Multi-cloud platform exception handling method, device and equipment based on single sign-on

By binding the single sign-on system with the multi-cloud platform and using the cloud platform control model to judge and handle abnormal behavior, the problem of weak user security on the multi-cloud platform is solved, and user account management is simplified and security is enhanced.

CN116074042BActive Publication Date: 2025-09-23ZHAOLIAN CONSUMER FINANCE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211560568.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-07
Publication Date
2025-09-23
Estimated Expiration
2042-12-07

AI Technical Summary

Technical Problem

When using multiple cloud platforms, users face weak security issues such as information authentication, cloud platform account management, and user behavior control, which leads to reduced user security and may cause unnecessary losses.

Method used

Through the single sign-on system, it is pre-bound with multiple cloud platforms to obtain user login and operation data, use the pre-configured cloud platform control model to judge abnormal behavior, and perform corresponding processing according to the abnormal type, including alarm and linkage management.

Benefits of technology

It reduces the complexity of user account management, enhances the security of user account management, ensures the security of users' use on multi-cloud platforms, and avoids unnecessary losses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116074042B_ABST
    Figure CN116074042B_ABST
Patent Text Reader

Abstract

The present application relates to a multi-cloud platform exception handling method, apparatus, computer equipment, storage medium and computer program product based on single sign-on. The method comprises: obtaining cloud audit data generated after a user logs in to a target cloud platform based on a single sign-on system, the cloud audit data including the user's login information and the user's operation data on the target cloud platform, the single sign-on system being pre-authenticated and bound to multiple cloud platforms, the target cloud platform being any one of the multiple cloud platforms; inputting the cloud audit data into a pre-configured cloud platform control model, and performing abnormal behavior judgment on the cloud audit data; if it is determined that the cloud audit data is abnormal, performing abnormal handling on the user according to the abnormal type of the cloud audit data. The use of this method can reduce the complexity of user account management, further ensure the user's security when using a multi-cloud platform, and avoid unnecessary losses to the user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of cloud platform technology, and in particular to a multi-cloud platform exception handling method, apparatus, computer equipment, storage medium, and computer program product based on single sign-on. Background Art

[0002] Cloud computing platforms, also known as cloud platforms, refer to services based on hardware and software resources, providing computing, networking, and storage capabilities. With the rapid development of cloud computing in recent years, many users are migrating their production operations to cloud platforms. Using both public and hybrid clouds has become a popular trend.

[0003] As the number of users using cloud platforms gradually increases, users also face a series of security issues when processing business on multi-cloud platforms. For example, the environmental security of cross-cloud platform information authentication, cloud platform account management, and cloud platform user behavior control is weak, which can easily lead to a decrease in user security and cause unnecessary losses. Summary of the Invention

[0004] Based on this, it is necessary to provide a multi-cloud platform exception handling method, device, computer equipment, computer-readable storage medium and computer program product based on single sign-on, which can improve the security of users when using multiple cloud platforms at the same time, in order to address the above technical problems.

[0005] In a first aspect, the present application provides a multi-cloud platform exception handling method based on single sign-on, the method comprising:

[0006] Obtaining cloud audit data generated after a user logs in to a target cloud platform based on a single sign-on system, the cloud audit data including the user's login information and the user's operation data on the target cloud platform, the single sign-on system being pre-authenticated and bound to multiple cloud platforms, and the target cloud platform being any one of the multiple cloud platforms;

[0007] Inputting the cloud audit data into a pre-configured cloud platform control model and performing abnormal behavior judgment on the cloud audit data;

[0008] If it is determined that the cloud audit data has an anomaly, the user is subjected to an anomaly processing according to the anomaly type of the cloud audit data.

[0009] In one embodiment, inputting the cloud audit data into a pre-configured cloud platform control model and performing abnormal behavior judgment based on the cloud audit data includes:

[0010] Inputting the cloud audit data into a pre-configured cloud platform control model, and performing data extraction on the cloud audit data to obtain target data;

[0011] Based on the target data, preset key data in the cloud platform control model and preset abnormal behavior detection rules, the cloud audit data is judged to be abnormal behavior;

[0012] When the comparison result between the target data and the preset key data satisfies the preset abnormal behavior checking rule, it is determined that an abnormality exists in the cloud audit data.

[0013] In one embodiment, the preset abnormal behavior inspection rule includes an alarm rule;

[0014] If it is determined that the cloud audit data has an anomaly, performing an anomaly processing on the user according to the anomaly type of the cloud audit data includes:

[0015] If the comparison result between the target data and the preset key data satisfies the alarm rule, determining that the abnormal type of the cloud audit data is an alarm type;

[0016] Generate alarm information based on the cloud audit data, where the alarm information is used to prompt the user that an alarm operation behavior has occurred on the target cloud platform;

[0017] The alarm information is sent to a designated user terminal based on a preset sending channel.

[0018] In one embodiment, the preset abnormal behavior inspection rules include linkage management rules;

[0019] If it is determined that the cloud audit data has an anomaly, performing an anomaly processing on the user according to the anomaly type of the cloud audit data includes:

[0020] If the comparison result between the target data and the preset key data satisfies the linkage management rule, determining that the abnormality type of the cloud audit data is a linkage management type;

[0021] Generate a linkage management instruction based on the cloud audit data, the linkage management instruction is used to instruct the linkage defense system to generate a single sign-on domain account management task and a multi-cloud platform account management task, control the single sign-on system to block the user's single sign-on domain account based on the single sign-on domain account management task, and control each cloud platform to block each cloud platform account of the user based on the multi-cloud platform account management task;

[0022] The linkage management instruction is sent to the linkage defense system.

[0023] In one embodiment, if the comparison result between the target data and the preset key data satisfies the alarm rule, determining that the abnormality type of the cloud audit data is an alarm type includes at least one of the following:

[0024] Item 1:

[0025] The target data includes account data, and the preset key data includes privileged account data; if the account data is consistent with the privileged account data, determining that the abnormality type of the cloud audit data is an alarm type;

[0026] Item 2:

[0027] The target data includes a source login address, and the preset key data includes a preset normal address list; if the source login address is not in the preset normal address list, determining that the abnormality type of the cloud audit data is an alarm type;

[0028] Item 3:

[0029] The target data includes a login time, and the preset key data includes a preset login time period; if the login time is not within the preset login time period, determining that the abnormality type of the cloud audit data is an alarm type;

[0030] Item 4:

[0031] The target data includes an event type, and the preset key data includes a preset event type; if the preset event type includes the event type, it is determined that the abnormal type of the cloud audit data is an alarm type.

