Security monitoring method and device, electronic equipment and storage medium

By using the risk operation command list, implementation basis prompts, and simulated execution of the network device monitoring platform, security risks during the use of network devices were resolved, and monitoring and compliance checks of high-risk operations were achieved, thereby improving the security and compliance of the devices.

CN115913716BActive Publication Date: 2026-05-15INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INDUSTRIAL AND COMMERCIAL BANK OF CHINA
Filing Date
2022-11-16
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

The current technology has a simple user permission division, which leads to security risks during the use of network devices. It lacks monitoring and blocking measures for high-risk operations, and user login lacks a dynamic authentication mechanism, making it impossible to detect non-compliant device configurations in a timely manner.

Method used

The system obtains operation commands through the network device monitoring platform, matches them with a list of risky operation commands, prompts users to provide implementation basis, simulates the execution of operation commands, compares compliance requirements, provides authentication methods of different strengths according to the importance level of the device and the login environment, and automatically identifies user status and configuration compliance.

Benefits of technology

It improves the security of network devices, ensures that every risky operation command is traceable, prevents unauthorized logins, and promptly blocks or approves high-risk operations, thereby enhancing compliance and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115913716B_ABST
    Figure CN115913716B_ABST
Patent Text Reader

Abstract

The present disclosure provides a security monitoring method, which can be applied to a network device monitoring platform, and can be applied to the field of information security and the field of finance. The security monitoring method comprises the following steps: obtaining an operation command sent by a client to a network device; in the case that the operation command is contained in a risk operation command list corresponding to the network device, sending prompt information to the client, wherein the prompt information is used to prompt the client to fill in an implementation basis corresponding to the operation command; and in response to the implementation basis from the client, in the case that the implementation basis is contained in a preset implementation basis list, sending the operation command to the network device, wherein the implementation basis list is an operation command list that has been pre-applied and passed, and the implementation basis list comprises an implementation basis corresponding to the operation command that has been applied and passed. The present disclosure also provides a security monitoring device, equipment and storage medium.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the fields of information security and finance, and more specifically to a security monitoring method, device, equipment, medium, and program product. Background Technology

[0002] With the development of network technology, computer networks play an irreplaceable role in various sectors of society, including commerce, finance, transportation, communications, and services. Network equipment, as the infrastructure of computer networks, carries the critical services of application systems in these sectors and plays a crucial supporting role in the normal operation of these services.

[0003] To improve network security, current network devices typically categorize users into high-privilege and low-privilege users, assigning different usage permissions to users with different privileges.

[0004] In the process of realizing the inventive concept disclosed herein, the inventors discovered that the related technologies have at least the following problems: Although the related technologies divide users into high-privilege users and low-privilege users, the division method is simple and there are still certain security risks in the process of using network devices. Summary of the Invention

[0005] In view of the above problems, this disclosure provides a security monitoring method, apparatus, equipment, medium and program product.

[0006] According to one aspect of this disclosure, a security monitoring method is provided, applied to a network device monitoring platform, the method comprising:

[0007] Obtain the operation commands sent by the client to the aforementioned network devices;

[0008] If the list of risk operation commands corresponding to the aforementioned network devices contains the aforementioned operation commands, a prompt message is sent to the aforementioned client, wherein the prompt message is used to prompt the aforementioned client to fill in the implementation basis corresponding to the aforementioned operation commands; and

[0009] In response to the aforementioned implementation basis from the aforementioned client, if it is determined that the aforementioned implementation basis is included in the preset implementation basis list, the aforementioned operation command is sent to the aforementioned network device, wherein the aforementioned implementation basis list is a list of operation commands that have been pre-approved, and the aforementioned implementation basis list includes the implementation basis corresponding to the aforementioned approved operation commands.

[0010] According to embodiments of this disclosure, the above method further includes:

[0011] Before sending the above operation command to the above network device, the above operation command is executed in a simulation environment to obtain simulation results;

[0012] If the simulation results meet the preset conditions, the above operation command is sent to the network device.

[0013] According to embodiments of this disclosure, sending the operation command to the network device when the simulation result meets preset conditions includes:

[0014] The simulation results were compared with the list of compliance requirements corresponding to the network devices to obtain the comparison results.

[0015] If the above comparison results indicate that the above simulation results meet the compliance requirements in the above compliance requirements list, then send the above operation command to the above network device.

[0016] According to embodiments of this disclosure, the above method further includes:

[0017] If the simulation results do not meet the preset conditions, the importance level of the network device shall be determined.

[0018] Determine the corresponding handling method based on the importance level of the aforementioned network devices;

[0019] The above-described handling method shall be used to process the above-described operation command.

[0020] According to embodiments of this disclosure, the above-mentioned method of determining the corresponding handling method based on the importance level of the network device includes:

[0021] If the importance level of the aforementioned network device is determined to be Level 1, the corresponding handling method is to block the aforementioned operation command.

[0022] If the importance level of the aforementioned network equipment is determined to be Level 2, the corresponding handling method is to send a first approval request to the first approver.

[0023] According to embodiments of this disclosure, the above method further includes:

[0024] In response to the login request to the aforementioned client, obtain the login environment information of the aforementioned client;

[0025] If the above login environment information does not conform to the preset login list, the login risk level is determined based on the login environment information;

[0026] Based on the above login risk level, the target processing method is determined from the preset login processing method set;

[0027] The login request is processed using the target processing method described above.

[0028] According to embodiments of this disclosure, the login environment information includes at least one login attribute and attribute data corresponding to the login attribute.

