System Patch Processing Method, Device, Computer Equipment and Storage Medium

Through the system patch processing method, patch inspection and installation of thousands of servers is realized, which solves the problem of untimely vulnerability blockade in traditional technology and improves the security of the server.

CN116339777BActive Publication Date: 2025-07-01INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310268759.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-15
Publication Date
2025-07-01
Estimated Expiration
2043-03-15

AI Technical Summary

Technical Problem

In traditional technology, facing thousands of servers, server maintenance personnel need to check for vulnerabilities one by one and install system patches, resulting in untimely blocking of vulnerabilities, increasing the risk of hacker attacks and reducing server security.

Method used

Provide a system patch processing method. By responding to system patch inspection instructions, obtaining the frequency and time of patch inspection execution, performing inspections, generating a full list of patch abnormalities, and determining the matching results of the patch professional group based on the list, server application information and human resources information, generating patch maintenance information, and notifying the corresponding maintenance objects for patch installation.

Benefits of technology

It improves the efficiency and timeliness of server patch installation, reduces the risk of hacker attacks, and improves the security of the server.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116339777B_ABST
    Figure CN116339777B_ABST
Patent Text Reader

Abstract

The present application relates to a system patch processing method, apparatus, computer device, and storage medium. The method includes: in response to a system patch inspection instruction for a target system, obtaining the patch inspection execution frequency and the patch inspection execution time; according to the patch inspection execution frequency and the patch inspection execution time, performing an inspection operation on the patch installation situation of the target system to obtain a target system inspection result; in the case where the target system inspection result indicates that there is an abnormality in the patches of the target system, determining a full-scale patch abnormality list; according to the full-scale patch abnormality list, server application information, and human resource information table, determining a patch professional group matching result; in the case where there is a corresponding patch maintenance professional group for the determined patch professional group matching result, generating system patch maintenance information. Using this method can improve the efficiency of server vulnerability blocking, reduce hacker attacks, and improve the security of the server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technologies, and particularly to a system patch processing method, apparatus, computer device, storage medium, and computer program product. Background Art

[0002] With the development of computer technologies, computer security technologies have emerged. With the popularization of computers, the scale of data center servers has shown explosive growth. Among them, the number of servers in some enterprises has reached the thousands level. The problem of server security vulnerabilities is extremely important. Hackers may attack servers through vulnerabilities, and problems such as the theft of sensitive server data and the destruction of server file structures are extremely intractable.

[0003] In traditional technologies, in the face of thousands of servers, server maintenance personnel need to check the vulnerabilities of each server one by one. When it is found that a server has a vulnerability, a system patch is used to block the vulnerability of the server. However, relying solely on server maintenance personnel to discover and summarize patch situations is inadequate, which easily leads to untimely blocking of server vulnerabilities, resulting in hacker attacks and low server security. Summary of the Invention

[0004] Based on this, in view of the above technical problems, it is necessary to provide a system patch processing method, apparatus, computer device, computer-readable storage medium, and computer program product that can improve the efficiency of blocking server vulnerabilities, reduce hacker attacks, and improve the security of servers.

[0005] In a first aspect, the present application provides a system patch processing method. The method includes: in response to a system patch inspection instruction for a target system, obtaining the patch inspection execution frequency and patch inspection execution time for the target system; according to the patch inspection execution frequency and the patch inspection execution time, performing an inspection operation on the patch installation situation of the target system to obtain a target system inspection result; in the case where the target system inspection result indicates that there is an abnormality in the patches of the target system, determining a full-scale patch abnormality list corresponding to the target system; according to the full-scale patch abnormality list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library, determining a patch professional group matching result corresponding to the target system; in the case where it is determined that there is a corresponding patch maintenance professional group in the patch professional group matching result, generating system patch maintenance information; the system patch maintenance information is used to notify each maintenance object corresponding to the patch maintenance professional group to install system patches for the target system.

[0006] In one embodiment, determining the patch professional group matching result corresponding to the target system according to the full patch exception list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library includes: matching the full patch exception list and the server application information corresponding to the system configuration platform to determine the maintenance personnel information and the application name information corresponding to the system configuration platform; respectively matching the maintenance personnel information and the application name information with the human resource information table corresponding to the human resource library to determine the patch professional group matching result corresponding to the target system.

[0007] In one embodiment, the human resource information table includes a professional personnel information table and an application management personnel information table; the step of respectively matching the maintenance personnel information and the application name information with the human resource information table corresponding to the human resource library to determine the patch professional group matching result corresponding to the target system includes: matching the maintenance personnel information with the professional personnel information table in the human resource library to obtain a maintenance personnel matching result; matching the application name information with the application management personnel information table in the human resource library to obtain a management personnel matching result; and determining the patch professional group matching result corresponding to the target system when the maintenance personnel matching result and the management personnel matching result meet preset conditions.

[0008] In one embodiment, the method further includes: generating manual patch maintenance information when it is determined that there is no corresponding patch maintenance professional group for the patch professional group matching result; the manual patch maintenance information is used to notify the selection of the maintenance object in each patch maintenance professional group to install system patches for the system.

[0009] In one embodiment, after the step of generating system patch maintenance information when it is determined that there is a corresponding patch maintenance professional group for the patch professional group matching result, the method further includes: obtaining the first system patch installation information corresponding to the system patch maintenance information and the second system patch installation information corresponding to the manual patch maintenance information; integrating the first system patch installation information and the second system patch installation information into a database and updating the patch update data of the database.