[0032] In one embodiment, if the comparison result between the target data and the preset key data satisfies the linkage management rule, determining that the abnormality type of the cloud audit data is a linkage management type includes at least one of the following:

[0033] Item 1:

[0034] The target data includes resource type and event operation, and the preset key data is batch stopping and / or deleting servers; if the target data is consistent with the preset key data, then determining that the abnormality type of the cloud audit data is a linkage management type;

[0035] Item 2:

[0036] The target data includes resource type, event operation and executor information, and the preset key data is a normal executor list user deletion database; if the target data is inconsistent with the preset key data, the abnormal type of the cloud audit data is determined to be a linkage management type;

[0037] Item 3:

[0038] The target data includes resource type, event operation and executor information, and the preset key data is a normal executor list user download backup database; if the target data is inconsistent with the preset key data, the abnormal type of the cloud audit data is determined to be a linkage management type.

[0039] In a second aspect, the present application further provides a multi-cloud platform exception handling device based on single sign-on, the device comprising:

[0040] A data acquisition module is configured to acquire cloud audit data generated after a user logs into a target cloud platform based on a single sign-on system, wherein the cloud audit data includes the user's login information and the user's operation data on the target cloud platform. The single sign-on system is pre-authenticated and bound to multiple cloud platforms, and the target cloud platform is any one of the multiple cloud platforms.

[0041] An abnormal behavior judgment module, used to input the cloud audit data into a pre-configured cloud platform control model and perform abnormal behavior judgment on the cloud audit data;

[0042] The exception handling module is used to perform exception handling on the user according to the exception type of the cloud audit data if it is determined that the cloud audit data has an exception.

[0043] In a third aspect, the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the above method when executing the computer program.

[0044] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which implements the steps of the above method when executed by a processor.

[0045] In a fifth aspect, the present application also provides a computer program product, comprising a computer program, which implements the steps of the above method when executed by a processor.

[0046] The above-mentioned multi-cloud platform exception handling method, apparatus, computer equipment, storage medium, and computer program product based on single sign-on enable users to log in to any of the multiple cloud platforms based on the single sign-on system. Since the single sign-on system is pre-authenticated and bound to the multiple cloud platforms, users only need to log in once to any of the multiple cloud platforms, reducing the complexity of user account management and enhancing the security of user account management. The cloud audit data generated after the user logs in to the cloud platform is obtained. The cloud audit data includes the user's login information and the user's operation data on the target cloud platform. The cloud audit data is input into a pre-configured cloud platform control model, and abnormal behavior is judged on the cloud audit data. If the cloud audit data is determined to be abnormal, the user is subjected to exception handling based on the abnormality type of the cloud audit data, further ensuring the user's security when using the multi-cloud platform and preventing the user from suffering unnecessary losses. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 This is an application environment diagram of a multi-cloud platform exception handling method based on single sign-on in one embodiment;

[0048] Figure 2 1 is a flowchart of a method for handling exceptions on a multi-cloud platform based on single sign-on in one embodiment;

[0049] Figure 3 A flowchart illustrating steps for inputting cloud audit data into a pre-configured cloud platform control model and performing abnormal behavior judgment based on the cloud audit data in one embodiment;

[0050] Figure 4 A flowchart of the steps of performing exception handling on the user according to the type of exception in the cloud audit data if it is determined that the cloud audit data has an exception in one embodiment;

[0051] Figure 5 A flowchart of the steps for handling the exception for the user according to the type of the abnormality in the cloud audit data if it is determined that the cloud audit data has an abnormality in one embodiment;

[0052] Figure 6 This is an application environment diagram of a multi-cloud platform exception handling method based on single sign-on in another embodiment;

[0053] Figure 7 1 is a flowchart of a method for handling exceptions on a multi-cloud platform based on single sign-on in another embodiment;

[0054] Figure 8 This is a structural block diagram of a multi-cloud platform exception handling device based on single sign-on in one embodiment;

[0055] Figure 9FIG. 1 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION

[0056] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0057] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.

[0058] The multi-cloud platform exception handling method based on single sign-on provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown, the security management system 102 communicates with the target cloud platform 104 via a network, and the target cloud platform 104 communicates with the single sign-on system 106. The single sign-on system 106 can be integrated with the user terminal, and the target cloud platform 104 is integrated in the cloud, which can be any cloud server from multiple cloud platforms. The data storage system can store data that the security management system 102 needs to process. The data storage system can be integrated with the security management system 102, or it can be located in the cloud or on another network server.

[0059] Specifically, the single sign-on system 106 is pre-authenticated and bound to multiple cloud platforms. A user logs into any target cloud platform 104 in the multi-cloud platform using the single sign-on system 106 integrated on the user terminal. The user performs data operations on the target cloud platform 104, generating cloud audit data. The cloud audit data includes the user's login information and the operational data generated by the user's data operations on the target cloud platform 104. The security management system 102 obtains the cloud audit data generated by the target cloud platform 104, inputs the cloud audit data into a pre-configured cloud control model, and determines abnormal behavior in the cloud audit data. If an abnormality is determined in the cloud audit data, the user is handled according to the abnormality type of the cloud audit data. The security management system 102 can be implemented using a standalone server or a server cluster consisting of multiple servers. The terminals integrated with the single sign-on system 106 include, but are not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices can include smart speakers, smart TVs, smart air conditioners, and smart in-vehicle devices. The portable wearable device may be a smart watch, a smart bracelet, a head-mounted device, etc., and the single sign-on system 106 may be any system that can implement single sign-on.

[0060] In one embodiment, the single sign-on system is an Active Directory Federation Services (ADFS) system.