[0029] In cases where the login environment information does not conform to the preset login list, the login risk level is determined based on the login environment information, including:

[0030] Identify login attributes and attribute data in the above login environment information that do not conform to the above preset login list, and obtain the target login attributes and target attribute data.

[0031] The login risk level is determined based on the aforementioned target login attributes and target attribute data.

[0032] According to embodiments of this disclosure, the login attributes include one or more of the following: login time identifier, login location identifier, client identifier, Internet protocol identifier, link identifier, and operating system identifier.

[0033] According to embodiments of this disclosure, the above-mentioned login processing methods include: blocking login, sending a second approval request to a second approver, and performing verification code authentication;

[0034] The target processing method determined from the preset set of login processing methods based on the aforementioned login risk level includes:

[0035] If the above-mentioned login risk level is determined to be high risk, the above-mentioned target handling method is determined to be blocking login;

[0036] If the above-mentioned login risk level is determined to be medium risk, the above-mentioned target processing method is to send a second approval request to the second approver;

[0037] If the above login risk level is determined to be high risk, the target processing method is to perform CAPTCHA authentication.

[0038] Another aspect of this disclosure provides a security monitoring device for use in a network device monitoring platform, the device comprising:

[0039] The first acquisition module is used to acquire operation commands sent by the client to the aforementioned network devices;

[0040] The first sending module is configured to send a prompt message to the client when the risk operation command list corresponding to the aforementioned network device contains the aforementioned operation command. The prompt message prompts the client to fill in the implementation basis corresponding to the aforementioned operation command.

[0041] The second sending module is used to respond to the implementation basis from the client and, if it is determined that the implementation basis is included in the preset implementation basis list, send the operation command to the network device, wherein the implementation basis list is a list of operation commands that have been applied for in advance, and the implementation basis list includes the implementation basis corresponding to the operation command that has been applied for in advance.

[0042] Another aspect of this disclosure provides an electronic device, including: one or more processors; and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors perform the security monitoring method described above.

[0043] Another aspect of this disclosure provides a computer-readable storage medium having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the aforementioned security monitoring method.

[0044] Another aspect of this disclosure provides a computer program product, including a computer program that, when executed by a processor, implements the aforementioned security monitoring method.

[0045] According to embodiments of this disclosure, a network device monitoring platform is used to obtain operation commands sent from a client to a network device. These operation commands are compared with a list of risky operation commands. If the operation command is included in the list, a prompt message is sent to the client, prompting the client to fill in the implementation basis corresponding to the operation command. After receiving the implementation basis sent by the client, this implementation basis is compared with a list of implementation basis. Since the list of implementation basis is a pre-approved list of operation commands, if it is determined that the implementation basis is included in the pre-approved list, the operation command can be sent to the network device. Because the operation commands are monitored through the network device monitoring platform, ensuring that each risky operation command has a basis, the technical problem of security risks during the use of network devices is at least partially overcome, thereby achieving the technical effect of improving the security of network devices. Attached Figure Description

[0046] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0047] Figure 1 The illustrations depict application scenarios of security monitoring methods, apparatuses, devices, media, and program products according to embodiments of the present disclosure.

[0048] Figure 2 A flowchart illustrating a security monitoring method according to an embodiment of the present disclosure is shown schematically.

[0049] Figure 3 A flowchart illustrating another security monitoring method according to an embodiment of the present disclosure is shown schematically;

[0050] Figure 4 A flowchart illustrating a login monitoring method according to an embodiment of the present disclosure is shown schematically.

[0051] Figure 5 An architectural diagram of a network device monitoring platform according to an embodiment of the present disclosure is illustrated schematically.

[0052] Figure 6 A schematic diagram illustrating the structure of a security monitoring device according to an embodiment of the present disclosure is shown; and

[0053] Figure 7 A block diagram schematically illustrates an electronic device suitable for implementing a security monitoring method according to an embodiment of the present disclosure. Detailed Implementation

[0054] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0055] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0056] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0057] When using expressions such as "at least one of A, B, and C", they should generally be interpreted in accordance with the meaning that is commonly understood by a person skilled in the art (e.g., "a system having at least one of A, B, and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B, and C, etc.).

[0058] Large enterprises need to inspect the user permission settings, device operation, and configuration of various network devices, and promptly address any issues discovered, such as excessively restrictive user permission settings, abnormal device operation, risky operations, or non-compliant configurations. During the inspection, the following problems were found in the network devices:

[0059] 1. Lack of monitoring and blocking measures for risky user operations: Network device users can be broadly categorized into two groups based on their permissions: high-privilege users and low-privilege users. It is impossible to achieve fine-grained control over user permissions for network devices according to specific operational commands. Certain high-risk commands (required for production and maintenance but with high operational risks) can still be executed, and the lack of effective monitoring and blocking measures may pose a threat to production security.

[0060] 2. Lack of dynamic authentication mechanism for user login: Once the network device's username and password are obtained, they can be used at any time without dynamic authorization based on the actual login environment, the necessity of use, the degree of risk of the operation, etc., or the legitimacy of the login user. If the current user's login environment is abnormal or even if the username and password are leaked, it may affect the enterprise's network environment.

[0061] 3. Inability to promptly detect non-compliant network device configurations: After network device maintenance personnel execute operation commands, these commands take effect directly on the devices regardless of whether they comply with the company's compliance requirements. Some of these commands can even have a significant impact on the company's network environment. Currently, checking network device configuration compliance mainly relies on manual auditing after the fact, lacking automated monitoring methods for both pre- and in-process monitoring.

