A terminal security management system and method
By designing the security control module, asset management module and operation supervision module of the terminal security management system, the real-time and efficient problems of enterprise intranet terminal security management are solved, and multi-dimensional real-time security management of network-entry terminals is realized, ensuring the security compliance of information assets and saving labor costs.
Patent Information
- Application Number
- CN202211441546.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-17
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-11-17
AI Technical Summary
The existing technology is difficult to achieve real-time security management of enterprise intranet terminals, resulting in high security risks and labor costs.
Design a terminal security management system, including security management module, asset management module and operation supervision module, through these modules, realize multi-dimensional real-time security management of network-entry terminals.
It realizes online and real-time security management of network access terminals, ensures the stable operation of enterprise intranet networks and information systems, ensures the security and compliance of information assets, and saves labor costs.
Smart Images

Figure CN115801620B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of terminal security management, and in particular, to a terminal security management system and method. Background Art
[0002] With the progress of the times, the informatization level of each company, enterprise and institution is getting higher and higher, and information and network security have become increasingly severe. As the basic equipment for employees to work and process data within an enterprise, the security management of terminals directly affects the development and progress of the enterprise. During the operation of the enterprise, there are strict regulations on the security management of terminals, such as regulations on the networking restrictions of terminals, the download permissions of terminals, the replacement of software and hardware of terminals, the requirement that terminals must install corresponding security products and be in a controllable state, terminal asset management, terminal operation monitoring management, etc.
[0003] When conducting terminal security management, a large amount of manpower and time need to be invested in the periodic inspection of enterprise internal network terminals. However, if manual inspection is carried out by administrators, there may be illegal operations. With the development of the information age, the scale of local area networks is getting larger and larger, and the number of enterprise internal network terminals is increasing. How to solve the terminal security management within the enterprise has become the focus of the enterprise's work. To meet the needs of terminal security management, traditional solutions mostly use terminal access control and host auditing software to implement network settings for user terminals, and perform verification through antivirus software settings and patch settings, and rectify non-compliant terminal configurations and other methods for terminal management. However, due to the inability to update and track in a timely manner, problems existing in the terminals cannot be learned in a timely manner, and there may be security risks. Summary of the Invention
[0004] The present invention provides a terminal security management system and method to achieve real-time and online multi-faceted security management of networked terminals, ensure the stable operation of the enterprise internal network and information system, and save labor costs.
[0005] In a first aspect, this embodiment provides a terminal security management system, which includes: a security control module, an asset management module, and an operation supervision module; wherein,
[0006] The security control module is used for performing security management on the control elements of networked terminals at each stage;
[0007] The asset management module is used for establishing resource information of the networked terminals and giving a change reminder when the resource information of the networked terminals changes;
[0008] The operation supervision module is used for monitoring the network processes of the networked terminals and the software installation conditions of the networked terminals.
[0009] In a second aspect, the present embodiment provides a terminal security management method, which is executed by the terminal security management system described in the embodiment of the first aspect. The method includes:
[0010] Performing security management on the control elements of the networked terminals at each stage through a security control module;
[0011] Establishing the resource information of the networked terminals through an asset management module, and giving a change reminder when the resource information of the networked terminals changes;
[0012] Monitoring the network processes of the networked terminals and the software installation conditions of the networked terminals through an operation supervision module.
[0013] The embodiment of the present invention discloses a terminal security management system and method. The system includes: a security control module, an asset management module, and an operation supervision module. Among them, the security control module is used for performing security management on the control elements of the networked terminals at each stage; the asset management module is used for establishing the resource information of the networked terminals and giving a change reminder when the resource information of the networked terminals changes; the operation supervision module is used for monitoring the network processes of the networked terminals and the software installation conditions of the networked terminals. Different from the manual implementation of security management in the prior art, by using this system, it is possible to perform security management, asset management, and operation monitoring on networked terminals online and in real time, realizing effective multi-faceted real-time security management of networked terminals, ensuring the stable operation of the enterprise internal network and information system, ensuring the security and compliance of information assets, and saving labor costs.
[0014] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0016] Figure 1 It is a schematic structural diagram of a terminal security management system provided in Embodiment 1 of the present invention;
[0017] Figure 2 It is a schematic structural diagram of another terminal security management system provided in Embodiment 1 of the present invention;
[0018] Figure 3Schematic diagram of another terminal security management system provided in Embodiment 1 of the present invention;
[0019] Figure 4 Flow chart of a terminal security management method provided in Embodiment 2 of the present invention;
[0020] Figure 5 Schematic diagram of an electronic device provided in Embodiment 3 of the present invention. Detailed implementation manners
[0021] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0022] It should be noted that the terms "target", "original", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0023] It can be understood that before using the technical solutions of the embodiments of the present invention, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present invention should be informed to users and the authorization of users should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0024] For example, when responding to an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested to be executed will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server, or a storage medium that executes the operation of the technical solution of the present invention according to the prompt message.
[0025] As an optional but non-limiting implementation, in response to receiving an active request from a user, the way to send a prompt message to the user can be, for example, in the form of a pop-up window, and the prompt message can be presented in text in the pop-up window. In addition, the pop-up window can also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0026] It can be understood that the above notification and user authorization acquisition process is only illustrative and does not limit the implementation of the present invention. Other ways that comply with relevant laws and regulations can also be applied to the implementation of the present invention.
