Patch update method and system based on hook function

By deploying hook functions in terminal devices to capture system behavior, obtain and report patch files, the problem of patch update interruption in the intranet environment is solved, and timely patch file acquisition and security assurance are achieved.

CN115329344BActive Publication Date: 2025-09-05BEIJING ANTIY NETWORK SAFETY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211021928.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-24
Publication Date
2025-09-05
Estimated Expiration
2042-08-24

AI Technical Summary

Technical Problem

In an intranet environment, patch updates are interrupted because terminal devices cannot access the external Internet, posing a security risk. In addition, the existing web crawler method is difficult and ineffective in obtaining patch files.

Method used

Deploy hook functions in terminal devices, capture system behavior, analyze whether it is a patch update, obtain patch files and report them to the patch management server, update the patch library, and provide the latest patch files to the intranet server.

Benefits of technology

It enables timely acquisition of patch files in the intranet environment, ensures the security of terminal devices, avoids patch update interruptions, and improves the timeliness of patch file acquisition.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115329344B_ABST
    Figure CN115329344B_ABST
Patent Text Reader

Abstract

The present invention provides a hook function-based patch update method and system. The method on the terminal device side includes: capturing the system behavior of the terminal device based on at least one hook function deployed in the terminal device; analyzing whether the captured system behavior is used for patch updates of the Windows system in the terminal device; if so, obtaining patch files and patch information for patch updates of the Windows system in the terminal device; reporting the patch update content to a patch management server to update the patch library, and then using the updated patch library to provide the required patch files to an intranet server; the patch update content includes at least the patch file, patch information, and the Windows system version of the terminal device, and the intranet server is used to provide Windows system patch updates to intranet terminals. This solution can promptly and easily obtain updated patch files to provide the required patch files to intranet terminals.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of computer technology, and in particular to a patch updating method and system based on a hook function. Background Art

[0002] Computer system updates are very frequent. To prevent vulnerabilities and other issues in the systems installed on terminals, Windows systems must be patched and updated promptly. Currently, some enterprises operating within intranet environments cannot access the internet for security reasons. This can cause interruptions during system updates, potentially exposing these terminals to vulnerabilities and other security risks.

[0003] The traditional method for patching intranet terminals is to use web crawlers to obtain updated patch files from the external network. These files are then uploaded to the enterprise's intranet server, which then provides the updated patch files to the intranet terminals. However, this method is not only difficult to crawl, but also suffers from poor timeliness in obtaining patch files. Summary of the Invention

[0004] The embodiment of the present invention provides a patch updating method and system based on a hook function, which can timely and easily obtain the patch files to be updated, so as to provide the required patch files for terminals deployed in the intranet.

[0005] In a first aspect, an embodiment of the present invention provides a patch update method based on a hook function, which is applied to a terminal device, wherein at least one hook function is deployed in the terminal device; the method comprises:

[0006] capturing a system behavior of the terminal device based on the at least one hook function;

[0007] Analyzing whether the captured system behavior is used for a patch update of the Windows system in the terminal device; if so, obtaining a patch file and patch information for the patch update of the Windows system in the terminal device;

[0008] Report the patch update content to the patch management server so that the patch management server updates the patch library based on the patch update content, and then uses the updated patch library to provide the required patch files to the intranet server; the patch update content includes at least the patch file, patch information and the Windows system version of the terminal device, and the intranet server is used to provide Windows system patch updates for terminals deployed on the intranet.

[0009] In a possible implementation, the hook function is used to capture the system behavior of the terminal device generating a file download to a disk;

[0010] The analyzing and determining whether the captured system behavior is used for a patch update of the Windows system in the terminal device includes:

[0011] Based on the file download path included in the system behavior, the downloaded file is obtained from the file download path; and based on the preset patch update characteristics, it is determined whether the downloaded file is a patch file. If so, it is determined that the system behavior is used for patch update of the Windows system in the terminal device.

[0012] In a possible implementation, obtaining a patch file for a Windows system patch update in the terminal device includes:

[0013] The downloaded file is determined as the patch file.

[0014] In a possible implementation, before reporting the patch update content to the patch management server, the method further includes:

[0015] Determine whether the patch file needs to be reported to the patch management server, and if so, report the patch update content to the patch management server.

