, the service interface corresponding to abnormal data is called, wherein, abnormal data has security account information;Security detection data is sent through service interface, wherein, security detection data carries abnormal data, and the application can effectively reduce the situation of missing scanning, missing test, and improve security performance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of artificial intelligence technology, and in particular to a security detection method, apparatus, device, and storage medium. Background Technology

[0002] With the rapid development of artificial intelligence (AI), system security testing is gradually moving away from manual processes and towards intelligent operation. Currently, with the massive increase in business volume, security has become increasingly important. However, existing security testing methods still suffer from omissions in scanning and testing, which can easily lead to security vulnerabilities. Summary of the Invention

[0003] The following is an overview of the subject matter described in detail herein. This overview is not intended to limit the scope of the claims.

[0004] The main objective of this application is to provide a security detection method, apparatus, device, and storage medium that can effectively reduce missed scans and missed detections, thereby improving security performance.

[0005] To achieve the above objectives, in a first aspect, embodiments of this application provide a security detection method, comprising:

[0006] Create scan record data, test record data, and system configuration data in the database. The system configuration data includes exemption data, non-exempt data, and security account information.

[0007] Obtain a data detection instruction, and based on the data detection instruction, the scan record data, the test record data, and the exempted data and non-exempt data in the system configuration data, detect the target to be detected to obtain abnormal data;

[0008] Based on the security account information in the system configuration data, the service interface corresponding to the abnormal data is retrieved, wherein the abnormal data corresponds to the security account information;

[0009] Security detection data is sent through the service interface, wherein the security detection data carries the abnormal data.

[0010] In some embodiments, the exemption data is obtained by the following steps:

[0011] Retrieve exemption information from the pre-defined document signing system;

[0012] The exemption object information is set as exemption data in the system configuration data.

[0013] In some embodiments, the method further includes:

[0014] The exemption data in the system configuration data is marked to obtain marked data, wherein the marked data represents data that is not subject to security detection.

[0015] In some embodiments, the abnormal data includes first abnormal data and second abnormal data. The step of detecting the target to be detected based on the data detection instruction, the scan record data, the test record data, and the exempted data and non-exempt data in the system configuration data to obtain abnormal data includes:

[0016] Based on the data detection instruction, the scan record data, and the exempted data and non-exempt data in the system configuration data, the target to be detected is detected to obtain the first abnormal data, wherein the first abnormal data represents abnormal unscanned data.

[0017] Based on the data detection instruction, the test record data, and the exempted data and non-exempt data in the system configuration data, the target to be detected is detected to obtain the second abnormal data, wherein the second abnormal data represents abnormal data that was not tested.

[0018] In some embodiments, creating scan record data, test record data, and system configuration data in the database includes:

[0019] Version plan data is created in the database, wherein the version plan data includes system data and version data, and the system data corresponds to the version data;

[0020] Based on the version data, create the scan record data and the test record data corresponding to the version data in the database;

[0021] Based on the system data, system configuration data corresponding to the system data is created in the database.

[0022] In some embodiments, sending security detection data through the service interface includes:

[0023] Security detection data and security alert data are sent through the service interface, wherein the security alert data corresponds to the abnormal data.

[0024] In some embodiments, sending security detection data and security alert data through the service interface includes one of the following:

[0025] Obtain a trigger notification instruction, and based on the trigger notification instruction, trigger the corresponding service interface to send the security detection data and the security notification data; or,

[0026] Obtain a scheduled sending instruction, generate a scheduled task based on the scheduled sending instruction, and trigger the corresponding service interface to send the security detection data and the security reminder data according to the scheduled task at regular intervals.

[0027] Secondly, embodiments of this application provide a security detection device, including:

[0028] The data creation module is used to create scan record data, test record data and system configuration data in the database. The system configuration data includes exempt data, non-exempt data and security account information.

[0029] The data detection module is used to acquire data detection instructions, and to detect the target to be detected based on the data detection instructions, the scan record data, the test record data, and the exempted data and non-exempt data in the system configuration data, thereby obtaining abnormal data.