[0010] In one embodiment, performing an inspection operation on the patch installation status of the target system according to the patch inspection execution frequency and the patch inspection execution time to obtain a target system inspection result, including: determining at least one patch inspection item corresponding to the target system according to the patch inspection execution frequency and the patch inspection execution time; and inspecting the patch installation status of the system according to each patch inspection item, the patch inspection execution frequency, and the patch inspection execution time to obtain the target system inspection result.

[0011] In one embodiment, the patch inspection items include production patch inspection items and office patch inspection items; the inspecting the patch installation status of the system according to each patch inspection item, the patch inspection execution frequency, and the patch inspection execution time to obtain the target system inspection result includes: inspecting the patch installation status of the production patch inspection items of the target system according to the patch inspection execution frequency and the patch inspection execution time to obtain a first target system inspection result; and inspecting the patch installation status of the office patch inspection items of the target system according to the patch inspection execution frequency and the patch inspection execution time to obtain a second target system inspection result; and integrating the first target system inspection result and the second target system inspection result to obtain the target system inspection result.

[0012] In a second aspect, the present application further provides a system patch processing device. The device includes: a data acquisition module, configured to obtain the patch inspection execution frequency and the patch inspection execution time for the target system in response to a system patch inspection instruction for the target system; a patch inspection module, configured to perform an inspection operation on the patch installation status of the target system according to the patch inspection execution frequency and the patch inspection execution time to obtain a target system inspection result; a list generation module, configured to determine a full-scale patch exception list corresponding to the target system when the target system inspection result indicates that there is an exception in the patches of the target system; a data matching module, configured to determine a patch professional group matching result corresponding to the target system according to the full-scale patch exception list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library; and a maintenance notification module, configured to generate system patch maintenance information when it is determined that there is a corresponding patch maintenance professional group in the patch professional group matching result; the system patch maintenance information is used to notify each maintenance object corresponding to the patch maintenance professional group to perform system patch installation on the target system.

[0013] In a third aspect, the present application also provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the following steps are implemented: in response to a system patch inspection instruction for a target system, obtain the patch inspection execution frequency and the patch inspection execution time for the target system; according to the patch inspection execution frequency and the patch inspection execution time, perform an inspection operation on the patch installation situation of the target system to obtain a target system inspection result; in the case where the target system inspection result indicates that there is an abnormality in the patches of the target system, determine a full-scale patch abnormality list corresponding to the target system; according to the full-scale patch abnormality list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library, determine a patch professional group matching result corresponding to the target system; in the case where it is determined that there is a corresponding patch maintenance professional group in the patch professional group matching result, generate system patch maintenance information; the system patch maintenance information is used to notify each maintenance object corresponding to the patch maintenance professional group to perform system patch installation on the target system.

[0014] In a fourth aspect, the present application also provides a computer-readable storage medium. On the computer-readable storage medium, there is a computer program stored, and when the computer program is executed by a processor, the following steps are implemented: in response to a system patch inspection instruction for a target system, obtain the patch inspection execution frequency and the patch inspection execution time for the target system; according to the patch inspection execution frequency and the patch inspection execution time, perform an inspection operation on the patch installation situation of the target system to obtain a target system inspection result; in the case where the target system inspection result indicates that there is an abnormality in the patches of the target system, determine a full-scale patch abnormality list corresponding to the target system; according to the full-scale patch abnormality list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library, determine a patch professional group matching result corresponding to the target system; in the case where it is determined that there is a corresponding patch maintenance professional group in the patch professional group matching result, generate system patch maintenance information; the system patch maintenance information is used to notify each maintenance object corresponding to the patch maintenance professional group to perform system patch installation on the target system.

[0015] Fifth aspect, the present application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the following steps are implemented: in response to a system patch inspection instruction for a target system, obtain the patch inspection execution frequency and the patch inspection execution time for the target system; according to the patch inspection execution frequency and the patch inspection execution time, perform an inspection operation on the patch installation situation of the target system to obtain a target system inspection result; in the case where the target system inspection result indicates that there is an abnormality in the patches of the target system, determine a full-scale patch abnormality list corresponding to the target system; according to the full-scale patch abnormality list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library, determine a patch professional group matching result corresponding to the target system; in the case where a corresponding patch maintenance professional group exists in the determined patch professional group matching result, generate system patch maintenance information; the system patch maintenance information is used to notify each maintenance object corresponding to the patch maintenance professional group to perform system patch installation on the target system.

[0016] The above-mentioned system patch processing method, device, computer device, storage medium and computer program product, by responding to a system patch inspection instruction for a target system, obtain the patch inspection execution frequency and the patch inspection execution time for the target system; according to the patch inspection execution frequency and the patch inspection execution time, perform an inspection operation on the patch installation situation of the target system to obtain a target system inspection result; in the case where the target system inspection result indicates that there is an abnormality in the patches of the target system, determine a full-scale patch abnormality list corresponding to the target system; according to the full-scale patch abnormality list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library, determine a patch professional group matching result corresponding to the target system; in the case where a corresponding patch maintenance professional group exists in the determined patch professional group matching result, generate system patch maintenance information; the system patch maintenance information is used to notify each maintenance object corresponding to the patch maintenance professional group to perform system patch installation on the target system.

