Protection methods and devices, servers and storage media

By generating and propagating security events through the local management system, the server network security problem was solved, proactive protection and cross-domain blocking attacks were achieved, and the server's protection capabilities were improved.

CN116032607BActive Publication Date: 2026-05-26LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
LENOVO ENTERPRISE SOLUTIONS (SINGAPORE) PTE LTD
Filing Date
2022-12-28
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

In large data centers or cloud computing bases, server network security faces serious threats. Existing technologies are insufficient to proactively protect the server's internal native management system and operating system, making it difficult to detect and block attacks in a timely manner.

Method used

The system generates security events by managing the local system and sends them to the operating system and management system of the managed server to achieve proactive protection. At the same time, the system propagates security events within the cluster to achieve cross-domain protection and block attack ports.

Benefits of technology

It achieves proactive defense within the server, enabling timely blocking of attacks, preventing the spread of attacks, and improving network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116032607B_ABST
    Figure CN116032607B_ABST
Patent Text Reader

Abstract

This application discloses a protection method and device, a server, and a storage medium. The protection method includes: if a local management system determines that it is under attack, generating a security event corresponding to the attack; the local management system sending the security event to the operating system of the managed server, enabling the operating system to perform proactive protection based on the security event; wherein the managed server supports the local management system in implementing management functions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security technology, and includes, but is not limited to, a protection method and device, a server, and a storage medium. Background Technology

[0002] With the rapid development of information technology and the computer industry, servers are widely and deeply used in people's production and daily lives. In some large data centers or cloud computing bases, tens of thousands or even hundreds of thousands of servers may be deployed. Therefore, server network security is of paramount importance. Summary of the Invention

[0003] In view of this, embodiments of this application provide a protection method and apparatus, a server, and a storage medium.

[0004] The technical solution of this application embodiment is implemented as follows:

[0005] In a first aspect, embodiments of this application provide a protection method, the method comprising:

[0006] If the local management system determines that it has been attacked, it generates a security event corresponding to the attack.

[0007] The local management system sends the security event to the operating system of the managed server, enabling the operating system to perform proactive protection based on the security event;

[0008] The managed server supports the local management system in implementing management functions.

[0009] In some embodiments, the method further includes: the local management system reporting the security event to the corresponding first management system, so that the first management system can propagate the security event to other local management systems in the first cluster besides the local management system, and then the other local management systems can perform proactive protection based on the security event; wherein, the first cluster includes multiple local management systems in the same network domain, and the first management system is used to manage each local management system in the first cluster.

[0010] In some embodiments, the method further includes at least one of the following: the local management system reports the security event to the corresponding second management system through the first management system, enabling the second management system to propagate the security event to other first management systems in the second cluster besides the first management system; wherein, the second cluster includes multiple first management systems belonging to different network domains, and the second management system is used to manage each first management system in the second cluster; the local management system reports the security event to the corresponding second management system through the first management system, enabling the second management system to block the attack port of the network switch corresponding to the security event.

[0011] In some embodiments, the first management system and the second management system are deployed on the same management device, or the first management system and the second management system are deployed on different management devices.

[0012] In some embodiments, the method further includes: if the operating system of the managed server determines that it has been attacked, generating a security event corresponding to the attack; the operating system sends the security event to the local management system via a Universal Serial Bus address, enabling the local management system to perform proactive protection based on the security event.

[0013] In some embodiments, the security event includes the attacking IP and at least one of the following parameters: the attacker's attempt, the start time of the attack, and the MAC address of the attack.

[0014] In some embodiments, the method further includes: acquiring system events; analyzing the system events to determine event information of the system events; and if the event information of the system events meets preset conditions, the local management system determines that it has been attacked.

[0015] Secondly, embodiments of this application provide a protective device, the device comprising:

[0016] The first event generation unit is used to generate a security event corresponding to the attack if the local management system determines that it has been attacked.

[0017] The first event sending unit is used by the local management system to send the security event to the operating system of the managed server, so that the operating system can perform proactive protection based on the security event;

[0018] The managed server supports the local management system in implementing management functions.

