A request sending method and apparatus, device, and storage medium

By conducting detection, evaluation, and vulnerability handling of cloud computing virtual machines, the problem of insufficient cloud computing security has been solved, achieving data security and user-friendly virtual machine management, and ensuring the security of legitimate user data and business operations.

CN115952541BActive Publication Date: 2026-07-24JINAN INSPUR DATA TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
JINAN INSPUR DATA TECH CO LTD
Filing Date
2022-12-29
Publication Date
2026-07-24

Smart Images

  • Figure CN115952541B_ABST
    Figure CN115952541B_ABST
Patent Text Reader

Abstract

The application discloses a request sending method and device, equipment and a storage medium, relates to the computer technical field, and is used for solving the security risks of the current cloud management platform data, and comprises the following steps: receiving a user access request and determining a corresponding target virtual machine; detecting the target virtual machine based on a preset detection mode to obtain a corresponding detection evaluation report; and when the detection evaluation report shows that the target virtual machine has no vulnerability, sending the user access request to a target area based on a preset data processing rule. The application detects the target virtual machine, judges whether to forward the user request according to the obtained detection evaluation report, does not forward the user request when the target virtual machine has a vulnerability, and improves the security of the data and reduces the use difficulty of the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer technology, and in particular to a request sending method, apparatus, device, and storage medium. Background Technology

[0002] With the widespread adoption of cloud-based technologies, the demand for cloud security is increasing, making threat detection and mitigation for advanced technologies ever more crucial. Under the cloud computing architecture, open networks and shared business scenarios are more complex and dynamic, posing greater security challenges and highlighting emerging security issues. Cloud computing provides elastic and variable IT services over the network; users need to log in to the cloud to use applications and services. The system must ensure the legitimacy of user identities before providing services. If unauthorized users gain access, it can jeopardize the data and business operations of legitimate users. Summary of the Invention

[0003] In view of this, the purpose of this invention is to provide a request sending method, apparatus, device, and storage medium that can improve data security and reduce the difficulty of use for users. The specific solution is as follows:

[0004] In a first aspect, this application discloses a request sending method, including:

[0005] Receive user access requests and determine the corresponding target virtual machine;

[0006] The target virtual machine is detected based on a preset detection method to obtain a corresponding detection and evaluation report;

[0007] When the detection and evaluation report shows that the target virtual machine does not have any vulnerabilities, the user access request is sent to the target area based on the preset data processing rules.

[0008] Optionally, the step of detecting the target virtual machine based on a preset detection method to obtain a corresponding detection evaluation report includes:

[0009] The target virtual machine is scanned using a preset scanning method, and the existence of a corresponding current vulnerability in the target virtual machine is determined based on the current vulnerability database.

[0010] If the target virtual machine contains the corresponding current vulnerability, the detection and evaluation report is generated based on the current vulnerability and the target detection information set; wherein, the target detection information set includes password validity period, time during which users are allowed to change their passwords, minimum password length, password expiration prompt, client connection failure exit time, and port open list.

[0011] Optionally, before scanning the target virtual machine using a preset scanning method and determining whether a corresponding current vulnerability exists in the target virtual machine based on the current vulnerability database, the method further includes:

[0012] The system regularly acquires the latest vulnerability information and updates the vulnerability database based on this information to obtain the current vulnerability database.

[0013] Optionally, after receiving the user access request and determining the corresponding target virtual machine, the process further includes:

[0014] Ports that meet the user's requirements are set as open ports, and ports that do not meet the user's requirements are set as closed ports, so as to obtain the list of open ports and the list of closed ports;

[0015] Based on the list of open ports, preset data processing rules are set for the data flow direction of the user access request.

[0016] Optionally, after detecting the target virtual machine based on a preset detection method to obtain a corresponding detection evaluation report, the method further includes:

[0017] When the detection and evaluation report shows that the target virtual machine has the vulnerability, and the vulnerability repair button on the preset vulnerability repair page is detected to be clicked, the preset vulnerability handling method is automatically invoked to handle the vulnerability in order to obtain the repaired virtual machine;

[0018] The repaired virtual machine is identified as the target virtual machine, and the process of re-entering the step of detecting the target virtual machine based on the preset detection method to obtain the corresponding detection evaluation report is carried out to obtain the current detection evaluation report.