[0061] In one embodiment, Figure 2 As shown, a multi-cloud platform exception handling method based on single sign-on is provided. Figure 1 The safety management system in the example is used to illustrate, which includes the following steps:

[0062] Step 202: Obtain cloud audit data generated after the user logs in to the target cloud platform based on the single sign-on system. The cloud audit data includes the user's login information and the user's operation data on the target cloud platform. The single sign-on system is pre-authenticated and bound to multiple cloud platforms, and the target cloud platform is any one of the multiple cloud platforms.

[0063] The single sign-on system is used to enable single sign-on for users across multiple cloud platforms. The system is pre-authenticated and bound to the multiple cloud platforms a user needs to use. When using the system, users only need to enter their domain account and password to log in to any cloud platform that has been authenticated and bound to the system. For example, if the single sign-on system is pre-authenticated and bound to cloud platforms A, B, and C, then when a user logs in to target cloud platform A through the single sign-on system, cloud platforms B and C will be aware of the login.

[0064] In one embodiment, users can also log in to multiple cloud platforms in the multi-cloud platform through the single sign-on system according to their own needs and perform business operations on multiple cloud platforms.

[0065] Cloud auditing refers to the process of building a platform based on cloud computing, digitizing various audit information through cloud storage, and optimizing the utilization of various audit resources. Cloud audit data is generated by users logging into the cloud platform and performing operations on it. Specifically, when users log in to the target cloud platform through a single sign-on system and perform operations, cloud auditing records the various user operation data generated to generate cloud audit data. As you can understand, cloud audit data includes user login information, such as the user's domain account, multiple cloud platform accounts corresponding to the user's domain account, login time, and source IP address. It also includes user operation data on the target cloud platform, such as resource type, event name, event type, event details, and event operations.

[0066] Specifically, a user logs in to any target cloud platform among multiple cloud platforms using the single sign-on system and performs operations on the target cloud platform. The target cloud platform records the user's operations and generates cloud audit data. The security management system obtains the cloud audit data.

[0067] Step 204: Input the cloud audit data into the pre-configured cloud platform control model and perform abnormal behavior judgment on the cloud audit data.

[0068] Among them, the cloud platform control model is a model used to judge anomalies in cloud audit data. The cloud platform control model is pre-designed by designers and configured in the security management system.

[0069] In one embodiment, designers can pre-generate a cloud platform control model based on abnormal behavior detection rules. The cloud platform control model can then analyze cloud audit data based on the pre-set abnormal behavior detection rules to determine whether the cloud audit data contains anomalies. It is understood that abnormal behavior detection rules can be generated based on cloud audit data, such as time, source IP address, event name, event type, and event action.

[0070] Specifically, the security management system calls a pre-configured cloud platform control model, inputs the acquired cloud audit data into the cloud platform control model, and uses the cloud platform control model to judge abnormal behavior of the cloud audit data to determine whether there are any abnormalities in the cloud audit data.

[0071] Step 206: If it is determined that there is an anomaly in the cloud audit data, the user is subjected to an anomaly processing according to the anomaly type of the cloud audit data.

[0072] Exception types are determined by designers based on specific user operations. Designers can categorize user operations into multiple exception types based on their impact on actual business operations and design corresponding exception handling solutions for each exception type. Exception types can include warnings, alerts, and linkage management.

[0073] Specifically, when the security management system determines that there is an anomaly in the cloud audit data, it determines a corresponding anomaly handling solution according to the anomaly type of the cloud audit data, and performs an anomaly handling on the user based on the anomaly handling solution.

[0074] In the above-mentioned multi-cloud platform exception handling method based on single sign-on, a user logs in to any one of the multiple cloud platforms using the single sign-on system. Since the single sign-on system is pre-authenticated and bound to the multiple cloud platforms, the user only needs to log in once to any of the multiple cloud platforms, reducing the complexity of user account management and enhancing the security of user account management. The cloud audit data generated after the user logs in to the cloud platform is obtained. The cloud audit data includes the user's login information and the user's operation data on the target cloud platform. The cloud audit data is input into a pre-configured cloud platform control model, and abnormal behavior is judged on the cloud audit data. If the cloud audit data is determined to be abnormal, the user is subjected to exception handling based on the abnormality type of the cloud audit data, further ensuring the user's security when using the multi-cloud platform and preventing the user from suffering unnecessary losses.

[0075] In one embodiment, Figure 3 As shown, cloud audit data is input into the pre-configured cloud platform control model, and abnormal behavior judgment is performed based on the cloud audit data, including:

[0076] Step 302: Input the cloud audit data into a pre-configured cloud platform control model, and extract the cloud audit data to obtain target data.

[0077] The target data is the actual operation data of the user that can trigger the preset abnormal behavior detection rules. The target data can be used to determine whether the user's operation behavior on the cloud platform is abnormal.

[0078] Specifically, the security management system inputs cloud audit data into a pre-configured cloud platform control model and extracts target data based on preset key fields. It is understood that the preset key fields are determined by the designer based on preset abnormal behavior inspection rules.

[0079] Step 304 : Based on the target data, preset key data in the cloud platform control model, and preset abnormal behavior checking rules, abnormal behavior judgment is performed on the cloud audit data.

[0080] Among them, the preset key data is the standard data in the preset abnormal behavior inspection rules used to determine whether the user's operating behavior on the cloud platform is abnormal. The preset key data may include key fields, character strings or thresholds, etc.

[0081] Specifically, the security management system judges abnormal behavior of cloud audit data based on target data extracted from the cloud audit data, as well as preset key data and preset abnormal behavior detection rules in the cloud platform control model.

[0082] Step 306: When the comparison result between the target data and the preset key data satisfies the preset abnormal behavior inspection rule, it is determined that there is an abnormality in the cloud audit data.

[0083] Specifically, the security management system compares the target data with the preset key data. If the comparison result between the target data and the standard preset key data meets the preset abnormal behavior inspection rules, it indicates that there is an abnormality in the cloud audit data.

[0084] In this embodiment, data extraction is performed on cloud audit data to obtain target data, and the target data is compared with standard preset key data. When the comparison result meets the preset abnormal behavior inspection rules, it is determined that there is an abnormality in the cloud audit data. By comparing the target data with the preset key data in the cloud platform control model, the security of the cloud audit data can be quickly determined, further accelerating the judgment of the security of the use of multi-cloud platforms, and effectively avoiding unnecessary losses for users.