[0019] Thirdly, embodiments of this application provide a managed server, including a memory and a processor. The memory stores a computer program that can run on the processor, and when the processor executes the program, it implements the steps in the above-described protection method.

[0020] Fourthly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the above-described method.

[0021] This application provides a protection method, device, server, and storage medium. If a local management system determines it is under attack, it generates a security event corresponding to the attack. The local management system sends the security event to the operating system of the managed server, enabling the operating system to perform proactive protection based on the security event. The managed server supports the local management system in implementing management functions, thus enabling proactive defense. When the local management system within the server is attacked, the operating system within the server receives the information and proactively blocks the attack. Attached Figure Description

[0022] Figure 1 This is a schematic diagram illustrating the implementation process of the protection method in the embodiments of this application. Figure 1 ;

[0023] Figure 2 This is a schematic diagram illustrating the implementation process of the protection method in the embodiments of this application. Figure 2 ;

[0024] Figure 3 This is a schematic diagram illustrating the implementation process of the protection method in the embodiments of this application. Figure 3 ;

[0025] Figure 4A Schematic diagram of the protection method corresponding to the embodiment of this application Figure 1 ;

[0026] Figure 4B Schematic diagram of the protection method corresponding to the embodiment of this application Figure 2 ;

[0027] Figure 4C Schematic diagram of the protection method corresponding to the embodiment of this application Figure 3 ;

[0028] Figure 5 This is a schematic diagram of the composition and structure of the protective device according to an embodiment of this application;

[0029] Figure 6 This is a schematic diagram of a hardware entity of the managed server in an embodiment of this application. Detailed Implementation

[0030] The technical solutions of this application will be further described in detail below with reference to the accompanying drawings and embodiments. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0031] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0032] In the following description, the use of suffixes such as "module," "part," or "unit" to denote elements is solely for the purpose of illustration and has no specific meaning in itself. Therefore, "module," "part," or "unit" may be used interchangeably.

[0033] It should be noted that the terms "first, second, and third" used in the embodiments of this application are merely to distinguish similar objects and do not represent a specific ordering of objects. It is understood that "first, second, and third" can be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0034] Based on this, this application provides a protection method. The function implemented by this method can be achieved by the processor in the managed server calling program code. Of course, the program code can be stored in the storage medium of the managed server. Figure 1 This is a schematic diagram illustrating the implementation process of the protection method in the embodiments of this application. Figure 1 ,like Figure 1 As shown, the method includes:

[0035] Step S101: If the local management system determines that it has been attacked, it generates a security event corresponding to the attack.

[0036] In this embodiment, the local management system can be any management system with server management capabilities, such as XCC (Lenovo XClarity Controller), which can monitor and manage the local machine. Each managed server corresponds to one XCC, and the XCC can obtain parameter information from the corresponding managed server, such as hardware configuration information, resource usage information, temperature information, power consumption information, and health status information. The XCC can be considered as the firmware built into the managed server itself.

[0037] Here, if the local management system on the managed server determines that it has been attacked, it generates a corresponding security event based on the attack. For example, the generated security event may include information such as the attacker's IP address (Internet Protocol), the attack attempt, and the time the attack occurred.

[0038] Step S102: The local management system sends the security event to the operating system of the managed server, enabling the operating system to perform proactive protection based on the security event; wherein, the managed server supports the local management system in implementing management functions.

[0039] In this embodiment, a managed server includes a local management system and an operating system. Furthermore, if the local management system is attacked, it can generate a security event based on the attack and send it to the operating system of the managed server. In this way, the operating system can proactively block the attacker's IP address in the security event through its own firewall rules, preventing itself from being attacked by the same attacker and achieving proactive protection. Of course, besides blocking the attacker's IP address in the security event through its own firewall rules, other methods and means can be used to achieve proactive protection after receiving a security event; this embodiment does not limit this approach.

[0040] Here, through the methods in steps S101 to S102 above, proactive defense can be achieved. When the local management system inside the server is attacked, the operating system inside the server will receive the information and then proactively block the attack.