[0019] Based on the current detection and evaluation report, determine whether the vulnerability exists in the repaired virtual machine; if not, the process ends.

[0020] If the vulnerability exists, the process will re-enter the steps described in the detection and evaluation report, which indicates that the target virtual machine has the vulnerability, and the vulnerability repair button on the preset vulnerability repair page is detected to be clicked. In this case, the preset vulnerability handling method will be automatically invoked to handle the vulnerability and obtain the repaired virtual machine.

[0021] Optionally, before automatically invoking the preset vulnerability handling method to handle the vulnerability when the detection and evaluation report shows that the target virtual machine has the vulnerability and the vulnerability repair button on the preset vulnerability repair page is clicked, the method further includes:

[0022] Obtain target data processing software generated based on Clam AV command line; wherein, the target data processing software includes a multi-threaded background program, a scanning program, and an automatic upgrade program;

[0023] Display the preset vulnerability repair page of the target data processing software.

[0024] Optionally, after receiving the user access request, the method further includes:

[0025] Obtain the target information corresponding to the user access request; wherein, the target information includes the access source IP, destination port, and user key;

[0026] Determine whether the target information meets the preset port access rules;

[0027] If the target information does not meet the preset port access rules, the target information is discarded and an alarm message is generated;

[0028] The alarm information is sent to the system management and maintenance area so that the system management and maintenance area can perform preset maintenance operations.

[0029] Secondly, this application discloses a request sending device, comprising:

[0030] The virtual machine determination module is used to receive user access requests and determine the corresponding target virtual machine;

[0031] The virtual machine detection module is used to detect the target virtual machine based on a preset detection method to obtain a corresponding detection evaluation report;

[0032] The request sending module is used to send the user access request to the target area based on preset data processing rules when the detection and evaluation report shows that the target virtual machine does not have any vulnerabilities.

[0033] Thirdly, this application discloses an electronic device, including:

[0034] Memory, used to store computer programs;

[0035] A processor for executing the computer program to implement the steps of the request sending method disclosed above.

[0036] Fourthly, this application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the request sending method disclosed above.

[0037] As can be seen, this application provides a request sending method, including: receiving a user access request and determining the corresponding target virtual machine; detecting the target virtual machine based on a preset detection method to obtain a corresponding detection evaluation report; when the detection evaluation report shows that the target virtual machine does not have vulnerabilities, sending the user access request to a target area based on preset data processing rules. Therefore, this application improves data security and reduces the difficulty of use for users by detecting the target virtual machine and determining whether to forward the user request based on the obtained detection evaluation report. When the target virtual machine has vulnerabilities, the user request is not forwarded. Attached Figure Description

[0038] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0039] Figure 1 This is a flowchart of a request sending method disclosed in this application;

[0040] Figure 2 This is a flowchart of a specific request sending method disclosed in this application;

[0041] Figure 3 This is a schematic diagram of the port hardening process disclosed in this application;

[0042] Figure 4 This is a schematic diagram of the data flow of the hardened port disclosed in this application;

[0043] Figure 5 This is a flowchart of a specific request sending method disclosed in this application;

[0044] Figure 6 This is the flowchart of the hardened alarm process disclosed in this application;

[0045] Figure 7 A schematic diagram of the request sending device provided for this application;

[0046] Figure 8 This application provides a structural diagram of an electronic device. Detailed Implementation

[0047] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0048] Currently, with the widespread adoption of cloud-based technologies, the demand for cloud security is also increasing, making threat detection and mitigation for advanced technologies increasingly important. Under the cloud computing architecture, open networks and shared business scenarios are more complex and dynamic, posing more severe security challenges and highlighting emerging security issues. Cloud computing provides elastic and variable IT services through the network; users need to log in to the cloud to use applications and services. The system needs to ensure the legitimacy of the user's identity before providing services. If an unauthorized user obtains a user's identity, it will jeopardize the data and business of legitimate users. Therefore, this application provides a request sending method that can improve data security and reduce the difficulty of use for users.