[0030] The data retrieval module is used to retrieve the service interface corresponding to the abnormal data based on the security account information in the system configuration data, wherein the abnormal data corresponds to the security account information;

[0031] The data sending module is used to send security detection data through the service interface, wherein the security detection data carries the abnormal data.

[0032] Thirdly, embodiments of this application provide a security detection device, including: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the security detection method of the preceding embodiments.

[0033] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer-executable program, the computer-executable program being used to execute the security detection method of the preceding embodiments.

[0034] The beneficial effects of this application's embodiments include: by creating scan record data, test record data, and system configuration data in a database, wherein the system configuration data includes exempt data, non-exempt data, and security account information; obtaining data detection instructions; detecting the target to be detected based on the data detection instructions, scan record data, test record data, and exempt and non-exempt data in the system configuration data to obtain abnormal data; calling the service interface corresponding to the abnormal data based on the security account information in the system configuration data, wherein the abnormal data corresponds to security account information; and sending security detection data through the service interface, wherein the security detection data carries the abnormal data. Compared with related technologies, this application's embodiments, by including scan record data, test record data, and system configuration data, can effectively reduce missed scans and missed tests, thereby improving security performance.

[0035] Other features and advantages of this application will be set forth in the following description and will be apparent in part from the description or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the description and the accompanying drawings. Attached Figure Description

[0036] The accompanying drawings are used to provide a further understanding of the technical solutions of this application and constitute a part of the specification. They are used together with the embodiments of this application to explain the technical solutions of this application and do not constitute a limitation on the technical solutions of this application.

[0037] Figure 1 This is a schematic flowchart of the security detection method according to an embodiment of this application;

[0038] Figure 2 This is a flowchart illustrating the exemption data in an embodiment of this application;

[0039] Figure 3 This is a flowchart illustrating the abnormal data in an embodiment of this application;

[0040] Figure 4 This is a flowchart illustrating the version plan data in an embodiment of this application.

[0041] Figure 5 This is a flowchart illustrating the security alert data in an embodiment of this application.

[0042] Figure 6 This is a schematic diagram of the structure of the security detection device according to an embodiment of this application;

[0043] Figure 7 This is a schematic diagram of the hardware structure of the security detection device according to an embodiment of this application. Detailed Implementation

[0044] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0045] It should be noted that although functional modules are divided in the device schematic diagram and a logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart. The terms "first," "second," etc., in the specification, claims, and the aforementioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.

[0046] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0047] First, let's analyze the terms used in this application:

[0048] Artificial Intelligence (AI) is a new branch of computer science that studies, develops, and applies theories, methods, technologies, and systems to simulate, extend, and expand human intelligence. It aims to understand the essence of intelligence and produce intelligent machines that can react in a way similar to human intelligence. Research in this field includes robotics, speech recognition, image recognition, natural language processing, and expert systems. AI can simulate the information processes of human consciousness and thought. Furthermore, AI utilizes digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceiving the environment, acquiring knowledge, and using that knowledge to achieve optimal results.

[0049] Python (a computer programming language): Designed in the early 1990s by Guido van Rossum of the Netherlands Organization for Mathematical and Computer Science as an alternative to a language called ABC. Python provides efficient high-level data structures and enables simple and efficient object-oriented programming. Its syntax, dynamic typing, and interpreted language nature make it a popular programming language for scripting and rapid application development on most platforms. With continuous updates and the addition of new features, it has gradually been used for independent, large-scale project development.

[0050] With the rapid development of artificial intelligence, system security testing is gradually moving away from manual processes and towards intelligent operation. Currently, with the massive volume of business operations, security is becoming increasingly important. However, existing security testing methods still suffer from omissions in scanning and testing, which can easily lead to security vulnerabilities.

[0051] Based on this, embodiments of this application provide a security detection method, apparatus, device, and storage medium. Embodiments of this application can effectively reduce missed scans and missed detections, thereby improving security performance.

[0052] It is understood that the embodiments of this application can acquire and process relevant data, such as scan record data, test record data, and system configuration data, based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.

[0053] Understandably, fundamental artificial intelligence technologies generally include technologies such as sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interactive systems, and mechatronics. Artificial intelligence software technologies mainly include computer vision, robotics, and machine learning / deep learning.