[0041] In some embodiments, the security event includes the attacking IP and at least one of the following parameters: the attacker's attempt, the start time of the attack, and the MAC (Media Access Control) address of the attack.

[0042] For example, the attacker's IP address could be 192.168.1.222, the attack could start at 8:00 AM on December 1, 2022, the attacker's attempt could be to fail to log in 10 times within 1 minute, and the attacker's MAC address could be 00-16-EA-AE-3C-40.

[0043] Based on the foregoing embodiments, this application further provides a protection method, which is applied to a managed server, and the method includes:

[0044] Step S111: If the local management system determines that it has been attacked, it generates a security event corresponding to the attack.

[0045] Step S112: The local management system sends the security event to the operating system of the managed server, enabling the operating system to perform proactive protection based on the security event; wherein, the managed server supports the local management system in implementing management functions.

[0046] In this embodiment of the application, if the attacked end comes from the local management system, the operating system can obtain the attacker's IP from the local management system through internal communication, and then update the firewall to achieve the purpose of proactive protection.

[0047] Step S113: If the operating system of the managed server determines that it has been attacked, it generates a security event corresponding to the attack.

[0048] Here, if the operating system on the managed server determines that it has been attacked, a corresponding security event is generated based on the attack. For example, the generated security event may include information such as the attacker's IP address (Internet Protocol), the attack attempt, and the time the attack occurred.

[0049] Step S114: The operating system sends the security event to the local management system via a Universal Serial Bus address, enabling the local management system to perform proactive protection based on the security event.

[0050] In this embodiment of the application, if the attacked end comes from the operating system, the operating system's firewall will communicate with its own local management system after performing initial protection. The local management system will then perform proactive protection after receiving the attack notification.

[0051] For example, when a managed server boots up, it normally uses two sets of IPs: one set is assigned to XCC, and the other set is assigned to the host node (belonging to the operating system). The XCC IP is an internal network IP, which is separate from the host node IP under the operating system. Under the operating system, there is a set of virtual IPs called Ethernet Over USB IPs. This set of virtual IPs acts as a bridge between the host node and XCC. When the operating system is attacked, it can notify XCC of the event through Ethernet Over USB IPs.

[0052] In this embodiment, for security reasons, security events are sent to the local management system via a Universal Serial Bus address (i.e., Ethernet Over USB IP). The device containing this Universal Serial Bus address (i.e., Ethernet Over USB) serves as a communication device separating the enterprise's internal network from the external network. If the server's operating system is infected, it cannot infect other devices or the network environment through this device. Therefore, this device is a highly secure broadcast medium, allowing the infected server to communicate with its own local management system through this medium. This enables the local management system to perform proactive protection and to spread the attacks it has suffered, thereby notifying other servers to perform proactive protection.

[0053] Here, through the methods described in steps S111 to S113 above, proactive defense can be achieved. When the local management system inside the server is attacked, the operating system inside the server will receive the information and proactively block the attack.

[0054] Based on the foregoing embodiments, this application further provides a protection method, which is applied to a managed server, and the method includes:

[0055] Step S121: Obtain system events;

[0056] Here, the system events can be events detected by detecting abnormal conditions in the server's hardware or operating system, or events detected by detecting input operations. Furthermore, in this embodiment, the presence of an attack can be determined by analyzing system events, and then a firewall can be used to block the source of the attack.

[0057] Step S122: Analyze the system events to determine the event information of the system events;

[0058] Step S123: If the event information of the system event meets the preset conditions, the local management system determines that it has been attacked.

[0059] For example, if a system event "failed to log in 3 times within one minute" is detected, and this system event has occurred multiple times, the login IPs are compared. If the login IPs are all from the same source and the attack behavior is consistent, but the username or password is wrong, an anomaly is initially determined. If another different IP continues to log in incorrectly, both IPs are considered to be attacker IPs, and an attack event is confirmed.

[0060] In other words, firewall rules in related technologies only block login for a preset time if the username and password are entered incorrectly too many times. After the preset time expires, the blocking is automatically lifted, allowing login again. Attackers can attempt to log in an unlimited number of times. However, in this application's embodiment, the analysis of the server's hardware status, operating system status, or input operations can determine whether an event is normal or an attack, thus enabling early detection of attacks and proactive protection.