[0062] In view of this, this disclosure addresses the above-mentioned technical issues by providing a security monitoring method. Through linkage with a network device user operation management system, the method employs three main mechanisms: First, it pre-configures a list of high-risk operation commands within the management system, checking in real-time whether each user's operation matches this list. Successfully matched operations require the user to provide supporting documentation; operations without such documentation are immediately blocked, ensuring that every high-risk operation is justifiable. Second, it automatically identifies user status and provides authentication methods of varying strengths to prevent unauthorized logins. Third, it automatically audits the execution results of operation commands in advance, ensuring that each command complies with the company's internal compliance requirements.

[0063] Specifically, embodiments of this disclosure provide a security monitoring method, comprising: acquiring an operation command sent by a client to the network device; if the operation command is found to be included in a risk operation command list corresponding to the network device, sending a prompt message to the client, wherein the prompt message prompts the client to fill in the implementation basis corresponding to the operation command; and in response to the implementation basis from the client, if the implementation basis is found to be included in a preset implementation basis list, sending the operation command to the network device, wherein the implementation basis list is a pre-approved operation command list, and the implementation basis list includes the implementation basis corresponding to the approved operation command.

[0064] It should be noted that the security monitoring method and apparatus provided in this disclosure can be used in the fields of information security and finance. The security monitoring method and apparatus provided in this disclosure can also be used in any field other than information security and finance. The application areas of the security monitoring method and apparatus provided in this disclosure are not limited.

[0065] In the technical solution disclosed herein, the user's authorization or consent is obtained before acquiring or collecting the user's personal information.

[0066] In the technical solution disclosed herein, the acquisition, collection, storage, use, processing, transmission, provision, disclosure, and application of data all comply with the provisions of relevant laws and regulations, necessary confidentiality measures have been taken, and they do not violate public order and good morals.

[0067] Figure 1 The illustration shows an application scenario diagram of a security monitoring method, apparatus, device, medium, and program product according to embodiments of the present disclosure.

[0068] like Figure 1 As shown, application scenario 100 according to this embodiment may include a network device monitoring platform 101, network 102, network 103, terminal device 104, and network device 105. Network 102 serves as a medium for providing a communication link between the network device monitoring platform 101 and the terminal device 104. Network 103 serves as a medium for providing a communication link between the network device monitoring platform 101 and the network device 105. Networks 102 and 103 may include various connection types, such as wired or wireless communication links or fiber optic cables, etc.

[0069] Users can use terminal device 104 to interact with network device monitoring platform 101 via network 102 to receive or send messages, etc. Various communication client applications can be installed on terminal device 104, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).

[0070] Terminal device 104 can be various electronic devices with a display screen and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0071] The network device monitoring platform 101 can interact with the network device 105 through the network 103 to receive or send messages, etc.

[0072] The network device monitoring platform 101 can be a server that provides various services, such as a backend management server that supports operation commands sent by users using terminal devices 104 (for example only). The backend management server can analyze and process data such as received user requests and feed the processing results back to the terminal devices.

[0073] Network devices 105 may include: computers, hubs, switches, bridges, routers, gateways, network interface cards (NICs), wireless access points (WAPs), printers and modems, fiber optic transceivers, optical cables, repeaters, bridges, routers, gateways, firewalls, switches, and other devices.

[0074] It should be noted that the security monitoring method provided in this embodiment can generally be executed by the network device monitoring platform 101. Correspondingly, the security monitoring device provided in this embodiment can generally be installed in the network device monitoring platform 101. The security monitoring method provided in this embodiment can also be executed by a server or server cluster that is different from the network device monitoring platform 101 and capable of communicating with the terminal device 104 and / or network device 105. Correspondingly, the security monitoring device provided in this embodiment can also be installed in a server or server cluster that is different from the network device monitoring platform 101 and capable of communicating with the terminal device 104 and / or network device 105.

[0075] It should be understood that Figure 1 The number of network device monitoring platforms, terminal devices, networks, and network devices shown is merely illustrative. Depending on implementation needs, there can be any number of network device monitoring platforms, terminal devices, networks, and network devices.

[0076] The following will be based on Figure 1 The described scene, through Figures 2-5 The security monitoring method of the disclosed embodiments is described in detail.

[0077] Figure 2 A flowchart illustrating a security monitoring method according to an embodiment of the present disclosure is shown schematically.

[0078] like Figure 2As shown, the security monitoring method of this embodiment includes operations S210 to S230, and the security monitoring method can be executed by a server.

[0079] In operation S210, the operation command sent by the client to the aforementioned network device is obtained.

[0080] According to embodiments of this disclosure, the operation command may include any command sent to the network device. For example, it may include a network device shutdown command, a network device restart command, a network device port closing command, etc.

[0081] In operation S220, if the risk operation command list corresponding to the above-mentioned network device contains the above-mentioned operation command, a prompt message is sent to the above-mentioned client, wherein the prompt message is used to prompt the above-mentioned client to fill in the implementation basis corresponding to the above-mentioned operation command.

[0082] According to embodiments of this disclosure, the list of risk operation commands may be a list of risk operation commands pre-configured based on network devices.

[0083] According to embodiments of this disclosure, a network device risk operation list is set up based on different operational risks, such as the type of network device, the importance of the network device, and the network area where the network device is deployed.

[0084] According to embodiments of this disclosure, the system automatically identifies information such as the type of network device currently logged in and the network area where it is deployed, and then matches the corresponding risk operation command list according to different network devices.