[0027] It can be understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the corresponding laws, regulations and related provisions.
[0028] In the existing terminal security management, due to the miscellaneous types and large numbers of terminals, there are currently the following main problems in the security management of these terminals: 1) The security status of the terminals is unknown: It is impossible to accurately query the specific number and type of terminals in the network. After a terminal obtains an Internet Protocol (IP), it can access the network, and it is impossible to determine whether the terminal is legal and compliant. 2) As the network scale continues to expand, complex dependency relationships will form among various user permissions. The traditional manual-based method of configuring network access control policies mainly distributes according to the actual needs of the business system and the principle of minimum permissions. This distribution method ignores the dependency relationships among permissions and is prone to over-authorization, thus bringing security risks to the network. 3) The operating status of the terminals is unknown: Currently, the method of manual statistics and manual inspection is used to record the terminal hardware assets and obtain the operating status of the terminals. The work efficiency is low, and asset changes cannot be detected in a timely manner, with poor real-time performance. It is difficult to count overdue terminals and abnormal terminals. 4) The operation and maintenance status of the terminals is unknown: This leads to low work efficiency, difficult statistics of operation and maintenance work, and repeated operation and maintenance work. To address the above problems, a terminal security management system is needed to solve these problems.
[0029] Embodiment 1
[0030] Figure 1 FIG. 16 is a schematic structural diagram of a terminal security management system provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of security management of networked terminals. The system can be implemented by hardware and / or software and is generally integrated in an electronic device.
[0031] The system includes: a security control module 10, an asset management module 20, and an operation supervision module 30; among them, the security control module 10 is used for security management of the control elements of the networked terminals at each stage; the asset management module 20 is used for establishing the resource information of the networked terminals and giving a change reminder when the resource information of the networked terminals changes; the operation supervision module 30 is used for monitoring the network processes of the networked terminals and the software installation conditions of the networked terminals.
[0032] The terminal security management system provided in this embodiment can perform online security management on networked terminals in real time and in multiple aspects. It can be understood that an enterprise, unit, or other organization with a local area network setting can install a set of terminal security management systems, and this terminal security management system can perform security management on the networked terminals within the local area network. The terminal security management system provided in this embodiment mainly includes a security control module 10, an asset management module 20, and an operation supervision module 30.
[0033] Among them, the security control module 10 is used for security management of the control elements of the networked terminals at each stage.
[0034] In this embodiment, the security control module 10 performs security management on the control elements of the networked terminals at each stage, comprehensively covering all elements of security control during the installation, delivery, and use processes of the terminals. Exemplarily, it can specifically include: achieving accurate traceability of the networked terminals, obtaining the device conditions of the networked terminals, and performing security checks on them, and performing software distribution, remote maintenance, sensitive information checks, etc. during the daily use of the networked terminals.
[0035] Among them, the networked terminals can be specifically understood as the terminals connected to the local area network. The networked terminals can be all network devices or terminal devices connected within the local area network. For example, switches, routers, firewalls, network address translation (Network Address Translation, NAT) devices, multi-port repeaters HUB, personal computers (Personal Computer, PC), mobile terminals, printers, IP phones, cameras, laptop computers, intelligent mobile devices, cloud terminals, and various dumb terminals, etc. The networked terminals are the objects to be controlled by the terminal security management system provided in this embodiment. For the management of the networked terminals, it is necessary to manage the entire life cycle of the networked terminals, including security control during the installation, delivery, and use processes of the terminals.
[0036] Specifically, the security control module 10 provides a network access control mechanism in the networking environment to control whether the networked terminals can enter the networking environment. It allows the access behaviors of legal or authorized devices and blocks, alarms, and audits the access behaviors of illegal or unauthorized devices in real time. In addition, during the use of the networked devices, the security control module 10 is also used to automatically discover all network devices and terminal devices in the network, that is, the connected networked terminals, and classify and count the connected networked terminals. At the same time, the secure login method of the terminal is set, such as secure login through a UKEY, username + password. A UKEY is a small storage device that is directly connected to a computer through a universal serial bus interface, has a password verification function, and is reliable and fast.
[0037] According to the above description, the security control module 10 is also used to perform security inspection and repair on the terminal, check the antivirus software, system patches, and domain joining status of the terminal, prohibit the access of non-compliant terminals to the network, and at the same time support one-key repair of terminals with violations in the inspection of antivirus software, system patches, and domain joining status.
[0038] Furthermore, the security control module 10 also has a function of file watermark tracing. By using technologies such as deep content recognition, watermarks are added to the illegal files stored on the networked terminals. For the behavior of file leakage, by extracting the specific watermarks on the files, it can be set that the watermarks on each networked terminal are different, and the corresponding confidential personnel can be located. Through various watermark technologies such as file watermarks, print watermarks, and vector watermarks, an effective deterrent is formed against the behavior of employees maliciously stealing the core data of the enterprise.
[0039] The asset management module 20 is used to establish the resource information of the networked terminals and send a change reminder when the resource information of the networked terminals changes.