[0061] Step S124: If the local management system determines that it has been attacked, it generates a security event corresponding to the attack.

[0062] Step S125: The local management system sends the security event to the operating system of the managed server, enabling the operating system to perform proactive protection based on the security event; wherein, the managed server supports the local management system in implementing management functions.

[0063] Based on the foregoing embodiments, this application further provides a protection method, which is applied to a managed server. Figure 2 This is a schematic diagram illustrating the implementation process of the protection method in the embodiments of this application. Figure 2 ,like Figure 2 As shown, the method includes:

[0064] Step S201: If the local management system determines that it has been attacked, it generates a security event corresponding to the attack.

[0065] Step S202: The local management system sends the security event to the operating system of the managed server, enabling the operating system to perform proactive protection based on the security event; wherein, the managed server supports the local management system in implementing management functions;

[0066] Step S203: The local management system reports the security event to the corresponding first management system, enabling the first management system to propagate the security event to other local management systems in the first cluster besides the local management system, so that the other local management systems can perform proactive protection based on the security event; wherein, the first cluster includes multiple local management systems within the same network domain, and the first management system is used to manage each local management system in the first cluster.

[0067] In this embodiment, the first management system can be any system with batch server management capabilities, such as LXCA (Lenovo XClarity Administrator). LXCA can provide batch deployment functions for a large number of servers, including operating system installation, server configuration, and firmware updates. The first management system can be software installed on a management server.

[0068] Here, the first cluster can be a service system consisting of a group (or several) of managed servers. Each managed server corresponds to a local management system, therefore the first cluster includes multiple local management systems within the same network domain. Furthermore, the first management system manages each local management system within the first cluster. For example, an LXCA can manage multiple XCCs corresponding to servers. That is, a managed server corresponds to its own system's XCC, and the LXCA is used to integrate XCCs from all network domains for unified and centralized management.

[0069] For example, if managed server A is attacked, the XCC (Xinjiang Control Center) of managed server A will report the security event generated by the attack to the corresponding LXCA (Local Level Management Center). The LXCA will then propagate the security event to the XCCs of managed servers B, C, and D. Upon receiving the security event, the XCCs of managed servers B, C, and D will proactively defend against it (e.g., blocking the attacker's IP address in the security event) and notify their local operating systems of the security event.

[0070] Here, through the methods in steps S201 to S203 above, proactive defense can be achieved. When a server is attacked, all servers in the same network domain will receive the information and proactively block the attack.

[0071] In some embodiments, the method further includes at least one of the following:

[0072] In the first method, the local management system reports the security event to the corresponding second management system through the first management system, enabling the second management system to propagate the security event to other first management systems in the second cluster besides the first management system; wherein, the second cluster includes multiple first management systems belonging to different network domains, and the second management system is used to manage each first management system in the second cluster;

[0073] The second method involves the local management system reporting the security event to the corresponding second management system through the first management system, enabling the second management system to block the attack port of the network switch corresponding to the security event.

[0074] Based on the foregoing embodiments, this application further provides a protection method, which is applied to a managed server. Figure 3 This is a schematic diagram illustrating the implementation process of the protection method in the embodiments of this application. Figure 3 ,like Figure 3 As shown, the method includes:

[0075] Step S301: If the local management system determines that it has been attacked, it generates a security event corresponding to the attack.

[0076] Step S302: The local management system sends the security event to the operating system of the managed server, enabling the operating system to perform proactive protection based on the security event; wherein, the managed server supports the local management system in implementing management functions;

[0077] Step S303: The local management system reports the security event to the corresponding first management system, enabling the first management system to propagate the security event to other local management systems in the first cluster besides the local management system, so that the other local management systems can perform proactive protection based on the security event; wherein, the first cluster includes multiple local management systems within the same network domain, and the first management system is used to manage each local management system in the first cluster.