[0017] Regular inspections are carried out by setting the patch inspection execution frequency and the patch inspection execution time in response to the patrol inspection tasks, summarizing the unpatched situations in the target system including production and office, obtaining the host names and configuring the linkage of relevant tool platforms such as the Configuration Management Database (CMDB), personnel library, job execution tools, etc. to obtain the corresponding maintainers; further comparing the personnel library to summarize the unpatched situations of each professional group and notifying each professional group to install patches in a timely manner. If no maintainer is found, it is summarized and sent to the management staff for manual confirmation. It can provide a friendly unified inspection result view for the operation and maintenance personnel, solve the blank of patch automation inspection in the data center, ensure that the application maintainers who have not installed patches are notified in time for installation, help improve the efficiency of server vulnerability blocking, reduce hacker attacks, and improve the security of the server. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 It is an application environment diagram of a system patch processing method in an embodiment;

[0019] Figure 2 It is a flow schematic diagram of a system patch processing method in an embodiment;

[0020] Figure 3 It is a flow schematic diagram of a method for determining the matching result of a patch professional group in an embodiment;

[0021] Figure 4 It is a flow schematic diagram of a method for determining the matching result of a patch professional group in another embodiment;

[0022] Figure 5 It is a flow schematic diagram of a method for integrating patch installation information in an embodiment;

[0023] Figure 6 It is a flow schematic diagram of a method for obtaining the inspection result of the target system in an embodiment;

[0024] Figure 7 It is a flow schematic diagram of a method for obtaining the inspection result of the target system in another embodiment;

[0025] Figure 8 It is a functional flow schematic diagram of a system patch processing method in an embodiment;

[0026] Figure 9 It is a structural block diagram of a system patch processing device in an embodiment;

[0027] Figure 10 It is an internal structure diagram of a computer device in an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0028] In order to make the objectives, technical solutions, and advantages of this application more clearly understood, the following further details this application in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely used to explain this application and are not used to limit this application.

[0029] A system patch processing method provided by an embodiment of this application can be applied to an application environment as Figure 1 shown. Among them, the terminal 102 communicates with the server 104 through a network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or can be placed in the cloud or on other network servers. In response to a system patch inspection instruction for the target system, the server 104 obtains the patch inspection execution frequency and the patch inspection execution time for the target system from the terminal 102; according to the patch inspection execution frequency and the patch inspection execution time, performs an inspection operation on the patch installation situation of the target system to obtain a target system inspection result; in the case where the target system inspection result indicates that there is an abnormality in the patches of the target system, determines a full-scale patch abnormality list for the target system; according to the full-scale patch abnormality list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library, determines the patch professional group matching result for the target system; in the case where it is determined that there is a corresponding patch maintenance professional group in the patch professional group matching result, generates system patch maintenance information; the system patch maintenance information is used to notify each maintenance object corresponding to the patch maintenance professional group to install system patches for the target system. Among them, the terminal 102 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server 104 can be implemented by an independent server or a server cluster composed of multiple servers.

[0030] In one embodiment, as Figure 2 shown, a system patch processing method is provided. Taking the server in Figure 1 as an example for description, the method includes the following steps:

[0031] Step 202, in response to a system patch inspection instruction for the target system, obtain the patch inspection execution frequency and the patch inspection execution time for the target system.

[0032] Among them, the target system can be the computer system used by the resource platform, such as: Windows system, Linux system, Unix system, MacOS system, Android system, iOS system, etc. Among them, the resource platform can use a single system or multiple systems simultaneously.

[0033] Among them, the system patch inspection instruction can be an instruction for inspecting whether there are vulnerabilities in each system used by the resource platform. This instruction can be sent from the terminal to the server or directly input from the interactive end of the server.

[0034] Among them, the patch inspection execution frequency can be the frequency of performing vulnerability inspections on the target system, that is, the number of times the server inspects the vulnerabilities of the installed systems within a unit of time.

[0035] Among them, the patch inspection execution time can be the time period for performing vulnerability inspections on the target system. Among them, the patch inspection execution time can set both the start time and the end time, or can set only the start time or the end time.

[0036] Specifically, in response to the system patch inspection instruction for the target system input from the terminal 102 or the interactive end of the server 104, the server 104 obtains the patch inspection execution frequency and the patch inspection execution time for the target system. Among them, the patch inspection execution frequency can be the number of inspections within one day of the patch inspection execution time, or can be the number of inspections within one month of the patch inspection execution time, or can be the number of inspections within any time period of the patch inspection execution time. When the server responds to the patch inspection execution frequency and the patch inspection execution time, it then executes the corresponding program code from the preset computer program. Among them, the patch inspection execution frequency and the patch inspection execution time can be input to the central processing unit as single data, or multiple data can be input to the central processing unit simultaneously.

[0037] Step 204, according to the patch inspection execution frequency and the patch inspection execution time, perform an inspection operation on the patch installation situation of the target system to obtain the target system inspection result.

[0038] Among them, the patch installation situation can be the installation situation of the patches for vulnerabilities in the target system.

[0039] Among them, the target system inspection result can be the abnormal result of whether the system patches have vulnerabilities obtained by performing vulnerability inspections on the target system with the patch inspection execution frequency and the patch inspection execution time as control variables.