[0040] Among them, the asset management module 20 can collect the software and hardware assets of the networked terminals in the internal network and their specific information. Specifically, the asset management module 20 is used to collect the assets of the networked terminals, specifically including automatically collecting the terminal hardware asset information, including information such as the manufacturer, model, central processing unit, memory, hard disk, network card, optical drive, monitor, keyboard, and mouse, establishing a mapping relationship between the terminal and the fixed asset system, and providing a data basis for cleaning up invalid assets. And when an asset change occurs, for the asset change situation, an alarm message is sent to avoid the loss of internal assets, support hardware asset change alarm and audit, and support exporting the asset change audit report.
[0041] Further, the asset management module 20 is also used to query terminal information, and the query conditions may include asset management number, terminal unique identifier, IP, Media Access Control (MAC), user, user department, whether it has been registered, whether the terminal status is valid or scrapped, activation date, terminal usage, access client status, hardware configuration information, etc.
[0042] The operation supervision module 30 is used to monitor the network processes of the networked terminals and the software installation conditions of the networked terminals.
[0043] In this embodiment, the operation supervision module 30 monitors and manages the operation conditions of the networked terminals, including monitoring and managing the real-time operation status, terminal performance, service life, terminal allocation, and online status of the networked terminals.
[0044] Specifically, the operation supervision module 30 monitors the operation conditions of the networked terminals, including network process monitoring and black and white list control of installed software. Among them, network process monitoring includes: uniformly summarizing and monitoring the processes of each terminal in the network. Exemplarily, it can incrementally display the newly emerged processes in the network, or count the most frequently running processes in the network, so as to count the usage of network client software. The operation supervision module 30 can locate and alarm abnormal processes in the network, and can directly block them when necessary, for example, virus processes.
[0045] In addition, the black and white list control of installed software includes black and white list control of the software installation conditions of the networked terminals. The black and white list of software installation can be formulated to specify the software that is prohibited from installation and the software that must be installed, and measures such as alarm prompt, terminal prompt, and blocking network connection can be taken for the networked terminals that violate the regulations.
[0046] At the same time, the operation supervision module 30 can analyze idle terminals. According to the identification criteria of idle terminals, it can analyze the number and list of idle terminals, providing a basis for revitalizing idle assets. Furthermore, the operation supervision module 30 can also count terminal reports, and count the number of normally used terminals, idle terminals, terminals that have had faults, the number of hardware risk alarms, the number of terminal hardware risk alarm stations, etc. according to month, department, terminal usage, terminal type, and manufacturer. Among them, the terminal type can be divided into desktop computers, laptops, and virtual terminals, etc. Through the setting of the operation supervision module 30, the operation status of the networked terminals can be effectively and timely obtained, with good real-time performance, which is convenient for the administrator to count overdue terminals and abnormal terminals in a timely manner.
[0047] The embodiment of the present invention discloses a terminal security management system, which includes: a security control module, an asset management module and an operation supervision module; wherein the security control module is used to perform security management on the control elements of the network-access terminal at each stage; the asset management module is used to establish the resource information of the network-access terminal and issue a change reminder when the resource information of the network-access terminal changes; the operation supervision module is used to monitor the network process of the network-access terminal and the software installation status of the network-access terminal. Different from the manual security management in the prior art, the system can perform security management, asset management and operation monitoring on the network-access terminal online and in real time, realizing effective multi-faceted real-time security management of the network-access terminal, ensuring the stable operation of the enterprise intranet and information system, ensuring the security and compliance of information assets, and saving labor costs.
[0048] Figure 2 A structural diagram of another terminal security management system provided for Embodiment 1 of the present invention. This optional embodiment is optimized based on Embodiment 1 above. In this embodiment, a security management and control module 10 includes: a network access management and control unit 11, which is used to control the network access of the network access terminal and repair the illegal network access terminal according to the network access mechanism when the network access terminal applies for network access; and a use management and control unit 12, which is used to mark illegal files stored on the network access terminal during the use of the network access terminal, so as to locate the illegal behavior according to the mark.
[0049] Among them, the network access control unit 11 is mainly used to manage the network access application stage of the network access terminal. The network access mechanism can be specifically understood as a pre-set judgment mechanism on whether the terminal can connect to the network. Specifically, when the network access terminal applies for network access, the network access control unit 11 judges whether the terminal can access the network according to the network access mechanism to perform network access control. Among them, the network environment applied for can be a networking environment such as a router, a switch, a HUB, a wireless access point (AccessPoint, AP), a virtual private network (Virtual Private Network, VPN), NAT, etc. The terminal applying for network access can include at least a PC, a laptop, a smart mobile device, a cloud terminal and various dumb terminals. The network access control unit 11 allows access to the access behavior of legal or authorized devices according to the network access mechanism, and blocks, alarms and audits the access behavior of illegal or unauthorized devices in real time.
[0050] The network access control unit 11 can automatically discover all network devices and terminal devices in the networking environment, and classify and count them, including switches, routers, firewalls, NAT devices, HUBs, PCs, mobile terminals, printers, IP phones, cameras, etc., and set a secure login method for the terminal, such as secure login through UKEY, username and password.
[0051] The network access control unit 11 is also used to perform security inspection and repair on the terminal, check the anti-virus software, system patches, and domain joining status of the terminal, prohibit illegal terminals from accessing the network, and at the same time support one-key repair of terminals with violations in the inspection of anti-virus software, system patches, and domain joining status.