[0049] This invention discloses a request sending method, see [link to relevant documentation]. Figure 1 As shown, the method includes:

[0050] Step S11: Receive user access requests and determine the corresponding target virtual machine.

[0051] In this embodiment, a user access request is received, and the corresponding target virtual machine is determined. It is understood that determining the target virtual machine based on the user access request is necessary to detect the target virtual machine and address any security vulnerabilities it may pose.

[0052] Step S12: Detect the target virtual machine based on a preset detection method to obtain a corresponding detection evaluation report.

[0053] In this embodiment, after receiving a user access request and identifying the corresponding target virtual machine, the system detects the target virtual machine based on a preset detection method to obtain a corresponding detection and evaluation report. It is understood that this system runs on a cloud management platform and provides a security detection tool to offer security detection functionality for virtual machines in the cloud, i.e., performing security detection on cloud virtual machines and automatically generating detection and evaluation reports. It should be noted that detecting the target virtual machine based on the preset detection method is a periodic security detection function; users can choose to periodically perform vulnerability detection updates and vulnerability patching according to their own business characteristics.

[0054] For example, it can perform vulnerability scans on business virtual machines based on UDP (User Datagram Protocol), TCP connect(), TCPSYN (half-open scan), FTP (File Transfer Protocol) proxy (bounce attack), reverse flag, ICMP (Internet Control Message Protocol), FIN, ACK (Acknowledgement) scan, Christmas tree scan, null scan, and other scanning modes to query vulnerabilities in cloud virtual machines and automatically generate detailed vulnerability scan results based on the vulnerability scan results.

[0055] It is understood that the target detection information set includes detailed vulnerability scan results, password expiration time, time during which users are allowed to change their passwords, minimum password length, password expiration prompts, client connection failure exit time, and a list of open ports.

[0056] Step S13: When the detection and evaluation report shows that the target virtual machine does not have any vulnerabilities, the user access request is sent to the target area based on the preset data processing rules.

[0057] In this embodiment, after detecting the target virtual machine based on a preset detection method to obtain a corresponding detection evaluation report, if the detection evaluation report shows that the target virtual machine has no vulnerabilities, the user access request is sent to the target area based on preset data processing rules. It can be understood that if the detection evaluation report shows that the target virtual machine has vulnerabilities, the vulnerabilities are processed based on the detection evaluation report and the target data processing software. After the vulnerability processing is completed, a second detection is performed. If the detection result still shows vulnerabilities, the repair continues until no vulnerabilities are found in the detection report. At this point, the detection stops, and the user access request is sent to the target area based on preset data processing rules.

[0058] This solution integrates all virtual machines within the cloud with security vulnerability scanning to eliminate potential security risks. It also performs periodic security vulnerability checks on all virtual machines to promptly address security vulnerabilities in all cloud hosts within the private cloud and prevent security incidents. All traffic to all hosts within the cloud is inspected through a designated firewall to ensure all access originates from legitimate sources, preventing intrusions by hackers or other exploits. When new security vulnerabilities are exposed externally, the vulnerability database is updated promptly. If a network security vulnerability has a significant impact on society, the system will immediately perform security vulnerability scanning and remediation on all cloud hosts within the cloud.

[0059] As can be seen, this application provides a request sending method, including: receiving a user access request and determining the corresponding target virtual machine; detecting the target virtual machine based on a preset detection method to obtain a corresponding detection evaluation report; when the detection evaluation report shows that the target virtual machine does not have vulnerabilities, sending the user access request to a target area based on preset data processing rules. Therefore, this application improves data security and reduces the difficulty of use for users by detecting the target virtual machine and determining whether to forward the user request based on the obtained detection evaluation report. When the target virtual machine has vulnerabilities, the user request is not forwarded.

[0060] See Figure 2 As shown, this embodiment of the invention discloses a request sending method. Compared with the previous embodiment, this embodiment further explains and optimizes the technical solution.

[0061] Step S21: Receive user access requests and determine the corresponding target virtual machine.