[0016] In a possible implementation, determining whether the patch file needs to be reported to the patch management server includes:

[0017] Calculating a hash value of the patch file, and sending the hash value and / or patch information to the patch management server, so that the patch management server determines whether the patch file is stored in the patch library based on the hash value and / or patch information;

[0018] When the reporting instruction sent by the patch management server is received, it is determined that the patch file needs to be uploaded to the patch management server.

[0019] In a second aspect, an embodiment of the present invention further provides a patch update method based on a hook function, which is applied to a patch management server. The method includes:

[0020] receiving patch update content reported by multiple terminal devices respectively; the patch update content includes at least a patch file, patch information, and a Windows system version of the corresponding terminal device; the patch file is obtained and reported by the corresponding terminal device when the corresponding terminal device detects that it is undergoing a Windows system patch update, and the patch file is obtained from system behavior captured by at least one hook function deployed on the corresponding terminal device;

[0021] Perform a security check on the received patch file. If the check passes, update the preset patch library based on the received patch update content; the patch library includes patch files and patch information corresponding to the Windows system version;

[0022] In response to receiving a patch file download request sent by the intranet server, the target patch file requested for download is sent to the intranet server according to the patch library and the download request, so that the intranet server uses the target patch file to provide Windows system patch updates for terminals deployed in the intranet.

[0023] In a possible implementation, before receiving the patch update contents respectively reported by the plurality of terminal devices, the method further includes:

[0024] receiving a hash value and / or patch information sent by the terminal device; the hash value is calculated by the terminal device for the patch file to be reported;

[0025] Based on the hash value and / or patch information, it is determined whether the patch file to be reported is stored in the patch library; if not, a reporting instruction is sent to the terminal device to instruct the terminal device to report patch update content including the patch file to be reported.

[0026] In a possible implementation, the plurality of terminal devices cover a plurality of different Windows system versions; and the patch library includes patch files and patch information corresponding to different Windows system versions.

[0027] In one possible implementation, the method further includes: establishing a patch whitelist, and updating the patch whitelist each time a patch update content reported by a terminal device is received; the patch whitelist includes a correspondence between different Windows system versions and patch information;

[0028] Before responding to the patch file download request sent by the intranet server, the method also includes: responding to the query request received by the intranet server and sending the patch whitelist list to the intranet server, so that the intranet server determines whether there is a patch file that needs to be updated based on the patch whitelist list and the patch installation status of the terminal deployed in the intranet, and requests to download the patch file that needs to be updated; the patch installation status includes: the Windows system version corresponding to the terminal deployed in the intranet and the patch information of the currently installed patch file.

[0029] In a third aspect, an embodiment of the present invention further provides a patch update system based on a hook function, comprising: a patch management server and a plurality of terminal devices; wherein each of the terminal devices is deployed with at least one hook function;

[0030] Each of the terminal devices is configured to capture system behavior of the terminal device based on the at least one hook function; analyze whether the captured system behavior is for a patch update of the Windows system in the terminal device; if so, obtain a patch file and patch information for the patch update of the Windows system in the terminal device; and report patch update content to the patch management server; the patch update content includes at least the patch file, patch information, and the Windows system version of the terminal device;

[0031] The patch management server is used to receive patch update content reported by multiple terminal devices respectively; perform a security check on the received patch files, and when the check passes, update the preset patch library according to the received patch update content; the patch library includes patch files and patch information corresponding to the Windows system version; in response to receiving a patch file download request sent by the intranet server, send the target patch file requested for download to the intranet server according to the patch library and the download request, so that the intranet server uses the target patch file to provide Windows system patch updates for terminals deployed on the intranet.

[0032] In a fourth aspect, an embodiment of the present invention further provides an electronic device, comprising a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the method described in any embodiment of this specification is implemented.

[0033] In a fifth aspect, an embodiment of the present invention further provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed in a computer, the computer is caused to execute the method described in any embodiment of this specification.