[0052] The usage control unit 12 is used for the file watermark tracing function during the usage of the networked terminal. For example, technologies such as deep content recognition can be adopted to add watermarks to illegal files stored on the networked terminal. For the behavior of file leakage, by extracting specific watermarks on the file, here a unique watermark can be set for each networked terminal. By tracing the file watermark, the corresponding confidential personnel can be located. Through various watermark technologies such as file watermarks, print watermarks, and vector watermarks, an effective deterrent can be formed against the behavior of employees maliciously stealing the core data of the enterprise.
[0053] Continue to refer to Figure 2 , furthermore, the security control module further includes a policy management unit 13, and the policy management unit 13 is specifically used for:
[0054] a1. According to the characteristic information and security configuration information of the visitor of the networked terminal, respectively determine the deserved permissions and actual permissions of the visitor.
[0055] Among them, the characteristic information of the visitor includes the basic characteristics and behavior characteristics of the visitor. Among them, the basic characteristics are the basic attributes of the visitor, including age, gender, occupation, and IP address, etc., and the behavior characteristics include the visitor terminal address level, the visitor's Internet access environment information, the visitor's Internet access time period information, etc.
[0056] In this embodiment, when performing a network security risk assessment on the networked terminal, permission allocation should be carried out according to the optimal security policy. In this embodiment, the policy management unit 13 is used to determine the optimal security policy to allocate permissions to the visitor according to the optimal security policy. When performing security policy allocation, the permissions of the visitor include the deserved permissions of the visitor, the initial permissions of the visitor, and the actual permissions of the visitor. Among them, the deserved permissions of the visitor refer to the permissions that the visitor should obtain according to the attribute information of the visitor. The initial permissions of the visitor refer to the permissions clearly allocated to the personnel according to the security policies of the physical domain and information domain of the cyberspace, and these permissions can be obtained by analyzing relevant security configurations; the actual permissions of the visitor are the visitor permissions obtained by the visitor according to the network initial permissions, and these permissions need to be inferred from the visitor initial permissions according to the dependency relationship between network permissions.
[0057] b1. According to the deserved permissions and actual permissions of the visitor, combined with the set security risk function, determine the security risk value.
[0058] In this step, the network risk security of the current visitor is evaluated, mainly measured according to the difference between the permissions the visitor should have and the actual permissions of the visitor. The weights of the visitor's permissions are set as follows: ω = (ω1, ω2, …, ω n ), where ω1, ω2, …, ω n respectively represent the access permission weight values of the visitor to each networked terminal. Under this security configuration, the security risk can be expressed as: where PA is the actual permission matrix of the visitor, PD is the permission matrix that the visitor should have, the function abs(S) represents calculating the absolute value of each element in the vector or matrix, and || ||1 represents the L1 norm of the matrix.
[0059] c1. For the configuration parameters in the security configuration information, the particle swarm optimization algorithm is used to calculate the security risk value until the security risk value meets the preset security risk condition to determine the target parameter value of the configuration parameter.
[0060] In this embodiment, by calculating the security risk values corresponding to different security configuration information, the particle swarm algorithm is used to automatically generate the optimal security policy, which can also be understood as the security configuration information under the optimal security policy. Among them, the preset security risk condition can be understood as that the security risk value is less than the set threshold, and the set threshold can be determined according to historical experience values. In this step, the particle swarm optimization algorithm is used to optimize the security configuration information. The particle swarm optimization algorithm is an evolutionary computing technology, originating from the study of the behavior of bird flocks. The basic idea of the particle swarm optimization algorithm is: to find the optimal solution through the cooperation and information sharing among individuals in the group. Reasonably configuring network security devices is an important task of network security management and an inevitable requirement to avoid potential security risks.
[0061] Considering the traditional method of manually configuring network security devices, it is difficult to reasonably match the configurations of multiple security devices when the network scale continues to expand, and configuration errors and policy conflicts are likely to occur. In this embodiment, by collecting user attribute information, the actual permissions of users are inferred under different security configurations, and the particle swarm algorithm is used to automatically generate network security device configurations, which can automatically generate reasonable network security device configurations according to network security policies and effectively reduce potential network security risks.
[0062] The principle of using the particle swarm algorithm for optimal setting is as follows:
[0063] S1: Population initialization. First, an initial population is generated, and the velocity and position of each particle are randomly initialized in the search space. The fitness function value is calculated, and the historical optimal position of the particle and the global optimal position of the group are obtained.
[0064] S2: Update the velocity and position of each particle, and update the velocity and position of the particle according to its own historical optimal position and the global position.
[0065] S3: Evaluate the fitness function value of the particle, and update the historical optimal position and the global optimal position of the particle.
[0066] S4: If the end condition is satisfied, output the global optimal result and end the program; otherwise, turn to S2 and continue to execute. The security policy corresponding to this global optimal result is the optimal policy found.
[0067] In this embodiment, by collecting the characteristic information of visitors, inferring the actual permissions of visitors under different security configurations, and using the particle swarm optimization algorithm to automatically generate network security device configurations, it is possible to automatically generate reasonable network security device configurations according to network security policies, effectively reducing potential network security risks.
[0068] Furthermore, the policy management unit is used to execute the steps of determining the target parameter values of the configuration parameters, including:
[0069] a. Set an iteration variable and initialize the value of the iteration variable to zero.