[0085] In one embodiment, the preset abnormal behavior detection rules include alarm rules, such as Figure 4 As shown, if it is determined that the cloud audit data has an anomaly, the user is subjected to an anomaly processing according to the anomaly type of the cloud audit data, including:

[0086] Step 402: If the comparison result between the target data and the preset key data satisfies the alarm rule, the abnormality type of the cloud audit data is determined to be an alarm type.

[0087] Among them, the alarm rules are used to determine whether to issue an alarm for user behavior. The alarm rules are designed by designers based on the user's specific business type and security requirements.

[0088] Specifically, the security management system compares the target data with the preset key data and the obtained comparison result with the preset alarm rules. If the comparison result meets the alarm rules, it means that the specific operation performed by the user on the cloud platform at this time is abnormal and an alarm is required. The abnormal type of the user's corresponding cloud audit data is determined as the alarm type.

[0089] Step 404: Generate alarm information based on the cloud audit data, where the alarm information is used to prompt the user that an alarm operation has occurred on the target cloud platform.

[0090] Specifically, when the security management system determines that cloud audit data is abnormal and the abnormality type is an alarm, the security management system generates an alarm message based on the cloud audit data to notify the current user of an alarm-causing operation on the target cloud platform. It is understood that the alarm message may include the user's specific abnormal data, the user's source IP address, the target cloud platform, the user's domain account, and other information.

[0091] Step 406: Send the alarm information to a designated user terminal based on a preset sending channel.

[0092] The preset sending channel is a channel for sending alarm information that is pre-set by the designer based on actual needs. It is understood that the preset sending channel can be an instant messaging channel within the domain or a communication transmission channel designated for alarm information transmission. The designated user terminal can be a terminal used by pre-determined on-duty personnel responsible for monitoring cloud platform security.

[0093] Specifically, after the security management system generates alarm information based on cloud audit data, it sends the alarm information to the designated user terminal through a preset sending channel to remind the designated user that there is abnormal operation behavior on the current target cloud platform.

[0094] In one of the embodiments, after the security management system sends the alarm information to the designated user terminal through the preset sending channel, it also retains the cloud audit data in the local database.

[0095] In the above embodiment, when it is determined that the comparison result between the target data in the cloud audit data and the preset key data meets the alarm rules, an alarm information is generated based on the cloud audit data, and the alarm information is sent to the designated user terminal based on the preset sending channel. It can provide real-time alarms for abnormal behaviors of cloud platform users and promptly notify designated on-duty personnel for confirmation and processing, effectively improving the security of users using multiple cloud platforms at the same time.

[0096] Furthermore, in one embodiment, if the comparison result between the target data and the preset key data satisfies the alarm rule, determining the abnormality type of the cloud audit data as an alarm type includes at least one of the following:

[0097] Item 1: The target data includes account data, and the preset key data includes privileged account data; if the account data is consistent with the privileged account data, the abnormal type of the cloud audit data is determined to be an alarm type.

[0098] Specifically, when a user logs in to the target cloud platform using the single sign-on system, the privileged account "admin" is not used by default. Privileged accounts are only used in emergencies, and the password and two-factor dynamic code for the privileged account are shared by two people. Therefore, the security management system extracts the account data from the cloud audit data and compares the account data with the preset privileged account data. If the account data is consistent with the privileged account data, it can be determined that the user corresponding to the cloud audit data used a privileged account to log in to the target cloud platform. At this time, the designated on-duty personnel need to confirm this behavior. The security management system determines that the abnormality type of the cloud audit data is an alarm type, generates an alarm message, and sends it to the designated user terminal for alarm.

[0099] Item 2: The target data includes the source login address, and the preset key data includes a preset normal address list; if the source login address is not in the preset normal address list, the abnormal type of the cloud audit data is determined to be an alarm type.

[0100] The preset normal address list is a list of all addresses that can be used to log in to various multi-cloud platforms based on the current single sign-on system. It is understood that the preset normal address list includes all egress IP addresses of multiple public and private clouds.

[0101] Specifically, to prevent external login addresses from logging into multiple cloud platforms based on the single sign-on system, the security management system extracts the source login address (source IP) from the cloud audit data and compares the source IP with a preset list of normal addresses. If the source IP is not in the preset list of normal addresses, it means that this IP address does not belong to the exit IP of multiple cloud platforms. There may be a risk of external IP login use, and this behavior needs to be confirmed by designated on-duty personnel. The security management system determines that the abnormal type of the cloud audit data is an alarm type, generates an alarm message, and sends it to the designated user terminal for warning.

[0102] Item 3: The target data includes the login time, and the preset key data includes the preset login time period; if the login time is not within the preset login time period, the abnormal type of the cloud audit data is determined to be an alarm type.

[0103] Among them, the preset login time period is the login time range pre-set by the designer based on the actual usage of the multi-cloud platform, which is the time range for normal manual operations.

[0104] Specifically, the security management system extracts the login time from the cloud audit data and compares it with the preset login time period. If the login time is not within the preset login time period, it means that the user corresponding to the cloud audit data logged into the target cloud platform during a non-manual operation period to perform operations. For example, if the security management system extracts a login time of 3:00 a.m. from the cloud audit data, and the preset login time period is 6:00-1:00 a.m., then it can be considered that the user corresponding to the cloud audit data logged into the target cloud platform during a non-manual operation period to perform operations, and there may be a risk of abnormal login. This behavior needs to be confirmed by designated on-duty personnel. The security management system determines that the abnormal type of the cloud audit data is an alarm type, generates an alarm message, and sends it to the designated user terminal for alarm.

[0105] Item 4: The target data includes an event type, and the preset key data includes a preset event type; if the preset event type includes an event type, the abnormal type of the cloud audit data is determined to be an alarm type.

[0106] The preset event type can be an event type that requires approval before execution, such as adding a new network IP, adding a new SLB, etc.

[0107] Specifically, the security management system extracts the event type from the cloud audit data and compares it with the preset event types. If the preset event types include the event type—for example, if the target data is a newly added cloud public network IP address, and the preset event types include a newly added cloud public network IP address—then the user is determined to have performed an operation requiring approval, and the designated on-duty personnel must review and confirm the action. The security management system determines that the abnormality type in the cloud audit data is an alarm type, generates an alarm message, and sends it to the designated user terminal for notification.