[0034] An embodiment of the present invention provides a patch update method and system based on a hook function. By deploying a hook function in a terminal device, the hook function can be used to capture the system behavior of the terminal device. By analyzing whether the captured system behavior is used for a patch update of the Windows system in the terminal device, when it is determined that the terminal device is performing a patch update of the Windows system, the patch file for the patch update is obtained and reported to the patch management server. The patch management server updates the patch library to provide the required patch files to the intranet server, and the intranet server then provides the Windows system patch update to the terminals deployed on the intranet. It can be seen that in this solution, capturing the system behavior of the terminal device through the hook function does not affect the business operation of the terminal device itself, and can timely monitor the patch update of the terminal device's Windows system and obtain the patch file, which is relatively easy. In addition, when a terminal device in a networked state performs a patch update, the patch file for the patch update can be quickly updated to the patch library, so that the patch file in the patch library is the latest, thereby ensuring the timely acquisition of the patch files required by the intranet terminal. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0036] Figure 1 This is a patch update system architecture diagram provided by an embodiment of the present invention;

[0037] Figure 2 This is a flow chart of a patch update method based on a hook function provided by one embodiment of the present invention;

[0038] Figure 3 This is a flow chart of another patch update method based on a hook function provided by an embodiment of the present invention;

[0039] Figure 4 This is a structural diagram of a patch update system based on hook functions provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0040] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0041] As mentioned above, obtaining updated patch files from the external network through web crawlers requires continuous web crawling to obtain the latest patch files in a timely manner. However, web crawlers are not only costly but also difficult to use. For example, network regulations may prohibit web crawlers. Therefore, there is no guarantee that the latest patch files can be crawled in a timely manner. If this is not possible, the required patch files cannot be provided to the terminals deployed on the intranet, affecting the security of the intranet terminals.

[0042] Based on the above problems, the inventive concept of the present invention is to build a patch management server, deploy at least one hook function in the terminal device, and use the hook function to monitor the terminal device. When the terminal device performs a patch update on the Windows system, the patch file of the patch update is obtained, and the patch library is quickly updated, so that the required patch files can be provided for the terminals managed by the intranet server, thereby ensuring the security of the intranet terminals.

[0043] Based on the above concept, the system architecture of the embodiment of the present invention is described.

[0044] Please refer to Figure 1 One embodiment of the present invention provides a patch update system, comprising: a patch management server 10 and multiple terminal devices 20. The patch management server 10 can connect to each terminal device 20 when needed; each terminal device 20 can connect to a Microsoft server 50 when needed. The patch management server 10 can connect to an intranet server 30 when needed. The intranet server 30 is connected to multiple terminals 40 via an intranet. These terminals 40 are all deployed within the intranet environment.

[0045] The specific implementation process of the concept of the present invention will be described below with respect to the patch management server and the terminal device in the patch update system.

[0046] Please refer to Figure 2 , a patch update method based on a hook function provided in one embodiment of the present invention, applied to a terminal device, wherein at least one hook function is deployed in the terminal device; the method comprises:

[0047] Step 200: Capture the system behavior of the terminal device based on the at least one hook function.

[0048] The Windows system is built on an event-driven message processing mechanism, and communication between various parts of the system is achieved through the exchange of messages. Hook functions are a platform within the Windows message processing mechanism. Applications can set up subroutines within the platform to monitor specific messages from designated windows, even those created by other processes. When a message arrives, it is processed before the target window's handler function. The hook mechanism allows applications to intercept and process window messages or specific events.

[0049] Among them, at least one hook function can be deployed in the terminal device. When multiple hook functions are deployed, they can be used to process different messages. Pointers of multiple different types of hook functions constitute a hook linked list, which is maintained by the Windows system.

[0050] In order to use the hook function to capture the system behavior of the terminal device, the SetWindowsHookEx function can be used to deploy the hook function to the terminal device.

[0051] In one implementation, the final deployment of the hook function can be achieved through the following function:

[0052]

[0053]

[0054] In the embodiment of the present invention, the hook function can be deployed in the security assistant or anti-virus software of the terminal device to monitor security issues and also to monitor the system behavior of the terminal device to capture the system behavior of the terminal device.

[0055] When a terminal device updates a Windows system patch, it generates system behaviors, such as requesting a patch file from a Microsoft server, receiving the patch file from the Microsoft server, and storing the file on disk. Therefore, it is possible to monitor whether the terminal device has updated the Windows system patch by capturing the terminal device's system behaviors.