[0070] Exemplarily, the particle swarm optimization algorithm is an iterative solution algorithm. Therefore, at the beginning of the algorithm, an iteration variable needs to be set and its value initialized to zero.
[0071] b. Determine the set of candidate configuration parameters in the security configuration information.
[0072] For the sake of easy expression, in this embodiment, a set of parameter values used as the input value of the algorithm is called a set of candidate parameter values and added to the set of candidate configuration parameters set.
[0073] c. Determine the corresponding update coefficients for each set of candidate parameter values in the set of candidate configuration parameters.
[0074] In this embodiment, it is also necessary to determine the corresponding update coefficients for each set of candidate parameter values in the set of candidate configuration parameters to update the corresponding candidate parameter values based on the update coefficients during the iteration process.
[0075] d. Based on the security risk function, calculate the security risk values corresponding to at least one set of candidate parameter values in the set of candidate configuration parameters.
[0076] e. Determine the minimum value among at least one security risk value, denote the minimum value as the candidate security risk value, and store the candidate security risk value and the corresponding candidate configuration parameter values in the set cache.
[0077] In this embodiment, based on steps d and e, the current optimal value of the algorithm at the current iteration can be determined. Exemplarily, the current optimal value can specifically be the minimum value among the calculated security risk values in this embodiment, and this minimum value is denoted as the candidate cost value.
[0078] Generally, for the particle swarm optimization algorithm, it is necessary to store the current optimal value determined in each iteration in a set cache to facilitate the determination of the final target optimal value. Therefore, in this embodiment, the candidate cost value and the corresponding candidate parameter values are stored in a set cache.
[0079] f. Determine whether the set security risk condition is satisfied. If not, execute step g; if so, execute step h.
[0080] Generally, it is necessary to end the loop iteration of the algorithm based on the security risk condition. In this embodiment, the set security risk value condition is used as the end condition.
[0081] g. Perform a self-increment operation on the iteration variable, and update the corresponding candidate configuration parameter values in the candidate configuration parameter set based on the update coefficient to form a new candidate configuration parameter set, and then return to step c.
[0082] h. Determine the minimum value of the candidate security risk values in the set cache, output the candidate configuration parameter value corresponding to the minimum value as the target parameter value of the configuration parameter, and end the loop operation.
[0083] Continue to refer to Figure 2 , further, the security control module 10 further includes a mobile device management unit 14, and the mobile device management unit 14 is used for:
[0084] a2. Set the mobile device to access the networked terminal according to the authorization information of the mobile device.
[0085] Among them, the mobile device refers to mobile storage media such as USB flash drives and external hard drives. Further, the security control module 10 further includes a mobile device management unit 14. The mobile device management unit 14 has the function of managing mobile storage devices, performs registration and authorization of mobile storage devices, writes protection labels on mobile storage media, first protects the information existing in devices such as USBs and external hard drives, and then through the authorization policy, assigns the permissions of terminals that can recognize this label. The assignment objects can be a computer, a region, a department, or a custom computer group.
[0086] Among them, the mobile device must be uniformly registered and authorized by the authorization center before use, including real-name registration, specifying an authorized computer, whether to use password protection, etc. The administrator can identify the mobile device and track the medium through the registration information. Specifically, the mobile device management unit 14 sets the access control permission of the mobile device. An authorized mobile device can be used normally on the enterprise intranet computer. When an unauthorized mobile device accesses the computer, the system will automatically close the USB port of the network access terminal, and the unauthorized mobile device cannot be used on the computer, effectively preventing the management chaos of USB storage devices and the occurrence of data leakage problems caused by the illegal use of USB storage devices.
[0087] b2. Encrypt the data in the mobile device to realize the display of data according to the authorization information of the mobile device.
[0088] Specifically, encrypt and protect the data in the mobile device. Exemplarily, transparent encryption technology is used to realize automatic encryption and decryption of data copying. The encrypted data can only be used on the network access terminal (such as a computer) installed with the engine. When using the mobile device on an unauthorized network access terminal, the data will exist in ciphertext and the user cannot use it. This function uses a public encryption algorithm and can replace the encryption algorithm according to the actual needs of the user.
[0089] c2. Set the access type of the network access terminal to the files in the mobile device.
[0090] Specifically, set the file access control function, and set that the network access terminal is only allowed to access the file extension types of the mobile device. For example, only office type files can be accessed, and other types of files cannot be accessed. In addition, all file access records are audited.
[0091] d2. Set the data copying function.
[0092] Specifically, set the out-of-office copying function. Exemplarily, when the user needs to carry a USB flash drive out of the office for data interaction, the out-of-office copying function can be used. The out-of-office copying function is to interact the data safely stored in the USB flash drive with a computer without a client program installed outside.
[0093] e2. Set the access permission and access range of the mobile device.
[0094] Specifically, set specific mobile device usage control rules, which can identify the usage control of mobile devices, classify and label the mobile devices to be accessed by the network access terminal, allow the access of mobile devices with specified labels, and disable the access of other mobile devices. At the same time, set the usage range of mobile storage devices to clarify which mobile devices can be used in which range. Exemplarily, set the authentication of USB flash drives for different companies or different departments of a unit to prevent the cross-use of mobile devices.