[0054] Specifically, user behavior data to be processed can be obtained through a terminal / device, which can be a mobile terminal device or a non-mobile terminal device. Among them, mobile terminal devices can be mobile phones, tablets, laptops, handheld computers, PDAs, ultra-mobile personal computers (UMPCs), wearable devices, netbooks, personal digital assistants (PDAs), augmented reality (AR) / virtual reality (VR) devices, etc.; non-mobile terminal devices can be personal computers, ATMs, or self-service machines, etc., and the implementation scheme of this application does not make specific limitations.

[0055] Specifically, refer to Figure 1 This application provides a security detection method, including but not limited to the following steps S100 to S400:

[0056] Step S100: Create scan record data, test record data and system configuration data in the database. The system configuration data includes exemption data, non-exempt data and security account information.

[0057] Step S200: Obtain data detection instructions; based on the data detection instructions, scan record data, test record data, and exempted and non-exempt data in the system configuration data, detect the target to be detected and obtain abnormal data.

[0058] Step S300: Based on the security account information in the system configuration data, retrieve the service interface corresponding to the abnormal data, where the abnormal data corresponds to security account information;

[0059] Step S400: Send security detection data through the service interface, wherein the security detection data carries abnormal data.

[0060] In this embodiment, scan record data, test record data, and system configuration data can be created in the database. The scan record data corresponds to the scanning platform, and the scan record data of the scanning platform is obtained through an interface. The synchronization of this scan record data can be achieved using a ktl tool or manually. Similarly, test record data can be created in the database. For example, the test record data can be a SOC test record table, obtained through the SOC interface. The data synchronization can also be achieved using a ktl tool or manually. Furthermore, system configuration data is maintained in the database, which can be a system configuration table. Since some systems are purely backend-based, they do not require scanning and testing. Therefore, these systems are often exempt from testing and testing, and are thus considered exempt data. When performing data statistics, exempt data (i.e., the aforementioned systems) needs to be excluded. Systems that require scanning and testing are considered non-exempt data. For example, the system configuration data is used to record which systems are exempt and which are not, and it also records security account information. In some embodiments, the security account information corresponds to the account information of each system security officer.

[0061] This application embodiment obtains abnormal data by detecting the target to be detected. Since the detection generates security detection data, which carries the abnormal data, and since the abnormal data corresponds to security account information, the service interface corresponding to the abnormal data can be retrieved based on the security account information in the system configuration data. The security detection data carrying the abnormal data is then sent to the receiving end through the corresponding service interface. It is understood that, given that the security account information corresponds to the account information of each system security officer, sending the security detection data carrying the abnormal data to the system security officer through the corresponding service interface allows the system security officer to promptly identify missed scans and missed tests, thereby reducing system security risks.

[0062] For example, non-exempt data corresponds to security account information; for instance, one non-exempt system corresponds to the account information of one system security officer. For example, the account information of one system security officer may correspond to multiple non-exempt systems.

[0063] For example, the scan record data can be a scan record table, which includes subsystem data, subsystem version data, release status, creation time, actual release time, whether the requirement review is completed, whether the code has been scanned, number of critical vulnerabilities, number of high-risk vulnerabilities, vulnerability rate per thousand lines, repair rate, code scan duration, whether the component has been scanned, number of critical components, number of high-risk components, number of blacklisted components, component scan duration (e.g., minutes), whether the scanning platform has scanned, number of critical vulnerabilities scanned, number of high-risk vulnerabilities scanned, number of medium-risk vulnerabilities scanned, last scan time, whether it was accessed from the external network, company data, department data, estimated release start time, estimated release end time, requirement type, etc.

[0064] For example, the test submission record data can be a SOC test submission record table, which includes data such as the development department, name data (e.g., space name, English abbreviation), version name data, planned launch time, actual launch time, source code scanning status, system source code scanning time, number of remaining critical and high-risk vulnerabilities in the source code scan, pre-launch inspection status, penetration testing time, number of remaining unpatched vulnerabilities in penetration testing, whether security test submission is exempted, and version status data.