[0078] Step S304: The local management system reports the security event to the corresponding second management system through the first management system, so that the second management system can propagate the security event to other first management systems in the second cluster besides the first management system; wherein, the second cluster includes multiple first management systems belonging to different network domains, and the second management system is used to manage each first management system in the second cluster;

[0079] In this embodiment, the second management system can be any system capable of managing the first management system, such as LXCO (Lenovo XClarity Orchestrator). LXCO can integrate all LXCAs for unified management, including LXCAs across domains, facilitating international management. LXCO's function is to monitor all LXCA-integrated XCC servers, including any attack events and terminal server version updates. This second management system can be software installed on a management server.

[0080] For example, a first LXCA manages multiple XCCs within a first network domain, a second LXCA manages multiple XCCs within a second network domain, and a third LXCA manages multiple XCCs within a third network domain. An LXCO manages the first, second, and third LXCAs. The first, second, and third network domains are three distinct network domains. If an XCC within the first network domain is attacked, the corresponding security event is reported to the LXCO via the first LXCA. The LXCO then propagates the security event to the second and third LXCAs, enabling multiple XCCs in the second and third network domains to proactively protect themselves based on this security event.

[0081] Step S305: The local management system reports the security event to the corresponding second management system through the first management system, so that the second management system can block the attack port of the network switch corresponding to the security event.

[0082] Here, the network switch is the first step for hackers or infected servers to connect to the network. As long as the network switch is identified and its attack ports are blocked, the attack can be stopped.

[0083] Here, through the methods in steps S301 to S305 above, proactive defense can be achieved. When a server is attacked, servers in different domains will receive the information and proactively block the attack.

[0084] In some embodiments, the first management system and the second management system are deployed on the same management device, or the first management system and the second management system are deployed on different management devices.

[0085] Here, the first management system and the second management system can be deployed on the same management device or on different management devices.

[0086] Unlike related technologies that typically use XCC (Lenovo XClarity Controller) to protect a single server (such as a managed server), this application aims to protect the security of all servers across a domain and internationally through LXCA and LXCO. Therefore, this application proposes a proactive defense method where, when one managed server is attacked, all servers receive the information and proactively block the attack.

[0087] The main components of this protective method include:

[0088] First, security incidents are transmitted between XCC and host nodes, and firewall rules are updated to prevent hacker attacks.

[0089] In this embodiment, a managed server has a host node and a corresponding XCC. Therefore, if the XCC is attacked, the security event generated by the attack can be transmitted to the host node, enabling the host node to perform proactive protection. Similarly, if the host node is attacked, the security event generated by the attack can be transmitted to the XCC, enabling the XCC to perform proactive protection.

[0090] Second, proactive protection against hacker attacks is achieved by transmitting security incidents between XCC and LXCA, and between LXCA and LXCO.

[0091] In this embodiment, LXCA is used to integrate XCCs across all domains for unified centralized management, while LXCO is used to integrate all LXCAs for unified management. LXCO can integrate LXCAs across domains, facilitating international management. The main function of LXCO is to monitor server version updates for all XCC servers and terminals integrated into all LXCAs. The difference between LXCO and LXCA is that LXCO presents a report-based view, making it easier for administrators to detect any anomalies occurring on servers in different locations.

[0092] The protection methods in the embodiments of this application are described in detail below:

[0093] (1) Protect the nodes managed by XCC: XCC will trigger security events with attack IP information.

[0094] That is, if an XCC node is attacked, the XCC node generates a security event using the attacker's intent, attacker's IP address, attack start time, and attacker's MAC address, and sends the generated security event to the host node (e.g., the operating system in the managed server). The host node then receives the security event via its internal LAN (Local Area Network) IP or USB (Universal Serial Bus) IP and updates its firewall rules to block the attacker's IP address carried in the security event, thus achieving proactive protection. Of course, after receiving a security event, the host node can use other means besides updating its firewall rules for proactive protection; this embodiment does not limit this approach.