[0056] In the embodiment of the present invention, different hook functions can be deployed to capture different system behaviors.

[0057] In one implementation, a hook function may be deployed to capture the system behavior of the terminal device generating network traffic data packets for interacting with the external network, and simultaneously capture the interactive network traffic data packets, and execute step 202 using the captured network traffic data packets.

[0058] In another implementation, a hook function may be deployed to capture the system behavior of the terminal device generating a file download to the disk, and use the system behavior to execute step 202.

[0059] Step 202 , analyzing whether the captured system behavior is used for patch update of the Windows system in the terminal device; if so, obtaining a patch file and patch information for patch update of the Windows system in the terminal device.

[0060] In an embodiment of the present invention, when a hook function is used to capture the system behavior of the terminal device generating a file to be downloaded to a disk, this step 202 may analyze whether the captured system behavior is used for a patch update of the Windows system in the terminal device in the following manner: based on the file download path included in the system behavior, obtaining the downloaded file from the file download path; and determining whether the downloaded file is a patch file based on a preset patch update feature; and if so, determining that the system behavior is used for a patch update of the Windows system in the terminal device.

[0061] The patch update feature may include: the name of the patch file, the format of the patch file and / or the suffix of the patch file.

[0062] Furthermore, when it is determined that the system behavior is for a patch update of the Windows system in the terminal device, the downloaded file is determined as a patch file.

[0063] It should be noted that patch information can be obtained from the downloaded file or parsed from the interactive network data traffic packets. Patch information may include: the operating system to which the patch belongs, the patch list, hardware information and drivers, patch acquisition channels, and official patch file information.

[0064] Step 204: Report the patch update content to the patch management server so that the patch management server updates the patch library based on the patch update content, and then uses the updated patch library to provide the required patch files to the intranet server; the patch update content at least includes the patch file, patch information and the Windows system version of the terminal device, and the intranet server is used to provide Windows system patch updates for terminals deployed on the intranet.

[0065] After obtaining the patch file, it needs to be reported to the patch management server in a timely manner to ensure the timely update of the patch file.

[0066] Considering that the patch management server is connected to multiple terminal devices, the patch management server may have obtained the patch file reported by other terminal devices. In order to prevent repeated reporting of patch files and waste of resources during the reporting process, in one embodiment of the present invention, before step 204, it can also include: determining whether the patch file needs to be reported to the patch management server, and if so, executing step 204.

[0067] In one implementation, it is possible to determine whether the corresponding patch file has been stored in the patch library of the patch management server by reporting patch information.

[0068] In another implementation, it may be possible to determine whether the corresponding patch file is already stored in the patch library of the patch management server by reporting a hash value.

[0069] The method of reporting the hash value may specifically include: calculating the hash value of the patch file, and sending the hash value to the patch management server, so that the patch management server determines whether the patch file is stored in the patch library based on the hash value; when receiving the reporting instruction sent by the patch management server, determining that the patch file needs to be uploaded to the patch management server.

[0070] The patch management server can pre-calculate a hash value for each stored patch file, creating a hash value list. Whenever a reported hash value is received, it is compared against the hash value list. If the reported hash value is included in the hash value list, it indicates that the patch file is already stored in the patch library; otherwise, it indicates that the patch file is not stored in the patch library. Using hash values ​​not only uniquely identifies patch files but also reduces the amount of data transmitted.

[0071] Since there are many Windows system versions on terminal devices, the types of patch files are complex, and the Windows system version corresponds to the patch file, when reporting the patch file, the Windows system version of the terminal device needs to be reported together.

[0072] Among them, the Windows system version can be Windows XP, Windows Vista, Windows 7, Windows 8 / Windows 8.1, Windows 10, Windows 11, etc.

[0073] In an embodiment of the present invention, the terminal device uses the system behavior captured by the hook function to monitor whether it is performing a patch update for the Windows system. When it is monitored that it is performing a patch update for the Windows system, the terminal device obtains the corresponding patch file and patch information, and reports the information to the patch management server. This can achieve rapid updating of the patch library, so that the patch management server can provide the required patch files to the intranet server, and the intranet server can then provide Windows system patch updates to the terminals deployed on the intranet, so as to ensure the timely acquisition of the patch files required by the intranet terminals.