[0095] Continue to refer to Figure 2 Furthermore, the security control module 10 further includes an auditing unit 15, and the auditing unit is used for:
[0096] a3. Determine the primary behavior permissions of the network access terminal according to the historical legal behaviors associated with the network access terminal and in combination with a set algorithm.
[0097] Specifically, the auditing unit 15 is used to audit the behaviors of the network access terminal. The terminal behaviors may specifically include the specific websites accessed by the terminal, email behaviors, access traffic, shared directories, account permissions, etc., which are not specifically limited here. Among them, the set algorithm is an association analysis algorithm, such as the FP-Growth algorithm. An unsupervised learning model is established based on the historical legal behavior data of the network access terminal, and using the association analysis algorithm, the primary behavior permissions of the behaviors of each network access terminal are analyzed from multiple dimensions such as the specific websites accessed by the terminal, email behaviors, access traffic, shared directories, account permissions, etc. The primary behavior permissions can be understood as the primary behavior threshold baseline.
[0098] b3. Modify the primary behavior permissions to obtain the behavior threshold baseline of the network access terminal.
[0099] Specifically, after determining the primary behavior permissions, that is, the primary behavior threshold baseline, the administrator can identify the size of the behavior permissions of each terminal one by one or by sampling according to the algorithm analysis results and modify the data. It can be understood that each network access terminal has a corresponding behavior threshold baseline.
[0100] c3. Compare the current behavior of the network access terminal with the behavior threshold baseline to determine whether the current behavior is an abnormal behavior.
[0101] Specifically, this step is used to identify whether there is an abnormal behavior of the network access terminal when there is a new behavior on the network access terminal. Each network access terminal has a corresponding behavior threshold baseline. When a new behavior occurs on the terminal, it will be automatically compared with the behavior threshold baseline to determine whether there is an over-standard behavior.
[0102] d3. If so, give an alarm prompt.
[0103] Specifically, when the auditing unit 15 identifies an over-standard behavior, it will automatically give an alarm.
[0104] In this optional embodiment, when auditing the terminal behaviors, an unsupervised learning model is established using the association analysis algorithm to analyze whether there is an abnormal behavior of the network access terminal, effectively solving the problem of huge workload caused by the large number of terminals, reducing the workload of the administrator, saving labor costs, and improving management efficiency.
[0105] Figure 3This is a schematic structural diagram of another terminal security management system provided by Embodiment 1 of the present invention. This optional embodiment is optimized based on the above-mentioned Embodiment 1. The system further includes an operation and maintenance support module 40, which is used for: remotely maintaining the networked terminals, remotely managing files, and performing remote control operations.
[0106] Specifically, the operation and maintenance support module 40 is used to remotely maintain the networked terminals. When performing remote maintenance, it must be approved by the controlled networked terminals before execution, and a prompt will be given to the controlled networked terminals when exiting. All operations of the remote maintenance are visible to the controlled terminals.
[0107] At the same time, the operation and maintenance support module 40 has the function of remote file management, which specifically includes: being able to view all files of the networked terminals; being able to copy files between the management end (local) and the managed end (remote); being able to create and delete folders on the management end and the managed end; being able to delete files on the management end and the managed end; for security reasons, the terminal users have the right to decide whether to accept the remote file management request.
[0108] Continue to refer to Figure 3 This optional embodiment is optimized based on the above-mentioned Embodiment 1. The system further includes a download management module 50, which is used for: recommending, downloading, and managing software for the networked terminals.
[0109] Specifically, the download management module 50 is used to recommend, download, and manage software for the networked terminals, quickly and conveniently locate the software to be downloaded according to classification, name, latest, popular, etc., and requires support for intelligent software recommendation and breakpoint resume.
[0110] Continue to refer to Figure 3 This optional embodiment is optimized based on the above-mentioned Embodiment 1. The system further includes a display module 60, which is used for: presenting the configuration information and prompt information associated in the entire life cycle of the networked terminals in a visual manner.
[0111] Specifically, the display module 60 is used to present the function configurations and various security warning events associated in the entire life cycle of the networked terminals to the administrator, facilitating the administrator to quickly and conveniently understand the security events of the networked terminals and comprehensively manage the networked terminals.
[0112] This optional embodiment specifies that the terminal security management system further includes an operation and maintenance support module, a download management module, and a display module. The working process of the terminal security management system can comprehensively cover all elements in the process of terminal installation, delivery, and use, can implement real-name network access detection, enable the administrator to timely master the operation status of the terminals, and can better achieve the safe and comprehensive management of each terminal.
[0113] Embodiment 2
[0114] Figure 4 This is a flowchart of a terminal security management method provided in the second embodiment of the present invention. This method is applicable to the situation of security management of networked terminals. This method can be executed by the terminal security management system provided in the above embodiment. The system can be implemented by hardware and / or software and is generally integrated in an electronic device. As Figure 4 shown, a terminal security management method provided in the second embodiment specifically includes the following steps:
[0115] S410. Perform security management on the control elements of the networked terminal at each stage through a security control module.