[0062] Step S22: Periodically obtain the latest vulnerability information and update the vulnerability database based on the latest vulnerability information to obtain the current vulnerability database.

[0063] In this embodiment, the latest vulnerability information is periodically acquired, and the vulnerability database is updated based on this latest vulnerability information to obtain the current vulnerability database. It is understood that this system supports online vulnerability database upgrades, periodically performs security checks on business virtual machines based on the continuously updated vulnerability database, and repairs the target virtual machines based on the test results and one-click vulnerability processing and hardening operations. After hardening, vulnerability checks are performed again until all vulnerabilities are fixed.

[0064] Step S23: Scan the target virtual machine using a preset scanning method, and determine whether the target virtual machine contains a corresponding current vulnerability based on the current vulnerability database.

[0065] In this embodiment, the latest vulnerability information is obtained, and the vulnerability database is updated based on the latest vulnerability information to obtain the current vulnerability database. Then, the target virtual machine is scanned using a preset scanning method, and the existence of the corresponding current vulnerability in the target virtual machine is determined based on the current vulnerability database. Specifically, if the corresponding current vulnerability exists in the target virtual machine, the detection and evaluation report is generated based on the current vulnerability and the target detection information set.

[0066] It is understandable that, such as Figure 3As shown, the user's request performs a preset scan on the target virtual machine in the security hardening input layer and generates a detection and evaluation report, such as performing vulnerability detection. When the detection and evaluation report shows that the vulnerability does not exist in the real-time target virtual machine, it enters the security hardening collection layer to set the opening and closing of ports, and sets the preset data processing rules for the data flow of the user access request based on the list of open ports. After the settings are completed, it enters the security hardening distribution layer to perform inbound, outbound, and forwarding operations on the user request.

[0067] Step S24: When the detection and evaluation report shows that the target virtual machine has the vulnerability and the vulnerability repair button on the preset vulnerability repair page is clicked, the preset vulnerability handling method is automatically invoked to handle the vulnerability in order to obtain the repaired virtual machine.

[0068] In this embodiment, as Figure 4 As shown, the target virtual machine is scanned using a preset scanning method. After determining whether a corresponding current vulnerability exists in the target virtual machine based on the current vulnerability database, when the detection and evaluation report shows that the target virtual machine has the vulnerability and the vulnerability repair button on the preset vulnerability repair page is clicked, the preset vulnerability handling method is automatically invoked to handle the vulnerability, resulting in a repaired virtual machine. It can be understood that before automatically invoking the preset vulnerability handling method to handle the vulnerability when the detection and evaluation report shows that the target virtual machine has the vulnerability and the vulnerability repair button on the preset vulnerability repair page is clicked, target data processing software generated based on the Clam AV command line is obtained. This target data processing software includes a multi-threaded background program, a scanning program, and an automatic update program. The preset vulnerability repair page of the target data processing software is displayed. The preset vulnerability repair page has a vulnerability repair button; when the vulnerability repair button is clicked, all currently detected vulnerabilities can be repaired with a single click.

[0069] It should be noted that the target virtual machine is periodically checked for security vulnerabilities based on the K8s cronJob (scheduled task) mechanism. That is, the vulnerability is compared with the detection results in the system according to the feature value of the vulnerability in the vulnerability database. If the comparison is successful, the system vulnerability is confirmed, and then automatic repair is performed according to the vulnerability detection results.

[0070] Understandably, the ClamAV-based command-line antivirus system provides configurable, graphical one-click antivirus capabilities (i.e., target data processing software). This primarily includes a flexible, upgradeable, multi-threaded background program, a scanner, and an automatic update program. The target data processing software is a shared library file released alongside the ClamAntivirus package, featuring the following characteristics: high efficiency, multi-threaded background program; support for sendmail's microprocessor interface; support for digitally signed virus definition updates; support for a C language library for virus scanning; support for scans by access; multiple daily virus definition updates; built-in support for RAR (2.0), Zip, Gzip, Bzip2, Tar, MS OLE2, MS Cabinet files, MS CHM (compressed HTML), and MS SZDD compression formats; built-in support for mbox, Maildir, and raw email file formats; and built-in support for UPX (the UltimatePacker for eXecutables, an executable file compressor), FSG, and Petite compressed PE executables.