[0074] Please refer to Figure 3 , a patch update method based on a hook function provided by an embodiment of the present invention, applied to a patch management server, the method comprising:

[0075] Step 300, receiving patch update content reported by multiple terminal devices respectively; the patch update content includes at least patch files, patch information and the Windows system version of the corresponding terminal device; the patch files are obtained and reported by the corresponding terminal device when it detects that it is performing a patch update on the Windows system.

[0076] In one implementation, the patch file is obtained from system behavior captured by at least one hook function deployed on the corresponding terminal device.

[0077] The patch information may include: the operating system to which the patch belongs, a patch list, hardware information and drivers, how to obtain the patch, and official information about the patch file.

[0078] Since there are many Windows system versions on terminal devices, the types of patch files are complex, and the Windows system version corresponds to the patch file, when reporting the patch file, the file information of the patch file and the Windows system version of the terminal device need to be reported together.

[0079] Among them, the Windows system version can be Windows XP, Windows Vista, Windows 7, Windows 8 / Windows 8.1, Windows 10, Windows 11, etc.

[0080] In this embodiment of the present invention, to ensure timely patch file acquisition, the terminal device generates the patch file based on system behavior after determining that the system behavior captured by at least one hook function is for a patch update for the Windows system on the terminal device. This indicates that the terminal device reports the patch file almost immediately upon detecting that the Windows system is undergoing a patch update, thereby ensuring timely patch file acquisition.

[0081] In one embodiment of the present invention, since the patch management server is connected to multiple terminal devices, any terminal device can report the patch file to the patch management server when performing a patch update for the Windows system. In order to prevent repeated reporting of patch files and waste of resources during the reporting process, this step may include: receiving a hash value and / or patch information sent by the terminal device; the hash value is calculated by the terminal device for the patch file to be reported; determining whether the patch file to be reported is stored in the patch library based on the hash value and / or patch information, and if not, sending a reporting instruction to the terminal device to instruct the terminal device to report the patch update content containing the patch file to be reported.

[0082] When using the hash value method to determine whether the patch library stores the patch file to be reported, specifically, the patch management server can pre-calculate the hash value for each stored patch file to form a hash value list. Whenever a reported hash value is received, it is compared with the hash value list. If the hash value list includes the reported hash value, it indicates that the patch library has stored the patch file to be reported; otherwise, it indicates that the patch library has not stored the patch file to be reported.

[0083] When using patch information to determine whether the patch library stores the patch file to be reported, specifically, the patch management server can compare the received patch information with the patch information stored in the patch library. If the patch information exists in the patch library, it indicates that the patch file to be reported has been stored in the patch library; otherwise, it indicates that the patch file to be reported is not stored in the patch library.

[0084] In one embodiment of the present invention, since terminals in an enterprise intranet may use different Windows system versions, in order to ensure the comprehensiveness of patch files in the patch library and to be able to provide the required patch files for terminals with different Windows system versions, multiple terminal devices connected to the patch management server can cover multiple different Windows system versions; the patch library includes patch files and patch information corresponding to different Windows system versions.

[0085] For example, the Windows system versions that need to be covered are Windows XP, Windows Vista, Windows 7, Windows 8 / Windows 8.1, Windows 10, and Windows 11. Then, for each of the above Windows system versions, at least one terminal device among the multiple terminal devices connected to the patch management server must have a Windows system of the corresponding covered Windows system version.

[0086] Step 302: Perform a security check on the received patch file. If the check passes, update the preset patch library according to the received patch update content. The patch library includes patch files and patch information corresponding to the Windows system version.

[0087] Since the patch management server needs to provide the required patch files to the intranet servers of different enterprises, it needs to ensure the security of the provided patch files. Therefore, after receiving the patch update content, the patch file can be checked for security to determine whether it is safe and legal.

[0088] In one implementation, the system can connect to external threat intelligence centers and various antivirus engines to perform security checks on patch files.

[0089] Step 304, in response to receiving the patch file download request sent by the intranet server, the target patch file requested for download is sent to the intranet server according to the patch library and the download request, so that the intranet server uses the target patch file to provide Windows system patch updates for terminals deployed in the intranet.