[0065] The security detection method of this application embodiment creates scan record data, test submission record data, and system configuration data in a database. The system configuration data includes exempt data, non-exempt data, and security account information. It obtains a data detection instruction and, based on the data detection instruction, the exempt data, and the non-exempt data in the scan record data, test submission record data, and system configuration data, detects the target to be detected to obtain abnormal data. Based on the security account information in the system configuration data, it retrieves the service interface corresponding to the abnormal data, where the abnormal data corresponds to security account information. Finally, it sends security detection data through the service interface, where the security detection data carries the abnormal data. Compared with related technologies, this application embodiment, by setting up scan record data, test submission record data, and system configuration data, can effectively reduce missed scans and missed tests, thereby improving security performance.

[0066] Reference Figure 2 The exemption data is obtained through the following steps:

[0067] Step S101: Retrieve exemption information from the preset document signing system;

[0068] Step S102: Set the exemption object information as exemption data in the system configuration data.

[0069] It should be noted that by retrieving exemption object information from the preset document signing system, this exemption object information can correspond to pure backend system data. The pure backend system represents systems that do not require scanning or testing. Subsequently, the exemption object information is set as exemption data in the system configuration data. This setting facilitates the retrieval of exemption data and improves data detection efficiency.

[0070] In some embodiments, the method further includes: marking exemption data in system configuration data to obtain marked data, wherein the marked data characterizes non-security detection data.

[0071] It should be noted that system configuration data is created in the database to maintain the system configuration data. For example, the system configuration data can be modified, and exempted data in the system configuration data can be marked to obtain marked data. For example, exempted systems are marked. Marked data represents data that is not subject to security testing, that is, marked data does not need to be scanned or tested.

[0072] Reference Figure 3 The abnormal data includes first abnormal data and second abnormal data. Based on the exempted data and non-exempted data in the data detection instructions, scan record data, test record data and system configuration data, the target to be detected is detected to obtain abnormal data, including but not limited to the following steps S210 to S220:

[0073] Step S210: According to the data detection instruction, the exempted data and non-exempted data in the scan record data and system configuration data, the target to be detected is detected to obtain the first abnormal data, wherein the first abnormal data represents abnormal unscanned data;

[0074] Step S220: Based on the data detection instructions, the test record data, and the exempted data and non-exempt data in the system configuration data, the target to be detected is detected to obtain the second abnormal data, wherein the second abnormal data represents abnormal data that was not tested.

[0075] This application embodiment detects the target to be detected, such as the database to be detected, based on the acquired data detection instructions, scan record data, and exempted data and non-exempt data in the system configuration data, and obtains the first abnormal data. It should be noted that the first abnormal data represents abnormal unscanned data. For example, if a system that needs to be scanned is not scanned, then the system belongs to the abnormal unscanned data.

[0076] By analyzing the exempted and non-exempted data in the acquired data detection instructions, test record data, and system configuration data, the target to be tested, such as the database to be tested, is detected to obtain second abnormal data. It should be noted that the second abnormal data represents data that was not submitted for testing. For example, if a system that needs to be tested but has not been tested, then that system belongs to the category of abnormally untested data. It should also be noted that, based on the exempted and non-exempt data, it is possible to determine which data needs to be scanned and tested, thereby facilitating the detection of the target and timely identifying systems that have been missed in scanning or testing, thus improving security performance.

[0077] Reference Figure 4 Create scan record data, test record data, and system configuration data in the database, including but not limited to the following steps S110 to S130:

[0078] Step S110: Create version plan data in the database, wherein the version plan data contains system data and version data, and the system data corresponds to the version data;

[0079] Step S120: Based on the version data, create scan record data and test record data corresponding to the version data in the database;

[0080] Step S130: Based on the system data, create system configuration data in the database that corresponds to the system data.

[0081] This application embodiment creates version plan data in a database. It is understood that the version plan data includes system data and version data, with the system data corresponding to the version data. Specifically, based on the version data, scan record data and test record data are created in the database, and these correspond to the version data. Similarly, based on the system data, system configuration data is created in the database, and these system data correspond to the system configuration data. Therefore, based on the version plan data, a relationship can be established between scan record data, test record data, and system configuration data to facilitate version information tracking, thereby aiding in data classification and filtering of security testing data.