[0095] For example, when a server boots up, it normally uses two sets of IPs: one for XCC and the other for the host nodes. The XCC IP is the company's internal network IP, which is separate from the host node IPs under the operating system. Under the operating system, there is a set of virtual IPs called Ethernet Over USB IPs. This set of virtual IPs acts as a bridge between the host nodes and XCC. When the operating system is attacked, it can notify XCC of the event through the Ethernet Over USB IP, and then XCC will report it to LXCA / LXCO.

[0096] Figure 4A Schematic diagram of the protection method corresponding to the embodiment of this application Figure 1 ,like Figure 4A As shown, the IP address of the XCC node in a managed server is 192.168.1.10, and the IP address of the host node in the managed server is 192.168.1.11. After the XCC node is attacked by an attacker with the IP address 192.168.1.222, the XCC node notifies the host node of the attack event carrying the attack IP address "192.168.1.222". The host node then updates its firewall rules to block the attacker's IP address. This attack event may include not only the attacker's IP address, but also the target attack IP address "192.168.1.10", the MAC address, the start time "2021 / 8 / 8 18:00", and the attack attempt "3 failed login attempts within 1 minute".

[0097] In this application embodiment, there are two types of events: security events and system events. System events are the detection of abnormal conditions in the server's hardware or operating system, while security events are the monitoring of abnormal operations, including any login information, both normal and abnormal information, and the artificial reduction of the system's security level.

[0098] (2) Protecting XCC nodes managed by LXCA: LXCA receives security events from attacked XCC nodes, notifies managed XCC nodes, and XCC nodes block attacker IPs after receiving the notification.

[0099] That is, an XCC node reports a security event to the LXCA, which then propagates the security event to multiple managed XCC nodes. These managed XCC nodes receive the security event and block the attacker's IP.

[0100] Figure 4B Schematic diagram of the protection method corresponding to the embodiment of this application Figure 2 ,like Figure 4BAs shown, LXCA with IP address 192.168.1.1 manages three XCC nodes: XCC nodes with IP addresses 192.168.1.20, 192.168.1.10, and 192.168.1.30. The XCC node with IP address 192.168.1.10 is attacked by an attacker with IP address 192.168.1.222. After the attack, the XCC node with IP address 192.168.1.10 generates a corresponding security event and sends it to LXCA with IP address 192.168.1.1. LXCA then propagates the security event to the other two XCC nodes, enabling them to take proactive protective measures based on the security event. This attack event may include not only the attacker's IP address but also information such as the target attack IP address "192.168.1.10".

[0101] Here, attackers typically launch global attacks on enterprise servers. Most servers have built-in defenses against excessively high password misses, but too many incorrect password attempts can lock the entire system's login, preventing server administrators from logging in for an extended period. Therefore, the best protection is to block the attacker's IP address to prevent a global server lockdown. Server administrators would then need to physically restart XCC on their local servers to immediately unlock the system. In this embodiment, XCC itself cannot notify other servers of an attack; global broadcasting via LXCA and LXCO is necessary to prevent all servers from proactively blocking login services after an attack. Blocking the attacker's IP address is sufficient for defense. This enables proactive global defense.

[0102] (3) Protecting clusters managed by LXCO: LXCO receives a security event sent by a certain LXCA, and LXCO notifies other managed LXCAs and managed network switches.

[0103] In other words, LXCA reports security incidents to LXCO. Upon receiving the incident, LXCO propagates it to the LXCA nodes it manages, enabling the LXCA nodes to further propagate the incident to multiple XCC nodes under their management for proactive protection. Additionally, LXCO nodes block attacker ports in the network switches they manage.

[0104] Here, when hackers attack or computers are infected by viruses, they usually don't just target a single host or a single domain. The network switch is the first step for hackers or infected computers to connect to the network. As long as LXCO / LXCA can identify this switch, they can block the attack.

[0105] Figure 4C Schematic diagram of the protection method corresponding to the embodiment of this application Figure 3 ,like Figure 4C As shown, the LXCO with IP address 192.168.200.1 manages two LXCAs with IP addresses of 192.168.100.1 and 192.168.1.10, respectively. The attacker's IP address is 192.168.1.222. Therefore, in addition to sending security events generated based on the attacker's IP address to the two LXCAs, enabling them to proactively block the attacker's IP, the LXCO also blocks the attacker's port on the attacked network switch. This attack event may include not only the attacker's IP address but also information such as the target attack IP address "192.168.1.10".