[0090] An intranet server is deployed within an enterprise to provide Windows system patch updates to terminals deployed on the intranet. A patch management server provides services for the intranet server, allowing it to download required patch files.

[0091] To improve user experience and ensure timely patch updates for intranet terminals, one embodiment of the present invention may also include: establishing a patch whitelist, which is updated each time a patch update is received from a terminal device; the patch whitelist includes a mapping between different Windows system versions and patch information. The patch whitelist may include only the latest patch information for the same Windows system version, or it may include both the latest patch information and historical patch information, for selection by the intranet server.

[0092] Before responding to the patch file download request sent by the intranet server, the method also includes: responding to the query request received by the intranet server and sending the patch whitelist list to the intranet server, so that the intranet server determines whether there is a patch file that needs to be updated based on the patch whitelist list and the patch installation status of the terminal deployed in the intranet, and requests to download the patch file that needs to be updated; the patch installation status includes: the Windows system version corresponding to the terminal deployed in the intranet and the patch information of the currently installed patch file.

[0093] Specifically, the intranet server can obtain the patch installation status of the intranet terminal in advance and determine whether there is a patch file that needs to be updated based on the received patch whitelist. The patch file that needs to be updated can be a patch file corresponding to the latest patch information or a patch file corresponding to historical patch information.

[0094] When the intranet server determines that there is a patch file that needs to be updated, it sends a patch file download request to the patch management server. The patch file download request carries the Windows system version and patch information.

[0095] In the embodiment of the present invention, the intranet server may periodically send a query request to the patch management server to determine whether there is a patch file that needs to be updated.

[0096] Furthermore, the patch management server can also classify patch files according to the urgency. When the urgency meets the set conditions, the corresponding patch files can be directly sent to the intranet server so that the intranet server can provide Windows system patch updates to the intranet terminals in a timely manner to ensure the security of the intranet terminals.

[0097] In addition, after obtaining the patch file that needs to be updated, the intranet server can control the intranet terminals to perform patch updates within an appropriate time period.

[0098] In an embodiment of the present invention, the patch management server updates the patch library through the patch update content reported by the terminal device, so that the patch library can provide the required patch files to the intranet server in a timely manner. In turn, the intranet server can provide Windows system patch updates to the terminals deployed on the intranet, thereby ensuring the security of the terminals on the intranet.

[0099] like Figure 4 As shown, an embodiment of the present invention provides a patch update system based on hook functions, comprising: a patch management server 401 and multiple terminal devices 402; wherein each of the terminal devices 402 is deployed with at least one hook function;

[0100] Each of the terminal devices 402 is configured to capture system behavior of the terminal device based on the at least one hook function; analyze whether the captured system behavior is for a patch update of the Windows system in the terminal device; if so, obtain a patch file and patch information for the patch update of the Windows system in the terminal device; and report patch update content to the patch management server; the patch update content includes at least the patch file, patch information, and the Windows system version of the terminal device;

[0101] The patch management server 401 is used to receive patch update content reported by multiple terminal devices respectively; perform a security check on the received patch files, and when the check passes, update the preset patch library according to the received patch update content; the patch library includes patch files and patch information corresponding to the Windows system version; in response to receiving a patch file download request sent by the intranet server, the target patch file requested for download is sent to the intranet server according to the patch library and the download request, so that the intranet server uses the target patch file to provide Windows system patch updates for terminals deployed on the intranet.

[0102] In one embodiment of the present invention, the hook function is used to capture the system behavior of the terminal device generating a file download to a disk;

[0103] When analyzing whether the captured system behavior is used for patch updates of the Windows system in the terminal device, the terminal device is specifically used to: obtain the downloaded file from the file download path based on the file download path included in the system behavior; and determine whether the downloaded file is a patch file based on preset patch update characteristics. If so, determine that the system behavior is used for patch updates of the Windows system in the terminal device.

[0104] In one embodiment of the present invention, when the terminal device obtains a patch file for a patch update of a Windows system in the terminal device, the terminal device is specifically configured to determine the downloaded file as the patch file.