[0085] According to embodiments of this disclosure, the list of risk operation commands may include the following operation commands: stopping network devices, restarting network devices, clearing network device configurations, clearing neighbor entries on switches, etc.

[0086] According to an embodiment of this disclosure, if the list of risk operation commands includes the above-mentioned operation commands, it indicates that the operation command is a risky operation and requires the provision of implementation basis; then, a prompt message is sent to the client to fill in the implementation basis corresponding to the above-mentioned operation command.

[0087] In operation S230, in response to the aforementioned implementation basis from the aforementioned client, if it is determined that the aforementioned implementation basis is included in the preset implementation basis list, the aforementioned operation command is sent to the aforementioned network device, wherein the aforementioned implementation basis list is a list of operation commands that have been pre-approved, and the aforementioned implementation basis list includes the implementation basis corresponding to the aforementioned approved operation command.

[0088] According to embodiments of this disclosure, the implementation basis list is a list of operation commands that have been pre-approved by the user, and the implementation basis list may include the implementation basis corresponding to the aforementioned approved operation commands.

[0089] Specifically, the implementation basis list may include: list number, applicant, approver, application time, implementation time, operation command identifier for the application, and reason for application. The implementation basis can include information such as the operation command identifier and the reason for application. By comparing the implementation basis sent by the client with the implementation basis list, and confirming that the preset implementation basis list contains the implementation basis, an operation command is sent to the network device, ensuring that every risky operation command is monitorable and improving the security of the network device.

[0090] According to embodiments of this disclosure, each time a network device is operated, an implementation basis list needs to be applied for before implementation, the information needs to be filled in, and the application needs to be approved. In actual operation, after logging in, the user enters information that is compared with an existing implementation basis list, such as whether an implementation basis list has been applied for beforehand, whether the implementation basis list has been approved, whether the implementation time is consistent, and so on.

[0091] According to embodiments of this disclosure, a network device monitoring platform is used to obtain operation commands sent from a client to a network device. These operation commands are compared with a list of risky operation commands. If the operation command is included in the list, a prompt message is sent to the client, prompting the client to fill in the implementation basis corresponding to the operation command. After receiving the implementation basis sent by the client, this implementation basis is compared with a list of implementation basis. Since the list of implementation basis is a pre-approved list of operation commands, if it is determined that the implementation basis is included in the pre-approved list, the operation command can be sent to the network device. Because the operation commands are monitored through the network device monitoring platform, ensuring that each risky operation command has a basis, the technical problem of security risks during the use of network devices is at least partially overcome, thereby achieving the technical effect of improving the security of network devices.

[0092] According to embodiments of this disclosure, if it is determined that the preset implementation basis list does not contain the aforementioned implementation basis, the operation command is blocked.

[0093] According to embodiments of this disclosure, if no implementation basis is received within a preset time, the operation command is blocked.

[0094] According to an embodiment of this disclosure, the method further includes: before sending the operation command to the network device, executing the operation command in a simulation environment to obtain a simulation result; and sending the operation command to the network device when it is determined that the simulation result meets a preset condition.

[0095] According to embodiments of this disclosure, the simulated environment can be a similar simulation environment created by copying the configuration file of a network device.

[0096] According to embodiments of this disclosure, the simulation result can be configuration information that takes effect on the network device after an operation command is executed. For example, if the operation command is to shut down port a of a switch, the corresponding simulation result can be that a "shutdown" field appears under port a in the switch's configuration file.

[0097] According to embodiments of this disclosure, the operation commands executed by the user are first verified in a simulation environment and the experimental results are given. If the implementation results do not meet the preset conditions, the user is notified in advance to avoid affecting the production environment of the network equipment.

[0098] According to embodiments of this disclosure, the preset conditions can be a preset list of compliance requirements. Compliance requirements may include, for example, access control lists or other means to restrict the range of addresses that a network device can log into; the network device should be included in 3a for user management; and user passwords for the network device should maintain a certain level of strength, etc.

[0099] According to an embodiment of this disclosure, sending the operation command to the network device when the simulation result meets the preset conditions includes: comparing the simulation result with the compliance requirement list corresponding to the network device to obtain a comparison result; and sending the operation command to the network device when the comparison result shows that the simulation result meets the compliance requirements in the compliance requirement list.

[0100] According to embodiments of this disclosure, the list of compliance requirements may be a standardized list of fields formed based on actual needs and the systems in use.

[0101] According to embodiments of this disclosure, the simulation result obtained after implementation in a simulated environment may be field information added after the operation command implementation. The field information in the simulation result is compared with the fields in the compliance requirement list. If the fields in the compliance requirement list include the fields in the simulation result, and the field results are consistent, it indicates that the simulation result complies with the compliance requirements in the compliance requirement list, and the operation command can be sent to the network device. If the fields in the compliance requirement list do not include the fields in the simulation result, or the field results are inconsistent, it indicates that the simulation result does not comply with the compliance requirements in the compliance requirement list, and the user needs to be notified.

[0102] According to embodiments of this disclosure, the method further includes: determining the importance level of the network device when the simulation result does not meet the preset conditions; determining a handling method corresponding to the importance level based on the importance level of the network device; and processing the operation command using the handling method.

[0103] According to embodiments of this disclosure, the importance level of a network device can be determined based on the environment in which it is deployed and the type of network device. For example, devices deployed at the enterprise internet boundary, which interact with the internet environment, require higher security requirements and can be considered high-importance network devices.