[0040] Specifically, the patch inspection execution frequency and the patch inspection execution time have been set in the server, and when the target system time inside the computer is already within the patch inspection execution time, that is, the target system time is within the patch inspection execution time (with an inspection start time and an inspection end time), or the target system time is after the patch inspection execution time (with an inspection start time), or the target system time is before the patch inspection execution time (with an inspection end time), at least one patch inspection item that needs to be inspected for the target system is determined under the patch inspection execution frequency and the patch inspection execution time, and according to each patch inspection item, the patch centralized management server corresponding to each patch inspection item is obtained from the patch resource platform. For example, it is determined that the patch inspection items that need to be inspected for the target system are the production patch inspection item and the office patch inspection item.

[0041] For the production patch inspection item, confirm again whether the target system time meets the patch inspection execution time. If the target system time meets the conditions, based on the set patch inspection execution frequency, inspect the patch installation status of the production patch inspection item for the target system to obtain the first target system inspection result. If the target system time does not meet the conditions, stop the inspection of the patch installation status and return the reason for stopping the inspection of the patch installation status. Similarly, for the office patch inspection item, confirm again whether the target system time meets the patch inspection execution time. If the target system time meets the conditions, based on the set patch inspection execution frequency, inspect the patch installation status of the office patch inspection item for the target system to obtain the second target system inspection result. If the target system time does not meet the conditions, stop the inspection of the patch installation status and return the reason for stopping the inspection of the patch installation status.

[0042] Step 206, when the target system inspection result indicates that there is an abnormality in the patches of the target system, determine the full - volume patch abnormality list corresponding to the target system.

[0043] Among them, the full - volume patch abnormality list can be a list representing the patch installation status of the target system. Generally, the full - volume patch abnormality list includes patches not downloaded, patches downloaded but not installed, patches installed but abnormal, and patches installed but not restarted.

[0044] Specifically, if it is found that there is an abnormality in the patch installation of the target system after inspecting the patch installation of the target system, determine the patch inspection item corresponding to the patch abnormality. If the patch abnormality is for the production patch inspection item, connect to the production patch management server, and through the production patch management server, obtain the full patch abnormality list corresponding to the production patch inspection item. If the patch abnormality is for the office patch inspection item, connect to the office patch management server, and through the office patch management server, obtain the full patch abnormality list corresponding to the office patch inspection item. Further, if the patch abnormality is for both the production patch inspection item and the office patch inspection item, connect to both the production patch management server and the office patch management server simultaneously, and obtain the full patch abnormality list corresponding to the production patch inspection item and the office patch inspection item.

[0045] Step 208, according to the full patch abnormality list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library, determine the patch professional group matching result corresponding to the target system.

[0046] Among them, the server application information can be the information saved in the configuration management platform in server 104. Among them, the server application information includes the application maintainer, the application name, etc.

[0047] Among them, the human resource information table can be the information table saved in the human resource library in server 104. Among them, the human resource information table includes the corresponding relationship between each maintainer and the patch professional group.

[0048] Among them, the patch professional group matching result can be the professional personnel group corresponding to the abnormal patches that can solve the full patch abnormality list through the server application information and the human resource information table.

[0049] Specifically, through the linkage with the configuration management platform in server 104, retrieve the server application information of the configuration management platform. Further, match the full patch abnormality list with the server application information, and find out the maintenance personnel information and the application name information corresponding to the abnormal patches that can solve the full patch abnormality list from the server application information.

[0050] Based on the maintenance personnel information obtained by matching, match the maintenance personnel information with the professional personnel information table in the human resources database, and find out the maintenance personnel corresponding to the abnormal patches in the full-scale patch exception list from the professional personnel information table to obtain the maintenance personnel matching result. Similarly, based on the application name information obtained by matching, match the application name information with the application management personnel information table in the human resources database, and find out the management personnel corresponding to the abnormal patches in the full-scale patch exception list from the application management personnel information table to obtain the management personnel matching result. If the maintenance personnel matching result and the management personnel matching result can meet the requirements of personnel allocation, professional matching, etc., then integrate the maintenance personnel matching result and the management personnel matching result to obtain the patch professional group matching result corresponding to the target system.

[0051] Step 210, when it is determined that there is a corresponding patch maintenance professional group for the patch professional group matching result, generate system patch maintenance information.

[0052] Among them, the patch maintenance professional group can be maintenance personnel with various professional knowledge who maintain the target system.

[0053] Among them, the system patch maintenance information can be information used to notify each maintenance object corresponding to the patch maintenance professional group to install system patches for the target system.

[0054] Specifically, in the patch maintenance professional groups saved in server 104, when there is a patch maintenance professional group that can meet the patch professional group matching result, that is, when a corresponding patch maintenance professional group is found from each patch maintenance professional group and matches the patch professional group matching result, obtain the professional group name of this patch maintenance professional group and generate system patch maintenance information. Among them, the system patch maintenance information can be sent for confirmation by email or SMS message notification to the patch maintenance professional group, and arrange for patch installation on the target system.

[0055] Similarly, in the patch maintenance professional groups saved in server 104, when there is no patch maintenance professional group that can meet the patch professional group matching result, that is, when a corresponding patch maintenance professional group cannot be found from each patch maintenance professional group and matches the patch professional group matching result, directly generate manual patch maintenance information. Among them, the manual patch maintenance information can notify the maintenance personnel of the server and arrange for patch installation on the target system.