[0071] Furthermore, the repaired virtual machine is identified as the target virtual machine, and the process re-enters the step of detecting the target virtual machine based on a preset detection method to obtain a corresponding detection and evaluation report, thus obtaining the current detection and evaluation report. Based on the current detection and evaluation report, it is determined whether the vulnerability exists in the repaired virtual machine. If not, the process ends; if it exists, the process re-enters the step of automatically invoking a preset vulnerability handling method to handle the vulnerability when the detection and evaluation report shows that the target virtual machine has the vulnerability and the vulnerability repair button on the preset vulnerability repair page is clicked, thus obtaining the repaired virtual machine. It is understood that since there are two possible outcomes during the vulnerability repair process—successful repair and failure—the vulnerability repair operation continues as long as the detection and evaluation report shows that the target virtual machine has a vulnerability. After each repair, the target virtual machine is detected again until the detection and evaluation report shows that the target virtual machine does not have a vulnerability.

[0072] This solution integrates all virtual machines within the cloud into a security detection and hardening system. This system comprehensively manages all security issues within the cloud, performing security alerts, hardening, and vulnerability scanning for virtual machines. The system uses multiple scanning methods to scan business hosts, effectively detecting system vulnerabilities and updating the vulnerability database promptly to address any shortcomings in detecting newly discovered vulnerabilities. It provides a user-friendly interface for customizing security rules and one-click updates for Linux antivirus scans, reducing user complexity. Based on task scheduling, it enables periodic port hardening and system antivirus processing. For users' Linux virtual machines, the security hardening system provides a user-friendly interface for vulnerability scanning and one-click repair, eliminating the need for complex Linux command-line execution. It also allows for customization of the source IP and destination port for incoming access, enabling user-friendly port and IP vulnerability hardening.

[0073] Step S25: When the detection and evaluation report shows that the repaired virtual machine does not have any vulnerabilities, the user access request is sent to the target area based on the preset data processing rules.

[0074] For details regarding steps S21, S22, and S25, please refer to the corresponding content disclosed in the foregoing embodiments, which will not be repeated here.

[0075] As can be seen, this application embodiment receives user access requests and determines the corresponding target virtual machine; periodically obtains the latest vulnerability information and updates the vulnerability database based on the latest vulnerability information to obtain the current vulnerability database; scans the target virtual machine using a preset scanning method and determines whether the target virtual machine contains the corresponding current vulnerability based on the current vulnerability database; when the detection and evaluation report shows that the target virtual machine contains the vulnerability and the vulnerability repair button on the preset vulnerability repair page is clicked, the preset vulnerability handling method is automatically invoked to handle the vulnerability to obtain a repaired virtual machine; when the detection and evaluation report shows that the repaired virtual machine does not contain the vulnerability, the user access request is sent to the target area based on preset data processing rules, thereby improving data security and reducing the difficulty of use for users.

[0076] See Figure 5 As shown, this embodiment of the invention discloses a request sending method. Compared with the previous embodiment, this embodiment further explains and optimizes the technical solution.

[0077] Step S31: Receive user access request and determine the corresponding target virtual machine.

[0078] Step S32: Set the ports that meet the user's requirements as open ports and set the ports that do not meet the user's requirements as closed ports to obtain the list of open ports and the list of closed ports.

[0079] In this embodiment, after receiving a user access request and determining the corresponding target virtual machine, ports that meet the user's requirements are set as open ports, and ports that do not meet the user's requirements are set as closed ports, thus obtaining the open port list and the closed port list. It is understood that a user-customizable security port hardening function is provided to enable or disable corresponding ports according to user business needs. Specifically, based on the operating system kernel's ipset and iptables methods, users can customize the set of ports that the business virtual machine needs to open and close.

[0080] Step S33: Based on the list of open ports, set the preset data processing rules for the data flow direction of the user access request.