[0104] According to embodiments of this disclosure, the above-mentioned determination of the handling method corresponding to the importance level of the network device includes: if the importance level of the network device is determined to be a first level, the handling method corresponding to the importance level is to block the operation command; if the importance level of the network device is determined to be a second level, the handling method corresponding to the importance level is to send a first approval request to a first approver.

[0105] According to embodiments of this disclosure, the first level can be a network device with a higher importance level. Network devices of this level have higher security requirements. Therefore, if the simulation results do not meet the above-mentioned preset conditions, the operation command is directly blocked.

[0106] According to embodiments of this disclosure, the second level can be a network device with a lower importance level. For network devices of this level, the security requirements are not high. Therefore, if the simulation results do not meet the above-mentioned preset conditions, a first approval request can be sent to the first approver. If the first approver approves, the operation command can be sent to the network device.

[0107] According to embodiments of this disclosure, the first approver may be the head of a department.

[0108] Figure 3 A flowchart illustrating another security monitoring method according to an embodiment of this disclosure is shown schematically.

[0109] like Figure 3 As shown, the security monitoring method of this embodiment includes operations S301 to S313.

[0110] In operation S301, the operation commands sent by the client to the network device are obtained.

[0111] In operation S302, determine whether the operation command is included in the risk operation command list corresponding to the network device. If the operation command is included in the risk operation command list, execute operation S303; if the operation command is not included in the risk operation command list, execute operation S306.

[0112] In operation S303, a prompt message is sent to the client to prompt the client to fill in the implementation basis corresponding to the operation command.

[0113] In operation S304, the implementation basis is received from the client.

[0114] In operation S305, determine whether the implementation basis is included in the preset implementation basis list. If the implementation basis is included in the implementation basis list, execute operation S306; if the implementation basis is not included in the implementation basis list, execute operation S312.

[0115] When operating S306, the operation command is executed using the simulation environment to obtain the simulation results.

[0116] When operating S307, the simulation results are compared with the list of compliance requirements corresponding to the network devices to obtain the comparison results.

[0117] In operation S308, determine whether the simulation results comply with the compliance requirements in the compliance requirements list based on the comparison results. If it is determined that the simulation results comply with the compliance requirements in the compliance requirements list, proceed to operation S309; ​​if it is determined that the simulation results do not comply with the compliance requirements in the compliance requirements list, proceed to operation S310.

[0118] In operation S309, the operation command is sent to the network device.

[0119] When operating S310, determine the importance level of network devices.

[0120] In operation S311, determine whether the importance level of the network device is Level 1. If the importance level of the network device is determined to be Level 1, execute operation S312; if the importance level of the network device is determined not to be Level 1, execute operation S313.

[0121] In operation S312, the operation command is blocked.

[0122] In operation S313, a first approval request is sent to the first approver.

[0123] According to embodiments of this disclosure, the method further includes: in response to a login request to log in to the client, obtaining login environment information of the client; if it is determined that the login environment information does not conform to a preset login list, determining a login risk level based on the login environment information; determining a target processing method from a preset set of login processing methods based on the login risk level; and processing the login request using the target processing method.

[0124] According to embodiments of this disclosure, login environment information may include login time, login location, login IP, etc. The preset login list may be a pre-set list of allowed login time periods, allowed computer names, allowed IP addresses, allowed MAC addresses, etc.

[0125] According to embodiments of this disclosure, the login processing methods may include directly denying the user's access, performing another graphical verification code authentication, or sending the user's login request to the person in charge of the network device for approval.

[0126] According to embodiments of this disclosure, the login environment information includes at least one login attribute and attribute data corresponding to the login attribute; determining the login risk level based on the login environment information when it is determined that the login environment information does not conform to the preset login list includes: determining the login attribute and attribute data in the login environment information that do not conform to the preset login list, obtaining the target login attribute and target attribute data; and determining the login risk level based on the target login attribute and the target attribute data.

[0127] According to embodiments of this disclosure, the login attributes include one or more of the following: login time identifier, login location identifier, client identifier, Internet protocol identifier, link identifier, and operating system identifier.

[0128] According to embodiments of this disclosure, the method for determining the login risk level may include classifying login behavior into three risk levels: high, medium, and low. For high-risk login behavior, the approach may be to block login; for low-risk login behavior, the approach may be to allow login or enhance authentication; and for medium-risk login behavior, an additional approval approach may be required. This can be set according to needs.

[0129] According to embodiments of this disclosure, the method for determining the login risk level can also adopt a point deduction system. For example, the maximum score is 100 points, the attention score is 80 points, and the passing score is 60 points. Then, different login situations are classified. For example, if the terminal patch is not installed, 5 points can be deducted, and if the user enters the wrong password multiple times, 10 points can be deducted. Once the score is reduced to below the attention score or the passing score, additional handling measures will be triggered.

[0130] According to embodiments of this disclosure, the aforementioned login processing method set includes: blocking login, sending a second approval request to a second approver, and performing verification code authentication; the determination of the target processing method from the preset login processing method set based on the login risk level includes: if the login risk level is determined to be high risk, determining the target processing method to block login; if the login risk level is determined to be medium risk, determining the target processing method to send a second approval request to a second approver; and if the login risk level is determined to be high risk, determining the target processing method to perform verification code authentication.

[0131] Figure 4 A flowchart illustrating a login monitoring method according to an embodiment of this disclosure is shown schematically.

[0132] like Figure 4 As shown, the login monitoring method in this embodiment includes operations S401 to S408.

