Methods and computer program products for operating networks
By configuring rule sets for network endpoints and determining measures based on compliance scores, the IT security issues of enterprise and production workshop networks were resolved, achieving higher security and attack protection.
Patent Information
- Application Number
- CN202180067222.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-09-30
- Filing Date
- 2021-09-30
- Publication Date
- 2025-12-02
- Estimated Expiration
- 2041-09-30
Smart Images

Figure CN116391348B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a method for operating a network and a computer program product having at least one endpoint for managing at least one network resource. Background Technology
[0002] Networks in enterprises and production facilities are frequently subjected to large-scale attacks from third parties. Therefore, ensuring IT security is of paramount importance.
[0003] Within the framework of this invention, IT security is advantageously understood as information security. Alternatively, additionally, and equally advantageously, IT security is understood as functional safety. Summary of the Invention
[0004] Therefore, the object of the present invention is to provide a method for operating a network, which can be executed securely and has an automation option. A further object of the present invention is to describe a computer program product that supports the execution of this method.
[0005] This task is accomplished using the method according to the invention and the computer program product according to the invention. Preferred extensions of the invention are described below and in the accompanying drawings.
[0006] The method according to the invention is a method for operating a network having at least one endpoint that manages at least one network resource. In other words, the method is a method for operating a network having at least one endpoint that manages at least one network resource. That is, the at least one endpoint manages the at least one network resource. Preferably, the at least one endpoint manages the at least one network resource by configuring the at least one network resource, preferably the endpoint's software, especially the operating system, at least one parameter that is important for IT security. In the method according to the invention, the at least one network resource is a network resource that is accessible not only to the at least one endpoint that manages the network resource but also to one or more other endpoints of the network. The method according to the invention includes the following steps:
[0007] - Define a rule set with at least one rule for the at least one endpoint, preferably for managing the at least one network resource through the at least one endpoint;
[0008] - Observe the compliance of at least one endpoint with the rule set;
[0009] - Scores are allocated based on this compliance; and
[0010] - Determine at least one measure based on the score.
[0011] Ideally, the method according to the present invention is a computer-implemented method.
[0012] Advantageously, in the method according to the invention, the at least one network resource may be part of the at least one endpoint managing the network resource. Alternatively and equally preferably, the at least one network resource is physically separated from the at least one endpoint managing the network resource.
[0013] In a particularly preferred extension of the invention, the at least one measure is executed after it has been determined based on a score. Preferably, the measure is a measure to improve the compliance of the at least one endpoint with the rule set and / or a measure to improve IT security when other endpoints on the network access network resources.
[0014] By means of the method according to the present invention, the network can be advantageously operated in accordance with IT security requirements.
[0015] Suitablely, the rule set includes rules for IT security, making it easy to protect networks, such as those in enterprises or production facilities, by means of the method according to the invention.
[0016] Preferably, the rule set includes at least one rule for managing the authorization of secure access to network resources by other endpoints that do not manage the network resources, in terms of IT security.
[0017] Preferably, in the method according to the invention, the at least one measure includes: restricting the privileges of the endpoint in the network based on a score. In particular, restricting privileges means restricting the privileges used to manage the network resources. This, for example, can limit the management of the network resources to a less security-critical subset of privileges.
[0018] Preferably, in an extension of the method according to the invention, the at least one measure includes interrupting the operation of the network. Interrupting the operation of the network may be considered in extreme cases where the continued operation of the network cannot be taken responsibility for. Alternatively, additionally, and equally preferably, in an extension of the invention, the at least one measure includes: interrupting the operation of the network resource; or restricting access to the network resource by other endpoints that do not manage the network resource.
[0019] In the method according to the invention, the at least one endpoint is preferably formed using at least one network resource and / or at least one administrator hardware and / or at least one hardware interface, wherein the administrator hardware is preferably a client computer and / or authentication hardware, and the hardware interface is preferably a user account. Advantageously, the client computer or the authentication hardware, such as an electronically readable corporate ID, can be linked to the administrator account, such that only one administrator can connect to the endpoint.
[0020] In an advantageous extension of the method according to the invention, the at least one network resource is formed using hardware and / or software, the hardware being, in particular, a server, and the software being, in particular, an operating system and / or an application used by means of the network.
[0021] In an advantageous extension of the method according to the invention, the endpoint forms an administrator interface.
[0022] Preferably, in the method according to the invention, the rule set specifies the regularity of updates to the software and / or the software on the hardware.
[0023] In a preferred extension of the method according to the invention, the score is formed based on the time period during which at least one update was missed and / or based on the number of missed updates and / or security criticality.
[0024] In an advantageous extension of the method according to the invention, the measure includes: changing or restricting administrative privileges; and / or changing the connection of the endpoint to the network, such as disconnecting the endpoint from the network or changing the authorization when connecting to the network; and / or training the administrator connected to the endpoint. Alternatively or additionally, the measure includes: changing or extending administrative privileges.