[0082] For example, the version plan data can be a version plan table, which contains the version plan, subsystem version data, development contact, planned release start time, planned release end time, etc.

[0083] It is understood that sending security detection data through the service interface includes, but is not limited to, the following steps: sending security detection data and security alert data through the service interface, wherein the security alert data corresponds to the abnormal data.

[0084] In order to facilitate the generation of an early warning mechanism, this application embodiment sets up a method to send security detection data and security reminder data through a service interface. The security reminder data corresponds to abnormal data. That is, by sending security detection data carrying abnormal data to the receiving end, such as a system security officer, and the abnormal data corresponding to security reminder data, the receiving end can be reminded to check the abnormal data in a timely manner, which effectively improves the timeliness of processing and enhances the efficiency of security detection.

[0085] In related technologies, security testing typically involves code-level scanning and testing of front-end interface SOCs to discover system vulnerabilities such as privilege escalation and SQL (Structured Query Language) injection. However, current testing teams operate on numerous systems, frequently resulting in missed scans and untested vulnerabilities, and lacking early warning mechanisms for security scanning and testing.

[0086] Reference Figure 5 Send security detection data and security alert data through the service interface, including but not limited to one of the following:

[0087] Step S410: Obtain the trigger reminder instruction; based on the trigger reminder instruction, trigger the corresponding service interface to send security detection data and security reminder data; or,

[0088] Step S420: Obtain the timed sending instruction, generate a timed task according to the timed sending instruction, and trigger the corresponding service interface to send security detection data and security reminder data according to the timed task.

[0089] To facilitate the generation of an automatic early warning mechanism, this application embodiment sets up multiple reminder methods. Specifically, a trigger button can be set on the interface of the security detection system. When the user clicks the trigger button, a trigger reminder command is generated. At this time, the trigger reminder command is acquired, and according to the trigger reminder command, the corresponding service interface is triggered to send security detection data and security reminder data. By manually triggering the mechanism, an early warning mechanism can be formed, which can meet the user's security detection needs.

[0090] Alternatively, a scheduled send button can be set on the security detection system interface. Users can set the timer and click the button, generating a scheduled send command. Based on this command, a scheduled task is created, which then triggers the corresponding service interface to send security detection data and security alerts at regular intervals. This scheduled triggering method forms an automatic early warning mechanism, effectively improving the efficiency of security detection.

[0091] For example, the service interface of this application embodiment can correspond to an email interface, which can promptly send emails to remind the corresponding system security personnel to perform testing and scanning work. The email contains security detection data and security reminder data. The security detection data carries abnormal data, while the security reminder data is used to remind the receiving end that the security detection result is abnormal and needs to be handled in a timely manner.

[0092] For example, a security detection button can also be set. By setting a security detection button on the interface of the security detection system, when the user clicks the security detection button, a data detection instruction is generated so that the target to be detected can be detected according to the data detection instruction, scan record data, test record data and exempted data and non-exempt data in the system configuration data, and abnormal data can be obtained.

[0093] The security detection method of this application embodiment can detect missed scans and missed detections in a timely manner, and can generate an automatic early warning mechanism to remind the receiving end to handle the abnormal data in a timely manner; in addition, it also saves manpower costs and is more time-saving and labor-saving compared with related technologies.

[0094] Reference Figure 6 One embodiment of this application also provides a security detection device, including but not limited to the following modules:

[0095] The data creation module 100 is used to create scan record data, test record data and system configuration data in the database. The system configuration data includes exempt data, non-exempt data and security account information.

[0096] The data detection module 200 is used to acquire data detection instructions, and to detect the target to be detected based on the data detection instructions, scan record data, test record data and exempted data and non-exempt data in the system configuration data, and to obtain abnormal data.

[0097] The data retrieval module 300 is used to retrieve the service interface corresponding to the abnormal data based on the security account information in the system configuration data. The abnormal data corresponds to the security account information.

[0098] The data sending module 400 is used to send security detection data through the service interface, wherein the security detection data carries abnormal data.