[0056] After the patch maintenance professional group or the maintenance personnel of the server install patches on the target system, server 104 obtains the system patch installation information corresponding to the system patch maintenance information, that is, the system patch installation information after the patch maintenance professional group installs patches on the target system; and obtains the system patch installation information corresponding to the manual patch maintenance information, that is, the system patch installation information after the maintenance personnel of the server install patches on the target system. Integrate the system patch installation information obtained from installing patches in two aspects into the database, and use the obtained system patch installation information to update the original patch data. For the inspection execution code of the target system, J2EE can be used as the development language. Figure 8 It is a functional flowchart of a system patch processing method for steps 202 to 210.

[0057] In the above system patch processing method, by responding to the system patch inspection instruction for the target system, obtain the patch inspection execution frequency and patch inspection execution time for the target system; according to the patch inspection execution frequency and patch inspection execution time, perform an inspection operation on the patch installation situation of the target system to obtain the target system inspection result; in the case where the target system inspection result indicates that there is an abnormality in the patches of the target system, determine the full-scale patch abnormality list corresponding to the target system; according to the full-scale patch abnormality list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library, determine the patch professional group matching result corresponding to the target system; in the case where it is determined that there is a corresponding patch maintenance professional group in the patch professional group matching result, generate system patch maintenance information; the system patch maintenance information is used to notify each maintenance object corresponding to the patch maintenance professional group to install system patches on the target system.

[0058] By responding to the inspection task, set the patch inspection execution frequency and patch inspection execution time for regular inspection, summarize the unpatched situation including production and office in the target system, obtain the host name and configure the linkage of related tool platforms such as the Configuration Management Database (CMDB), personnel library, and job execution tool to obtain the corresponding maintainer; further compare the personnel library to summarize the unpatched situation of each professional group and notify each professional group to install patches in a timely manner. If no maintainer is found, summarize and send it to the management staff for manual confirmation. It can provide a friendly unified inspection result view for the operation and maintenance personnel, solve the blank of patch automated inspection in the data center, ensure that the application maintainer who has not installed patches is notified in time for installation, help improve the efficiency of server vulnerability blocking, reduce hacker attacks, and improve the security of the server.

[0059] In one embodiment, as Figure 3As shown, according to the full - volume patch exception list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library, determine the patch professional group matching result corresponding to the target system, including:

[0060] Step 302: Match the full - volume patch exception list and the server application information corresponding to the system configuration platform to determine the maintenance personnel information and application name information corresponding to the system configuration platform.

[0061] Among them, the maintenance personnel information can be the information of each system maintenance personnel recorded in the system configuration platform. The maintenance personnel information includes name, job number, specialty, good at field, level, etc.

[0062] Among them, the application name information can be the information of the names of each application in the system configuration platform.

[0063] Specifically, through the configuration management platform in the linkage server 104, retrieve the server application information of the configuration management platform. Further, match the full - volume patch exception list and the server application information, and find out the maintenance personnel information and application name information corresponding to the abnormal patches in the full - volume patch exception list from the server application information.

[0064] Step 304: Match the maintenance personnel information and the application name information with the human resource information table corresponding to the human resource library respectively to determine the patch professional group matching result corresponding to the target system.

[0065] Specifically, based on the obtained maintenance personnel information, match the maintenance personnel information with the professional personnel information table in the human resource library, and find out the maintenance personnel corresponding to the abnormal patches in the full - volume patch exception list from the professional personnel information table to obtain the maintenance personnel matching result. Similarly, based on the obtained application name information, match the application name information with the application management personnel information table in the human resource library, and find out the management personnel corresponding to the abnormal patches in the full - volume patch exception list from the application management personnel information table to obtain the management personnel matching result. Combine the maintenance personnel matching result and the management personnel matching result to obtain the patch professional group matching result corresponding to the target system.

[0066] In this embodiment, by using the matching result of the full - volume patch exception list and the server application information, and further matching with the human resource information table, it can accurately match the patch professional group that can solve the abnormal patches in the full - volume patch exception list, which helps to improve the efficiency of patch maintenance for the target system.

[0067] In one embodiment, as Figure 4As shown in the figure, the maintenance personnel information and the application name information are respectively matched with the human resources information table corresponding to the human resources library to determine the matching result of the patch professional group corresponding to the target system, including:

[0068] Step 402: Match the maintenance personnel information with the professional personnel information table in the human resources library to obtain the maintenance personnel matching result.

[0069] Among them, the maintenance personnel matching result can be the matching result obtained by matching the maintenance personnel information with the professional personnel information table.

[0070] Specifically, based on the obtained maintenance personnel information, the maintenance personnel information is matched with the professional personnel information table in the human resources library, and the maintenance personnel corresponding to the abnormal patches in the full-scale patch exception list are found from the professional personnel information table to obtain the maintenance personnel matching result.

[0071] Step 404: Match the application name information with the application management personnel information table in the human resources library to obtain the management personnel matching result.

[0072] Among them, the management personnel matching result can be the matching result obtained by matching the application name information with the application management personnel information.

[0073] Specifically, based on the obtained application name information, the application name information is matched with the application management personnel information table in the human resources library, and the management personnel corresponding to the abnormal patches in the full-scale patch exception list are found from the application management personnel information table to obtain the management personnel matching result.

[0074] Step 406: When the maintenance personnel matching result and the management personnel matching result meet the preset conditions, determine the matching result of the patch professional group corresponding to the target system.

[0075] Specifically, if the maintenance personnel matching result and the management personnel matching result can meet the conditions such as personnel deployment and professional matching, the maintenance personnel matching result and the management personnel matching result are integrated to obtain the matching result of the patch professional group corresponding to the target system.