[0108] In this embodiment, by comparing the target data of various situations with the preset key data, when it is determined that the comparison result between the target data in the cloud audit data and the preset key data meets the alarm rules, an alarm information is generated according to the cloud audit data, and the alarm information is sent to the designated user terminal based on the preset sending channel. This can provide real-time alarms for abnormal behaviors of cloud platform users and promptly notify designated on-duty personnel for confirmation and processing, further ensuring the security of users when using the multi-cloud platform and avoiding unnecessary losses for users.

[0109] In order to further improve the security of the multi-cloud platform, in one embodiment, the preset abnormal behavior inspection rules include linkage management rules, such as Figure 5 As shown, if it is determined that there is an anomaly in the cloud audit data, the user will be handled according to the anomaly type of the cloud audit data, including:

[0110] Step 502: If the comparison result between the target data and the preset key data satisfies the linkage management rule, the abnormality type of the cloud audit data is determined to be the linkage management type.

[0111] Among them, the linkage management rules are rules used to determine whether to conduct linkage management on user behavior. The linkage management rules are pre-designed by designers based on the user's specific business type and security requirements.

[0112] Specifically, the security management system compares the target data with the preset key data and the obtained comparison result with the preset linkage management rules. If the comparison result meets the linkage management rules, it means that the specific operation performed by the user on the cloud platform at this time is a serious abnormal operation, and multi-cloud platform linkage management is required. The abnormal type of the cloud audit data corresponding to the user is determined as the linkage management type.

[0113] Step 504: Generate linkage management instructions based on cloud audit data. The linkage management instructions are used to instruct the linkage defense system to generate single sign-on domain account management tasks and multi-cloud platform account management tasks. Based on the single sign-on domain account management tasks, the single sign-on system controls the single sign-on domain account of the blocked user, and based on the multi-cloud platform account management tasks, the cloud platform accounts of the blocked user on each cloud platform are controlled.

[0114] Among them, the linkage defense system is connected with the single sign-on system and each cloud platform in the multi-cloud platform to realize the joint defense of the multi-cloud platform.

[0115] Among them, the single sign-on domain account management task includes the domain account corresponding to the user who generates cloud audit data. When the user enters the domain account in the single sign-on system to log in to the target cloud platform, the cloud platform will obtain the domain account entered by the user and record it in the cloud audit data.

[0116] The multi-cloud platform account management task includes multiple cloud platform interface addresses corresponding to the domain account entered by the user generating the cloud audit data. Based on the multi-cloud platform account management task, the coordinated defense system can call the cloud API interface to change the status of each cloud platform account, for example, changing the status of each cloud platform account to unavailable, thereby blocking each cloud platform account. It is understood that each cloud platform account can also be obtained from the single sign-on system by the target cloud platform when the user logs in to the target cloud platform through the single sign-on system and recorded in the cloud audit data.

[0117] Specifically, if cloud audit data is determined to be abnormal and the abnormality type is linkage management, it indicates that the user's operation on the target cloud platform is a serious abnormal operation and requires linkage management processing. The security management system generates linkage management instructions based on the cloud audit data. The linkage management instructions are used to instruct the linkage defense system to generate single sign-on domain account management tasks and multi-platform account management tasks.

[0118] Step 506: Send the linkage management instruction to the linkage defense system.

[0119] Specifically, the security management system sends the generated linkage management instruction to the linkage defense system. The linkage defense system receives the linkage management instruction, generates a single sign-on domain account management task and a multi-platform account management task based on the linkage management instruction, and submits the single sign-on domain account management task and the multi-platform account management task to the message queue.

[0120] Upon receiving the task, the task engine of the Linked Defense System executes it according to the task script. Based on the single sign-on domain account management task, it connects to the domain control module of the single sign-on system and remotely changes the domain account status to unavailable. Based on the multi-platform account management task, the Linked Defense System uses the task execution child node to call the cloud API to change the status of each cloud platform account corresponding to the user, changing the status of each cloud platform account to unavailable.

[0121] In this embodiment, when the security management system determines that the user's operation based on the target cloud platform is a serious abnormal operation based on the cloud audit data, a linkage management instruction is generated to jointly manage the user's single sign-on system domain account and the various cloud platform accounts of the multi-cloud platform, and the status of the user's single sign-on system domain account and the various cloud platform accounts of the multi-cloud platform are changed to an unavailable state, effectively avoiding user losses caused by serious abnormal operations of the user, and further improving the user's security when using the multi-cloud platform.

[0122] In one embodiment, after the security management system determines that the abnormal type of the cloud audit data is the linkage management type, it also includes: generating alarm information based on the cloud audit data, sending the alarm information to the designated user terminal based on the preset sending channel, real-time alarm for abnormal behavior of cloud platform users, and promptly notifying designated on-duty personnel for confirmation and processing.

[0123] Furthermore, in one embodiment, if the comparison result between the target data and the preset key data satisfies the linkage management rule, then determining the abnormality type of the cloud audit data as the linkage management type includes at least one of the following:

[0124] Item 1: The target data includes resource types and event operations, and the preset key data is batch stopping or deleting servers. If the target data is consistent with the preset key data, the abnormal type of the cloud audit data is determined to be the linkage management type.

[0125] The resource type is the resource type that the user operates on the cloud platform. It can be understood that the resource type can be a server, database, etc. The event operation is the specific operation that the user performs on the resource type on the cloud platform.

[0126] Specifically. The security management system defaults to stopping and / or deleting servers at the same time as serious abnormal behavior. The security management system extracts resource types and event operations from the cloud audit data, and compares the resource types and event operations with the preset key data. If the resource type recorded in the cloud audit data is a server, and the event operation is to stop and / or delete servers in batches, it means that the target data is consistent with the preset key data. At this time, the specific operation of the user corresponding to the cloud audit data on the target cloud platform is a serious abnormal operation, which requires multi-cloud platform linkage management. The security management platform determines the abnormal type of the cloud audit data corresponding to the user as the linkage management type.

[0127] Item 2: The target data includes resource type, event operation and executor information. The preset key data is the normal executor list user deletion database; if the target data is inconsistent with the preset key data, the abnormal type of the cloud audit data is determined to be the linkage management type.