[0105] In one embodiment of the present invention, the terminal device is further configured to determine whether the patch file needs to be reported to the patch management server, and if so, to report the patch update content to the patch management server.

[0106] In one embodiment of the present invention, when determining whether the patch file needs to be reported to the patch management server, the terminal device is specifically configured to: calculate a hash value of the patch file, and send the hash value and / or patch information to the patch management server; and upon receiving a reporting instruction sent by the patch management server, determine that the patch file needs to be uploaded to the patch management server;

[0107] The patch management server is further configured to receive the hash value and / or patch information sent by the terminal device, and determine whether the patch file to be reported is stored in the patch library based on the hash value and / or patch information; if not, a reporting instruction is sent to the terminal device.

[0108] In one embodiment of the present invention, the plurality of terminal devices cover a plurality of different Windows system versions; the patch library includes patch files and patch information corresponding to different Windows system versions.

[0109] In one embodiment of the present invention, the patch management server is also used to establish a patch whitelist list, and update the patch whitelist list whenever the patch update content reported by the terminal device is received; the patch whitelist list includes the correspondence between different Windows system versions and patch information; and in response to receiving a query request from the intranet server, the patch whitelist list is sent to the intranet server, so that the intranet server determines whether there is a patch file that needs to be updated based on the patch whitelist list and the patch installation status of the terminal deployed in the intranet, and requests to download the patch file that needs to be updated; the patch installation status includes: the Windows system version corresponding to the terminal deployed in the intranet and the patch information of the currently installed patch file.

[0110] An embodiment of the present invention further provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, a patch update method based on a hook function in any embodiment of the present invention is implemented.

[0111] An embodiment of the present invention further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the processor executes a patch update method based on a hook function in any embodiment of the present invention.

[0112] Specifically, a system or device equipped with a storage medium can be provided, on which software program codes that implement the functions of any of the above-mentioned embodiments are stored, and a computer (or CPU or MPU) of the system or device can be enabled to read and execute the program codes stored in the storage medium.

[0113] In this case, the program code itself read from the storage medium can realize the function of any one of the above-mentioned embodiments, and thus the program code and the storage medium storing the program code constitute part of the present invention.

[0114] Examples of storage media for providing program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Alternatively, the program code can be downloaded from a server computer via a communication network.

[0115] In addition, it should be clear that the functions of any of the above embodiments can be achieved not only by executing the program code read by the computer, but also by enabling the operating system operating on the computer to complete part or all of the actual operations based on the instructions of the program code.

[0116] In addition, it can be understood that the program code read from the storage medium is written into a memory provided in an expansion board inserted into the computer or into a memory provided in an expansion module connected to the computer, and then based on the instructions of the program code, a CPU installed on the expansion board or expansion module is enabled to perform part or all of the actual operations, thereby realizing the functions of any of the above embodiments.

[0117] It should be noted that, in this article, relational terms such as first and second are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises", "comprising" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprising a ..." do not exclude the presence of other identical factors in the process, method, article or device comprising the elements.

[0118] Those skilled in the art will understand that all or part of the steps of implementing the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: ROM, RAM, disk or optical disk, etc. Various media that can store program codes.

[0119] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A patch update method based on a hook function, characterized in that: Applied to a terminal device, wherein at least one hook function is deployed in the terminal device; the method comprises: capturing a system behavior of the terminal device based on the at least one hook function; Analyzing whether the captured system behavior is used for a patch update of the Windows system in the terminal device; if so, obtaining a patch file and patch information for the patch update of the Windows system in the terminal device; Report the patch update content to the patch management server so that the patch management server updates the patch library based on the patch update content, and then uses the updated patch library to provide the required patch files to the intranet server; the patch update content includes at least the patch file, patch information and the Windows system version of the terminal device, and the intranet server is used to provide Windows system patch updates for terminals deployed on the intranet.

2. The method according to claim 1, characterized in that The hook function is used to capture the system behavior of the terminal device generating a file download to the disk; The analyzing and determining whether the captured system behavior is used for a patch update of the Windows system in the terminal device includes: Based on the file download path included in the system behavior, obtaining the downloaded file from the file download path; And based on the preset patch update feature, it is determined whether the downloaded file is a patch file. If so, it is determined that the system behavior is used for patch update of the Windows system in the terminal device.