[0116] In this embodiment, security management is performed on the control elements of the networked terminal at each stage through a security control module, comprehensively covering all elements of security control during the installation, delivery, and use of the terminal. Exemplarily, it can specifically include: achieving accurate traceability of the networked terminal, obtaining the device situation of the networked terminal, and performing a security check on it. During the daily use of the networked terminal, software distribution, remote maintenance, sensitive information check, etc. are performed on it.
[0117] Among them, the networked terminal can be specifically understood as a terminal connected to a local area network. The networked terminal can be all network devices or terminal devices connected within the local area network. For example, switches, routers, firewalls, network address translation (Network Address Translation, NAT) devices, multi-port repeaters HUB, personal computers (Personal Computer, PC), mobile terminals, printers, IP phones, cameras, laptop computers, intelligent mobile devices, cloud terminals, and various dumb terminals, etc. The networked terminal is the object controlled by the terminal security management system provided in this embodiment. For the management of the networked terminal, it is necessary to manage the entire life cycle of the networked terminal, including security control during the installation, delivery, and use of the terminal.
[0118] S420. Establish resource information of the networked terminal through an asset management module and give a change reminder when the resource information of the networked terminal changes.
[0119] Among them, through the asset management module, the software and hardware assets of the networked terminals in the intranet and their specific information can be collected. Specifically, through the asset management module, the assets of the networked terminals are collected, specifically including automatically collecting the information of the terminal hardware assets, including information such as the manufacturer, model, central processing unit, memory, hard disk, network card, optical drive, monitor, keyboard, and mouse, establishing the mapping relationship between the terminal and the fixed asset system, and providing a data basis for cleaning up invalid assets. And when asset changes occur, warning information is sent according to the asset change situation to avoid the loss of internal assets, support hardware asset change warnings and audits, and support exporting asset change audit reports.
[0120] Furthermore, through the asset management module, terminal information can also be queried, and the query conditions can include the asset management number, terminal unique identifier, IP, MAC, user, user department, whether it has been registered, whether the terminal status is valid or scrapped, start date, terminal usage, access client status, hardware configuration information, etc.
[0121] S430. Monitor the network processes of the networked terminals and the software installation situation of the networked terminals through the operation supervision module.
[0122] In this embodiment, the operation situation of the networked terminals is monitored and managed through the operation supervision module, including monitoring and managing the real-time operation status, terminal performance, service life, terminal allocation, and online situation of the networked terminals.
[0123] Specifically, the operation situation of the networked terminals is monitored through the operation supervision module, including network process monitoring and black and white list control of installed software. Among them, network process monitoring includes: uniformly summarizing and monitoring the processes of each terminal in the network. Exemplarily, newly emerging processes in the network can be incrementally displayed, or the most frequently running processes in the network can be counted, so as to count the usage of network client software. This operation supervision module can locate and alarm abnormal processes in the network and directly block them when necessary, such as virus processes.
[0124] In addition, black and white list control of installed software includes black and white list control of the software installation situation of the networked terminals. The black and white list of software installation can be formulated, specifying the software that is prohibited from installation and the software that must be installed, and measures such as alarm prompts, terminal prompts, and blocking network access can be taken for the networked terminals that violate the regulations.
[0125] Meanwhile, through the operation supervision module, idle terminal analysis can be carried out. According to the identification criteria of idle terminals, the number and list of idle terminals can be analyzed, providing a basis for revitalizing idle assets. Moreover, through the operation supervision module, terminal reports can also be statistically analyzed. According to months, departments, terminal usage, terminal types, and manufacturers, the number of terminals in normal use, the number of idle terminals, the number of terminals that have had failures, the number of hardware risk alarms, and the number of terminal hardware risk alarm stations can be statistically obtained. Among them, terminal types can be divided into desktop computers, laptops, and virtual terminals, etc. Through the settings of the operation supervision module, the operation status of networked terminals can be effectively and timely obtained, with good real-time performance, facilitating administrators to statistically analyze overdue terminals and abnormal terminals in a timely manner.
[0126] An embodiment of the present invention discloses a terminal security management method, which includes: performing security management on the control elements of networked terminals at each stage through a security control module; establishing resource information of networked terminals through an asset management module and giving a change reminder when the resource information of networked terminals changes; monitoring the network processes of networked terminals and the software installation conditions of networked terminals through an operation supervision module. Different from the prior art in which security management is manually implemented, using this system, it is possible to perform security management, asset management, and operation monitoring on networked terminals online and in real time, achieving effective multi-faceted real-time security management of networked terminals, ensuring the stable operation of the enterprise intranet network and information system, ensuring the security and compliance of information assets, and saving labor costs.
[0127] The above method can be executed by the terminal security management system provided by the embodiments of the present invention and has the beneficial effects of the terminal security management system.
[0128] Embodiment III
[0129] Figure 5 It is a schematic structural diagram of an electronic device provided for Embodiment III of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present invention described herein and / or required.
[0130] Such as Figure 5As shown, the electronic device 50 includes at least one processor 51 and a memory communicatively connected to the at least one processor 51, such as a read-only memory (ROM) 52, a random access memory (RAM) 53, etc. The memory stores a computer program executable by the at least one processor. The processor 51 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 52 or the computer program loaded from the storage unit 58 into the random access memory (RAM) 53. In the RAM 53, various programs and data required for the operation of the electronic device 50 can also be stored. The processor 51, the ROM 52, and the RAM 53 are connected to each other via a bus 54. An input / output (I / O) interface 55 is also connected to the bus 54.