[0081] In this embodiment, ports that meet the user's requirements are set as open ports, and ports that do not meet the user's requirements are set as closed ports. After obtaining the list of open ports and the list of closed ports, preset data processing rules are set based on the list of open ports to determine the data flow direction of the user's access request. Specifically, data processing rules are set according to the set port set for the received access data in the inbound, forwarding, and outbound data flow directions.

[0082] It is understandable, for example Figure 6 As shown, after receiving a user request, the user request can be forwarded via routing, or the user request can be sent to POSTROUTING via routing.

[0083] Step S34: Obtain the target information corresponding to the user access request, and determine whether the target information meets the preset port access rules.

[0084] In this embodiment, after setting the preset data processing rules for the data flow of the user access request based on the open port list, the target information corresponding to the user access request is obtained, and it is determined whether the target information meets the preset port access rules; wherein, the target information includes the access source IP, destination port, and user key. Specifically, if the target information does not meet the preset port access rules, the target information is discarded and an alarm message is generated; the alarm message is sent to the system management and maintenance area so that the system management and maintenance area can perform preset maintenance operations.

[0085] It is understood that the preset port access rules may be, for example, sending the user request when the user's access IP and port are on the whitelist, or sending the user request when the user uses the corresponding key for accessing the business backend, or combining all of the above information to obtain the preset port access rules. It should be noted that the preset port access rules are not limited to the above examples and can be customized according to current user needs.

[0086] This solution supports abnormal access alarm function. For example, when a user accesses the business backend using an IP address and port that are not on the whitelist or without using the corresponding key, the system will automatically discard the current user request and trigger the security alarm system. The alarm information will be sent to the maintenance personnel via the configured email or SMS so that the maintenance personnel can intervene and handle the maintenance as soon as possible after receiving the information.

[0087] Step S35: If the target information meets the preset port access rules, then the target virtual machine is detected based on the preset detection method to obtain the corresponding detection evaluation report.

[0088] Step S36: When the detection and evaluation report shows that the target virtual machine does not have any vulnerabilities, the user access request is sent to the target area based on the preset data processing rules.

[0089] For details regarding steps S31, S35, and S36, please refer to the corresponding content disclosed in the foregoing embodiments, which will not be repeated here.

[0090] As can be seen, this application embodiment receives user access requests and determines the corresponding target virtual machine; sets ports that meet the user's requirements as open ports and ports that do not meet the user's requirements as closed ports to obtain an open port list and a closed port list; sets a preset data processing rule for the data flow of the user access request based on the open port list; obtains the target information corresponding to the user access request and determines whether the target information meets the preset port access rule; if the target information meets the preset port access rule, the target virtual machine is detected based on a preset detection method to obtain a corresponding detection evaluation report; when the detection evaluation report shows that the target virtual machine has no vulnerabilities, the user access request is sent to the target area based on the preset data processing rule, thereby improving data security and reducing the difficulty of use for users.

[0091] See Figure 7 As shown in the illustration, this application also discloses a request sending device, comprising:

[0092] The virtual machine determination module 11 is used to receive user access requests and determine the corresponding target virtual machine;

[0093] The virtual machine detection module 12 is used to detect the target virtual machine based on a preset detection method to obtain a corresponding detection evaluation report;

[0094] The request sending module 13 is used to send the user access request to the target area based on preset data processing rules when the detection and evaluation report shows that the target virtual machine does not have any vulnerabilities.

[0095] As can be seen, this application includes: receiving a user access request and determining the corresponding target virtual machine; detecting the target virtual machine based on a preset detection method to obtain a corresponding detection evaluation report; when the detection evaluation report shows that the target virtual machine does not have vulnerabilities, sending the user access request to the target area based on preset data processing rules. Therefore, this application improves data security and reduces the difficulty of use for users by detecting the target virtual machine and determining whether to forward the user request based on the obtained detection evaluation report. When the target virtual machine has vulnerabilities, the user request is not forwarded.