3. The method according to claim 2, characterized in that The obtaining of a patch file for a patch update of the Windows system in the terminal device includes: The downloaded file is determined as the patch file.

4. The method according to claim 1, wherein Before reporting the patch update content to the patch management server, the method further includes: Determine whether the patch file needs to be reported to the patch management server, and if so, report the patch update content to the patch management server.

5. The method according to claim 4, characterized in that The determining whether the patch file needs to be reported to the patch management server includes: Calculating a hash value of the patch file, and sending the hash value and / or patch information to the patch management server, so that the patch management server determines whether the patch file is stored in the patch library based on the hash value and / or patch information; When the reporting instruction sent by the patch management server is received, it is determined that the patch file needs to be uploaded to the patch management server.

6. A patch update method based on hook function, characterized in that: Applied to a patch management server, the method includes: receiving patch update content reported by multiple terminal devices respectively; the patch update content includes at least a patch file, patch information, and a Windows system version of the corresponding terminal device; the patch file is obtained and reported by the corresponding terminal device when the corresponding terminal device detects that it is undergoing a Windows system patch update, and the patch file is obtained from system behavior captured by at least one hook function deployed on the corresponding terminal device; Perform a security check on the received patch file. If the check passes, update the preset patch library based on the received patch update content; the patch library includes patch files and patch information corresponding to the Windows system version; In response to receiving a patch file download request sent by the intranet server, the target patch file requested for download is sent to the intranet server according to the patch library and the download request, so that the intranet server uses the target patch file to provide Windows system patch updates for terminals deployed in the intranet.

7. The method according to claim 6, characterized in that Before receiving the patch update contents reported by the plurality of terminal devices respectively, the method further includes: receiving a hash value and / or patch information sent by the terminal device; the hash value is calculated by the terminal device for the patch file to be reported; Based on the hash value and / or patch information, it is determined whether the patch file to be reported is stored in the patch library; if not, a reporting instruction is sent to the terminal device to instruct the terminal device to report patch update content including the patch file to be reported.

8. The method according to claim 6, characterized in that The multiple terminal devices cover multiple different Windows system versions; the patch library includes patch files and patch information corresponding to different Windows system versions.

9. The method according to claim 8, characterized in that The method also includes: establishing a patch whitelist list, and updating the patch whitelist list each time a patch update content reported by a terminal device is received; the patch whitelist list includes a correspondence between different Windows system versions and patch information; Before responding to the patch file download request sent by the intranet server, the method also includes: responding to the query request received by the intranet server and sending the patch whitelist list to the intranet server, so that the intranet server determines whether there is a patch file that needs to be updated based on the patch whitelist list and the patch installation status of the terminal deployed in the intranet, and requests to download the patch file that needs to be updated; the patch installation status includes: the Windows system version corresponding to the terminal deployed in the intranet and the patch information of the currently installed patch file.

10. A patch update system based on hook function, characterized in that: include: A patch management server and multiple terminal devices; wherein each of the terminal devices is deployed with at least one hook function; Each of the terminal devices is configured to capture system behavior of the terminal device based on the at least one hook function; analyze whether the captured system behavior is for a patch update of the Windows system in the terminal device; if so, obtain a patch file and patch information for the patch update of the Windows system in the terminal device; and report patch update content to the patch management server; the patch update content includes at least the patch file, patch information, and the Windows system version of the terminal device; The patch management server is used to receive patch update content reported by multiple terminal devices respectively; perform a security check on the received patch files, and when the check passes, update the preset patch library according to the received patch update content; the patch library includes patch files and patch information corresponding to the Windows system version; in response to receiving a patch file download request sent by the intranet server, send the target patch file requested for download to the intranet server according to the patch library and the download request, so that the intranet server uses the target patch file to provide Windows system patch updates for terminals deployed on the intranet.

11. A computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to execute the method according to any one of claims 1 to 5 or the method according to any one of claims 6 to 9.

Citation Information

Patent Citations

  • Batch automatic updating management method and system for operating system patch

    CN110912728A

  • Vulnerability repair method and device based on intranet patch sharing

    CN111163080A