[0131] Multiple components in the electronic device 50 are connected to the I / O interface 55, including: an input unit 56, such as a keyboard, a mouse, etc.; an output unit 57, such as various types of displays, speakers, etc.; a storage unit 58, such as a magnetic disk, an optical disc, etc.; and a communication unit 59, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 59 allows the electronic device 50 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0132] The processor 51 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 51 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 51 executes the various methods and processes described above, such as the terminal security management method.
[0133] In some embodiments, the terminal security management method can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as the storage unit 58. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 50 via the ROM 52 and / or the communication unit 59. When the computer program is loaded into the RAM 53 and executed by the processor 51, one or more steps of the terminal security management method described above can be executed. Alternatively, in other embodiments, the processor 51 can be configured to execute the terminal security management method by any other appropriate means (e.g., by means of firmware).
[0134] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.
[0135] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine, or entirely on the remote machine or server.
[0136] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0137] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0138] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0139] The computing system can include a client and a server. The client and the server are generally far from each other and usually interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0140] It should be understood that various forms of the processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is imposed herein.
[0141] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A terminal security management system, characterized in that, include: Security control module, asset management module and operation supervision module; among them, The security control module is used to perform security management on the control elements of network terminals at various stages; An asset management module, used to establish resource information of the network access terminal and to provide a change reminder when the resource information of the network access terminal changes; An operation monitoring module, used to monitor the network process of the network-access terminal and the software installation status of the network-access terminal; The security control module further includes a policy management unit, which is specifically used to: Determining the visitor's due authority and actual authority according to the visitor's characteristic information and security configuration information; Determine the security risk value according to the visitor's due authority and actual authority, combined with a set security risk function; wherein the visitor's actual authority is inferred from the visitor's initial authority based on the dependency relationship between network authorities; For the configuration parameters in the security configuration information, the security risk value is calculated based on a particle swarm optimization algorithm until the security risk value meets a preset security risk condition, so as to determine a target parameter value of the configuration parameter; The security control module also includes an audit unit, which is used to: Determine the primary behavior authority of the network access terminal according to the historical legal behavior associated with the network access terminal and in combination with a setting algorithm; wherein the setting algorithm is a correlation analysis algorithm; Modifying the primary behavior authority to obtain a behavior threshold baseline of the network access terminal; Compare the current behavior of the network access terminal with the behavior threshold baseline to determine whether the current behavior is abnormal behavior; If so, an alarm is issued.
2. The system according to claim 1, wherein The security control module includes: A network access control unit, configured to control the network access of the network access terminal and repair the illegal network access terminal according to the network access mechanism when the network access terminal applies for network access; A control unit is used to mark illegal files stored on the network access terminal during use of the network access terminal, so as to locate the illegal behavior according to the mark.
3. The system according to claim 1, wherein The policy management unit is used to perform a step of determining a target parameter value of the configuration parameter, including: a. Set an iteration variable and initialize the value of the iteration variable to zero; b. determining a candidate configuration parameter set in the security configuration information; c. determining a corresponding update coefficient for each group of candidate parameter values in the candidate configuration parameter set; d. calculating, based on the security risk function, a security risk value corresponding to at least one set of candidate parameter values in the candidate configuration parameter set; e. determining a minimum value among the at least one security risk value, recording the minimum value as a candidate security risk value, and storing the candidate security risk value and the corresponding candidate configuration parameter value in a setting cache; f. Determine whether the set security risk conditions are met. If not, execute step g; if yes, execute step h; g. Perform an auto-increment operation on the iteration variable, and based on the update coefficient, perform an update operation on the corresponding candidate configuration parameter value in the candidate configuration parameter set to form a new candidate configuration parameter set, and then return to step c; h. Determine the minimum value of the candidate security risk value in the set cache, output the candidate configuration parameter value corresponding to the minimum value as the target parameter value of the configuration parameter, and end the loop operation.
4. The system according to claim 1, wherein The security control module further includes a mobile device management unit, and the mobile device management unit is configured to: Set the mobile device to access the networked terminal according to the authorization information of the mobile device; Encrypt the data in the mobile device to enable the display of the data according to the authorization information of the mobile device; Set the access type of the networked terminal to the files in the mobile device; Set the data copy function; Set the access permission and access range of the mobile device.
5. The system according to claim 1, wherein It further includes an operation and maintenance support module, which is used to: Perform remote maintenance, remote file management, and remote control operations on the networked terminal.
6. The system according to claim 1, wherein It further includes a download management module, which is used to: Recommend, download, and manage software for the networked terminal.
7. The system according to claim 1, characterized in that It further includes a display module, which is used to: Present the configuration information and prompt information associated with the entire life cycle of the networked terminal in a visual manner.
8. A terminal security management method, characterized in that, Executed by the terminal security management system according to any one of claims 1-7, the method includes: Perform security management on the control elements of the networked terminal at each stage through the security control module; Establish the resource information of the networked terminal through the asset management module, and give a change reminder when the resource information of the networked terminal changes; Monitor the network processes of the networked terminal and the software installation status of the networked terminal through the operation and supervision module.
Citation Information
Patent Citations
Implementation method for safely managing intranet terminal
CN105138920A