[0096] In some specific embodiments, the virtual machine determination module 11 specifically includes:

[0097] The request receiving unit is used to receive user access requests;

[0098] The target information acquisition unit is used to acquire the target information corresponding to the user access request; wherein, the target information includes the access source IP, the destination port, and the user key;

[0099] A preset port access rule judgment unit is used to determine whether the target information meets the preset port access rules;

[0100] An alarm information generation unit is used to discard the target information and generate an alarm information if the target information does not meet the preset port access rules.

[0101] An alarm information sending unit is used to send the alarm information to the system management and maintenance area so that the system management and maintenance area can perform preset maintenance operations;

[0102] The target virtual machine determination unit is used to determine the corresponding target virtual machine;

[0103] The port setting unit is used to set the ports that meet the user's requirements as open ports and the ports that do not meet the user's requirements as closed ports, so as to obtain the list of open ports and the list of closed ports.

[0104] The preset data processing rule setting unit is used to set the preset data processing rules for the data flow direction of the user access request based on the open port list.

[0105] In some specific embodiments, the virtual machine detection module 12 specifically includes:

[0106] The vulnerability database updating unit is used to periodically obtain the latest vulnerability information and update the vulnerability database based on the latest vulnerability information to obtain the current vulnerability database.

[0107] The virtual machine scanning unit is used to scan the target virtual machine using a preset scanning method and determine whether the target virtual machine contains a corresponding current vulnerability based on the current vulnerability database.

[0108] The detection and evaluation report generation unit is used to generate the detection and evaluation report based on the current vulnerability and the target detection information set if the target virtual machine contains the corresponding current vulnerability; wherein, the target detection information set includes password validity period, time during which the user is allowed to change the password, minimum password length, password expiration prompt, client connection failure exit time, and port open list;

[0109] The target data processing software acquisition unit is used to acquire target data processing software generated based on the Clam AV command line; wherein, the target data processing software includes a multi-threaded background program, a scanning program, and an automatic upgrade program;

[0110] A preset vulnerability repair page display unit is used to display the preset vulnerability repair page of the target data processing software;

[0111] The first vulnerability handling unit is used to automatically call a preset vulnerability handling method to handle the vulnerability when the detection and evaluation report shows that the target virtual machine has the vulnerability and the vulnerability repair button on the preset vulnerability repair page is clicked, so as to obtain a repaired virtual machine.

[0112] The virtual machine secondary detection unit is used to identify the repaired virtual machine as the target virtual machine, and re-enter the step of detecting the target virtual machine based on the preset detection method to obtain the corresponding detection evaluation report, so as to obtain the current detection evaluation report;

[0113] The vulnerability determination unit is used to determine whether the vulnerability exists in the repaired virtual machine based on the current detection and evaluation report; if it does not exist, the process ends.

[0114] The second vulnerability handling unit is used to automatically invoke a preset vulnerability handling method to handle the vulnerability if the vulnerability exists, in order to obtain the repaired virtual machine. This is done when the detection and evaluation report shows that the target virtual machine has the vulnerability and the vulnerability repair button on the preset vulnerability repair page is clicked.

[0115] In some specific embodiments, the request sending module 13 specifically includes:

[0116] The request sending unit is used to send the user access request to the target area based on preset data processing rules when the detection and evaluation report shows that the target virtual machine does not have any vulnerabilities.

[0117] Furthermore, embodiments of this application also provide an electronic device. Figure 8 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.

[0118] Figure 8 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the request sending method disclosed in any of the foregoing embodiments. Furthermore, the electronic device 20 in this embodiment may specifically be an electronic computer.

[0119] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.

[0120] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.

[0121] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the request sending method executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include a computer program capable of performing other specific tasks.

[0122] Furthermore, embodiments of this application also disclose a storage medium storing a computer program, which, when loaded and executed by a processor, implements the request sending method steps disclosed in any of the foregoing embodiments.

[0123] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.