[0106] In this embodiment, the administrator LXCA of the XCC can monitor an XCC that is under attack, and then broadcast the attack IP to other XCCs through LXCA. LXCA then notifies LXCO to perform global broadcast of LXCA, which can further prevent attacks on servers across domains or different regions.

[0107] Based on the foregoing embodiments, this application provides a protection device, which includes each unit, each module included in each unit, and each component included in each module. It can be implemented by a processor in a managed server; of course, it can also be implemented by specific logic circuits. In the implementation process, the processor can be a CPU (Central Processing Unit), MPU (Microprocessor Unit), DSP (Digital Signal Processor), or FPGA (Field Programmable Gate Array), etc.

[0108] Figure 5 This is a schematic diagram of the composition and structure of the protective device according to an embodiment of this application, as shown below. Figure 5 As shown, the device 500 includes:

[0109] The first event generation unit 501 is used to generate a security event corresponding to the attack if the local management system determines that it has been attacked.

[0110] The first event sending unit 502 is used by the local management system to send the security event to the operating system of the managed server, so that the operating system can perform active protection based on the security event;

[0111] The managed server supports the local management system in implementing management functions.

[0112] In some embodiments, the apparatus further includes:

[0113] The first reporting unit is used by the local management system to report the security event to the corresponding first management system, so that the first management system can propagate the security event to other local management systems in the first cluster other than the local management system, and then the other local management systems can perform proactive protection based on the security event;

[0114] The first cluster includes multiple local management systems within the same network domain, and the first management system is used to manage each local management system in the first cluster.

[0115] In some embodiments, the device further includes at least one of the following:

[0116] The second reporting unit is used by the local management system to report the security event to the corresponding second management system through the first management system, so that the second management system can propagate the security event to other first management systems in the second cluster besides the first management system; wherein, the second cluster includes multiple first management systems belonging to different network domains, and the second management system is used to manage each first management system in the second cluster;

[0117] The second reporting unit is further configured to allow the local management system to report the security event to the corresponding second management system through the first management system, so that the second management system can block the attack port of the network switch corresponding to the security event.

[0118] In some embodiments, the first management system and the second management system are deployed on the same management device, or the first management system and the second management system are deployed on different management devices.

[0119] In some embodiments, the apparatus further includes:

[0120] The second event generation unit is used to generate a security event corresponding to the attack if the operating system of the managed server determines that it has been attacked.

[0121] The second event sending unit is used by the operating system to send the security event to the local management system via a universal serial bus address, so that the local management system can perform proactive protection based on the security event.

[0122] In some embodiments, the security event includes the attacking IP and at least one of the following parameters: the attacker's attempt, the start time of the attack, and the MAC address of the attack.

[0123] In some embodiments, the apparatus further includes:

[0124] The system event acquisition unit is used to acquire system events;

[0125] An analysis unit is used to analyze the system events and determine the event information of the system events;

[0126] The determining unit is used to determine that the local management system is under attack if the event information of the system event meets preset conditions.

[0127] The descriptions of the above device embodiments are similar to those of the above method embodiments, and have similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0128] It should be noted that, in the embodiments of this application, if the above-mentioned protection method is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of this application, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause an electronic device (which may be a personal computer, server, etc.) to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM (Read Only Memory), magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware and software combination.

[0129] Correspondingly, this application provides a managed server, including a memory and a processor. The memory stores a computer program that can run on the processor. When the processor executes the program, it implements the steps in the protection method provided in the above embodiments.

[0130] Correspondingly, embodiments of this application provide a readable storage medium on which a computer program is stored, which, when executed by a processor, implements the steps in the above-described protection method.

[0131] It should be noted that the descriptions of the storage medium and device embodiments above are similar to the descriptions of the method embodiments above, and have similar beneficial effects. For technical details not disclosed in the storage medium and device embodiments of this application, please refer to the descriptions of the method embodiments of this application for understanding.