[0128] The executor information is the identity information corresponding to the cloud audit user, such as name information or identity classification information.

[0129] The "normal executor list" contains all user information that can normally delete a database. The executors in the "normal executor list" have the authority to delete and maintain the database. Users in the "non-normal executor list" cannot delete the database at will. It is understood that the number of users in the "normal executor list" can be set based on actual circumstances.

[0130] Specifically, in order to prevent users from arbitrarily deleting databases, the security management system extracts resource types, event operations, and executor information from the cloud audit data. If the resource type extracted from the cloud audit data is database, the event operation is to delete the database, and the executor information is not included in the normal executor list, then it can be considered that the target data extracted from the cloud audit data is inconsistent with the preset key data, that is, the normal executor list user deletes the database. At this time, the specific operation of the user corresponding to the cloud audit data on the target cloud platform is a serious abnormal operation, and multi-cloud platform linkage management is required. The security management platform determines the abnormal type of the cloud audit data corresponding to the user as the linkage management type.

[0131] Item 3: The target data includes resource type, event operation and executor information. The preset key data is the normal executor list user download backup database; if the target data is inconsistent with the preset key data, the abnormal type of the cloud audit data is determined to be the linkage management type.

[0132] Among them, users in the normal executor list also have the permission to download data backup, while users in the non-normal executor list cannot download the backup database at will.

[0133] Specifically, in order to prevent users from arbitrarily downloading backup databases and causing data leakage, the security management system extracts resource types, event operations and executor information from the cloud audit data. If the resource type extracted from the cloud audit data is a database, the event operation is to download a backup database, and the executor information is not included in the normal executor list, then it can be considered that the target data extracted from the cloud audit data is inconsistent with the preset key data, that is, the backup database downloaded by the user in the normal executor list. At this time, the specific operation of the user corresponding to the cloud audit data on the target cloud platform is a serious abnormal operation, and multi-cloud platform linkage management is required. The security management platform determines the abnormal type of the cloud audit data corresponding to the user as the linkage management type.

[0134] In this embodiment, by comparing the target data of various situations with the preset key data, when it is determined that the comparison result between the target data in the cloud audit data and the preset key data meets the linkage management rules, a linkage management instruction is generated according to the cloud audit data, and the user's single sign-on system domain account and each cloud platform account of the multi-cloud platform are jointly blocked, effectively avoiding user losses caused by serious abnormal operations of users, and further improving the user's use security when using the multi-cloud platform.

[0135] In one embodiment, a multi-cloud platform exception handling method based on single sign-on is provided. Figure 6 The security management system in the multi-cloud platform exception handling system based on single sign-on is used as an example to illustrate. Figure 6 As shown, the single sign-on system (ADFS SSO) is integrated in the user terminal of the domain user. ADFS SSO is pre-authenticated and bound to each cloud platform in the multi-cloud platform, and the security management system (SIEM) communicates with each cloud platform and the linkage defense system.

[0136] Specifically, if Figure 7 As shown in the figure, domain users use their domain account and password to log in to ADFS SSO. After passing the AD domain authentication, they are redirected to the cloud console of the target cloud platform. Users perform operations in the cloud console. Cloud audit records cloud audit data such as the user's domain account, corresponding cloud platform account, operation time, source IP, resource type, event name, event type, event details, and event operations, and stores them in the COS / OSS object storage bucket through the tracking set.

[0137] The SIEM system's data capture module regularly executes the object storage command-line tool coscmd (ossutil) and develops scripts to obtain cloud audit data. With the SIEM system's unique forwarder function, the general forwarder monitors log files and sends them to the heavy forwarder, which then distributes them to the data storage nodes in the cluster. At this point, the cluster's search head can successfully search for relevant cloud audit data using the SPL language.

[0138] The SIEM system is pre-configured with a cloud platform control model, which is supported by cloud audit data. The data is stored in a COS bucket or an OSS bucket and serves as the data source. The model includes necessary fields: domain account, cloud platform account, time, event name, event type, event details, event operation or executor information, etc.; additional fields for some special events: network component-associated IP ports, privileged logins, or abnormal behavior-associated servers, etc. The model mainly matches key fields, strings, or thresholds as triggering alarm conditions, which are preset in advance. The abnormal log mainly focuses on the writing behavior of key resources: such as the stopping, deletion, leakage, and addition of public network entrances to computing, network, and data resources, as well as abnormal access time, location, and source IP. Specifically, designers use the SPL language to analyze the preset abnormal behavior inspection rules, extract the fields that may trigger the rules as the basis for judgment, and determine the matching string or threshold or other judgment method based on the display situation to obtain the preset key data.

[0139] The SIEM system populates cloud audit data into the pre-set cloud platform control model and extracts target data from the cloud audit data. The target data is then compared with pre-set key data. If the comparison results indicate that the user has logged in with at least one of the following: abnormal privileged account login behavior, login behavior from an abnormal address, login behavior outside the pre-set login time period, newly added public IP behavior, or newly added public SLB behavior, the cloud audit data is considered abnormal and the abnormality type is an alarm. The SIEM system generates an alarm message notification based on the cloud audit data and transmits the alarm message notification to the on-duty personnel via the pre-set IM communication system.

[0140] If the SIEM system determines, based on the comparison results, that the user has engaged in at least one of the following: server deletion, database deletion, and abnormal download of backup databases, the cloud audit data is deemed to have a serious anomaly, and the anomaly type is a linkage management type. The SIEM system generates an alarm notification based on the cloud audit data and sends it back to the on-duty personnel via the pre-set IM communication system. The SIEM system also stores the cloud audit data locally and generates linkage management instructions based on the cloud audit data. These instructions are uploaded along with the cloud audit data to the linkage defense system.

[0141] After receiving the linkage management command, the linkage defense system responds to it, generates single sign-on domain account management tasks and multi-cloud platform account management tasks based on the alarm configuration, and submits the tasks to the message queue. After receiving the tasks, the task engine executes them according to the task script. Based on the single sign-on domain account management task, it connects to the domain control module of the single sign-on system and remotely executes the domain account status change operation, changing the domain account status to unavailable. Based on the multi-platform account management task, the linkage defense system calls the cloud API interface through the task execution child node to change the status of each cloud platform account corresponding to the user, changing the status of each cloud platform account to unavailable.