[0124] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0125] The above provides a detailed description of a request sending method, apparatus, device, and storage medium provided by the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A request sending method, characterized in that, include: Receive user access requests and determine the corresponding target virtual machine; The target virtual machine is detected based on a preset detection method to obtain a corresponding detection and evaluation report; When the detection and evaluation report shows that the target virtual machine does not have any vulnerabilities, the user access request is sent to the target area based on the preset data processing rules; The step of detecting the target virtual machine based on a preset detection method to obtain a corresponding detection evaluation report includes: The target virtual machine is scanned using a preset scanning method, and the existence of a corresponding current vulnerability in the target virtual machine is determined based on the current vulnerability database. If the target virtual machine contains the corresponding current vulnerability, the detection and evaluation report is generated based on the current vulnerability and the target detection information set. The target detection information set includes password validity period, time during which users are allowed to change their passwords, minimum password length, password expiration prompt, client connection failure exit time, and a list of open ports. The step of scanning the target virtual machine using a preset scanning method includes: Vulnerability scanning of business virtual machines is performed using UDP, TCP connect, TCP SYN, FTP proxy, reverse flag, ICMP, FIN, ACK scanning, Christmas tree, and Null scanning modes. After detecting the target virtual machine based on a preset detection method to obtain a corresponding detection evaluation report, the method further includes: When the detection and evaluation report shows that the target virtual machine has the vulnerability and the vulnerability repair button on the preset vulnerability repair page is clicked, the preset vulnerability handling method is automatically invoked to handle the vulnerability and obtain a repaired virtual machine; the repaired virtual machine is identified as the target virtual machine, and the step of detecting the target virtual machine based on the preset detection method to obtain the corresponding detection and evaluation report is re-entered to obtain the current detection and evaluation report; based on the current detection and evaluation report, it is determined whether the vulnerability exists in the repaired virtual machine. If it does not exist, the process ends; if it exists, the step of automatically invoking the preset vulnerability handling method to handle the vulnerability and obtain a repaired virtual machine when the detection and evaluation report shows that the target virtual machine has the vulnerability and the vulnerability repair button on the preset vulnerability repair page is clicked is re-entered is re-entered.

2. The request sending method according to claim 1, characterized in that, Before scanning the target virtual machine using a preset scanning method and determining whether a corresponding current vulnerability exists in the target virtual machine based on the current vulnerability database, the method further includes: The system regularly acquires the latest vulnerability information and updates the vulnerability database based on this information to obtain the current vulnerability database.

3. The request sending method according to claim 1, characterized in that, After receiving the user access request and determining the corresponding target virtual machine, the process further includes: Ports that meet the user's requirements are set as open ports, and ports that do not meet the user's requirements are set as closed ports, so as to obtain the list of open ports and the list of closed ports; Based on the list of open ports, preset data processing rules are set for the data flow direction of the user access request.

4. The request sending method according to claim 1, characterized in that, Before automatically invoking the preset vulnerability handling method to handle the vulnerability when the detection and evaluation report shows that the target virtual machine has the vulnerability and the vulnerability repair button on the preset vulnerability repair page is clicked, the method further includes: Obtain target data processing software generated based on Clam AV command line; wherein, the target data processing software includes a multi-threaded background program, a scanning program, and an automatic upgrade program; Display the preset vulnerability repair page of the target data processing software.

5. The request sending method according to any one of claims 1 to 4, characterized in that, After receiving the user access request, the process also includes: Obtain the target information corresponding to the user access request; wherein, the target information includes the access source IP, destination port, and user key; Determine whether the target information meets the preset port access rules; If the target information does not meet the preset port access rules, the target information is discarded and an alarm message is generated; The alarm information is sent to the system management and maintenance area so that the system management and maintenance area can perform preset maintenance operations.

6. A request sending device, characterized in that, The steps for implementing the request sending method as described in any one of claims 1 to 5 include: The virtual machine determination module is used to receive user access requests and determine the corresponding target virtual machine; The virtual machine detection module is used to detect the target virtual machine based on a preset detection method to obtain a corresponding detection evaluation report; The request sending module is used to send the user access request to the target area based on preset data processing rules when the detection and evaluation report shows that the target virtual machine does not have any vulnerabilities.

7. An electronic device, characterized in that, include: Memory, used to store computer programs; A processor for executing the computer program to implement the steps of the request sending method as described in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, Used to store a computer program; wherein, when the computer program is executed by a processor, it implements the request sending method as described in any one of claims 1 to 5.