[0133] In operation S401, in response to the login request from the login client, the login environment information of the client is obtained, wherein the login environment information includes at least one login attribute and attribute data corresponding to the login attribute.

[0134] In operation S402, determine whether the login environment information meets the preset login list. If the login environment information meets the preset login list, execute operation S403; if the login environment information does not meet the preset login list, execute operation S404.

[0135] When operating S403, grant permission for the user to log in to the client.

[0136] In operation S404, the login attributes and attribute data in the login environment information that do not conform to the preset login list are determined, and the target login attributes and target attribute data are obtained.

[0137] In S405, the login risk level is determined based on the target login attributes and target attribute data.

[0138] When operating S406, if the login risk level is determined to be high, the login request is blocked.

[0139] When operating S407, if the login risk level is determined to be medium risk, a second approval request is sent to the second approver.

[0140] When operating S408, if the login risk level is determined to be low, then perform CAPTCHA authentication.

[0141] According to embodiments of this disclosure, authentication methods of varying strengths are provided based on changes in the user login environment. These methods include directly denying the user's access, performing another graphical CAPTCHA authentication, or sending the user's login request to the network device's administrator for approval. This approach aims to better authenticate the authenticity of the user's login and improve the security of the network device.

[0142] Figure 5 An architectural diagram of a network device monitoring platform according to an embodiment of the present disclosure is shown schematically.

[0143] like Figure 5 As shown in the diagram, the architecture includes client 510, network device monitoring platform 520, and network device 530, and its processing logic is as follows:

[0144] First, the user operation management system of network device 530 is pre-set with information such as the time period, computer name, IP address, and MAC address of users allowed to log in, i.e., a pre-set login list.

[0145] Then, the client 510 collects user login environment information and operation commands in real time through the user login. The login environment information includes, but is not limited to: login time, computer name, IP address, operating system, login location, and the software used by the user.

[0146] Next, it determines whether the login environment information is in the preset login list. If it is in the login list, the user is allowed to log in. If it is not in the login list, different levels of handling are provided according to the risk level of the login behavior (such as logging in in an internet location). For example, the user's access may be directly denied, another graphical CAPTCHA authentication may be performed, or the user's login request may be sent to the person in charge of the network device for approval.

[0147] After a user successfully logs in, the 520 network device monitoring platform automatically identifies the type of network device the user is logged into, the network area it is deployed in, and then matches the corresponding high-risk command list for each network device. If the command is on the high-risk command list, the user is required to provide additional justification. The system then automatically judges whether the provided justification is reasonable. Operations without justification or that are unreasonable are immediately blocked. For reasonable operations, the system simulates the command in a simulation environment to obtain the execution result.

[0148] Next, the implementation results obtained from the simulation environment will be compared with the enterprise's compliance requirements. If an operation does not meet the requirements, the user will be notified, and different handling measures will be provided based on the importance of the network device, such as blocking the operation or submitting it for department head approval. For operations that meet the requirements, the operation command will be sent to network device 530.

[0149] It should be noted that, unless it is explicitly stated that there is a sequential order of execution between different operations, or that there is a sequential order of execution between different operations in terms of technical implementation, the execution order between multiple operations may not be significant, and multiple operations may be executed simultaneously.

[0150] Based on the above-described security monitoring method, this disclosure also provides a security monitoring device. The following will be combined with... Figure 6 The device is described in detail.

[0151] Figure 6 A schematic block diagram of a security monitoring device according to an embodiment of the present disclosure is shown.

[0152] like Figure 6 As shown, the security monitoring device 600 in this embodiment includes a first acquisition module 610, a first transmission module 620, and a second transmission module 630.

[0153] The first acquisition module 610 is used to acquire operation commands sent by the client to the aforementioned network device. In one embodiment, the first acquisition module 610 can be used to execute the operation S210 described above, which will not be repeated here.

[0154] The first sending module 620 is used to send a prompt message to the client when the risk operation command list corresponding to the network device is found to contain the aforementioned operation command. The prompt message prompts the client to fill in the implementation basis corresponding to the aforementioned operation command. In one embodiment, the first sending module 620 can be used to execute the operation S220 described above, which will not be repeated here.

[0155] The second sending module 630 is configured to respond to the aforementioned implementation basis from the client, and, if it is determined that the aforementioned implementation basis is included in the preset implementation basis list, send the aforementioned operation command to the network device. The aforementioned implementation basis list is a list of pre-approved operation commands, and includes the implementation basis corresponding to the aforementioned approved operation command. In one embodiment, the second sending module 630 may be used to execute the operation S230 described above, which will not be repeated here.

[0156] According to embodiments of this disclosure, the aforementioned security monitoring device further includes an execution module and a third sending module.

[0157] The execution module is used to execute the operation command in a simulation environment and obtain simulation results before sending the operation command to the network device.

[0158] The third sending module is used to send the above operation command to the above network device when it is determined that the above simulation results meet the preset conditions.

[0159] According to embodiments of this disclosure, the third sending module includes a comparison unit and a sending unit.

[0160] The comparison unit is used to compare the above simulation results with the list of compliance requirements corresponding to the above network devices to obtain the comparison results.

[0161] The sending unit is used to send the operation command to the network device when the comparison results show that the simulation results meet the compliance requirements in the compliance requirements list.

[0162] According to embodiments of this disclosure, the aforementioned security monitoring device further includes: a first determining module, a second determining module, and a first processing module.

[0163] The first determining module is used to determine the importance level of the network device when the simulation results do not meet the preset conditions.