[0132] It should be noted that, Figure 6 This is a schematic diagram of a hardware entity of the managed server in an embodiment of this application, such as... Figure 6 As shown, the hardware entity of the managed server 600 includes: a processor 601, a communication interface 602, and a memory 603, wherein...

[0133] Processor 601 typically controls the overall operation of the managed server 600.

[0134] The communication interface 602 enables the managed server 600 to communicate with other managed servers, electronic devices, or platforms via a network.

[0135] The memory 603 is configured to store instructions and applications executable by the processor 601, and can also cache data to be processed or already processed by the various modules in the processor 601 and the managed server 600 (e.g., image data, audio data, voice communication data and video communication data), which can be implemented by FLASH (flash memory) or RAM (Random Access Memory).

[0136] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components can be combined, or integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed can be through some interfaces, and the indirect coupling or communication connection between devices or units can be electrical, mechanical, or other forms.

[0137] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the units may be selected to achieve the purpose of this embodiment according to actual needs.

[0138] Furthermore, in the various embodiments of this application, all functional units can be integrated into one processing module, or each unit can be a separate unit, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in a combination of hardware and software functional units. Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as mobile storage devices, ROM, RAM, magnetic disks, or optical disks.

[0139] The methods disclosed in the several method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.

[0140] The features disclosed in the several product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.

[0141] The features disclosed in the several method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.

[0142] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A protection method, characterized in that, The method includes: If the local management system of the managed server determines that it has been attacked, it generates a security event corresponding to the attack. The local management system of the managed server sends the security event to the operating system of the managed server, enabling the operating system to perform proactive protection based on the security event; The managed server supports the local management system in implementing management functions; The method further includes: The local management system reports the security event to the corresponding first management system, enabling the first management system to propagate the security event to other local management systems in the first cluster besides the local management system, so that the other local management systems can perform proactive protection based on the security event; wherein, the first cluster includes multiple local management systems within the same network domain, and the first management system is used to manage each local management system in the first cluster.

2. The method according to claim 1, characterized in that, The method further includes at least one of the following: The local management system reports the security event to the corresponding second management system through the first management system, enabling the second management system to propagate the security event to other first management systems in the second cluster besides the first management system; wherein, the second cluster includes multiple first management systems belonging to different network domains, and the second management system is used to manage each first management system in the second cluster; The local management system reports the security event to the corresponding second management system through the first management system, enabling the second management system to block the attack port of the network switch corresponding to the security event.

3. The method according to claim 2, characterized in that, The first management system and the second management system are deployed on the same management device, or the first management system and the second management system are deployed on different management devices.

4. The method according to claim 1, characterized in that, The method further includes: If the operating system of the managed server determines that it has been attacked, it generates a security event corresponding to the attack. The operating system sends the security event to the local management system via a Universal Serial Bus address, enabling the local management system to perform proactive protection based on the security event.

5. The method according to any one of claims 1 to 4, characterized in that, The security event includes the attacking IP and at least one of the following parameters: the attacker's intent, the start time of the attack, and the MAC address of the attack.

6. The method according to any one of claims 1 to 4, characterized in that, The method further includes: Get system events; The system events are analyzed to determine the event information of the system events; If the event information of the system event meets the preset conditions, the local management system determines that it has been attacked.

7. A protective device, characterized in that, The device includes: The first event generation unit is used to generate a security event corresponding to the attack if the local management system of the managed server determines that it has been attacked. The first event sending unit is used for the local management system of the managed server to send the security event to the operating system of the managed server, so that the operating system can perform active protection based on the security event; The managed server supports the local management system in implementing management functions; The first reporting unit is used by the local management system to report the security event to the corresponding first management system, so that the first management system can propagate the security event to other local management systems in the first cluster besides the local management system, and then the other local management systems can perform proactive protection based on the security event; wherein, the first cluster includes multiple local management systems in the same network domain, and the first management system is used to manage each local management system in the first cluster.

8. A managed server, comprising a memory and a processor, the memory storing a computer program executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the protection method according to any one of claims 1 to 6.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the protection method according to any one of claims 1 to 6.