[0142] The method in this embodiment first supports single sign-on across multiple cloud platforms and automatic detection of abnormal user behavior on multiple cloud platforms. It issues real-time alerts for abnormal cloud platform user behavior and notifies on-duty personnel to confirm and handle the situation. Secondly, it supports automatic linkage processing of abnormal behavior on multiple cloud platforms, including changing the status of both domain and cloud platform accounts to unavailable. This is done automatically without manual intervention, and a rapid response is available 24 hours a day. While reducing the complexity and enhancing the security of user account management, the safety of users using the multi-cloud platform is further ensured by handling exceptions on the multi-cloud platform, preventing users from suffering unnecessary losses.

[0143] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0144] Based on the same inventive concept, an embodiment of the present application further provides a multi-cloud platform exception handling device based on single sign-on for implementing the multi-cloud platform exception handling method based on single sign-on. The implementation solution provided by the device is similar to the implementation solution described in the above method. Therefore, the specific limitations of one or more embodiments of the multi-cloud platform exception handling device based on single sign-on provided below can be found in the above limitations of the multi-cloud platform exception handling method based on single sign-on, and will not be repeated here.

[0145] In one embodiment, Figure 8As shown, a multi-cloud platform exception handling device 800 based on single sign-on is provided, comprising: a data acquisition module 801, an abnormal behavior judgment module 802 and an exception handling module 803, wherein:

[0146] The data acquisition module 801 is used to obtain the cloud audit data generated after the user logs in to the target cloud platform based on the single sign-on system. The cloud audit data includes the user's login information and the user's operation data on the target cloud platform. The single sign-on system is pre-authenticated and bound to multiple cloud platforms, and the target cloud platform is any one of the multiple cloud platforms.

[0147] The abnormal behavior judgment module 802 is used to input the cloud audit data into a pre-configured cloud platform control model and perform abnormal behavior judgment on the cloud audit data.

[0148] The exception handling module 803 is used to perform exception handling on the user according to the exception type of the cloud audit data if it is determined that there is an exception in the cloud audit data.

[0149] The above-mentioned multi-cloud platform exception handling device based on single sign-on allows users to log in to any of the multiple cloud platforms based on the single sign-on system. Since the single sign-on system is pre-authenticated and bound to multiple cloud platforms, users only need to log in once to any of the multiple cloud platforms, reducing the complexity of user account management and enhancing the security of user account management. The cloud audit data generated after the user logs in to the cloud platform is obtained. The cloud audit data includes the user's login information and the user's operation data on the target cloud platform. The cloud audit data is input into a pre-configured cloud platform control model, and abnormal behavior is judged on the cloud audit data. If the cloud audit data is determined to be abnormal, the user is subjected to exception handling based on the abnormality type of the cloud audit data, further ensuring the user's security when using the multi-cloud platform and preventing the user from suffering unnecessary losses.

[0150] In one embodiment, the abnormal behavior judgment module is also used to: input cloud audit data into a pre-configured cloud platform control model, extract data from the cloud audit data to obtain target data; judge abnormal behavior of the cloud audit data based on the target data, preset key data in the cloud platform control model, and preset abnormal behavior inspection rules; when the comparison result between the target data and the preset key data meets the preset abnormal behavior inspection rules, it is determined that there is an abnormality in the cloud audit data.

[0151] In one embodiment, the exception handling module is also used to: if the comparison result between the target data and the preset key data meets the alarm rules, determine that the abnormal type of the cloud audit data is an alarm type; generate alarm information based on the cloud audit data, and the alarm information is used to prompt the user that there is an alarm operation behavior on the target cloud platform; and send the alarm information to the designated user terminal based on the preset sending channel.

[0152] In one embodiment, the exception handling module is also used to: if the comparison result between the target data and the preset key data meets the linkage management rules, then determine that the exception type of the cloud audit data is a linkage management type; generate a linkage management instruction based on the cloud audit data, the linkage management instruction is used to instruct the linkage defense system to generate a single sign-on domain account management task and a multi-cloud platform account management task, control the single sign-on domain account of the single sign-on system to block the user's single sign-on domain account based on the single sign-on domain account management task, and control the cloud platform accounts of the blocked user on each cloud platform based on the multi-cloud platform account management task; send the linkage management instruction to the linkage defense system.

[0153] In one embodiment, the abnormal behavior determination module is further configured to:

[0154] Item 1:

[0155] The target data includes account data, and the preset key data includes privileged account data. If the account data is consistent with the privileged account data, the abnormal type of the cloud audit data is determined to be an alarm type.

[0156] Item 2:

[0157] The target data includes the source login address, and the preset key data includes a preset normal address list; if the source login address is not in the preset normal address list, the abnormal type of the cloud audit data is determined to be an alarm type;

[0158] Item 3:

[0159] The target data includes the login time, and the preset key data includes the preset login time period; if the login time is not within the preset login time period, the abnormal type of the cloud audit data is determined to be an alarm type;

[0160] Item 4:

[0161] The target data includes an event type, and the preset key data includes a preset event type; if the preset event type includes an event type, the abnormal type of the cloud audit data is determined to be an alarm type.

[0162] In one embodiment, the abnormal behavior determination module is further configured to:

[0163] Item 1:

[0164] The target data includes resource type and event operation, and the preset key data is batch stopping and / or deleting servers. If the target data is consistent with the preset key data, the abnormal type of the cloud audit data is determined to be the linkage management type.

[0165] Item 2:

[0166] The target data includes resource type, event operation, and executor information. The preset key data is the normal executor list user deletion database. If the target data is inconsistent with the preset key data, the abnormal type of the cloud audit data is determined to be the linkage management type.

[0167] Item 3:

[0168] The target data includes resource type, event operation, and executor information. The preset key data is the normal executor list user download backup database. If the target data is inconsistent with the preset key data, the abnormal type of the cloud audit data is determined to be the linkage management type.

[0169] Each module in the above-mentioned multi-cloud platform exception handling device based on single sign-on can be implemented in whole or in part through software, hardware, or a combination thereof. Each of the above modules can be embedded in or independent of the processor of the computer device in hardware form, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each of the above modules.