[0164] The second determining module is used to determine the handling method corresponding to the importance level of the aforementioned network devices.

[0165] The first processing module is used to process the above-mentioned operation commands using the above-mentioned processing method.

[0166] According to embodiments of this disclosure, the second determining module includes: a first determining unit and a second determining unit.

[0167] The first determining unit is configured to, when determining that the importance level of the network device is first level, determine the corresponding handling method as blocking the operation command.

[0168] The second determining unit is used to determine, when the importance level of the aforementioned network device is determined to be Level 2, the corresponding handling method is to send a first approval request to the first approver.

[0169] According to embodiments of this disclosure, the security monitoring device further includes: a second acquisition module, a third determination module, a fourth determination module, and a second processing module.

[0170] The second acquisition module is used to obtain the login environment information of the client in response to the login request of the client.

[0171] The third determination module is used to determine the login risk level based on the login environment information if the above login environment information does not conform to the preset login list.

[0172] The fourth determination module is used to determine the target processing method from the preset set of login processing methods based on the above login risk level.

[0173] The second processing module is used to process the login request using the aforementioned target processing method.

[0174] According to embodiments of this disclosure, the login environment information includes at least one login attribute and attribute data corresponding to the login attribute.

[0175] According to embodiments of this disclosure, the third determining module includes a third determining unit and a fourth determining unit.

[0176] The third determining unit is used to determine the login attributes and attribute data in the above login environment information that do not conform to the above preset login list, and to obtain the target login attributes and target attribute data.

[0177] The fourth determining unit is used to determine the login risk level based on the target login attributes and the target attribute data.

[0178] According to embodiments of this disclosure, the login attributes include one or more of the following: login time identifier, login location identifier, client identifier, Internet protocol identifier, link identifier, and operating system identifier.

[0179] According to embodiments of this disclosure, the above-mentioned login processing methods include: blocking login, sending a second approval request to a second approver, and performing verification code authentication.

[0180] According to embodiments of this disclosure, the fourth determining module includes a fifth determining unit, a sixth determining unit, and a seventh determining unit.

[0181] The fifth determining unit is used to determine the target handling method as blocking login when the above-mentioned login risk level is determined to be high risk.

[0182] The sixth determining unit is used to determine, when the above-mentioned login risk level is determined to be medium risk, the above-mentioned target processing method is to send a second approval request to the second approver.

[0183] The seventh determining unit is used to determine the target processing method as CAPTCHA authentication when the above login risk level is determined to be high risk.

[0184] Any one or more of the modules, submodules, units, and subunits according to embodiments of the present disclosure, or at least part of the functions of any one or more of them, can be implemented in one module. Any one or more of the modules, submodules, units, and subunits according to embodiments of the present disclosure can be implemented by dividing them into multiple modules. Any one or more of the modules, submodules, units, and subunits according to embodiments of the present disclosure can be at least partially implemented as hardware circuitry, such as Field Programmable Gate Arrays (FPGAs), Programmable Logic Arrays (PLAs), Systems-on-Chip, Systems-on-Substrate, Systems-on-Package, Application-Specific Integrated Circuits (ASICs), or implemented in hardware or firmware by any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, one or more of the modules, submodules, units, and subunits according to embodiments of the present disclosure can be at least partially implemented as computer program modules, which, when run, can perform corresponding functions.

[0185] According to embodiments of this disclosure, any plurality of modules among the first acquisition module 610, the first transmission module 620, and the second transmission module 630 may be combined into one module, or any one of these modules may be split into multiple modules. Alternatively, at least a portion of the functionality of one or more of these modules may be combined with at least a portion of the functionality of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the first acquisition module 610, the first transmission module 620, and the second transmission module 630 may be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or implemented by any other reasonable means of integrating or packaging the circuitry, or implemented in any one of software, hardware, and firmware methods, or in a suitable combination of any of these. Alternatively, at least one of the first acquisition module 610, the first transmission module 620, and the second transmission module 630 may be at least partially implemented as a computer program module, which, when run, can perform corresponding functions.

[0186] It should be noted that the security monitoring device part in the embodiments of this disclosure corresponds to the security monitoring method part in the embodiments of this disclosure. For a detailed description of the security monitoring device part, please refer to the security monitoring method part, which will not be repeated here.

[0187] Figure 7 A block diagram schematically illustrates an electronic device suitable for implementing a security monitoring method according to an embodiment of the present disclosure.

[0188] like Figure 7 As shown, an electronic device 700 according to an embodiment of the present disclosure includes a processor 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage portion 708 into a random access memory (RAM) 703. The processor 701 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 701 may also include onboard memory for caching purposes. The processor 701 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0189] RAM 703 stores various programs and data required for the operation of electronic device 700. Processor 701, ROM 702, and RAM 703 are interconnected via bus 704. Processor 701 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 702 and / or RAM 703. It should be noted that the programs may also be stored in one or more memories other than ROM 702 and RAM 703. Processor 701 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in said one or more memories.

[0190] According to embodiments of this disclosure, the electronic device 700 may further include an input / output (I / O) interface 705, which is also connected to a bus 704. The electronic device 700 may also include one or more of the following components connected to the I / O interface 705: an input section 706 including a keyboard, mouse, etc.; an output section 707 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 708 including a hard disk, etc.; and a communication section 709 including a network interface card such as a LAN card, modem, etc. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the I / O interface 705 as needed. A removable medium 711, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 710 as needed so that computer programs read from it can be installed into the storage section 708 as needed.

[0191] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.