[0076] In this embodiment, by matching the maintenance personnel information with the professional personnel information table and matching the application name information with the application management personnel information table, the patch professional group that can include the target maintenance personnel is accurately selected, ensuring the professionalism of the patch professional group and improving the security of patch maintenance for the target system.

[0077] In one embodiment, the method further includes:

[0078] In the case where it is determined that there is no corresponding patch maintenance professional group for the patch professional group matching result, manual patch maintenance information is generated.

[0079] Among them, the manual patch maintenance information can be information used to notify the selection of maintenance objects in each patch maintenance professional group to install system patches on the system.

[0080] Specifically, in the patch maintenance professional groups saved in server 104, when there is no patch maintenance professional group that can meet the patch professional group matching result, that is, when no corresponding patch maintenance professional group can be found from each patch maintenance professional group and it matches the patch professional group matching result, manual patch maintenance information is directly generated. Among them, the manual patch maintenance information can notify the maintenance personnel of the server to arrange patch installation for the target system.

[0081] In this embodiment, by switching to notifying the corresponding maintenance personnel for manual maintenance in the case where there is no corresponding patch maintenance professional group for the patch professional group matching result, it can ensure that the patch defects of the target system are still maintained when the professional maintenance group fails to meet the maintenance conditions, reducing the losses caused by patch problems in the target system.

[0082] In one embodiment, as Figure 5 shown, after the step of generating system patch maintenance information in the case where it is determined that there is a corresponding patch maintenance professional group for the patch professional group matching result, it further includes:

[0083] Step 502, obtain the first system patch installation information corresponding to the system patch maintenance information, and the second system patch installation information corresponding to the manual patch maintenance information.

[0084] Among them, the first system patch installation information can be the patch installation information generated after the patch maintenance professional group performs patch maintenance.

[0085] Among them, the second system patch installation information can be the patch installation information generated after the maintenance personnel of some servers in the patch maintenance professional group perform patch maintenance.

[0086] Specifically, server 104 obtains the system patch installation information corresponding to the system patch maintenance information, that is, the first system patch installation information after the patch maintenance professional group installs patches on the target system; and obtains the system patch installation information corresponding to the manual patch maintenance information, that is, the second system patch installation information after the maintenance personnel of the server install patches on the target system.

[0087] Step 504, integrate the first system patch installation information and the second system patch installation information into the database, and update the patch update data in the database.

[0088] Specifically, integrate the system patch installation information obtained from installing patches in two aspects into the database, and use the obtained system patch installation information to update the original patch data. Among them, the database can be a database developed by MySQL, Jetty, or quartz.

[0089] In this embodiment, by inputting the maintenance information after patch maintenance of the target system into the database and updating the data in the database, it is possible to keep a record of the iteration of patch maintenance of the target system, which helps to find corresponding solutions when vulnerabilities are discovered in the target system and improve the security of the target system.

[0090] In one embodiment, as Figure 6 shown, perform a patrol operation on the patch installation status of the target system according to the patch patrol execution frequency and the patch patrol execution time to obtain the target system patrol result, including:

[0091] Step 602, determine at least one patch patrol item corresponding to the target system according to the patch patrol execution frequency and the patch patrol execution time.

[0092] Among them, the patch patrol item can be the content for patrolling the target system. Among them, the patch patrol items include production patch patrol items and office patch patrol items.

[0093] Specifically, when the patch patrol execution frequency and the patch patrol execution time have been set in the server and the target system time inside the computer is already within the patch patrol execution time, that is, the target system time is within the patch patrol execution time (with a patrol start time and a patrol end time), or the target system time is after the patch patrol execution time (with a patrol start time), or the target system time is before the patch patrol execution time (with a patrol end time), determine at least one patch patrol item that needs to patrol the target system under this patch patrol execution frequency and the patch patrol execution time, and according to each patch patrol item, obtain the patch centralized management server corresponding to each patch patrol item from the patch resource platform. For example, determine that the patch patrol items that need to patrol the target system are production patch patrol items and office patch patrol items.

[0094] Step 604, patrol the patch installation status of the system according to each patch patrol item, the patch patrol execution frequency, and the patch patrol execution time to obtain the target system patrol result.

[0095] Specifically, for the production patch inspection project, reconfirm whether the target system time meets the patch inspection execution time. If the target system time meets the conditions, based on the set patch inspection execution frequency, conduct an inspection of the patch installation status of the production patch inspection project for the target system to obtain the first target system inspection result. If the target system time does not meet the conditions, stop the inspection of the patch installation status and return the reason for stopping the inspection of the patch installation status. Similarly, for the office patch inspection project, reconfirm whether the target system time meets the patch inspection execution time. If the target system time meets the conditions, based on the set patch inspection execution frequency, conduct an inspection of the patch installation status of the office patch inspection project for the target system to obtain the second target system inspection result. If the target system time does not meet the conditions, stop the inspection of the patch installation status and return the reason for stopping the inspection of the patch installation status. Integrate the first target system inspection result and the second target system inspection result according to the preset integration rules to obtain the target system inspection result.

[0096] In this embodiment, by refining the patch inspection projects for inspecting the target system, the patch inspection for the target system can be more purposeful. Different arrangements for inspections can be realized for different inspection projects, saving the resource occupancy of the server and improving the computing and running efficiency.