[0099] It should be noted that the content of the method embodiments of this application is applicable to the device embodiments. The specific functions implemented by the device embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above methods. Therefore, they will not be repeated here.

[0100] This application also provides a security detection device, which includes: a memory, a processor, a program stored in the memory and executable on the processor, and a data bus for communication between the processor and the memory. When the program is executed by the processor, it implements the aforementioned security detection method. This security detection device can be any smart terminal, including tablet computers, in-vehicle computers, etc.

[0101] It should be noted that the security detection device in this embodiment can be applied to the security detection method as described in the above embodiments. The security detection device in this embodiment and the security detection method as described in the above embodiments have the same inventive concept. Therefore, these embodiments have the same implementation principle and technical effect, which will not be described in detail here.

[0102] Please see Figure 7 , Figure 7 The hardware structure of a security detection device according to another embodiment is illustrated. The security detection device includes:

[0103] The processor 801 can be implemented using a general-purpose CPU (Central Processing Unit), microprocessor, application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this application.

[0104] The memory 802 can be implemented as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 802 can store the operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 802 and is called and executed by the processor 801 using the security detection method of the embodiments of this application.

[0105] The 803 input / output interface is used to implement information input and output.

[0106] The communication interface 804 is used to enable communication and interaction between this device and other devices. Communication can be achieved through wired means (such as USB, Ethernet cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).

[0107] Bus 805 transmits information between various components of the device (e.g., processor 801, memory 802, input / output interface 803, and communication interface 804);

[0108] The processor 801, memory 802, input / output interface 803, and communication interface 804 are connected to each other within the device via bus 805.

[0109] The security detection equipment embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0110] This application also provides a computer-readable storage medium for computer-readable storage, which stores one or more programs that can be executed by one or more processors to implement the above-described security detection method.

[0111] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs and non-transitory computer-executable programs. Furthermore, memory may include high-speed random access memory, and may also include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory may optionally include memory remotely located relative to the processor, and these remote memories can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0112] The security detection method, apparatus, device, and storage medium of this application embodiment create scan record data, test record data, and system configuration data in a database. The system configuration data includes exempt data, non-exempt data, and security account information. The method acquires a data detection instruction and, based on the data detection instruction, the scan record data, the test record data, and the exempt and non-exempt data in the system configuration data, detects the target to be detected to obtain abnormal data. Based on the security account information in the system configuration data, the method retrieves the service interface corresponding to the abnormal data, where the abnormal data corresponds to security account information. Finally, the method sends security detection data through the service interface, where the security detection data carries the abnormal data. Compared with related technologies, this application embodiment, by including scan record data, test record data, and system configuration data, can effectively reduce missed scans and missed tests, thereby improving security performance.

[0113] The embodiments described in this application are for the purpose of more clearly illustrating the technical solutions of the embodiments of this application, and do not constitute a limitation on the technical solutions provided by the embodiments of this application. As those skilled in the art will know, with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of this application are also applicable to similar technical problems.

[0114] It will be understood by those skilled in the art that Figure 1-5 The technical solutions shown do not constitute a limitation on the embodiments of this application, and may include more or fewer steps than shown, or combine certain steps, or different steps.

[0115] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0116] Those skilled in the art will understand that all or some of the steps in the methods disclosed above, as well as the functional modules / units in the systems and devices, can be implemented as software, firmware, hardware, or suitable combinations thereof.

[0117] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0118] It should be understood that in this application, "at least one (item)" means one or more, and "more than" means two or more. "And / or" is used to describe the relationship between related objects, indicating that three relationships can exist. For example, "A and / or B" can represent three cases: only A exists, only B exists, and both A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0119] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of the units described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0120] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0121] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0122] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes multiple instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this application. The aforementioned storage medium includes various media capable of storing programs, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0123] The above is a detailed description of the preferred embodiments of this application. However, this application is not limited to the above embodiments. Those skilled in the art can make various equivalent modifications or substitutions without departing from the spirit of this application. All such equivalent modifications or substitutions are included within the scope defined by the claims of this application.