[0192] According to embodiments of this disclosure, the computer-readable storage medium may be a non-volatile computer-readable storage medium, such as, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 702 and / or RAM 703 and / or one or more memories other than ROM 702 and RAM 703 described above.

[0193] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code enables the computer system to implement the security monitoring methods provided in the embodiments of this disclosure.

[0194] When the computer program is executed by the processor 701, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0195] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 709, and / or installed from a removable medium 711. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0196] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 709, and / or installed from the removable medium 711. When the computer program is executed by the processor 701, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0197] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0198] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0199] Those skilled in the art will understand that the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure can be combined or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0200] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. A security monitoring method applied to a network device monitoring platform, the method comprising: Obtain the operation commands sent by the client to the network device; If the operation command is included in the list of risk operation commands corresponding to the network device, a prompt message is sent to the client, wherein the prompt message prompts the client to fill in the implementation basis corresponding to the operation command; and In response to the implementation basis from the client, if it is determined that the implementation basis is included in the preset implementation basis list, the operation command is sent to the network device, wherein the implementation basis list is a list of operation commands that have been applied for in advance, the implementation basis list includes the implementation basis corresponding to the applied operation command, and the implementation basis includes the operation command identifier and the application reason; Also includes: Before sending the operation command to the network device, the operation command is executed in a simulation environment to obtain simulation results, wherein the simulation results include field information added after the operation command implementation; If the simulation result does not meet the preset conditions, the importance level of the network device is determined according to the deployment environment and type of the network device. The preset conditions are a preset list of compliance requirements, which is a standardized list of fields. The simulation result not meeting the preset conditions includes: if the fields in the compliance requirements list do not include the fields in the simulation result, or if the field results are inconsistent, it indicates that the simulation result does not meet the preset conditions. If the importance level of the network device is determined to be Level 1, the corresponding handling method is to block the operation command. If the importance level of the network device is determined to be Level 2, the corresponding handling method is to send a first approval request to the first approver. The operation command is processed using the aforementioned handling method; If the simulation results meet the preset conditions, the operation command is sent to the network device.

2. The method according to claim 1, wherein, Sending the operation command to the network device when the simulation result meets the preset conditions includes: The simulation results are compared with the list of compliance requirements corresponding to the network device to obtain the comparison results; If the comparison result indicates that the simulation result meets the compliance requirements in the compliance requirements list, the operation command is sent to the network device.

3. The method according to claim 1, further comprising: In response to a login request to the client, obtain the client's login environment information; If the login environment information does not conform to the preset login list, the login risk level is determined based on the login environment information; The target processing method is determined from the preset set of login processing methods based on the login risk level. The login request is processed using the target processing method described above.

4. The method according to claim 3, wherein, The login environment information includes at least one login attribute, and attribute data corresponding to the login attribute; The step of determining the login risk level based on the login environment information when it is determined that the login environment information does not conform to the preset login list includes: Determine the login attributes and attribute data in the login environment information that do not conform to the preset login list, and obtain the target login attributes and target attribute data; The login risk level is determined based on the target login attributes and the target attribute data.

5. The method according to claim 3, wherein, Login attributes include one or more of the following: login time identifier, login location identifier, client identifier, Internet protocol identifier, link identifier, and operating system identifier.

6. The method according to claim 3, wherein, The login processing methods include: blocking login, sending a second approval request to a second approver, and performing verification code authentication. The step of determining the target processing method from the preset set of login processing methods based on the login risk level includes: If the login risk level is determined to be high risk, the target handling method is determined to be blocking login; If the login risk level is determined to be medium risk, the target processing method is to send a second approval request to the second approver. If the login risk level is determined to be high risk, the target processing method is determined to be CAPTCHA authentication.

7. A security monitoring device applied to a network device monitoring platform, the device comprising: The first acquisition module is used to acquire operation commands sent by the client to the network device; The first sending module is configured to send a prompt message to the client when, upon determining that the operation command is included in the risk operation command list corresponding to the network device, the prompt message prompts the client to fill in the implementation basis corresponding to the operation command, wherein the implementation basis includes the operation command identifier, the reason for the application, and... The second sending module is configured to respond to the implementation basis from the client and, if it is determined that the implementation basis is included in the preset implementation basis list, send the operation command to the network device, wherein the implementation basis list is a list of operation commands that have been pre-approved, and the implementation basis list includes the implementation basis corresponding to the approved operation command; The execution module executes the operation command using a simulation environment to obtain simulation results, wherein the simulation results include field information added after the operation command implementation; The first determining module is used to determine the importance level of the network device based on the deployment environment and type of the network device when the simulation result does not meet the preset conditions. The preset conditions are a preset list of compliance requirements, which is a standardized list of fields. The simulation result not meeting the preset conditions includes: the fields in the compliance requirements list do not include the fields in the simulation result, or the field results are inconsistent, indicating that the simulation result does not meet the preset conditions. The second determining module is used to determine, when the importance level of the network device is determined to be first level, the corresponding handling method is to block the operation command; and when the importance level of the network device is determined to be second level, the corresponding handling method is to send a first approval request to the first approver. The first processing module is used to process the operation command using the aforementioned processing method; The third sending module is used to send the operation command to the network device when it is determined that the simulation result meets the preset conditions.

8. An electronic device, comprising: One or more processors; Storage device for storing one or more programs. Wherein, when the one or more programs are executed by the one or more processors, the one or more processors perform the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having stored thereon executable instructions that, when executed by a processor, cause the processor to perform the method according to any one of claims 1 to 6.

10. A computer program product comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 6.