[0097] In one embodiment, as Figure 7 shown, according to each patch inspection project, patch inspection execution frequency, and patch inspection execution time, inspect the patch installation status of the system to obtain the target system inspection result, including:

[0098] Step 702, according to the patch inspection execution frequency and patch inspection execution time, inspect the patch installation status of the production patch inspection project of the target system to obtain the first target system inspection result.

[0099] Among them, the production patch inspection project can be an inspection of the patches for the production aspect of the target system.

[0100] Among them, the first target system inspection result can be the inspection result obtained from the inspection of the patches for the production aspect of the target system.

[0101] Specifically, for the production patch inspection project, confirm again whether the target system time meets the patch inspection execution time. If the target system time meets the conditions, based on the set patch inspection execution frequency, inspect the patch installation status of the production patch inspection project for the target system to obtain the first target system inspection result. If the target system time does not meet the conditions, stop the inspection of the patch installation status and return the reason for stopping the inspection of the patch installation status.

[0102] Step 704: According to the patch inspection execution frequency and the patch inspection execution time, inspect the patch installation status of the office patch inspection project for the target system to obtain the second target system inspection result.

[0103] Among them, the office patch inspection project can be an inspection of patches for the office aspect of the target system.

[0104] Among them, the second target system inspection result can be the inspection result obtained from the inspection of patches for the office aspect of the target system.

[0105] Specifically, for the office patch inspection project, confirm again whether the target system time meets the patch inspection execution time. If the target system time meets the conditions, based on the set patch inspection execution frequency, inspect the patch installation status of the office patch inspection project for the target system to obtain the second target system inspection result. If the target system time does not meet the conditions, stop the inspection of the patch installation status and return the reason for stopping the inspection of the patch installation status.

[0106] Step 706: Integrate the first target system inspection result and the second target system inspection result to obtain the target system inspection result.

[0107] Specifically, integrate the first target system inspection result and the second target system inspection result according to the preset integration rules to obtain the target system inspection result.

[0108] In this embodiment, by determining the inspection projects as the production patch inspection project and the office patch inspection project and then conducting inspections, it is possible to perform real-time targeted inspections on the resource platform, avoid excessive computing tasks, and improve the utilization rate of computer resources.

[0109] It should be understood that although the steps in the flowcharts involved in the above embodiments are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0110] Based on the same inventive concept, an embodiment of the present application also provides a system patch processing device for implementing the system patch processing method involved above. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the system patch processing device provided below can refer to the limitations on a system patch processing method in the above text, and will not be repeated here.

[0111] In one embodiment, as Figure 9 shown, a system patch processing device is provided, including: a data acquisition module 902, a patch inspection module 904, a list generation module 906, a data matching module 908, and a maintenance notification module 910, where:

[0112] The data acquisition module 902 is configured to obtain the patch inspection execution frequency and the patch inspection execution time for the target system in response to a system patch inspection instruction for the target system;

[0113] The patch inspection module 904 is configured to perform an inspection operation on the patch installation status of the target system according to the patch inspection execution frequency and the patch inspection execution time to obtain a target system inspection result;

[0114] The list generation module 906 is configured to determine a full - volume patch exception list corresponding to the target system when the target system inspection result indicates that there is an exception in the patches of the target system;

[0115] The data matching module 908 is configured to determine a patch professional group matching result corresponding to the target system according to the full - volume patch exception list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library;

[0116] A maintenance notification module 910 is configured to generate system patch maintenance information when it is determined that there is a corresponding patch maintenance professional group for the patch professional group matching result; the system patch maintenance information is used to notify each maintenance object corresponding to the patch maintenance professional group to install system patches on the target system.

[0117] In one embodiment, the data matching module 908 is further configured to match the full - volume patch exception list and the server application information corresponding to the system configuration platform, determine the maintenance personnel information and the application name information corresponding to the system configuration platform; match the maintenance personnel information and the application name information with the human resource information table corresponding to the human resource library respectively to determine the patch professional group matching result corresponding to the target system.

[0118] In one embodiment, the data matching module 908 is further configured to match the maintenance personnel information with the professional personnel information table in the human resource library to obtain a maintenance personnel matching result; match the application name information with the application management personnel information table in the human resource library to obtain a management personnel matching result; determine the patch professional group matching result corresponding to the target system when the maintenance personnel matching result and the management personnel matching result meet the preset conditions.

[0119] In one embodiment, the maintenance notification module 910 is further configured to generate manual patch maintenance information when it is determined that there is no corresponding patch maintenance professional group for the patch professional group matching result; the manual patch maintenance information is used to notify the selection of maintenance objects from each patch maintenance professional group to install system patches on the system.

[0120] In one embodiment, the maintenance notification module 910 is further configured to obtain the first system patch installation information corresponding to the system patch maintenance information and the second system patch installation information corresponding to the manual patch maintenance information; integrate the first system patch installation information and the second system patch installation information into the database and update the patch update data in the database.

[0121] In one embodiment, the patch inspection module 904 is further configured to determine at least one patch inspection item corresponding to the target system according to the patch inspection execution frequency and the patch inspection execution time; inspect the patch installation situation of the system according to each patch inspection item, the patch inspection execution frequency and the patch inspection execution time to obtain the target system inspection result.