[0170] In one embodiment, a computer device is provided. The computer device may be a server integrated with a security management system. The internal structure diagram thereof may be as follows: Figure 9 As shown. The computer device includes a processor, a memory and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store cloud audit data, cloud platform control models, exception types and other data. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a multi-cloud platform exception handling method based on single sign-on is implemented.

[0171] Those skilled in the art will understand that Figure 9 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0172] In one embodiment, a computer device is provided, including a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the specific steps in the above-mentioned embodiments of the multi-cloud platform exception handling method based on single sign-on.

[0173] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the specific steps in the above-mentioned embodiments of the multi-cloud platform exception handling method based on single sign-on are implemented.

[0174] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the computer program implements the specific steps in the above-mentioned embodiments of the multi-cloud platform exception handling method based on single sign-on.

[0175] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0176] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.

[0177] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0178] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A multi-cloud platform exception handling method based on single sign-on, characterized in that: The method comprises: Obtaining cloud audit data generated after a user logs in to a target cloud platform based on a single sign-on system, the cloud audit data including the user's login information and the user's operation data on the target cloud platform, the single sign-on system being pre-authenticated and bound to multiple cloud platforms, and the target cloud platform being any one of the multiple cloud platforms; Inputting the cloud audit data into a pre-configured cloud platform control model and performing abnormal behavior judgment on the cloud audit data; In the case where it is determined that the abnormal type of the cloud audit data is a linkage management type, a linkage management instruction is generated according to the cloud audit data, the linkage management instruction is used to instruct the linkage defense system to generate a single sign-on domain account management task and a multi-cloud platform account management task, the single sign-on domain account management task includes the domain account corresponding to the user who generated the cloud audit data; based on the single sign-on domain account management task, the single sign-on system is controlled to remotely change the status of the domain account to an unavailable state; based on the multi-cloud platform account management task, each cloud platform is controlled to change the status of each cloud platform account of the user to an unavailable state; The linkage management instruction is sent to the linkage defense system.

2. The method according to claim 1, characterized in that Inputting the cloud audit data into a pre-configured cloud platform control model and performing abnormal behavior judgment based on the cloud audit data includes: Inputting the cloud audit data into a pre-configured cloud platform control model, and performing data extraction on the cloud audit data to obtain target data; Based on the target data, preset key data in the cloud platform control model and preset abnormal behavior detection rules, the cloud audit data is judged to be abnormal behavior; When the comparison result between the target data and the preset key data satisfies the preset abnormal behavior checking rule, it is determined that an abnormality exists in the cloud audit data.

3. The method according to claim 2, characterized in that The preset abnormal behavior inspection rules include alarm rules; The method further comprises: If the comparison result between the target data and the preset key data satisfies the alarm rule, determining that the abnormal type of the cloud audit data is an alarm type; Generate alarm information based on the cloud audit data, where the alarm information is used to prompt the user that an alarm operation behavior has occurred on the target cloud platform; The alarm information is sent to a designated user terminal based on a preset sending channel.

4. The method according to claim 2, characterized in that The preset abnormal behavior inspection rules include linkage management rules; When the comparison result between the target data and the preset key data satisfies the preset abnormal behavior inspection rule, determining that the cloud audit data has an abnormality includes: If the comparison result between the target data and the preset key data satisfies the linkage management rule, the abnormality type of the cloud audit data is determined to be a linkage management type.

5. The method according to claim 3, characterized in that If the comparison result between the target data and the preset key data satisfies the alarm rule, determining that the abnormality type of the cloud audit data is an alarm type includes at least one of the following: Item 1: The target data includes account data, and the preset key data includes privileged account data; if the account data is consistent with the privileged account data, determining that the abnormality type of the cloud audit data is an alarm type; Item 2: The target data includes a source login address, and the preset key data includes a preset normal address list; if the source login address is not in the preset normal address list, determining that the abnormality type of the cloud audit data is an alarm type; Item 3: The target data includes a login time, and the preset key data includes a preset login time period; if the login time is not within the preset login time period, determining that the abnormality type of the cloud audit data is an alarm type; Item 4: The target data includes an event type, and the preset key data includes a preset event type; if the preset event type includes the event type, it is determined that the abnormal type of the cloud audit data is an alarm type.

6. The method according to claim 4, characterized in that If the comparison result between the target data and the preset key data satisfies the linkage management rule, determining the abnormality type of the cloud audit data as the linkage management type includes at least one of the following: Item 1: The target data includes resource type and event operation, and the preset key data is batch stopping and / or deleting servers; if the target data is consistent with the preset key data, then determining that the abnormality type of the cloud audit data is a linkage management type; Item 2: The target data includes resource type, event operation and executor information, and the preset key data is a normal executor list user deletion database; if the target data is inconsistent with the preset key data, the abnormal type of the cloud audit data is determined to be a linkage management type; Item 3: The target data includes resource type, event operation and executor information, and the preset key data is a normal executor list user download backup database; if the target data is inconsistent with the preset key data, the abnormal type of the cloud audit data is determined to be a linkage management type.

7. A multi-cloud platform exception handling device based on single sign-on, characterized in that: The device comprises: A data acquisition module is configured to acquire cloud audit data generated after a user logs into a target cloud platform based on a single sign-on system, wherein the cloud audit data includes the user's login information and the user's operation data on the target cloud platform. The single sign-on system is pre-authenticated and bound to multiple cloud platforms, and the target cloud platform is any one of the multiple cloud platforms. An abnormal behavior judgment module, used to input the cloud audit data into a pre-configured cloud platform control model and perform abnormal behavior judgment on the cloud audit data; An exception handling module is used to generate a linkage management instruction based on the cloud audit data when it is determined that the exception type of the cloud audit data is a linkage management type. The linkage management instruction is used to instruct the linkage defense system to generate a single sign-on domain account management task and a multi-cloud platform account management task. The single sign-on domain account management task includes the domain account corresponding to the user who generated the cloud audit data; based on the single sign-on domain account management task, the single sign-on system is controlled to remotely change the status of the domain account to an unavailable state; based on the multi-cloud platform account management task, each cloud platform is controlled to change the status of each cloud platform account of the user to an unavailable state; and the linkage management instruction is sent to the linkage defense system.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.