Claims

1. A security detection method, characterized in that, include: Create version plan data in the database, wherein the version plan data includes system data and version data, and the system data corresponds to the version data; Based on the version data, create scan record data and test record data corresponding to the version data in the database; Based on the system data, system configuration data corresponding to the system data is created in the database, wherein the system configuration data includes exemption data, non-exempt data, and security account information; Obtain a data detection instruction, and based on the data detection instruction, the scan record data, the test record data, and the exempted data and non-exempt data in the system configuration data, detect the target to be detected to obtain abnormal data; Based on the security account information in the system configuration data, the service interface corresponding to the abnormal data is retrieved, wherein the abnormal data corresponds to the security account information; Security detection data is sent through the service interface, wherein the security detection data carries the abnormal data; The abnormal data includes first abnormal data and second abnormal data. The abnormal data is obtained by detecting the target to be detected based on the data detection instruction, the scan record data, the test record data, and the exempted data and non-exempt data in the system configuration data, including: Based on the data detection instruction, the scan record data, and the exempted data and non-exempt data in the system configuration data, the target to be detected is detected to obtain the first abnormal data, wherein the first abnormal data represents abnormal unscanned data. Based on the data detection instruction, the test record data, and the exempted data and non-exempt data in the system configuration data, the target to be detected is detected to obtain the second abnormal data, wherein the second abnormal data represents abnormal data that was not tested.

2. The security detection method according to claim 1, characterized in that, The exemption data is obtained through the following steps: Retrieve exemption information from the pre-defined document signing system; The exemption object information is set as exemption data in the system configuration data.

3. The security detection method according to claim 1, characterized in that, The method further includes: The exemption data in the system configuration data is marked to obtain marked data, wherein the marked data represents data that is not subject to security detection.

4. The security detection method according to any one of claims 1 to 3, characterized in that, Sending security detection data through the service interface includes: Security detection data and security alert data are sent through the service interface, wherein the security alert data corresponds to the abnormal data.

5. The security detection method according to claim 4, characterized in that, The sending of security detection data and security alert data through the service interface includes one of the following: Obtain a trigger reminder instruction, and trigger the corresponding service interface to send the security detection data and the security reminder data according to the trigger reminder instruction; or, Obtain a scheduled sending instruction, generate a scheduled task based on the scheduled sending instruction, and trigger the corresponding service interface to send the security detection data and the security reminder data according to the scheduled task at regular intervals.

6. A safety detection device, characterized in that, include: The data creation module is used to create version plan data in the database, wherein the version plan data includes system data and version data, and the system data corresponds to the version data; based on the version data, scan record data and test record data corresponding to the version data are created in the database; based on the system data, system configuration data corresponding to the system data is created in the database, wherein the system configuration data includes exemption data, non-exempt data, and security account information; The data detection module is used to acquire data detection instructions, and to detect the target to be detected based on the data detection instructions, the scan record data, the test record data, and the exempted data and non-exempt data in the system configuration data, thereby obtaining abnormal data. The data retrieval module is used to retrieve the service interface corresponding to the abnormal data based on the security account information in the system configuration data, wherein the abnormal data corresponds to the security account information; A data sending module is used to send security detection data through the service interface, wherein the security detection data carries the abnormal data; The abnormal data includes first abnormal data and second abnormal data. The abnormal data is obtained by detecting the target to be detected based on the data detection instruction, the scan record data, the test record data, and the exempted data and non-exempt data in the system configuration data, including: Based on the data detection instruction, the scan record data, and the exempted data and non-exempt data in the system configuration data, the target to be detected is detected to obtain the first abnormal data, wherein the first abnormal data represents abnormal unscanned data. Based on the data detection instruction, the test record data, and the exempted data and non-exempt data in the system configuration data, the target to be detected is detected to obtain the second abnormal data, wherein the second abnormal data represents abnormal data that was not tested.

7. A safety detection device, characterized in that, include: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the computer program, implements the security detection method as described in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, The device contains a computer-executable program for performing the security detection method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Loophole detection method and server

    CN104519007A

  • Detection anomaly detection method and device, and equipment and storage medium

    CN112181841A