[0122] In one embodiment, the patch inspection module 904 is further configured to inspect the patch installation status of the production patch inspection items of the target system according to the patch inspection execution frequency and the patch inspection execution time, so as to obtain the first target system inspection result; and, inspect the patch installation status of the office patch inspection items of the target system according to the patch inspection execution frequency and the patch inspection execution time, so as to obtain the second target system inspection result; integrate the first target system inspection result and the second target system inspection result to obtain the target system inspection result.

[0123] Each module in the above system patch processing device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.

[0124] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 10 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store server data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a system patch processing method.

[0125] Those skilled in the art can understand that Figure 10 the structure shown in is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.

[0126] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0127] In one embodiment, a computer-readable storage medium is provided, storing a computer program, and when the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0128] In one embodiment, a computer program product or a computer program is provided. The computer program product or the computer program includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, causing the computer device to perform the steps in the above method embodiments.

[0129] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0130] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, a database, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.

[0131] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.

[0132] The above-described embodiments merely represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A system patch processing method, characterized in that The method includes: In response to a system patch inspection instruction for a target system, obtaining the patch inspection execution frequency and the patch inspection execution time for the target system; Performing an inspection operation on the patch installation status of the target system according to the patch inspection execution frequency and the patch inspection execution time, to obtain a target system inspection result; In the case where the target system inspection result indicates that there are abnormalities in the patches of the target system, determining a full - volume patch exception list corresponding to the target system; According to the full - volume patch exception list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library, determining a patch professional group matching result corresponding to the target system; In the case where a corresponding patch maintenance professional group exists in the determined patch professional group matching result, generating system patch maintenance information; the system patch maintenance information is used to notify each maintenance object corresponding to the patch maintenance professional group to install system patches for the target system.

2. The method according to claim 1, wherein The determining the patch professional group matching result corresponding to the target system according to the full - volume patch exception list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library includes: Matching the full - volume patch exception list and the server application information corresponding to the system configuration platform to determine the maintenance personnel information and the application name information corresponding to the system configuration platform; Respectively matching the maintenance personnel information and the application name information with the human resource information table corresponding to the human resource library to determine the patch professional group matching result corresponding to the target system.

3. The method according to claim 2, wherein The human resource information table includes a professional personnel information table and an application management personnel information table; the respectively matching the maintenance personnel information and the application name information with the human resource information table corresponding to the human resource library to determine the patch professional group matching result corresponding to the target system includes: Matching the maintenance personnel information with the professional personnel information table in the human resource library to obtain a maintenance personnel matching result; Matching the application name information with the application management personnel information table in the human resource library to obtain a management personnel matching result; In the case where the maintenance personnel matching result and the management personnel matching result meet the preset conditions, determining the patch professional group matching result corresponding to the target system.

4. The method according to claim 1, wherein The method further includes: In the case where no corresponding patch maintenance professional group exists in the determined patch professional group matching result, generating manual patch maintenance information; the manual patch maintenance information is used to notify the selection of the maintenance object from each of the patch maintenance professional groups to install system patches for the system.

5. The method according to claim 4, wherein After the step of generating system patch maintenance information in the case where a corresponding patch maintenance professional group exists in the determined patch professional group matching result, it further includes: Obtaining first system patch installation information corresponding to the system patch maintenance information, and second system patch installation information corresponding to the manual patch maintenance information; Integrate the first system patch installation information and the second system patch installation information into a database, and update the patch update data of the database.

6. The method according to claim 1, characterized in that Performing an inspection operation on the patch installation status of the target system according to the patch inspection execution frequency and the patch inspection execution time to obtain a target system inspection result, including: Determine at least one patch inspection item corresponding to the target system according to the patch inspection execution frequency and the patch inspection execution time; Inspect the patch installation status of the system according to each of the patch inspection items, the patch inspection execution frequency, and the patch inspection execution time to obtain the target system inspection result.

7. The method according to claim 6, wherein The patch inspection items include a production patch inspection item and an office patch inspection item; performing an inspection operation on the patch installation status of the system according to each of the patch inspection items, the patch inspection execution frequency, and the patch inspection execution time to obtain the target system inspection result, including: Inspect the patch installation status of the production patch inspection item of the target system according to the patch inspection execution frequency and the patch inspection execution time to obtain a first target system inspection result; And, inspect the patch installation status of the office patch inspection item of the target system according to the patch inspection execution frequency and the patch inspection execution time to obtain a second target system inspection result; Integrate the first target system inspection result and the second target system inspection result to obtain the target system inspection result.

8. A system patch processing device, characterized in that, The device includes: A data acquisition module, configured to obtain the patch inspection execution frequency and the patch inspection execution time for the target system in response to a system patch inspection instruction for the target system; A patch inspection module, configured to perform an inspection operation on the patch installation status of the target system according to the patch inspection execution frequency and the patch inspection execution time to obtain a target system inspection result; A list generation module, configured to determine a full-scale patch exception list corresponding to the target system when the target system inspection result indicates that there is an exception in the patches of the target system; A data matching module, configured to determine a patch professional group matching result corresponding to the target system according to the full-scale patch exception list, the server application information corresponding to the system configuration platform, and the human resource information table corresponding to the human resource library; A maintenance notification module, configured to generate system patch maintenance information when it is determined that there is a corresponding patch maintenance professional group in the patch professional group matching result; the system patch maintenance information is used to notify each maintenance object corresponding to the patch maintenance professional group to perform system patch installation on the target system.

9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.

11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Automatic operating system patch installation method and system based on deep learning

    CN111857771A

  • Effective action classification method and device for host security vulnerability patch program

    CN115758378A