[0025] Suitablely, in the latter case of the above-described extension scheme, the score is assigned in at least two categories, and the training is preferably adjusted by means of modules based on the scores in these categories, preferably based on the occupancy of these categories and / or the absolute and / or relative weights of these categories.
[0026] In an extended embodiment of the invention, administrators are appropriately allowed network access only after training.
[0027] Preferably, in the method according to the invention, the score is given or maintained based on training, preferably repeated training and / or inspection, preferably repeated inspection.
[0028] The computer program product according to the invention is designed for application in the method according to the invention as described above. The computer program product according to the invention is designed to store a rule set having at least one rule for the at least one endpoint, to receive observation data regarding the compliance of the at least one endpoint with respect to the rule set, and to assign scores based on the compliance. Attached Figure Description
[0029] The invention will then be further described based on the embodiments shown in the accompanying drawings. (Unique Appendix) Figure 1 A cross-sectional diagram schematically illustrates an enterprise network with network resources that are managed through the enterprise network. Detailed Implementation
[0030] Figure 1 The network 10 shown is an enterprise network with interconnected computers. Some of the computers in network 10 form distributed servers 30 for network resources. Other computers in network 10 are implemented as client computers 50 for managing these servers 30. Both the servers 30 and the client computers 50 form endpoints of network 10, either feeding content or services into network 10 as servers 30 or providing an interface with the administrator for management tasks as client computers 50. In the illustrated embodiment, network 10 is designed as a cloud network. In this cloud network, the servers 30 do not exist as separate computers isolated from each other in their respective hardware, but rather as logical servers 30 for a distributed database stored on multiple computers in network 10. In other embodiments, not specifically shown, network 10 may also be designed as another, conventional, such as a hierarchical network 10, in which the servers 30 exist as separate, physically separated hardware servers.
[0031] These servers 30 are configured to run project coordination software via network 10. Using this project coordination software, users can feed project milestones into the system and coordinate their achievements, enabling users to quickly understand the project status and their fulfillment of responsibilities regarding project milestones.
[0032] The network additionally includes a central access control server 60, which grants or denies access to network resources.
[0033] The network 10 also includes an observation unit 70, which observes the security status of the network 10. The observation unit 70 periodically or continuously checks the update status of the operating system of the server 30, such as the update status of the Linux system of the server 30. Here, the observation unit 70 records the current status of the corresponding operating system. The current state of the operating system is compared to a target state, such as the recommendation of a Linux distribution repository maintainer. If, for example, a current patch for the Linux system has not been installed, a score is calculated based on the time period during which the Linux system has not been updated despite the possibility of updates, and the security criticality of the patches, such as those categorized from developers or repository maintainers. This score is then assigned to the corresponding server 30. For example, the score includes a magnitude proportional to the aforementioned time period (e.g., data with a scaling factor for time periods in hours) and a sum of the magnitudes of the security criticality of each patch that was missed despite being available (e.g., a value of "5" for "highly critical," "3" for "critical," and "1" for "recommended"). In this way, each server 30 is assigned a security score for the operating system, with higher scores awarded for the more or more severe security vulnerabilities on that server 30.
[0034] Similar scores are also assigned to the project coordination software based on the patches or updates available for it.
[0035] The sum of the project coordination software's score and the operating system's score forms the total score for server 30, which is then assigned to server 30 as a certificate. If this total score exceeds a first critical threshold, the total score or information regarding exceeding the first threshold is transmitted to the access control server 60. Due to exceeding the first threshold, the access control server introduces measures to enhance the security of network 10. These measures could, for example, involve restricting server 30's operation in emergency mode; or—if the threshold is significantly exceeded, such as exceeding 50%—disconnecting server 30 or network 10.
[0036] Additionally, this total score is not only allocated to server 30. More precisely, the total score is also allocated to the corresponding administrator (not explicitly shown in the accompanying drawings) who is responsible for updating server 30 and the project coordination software. Here, this allocation either occurs to the corresponding administrator's client computer 50, or in cases where the client computer 50 may be changed to an administrator account for privileged access to network 10.
[0037] In the illustrated embodiment, total scores are allocated to server 30 and scores are assigned to administrator accounts using scoring accounts, which are uniquely assigned to both server 30 and the administrator account. The administrator's scoring account on server 30 is on standby on the access control server 60.
[0038] In the illustrated embodiment, an administrator account is assigned, which is uniquely assigned to a specific administrator. Here, only the software assigned to that administrator account, specifically the score for the administrator's actual update tasks, is attributed to that administrator account.
[0039] exist Figure 2 The document describes access control:
[0040] To be specifically authorized to assume the administrator role on Server 30 of Network 10, the administrator must complete Cybersecurity Training (CYTR). This training provides information on the administrator's rule set regarding security-related rules for Network 10. These security-related rules primarily include requirements for timely and comprehensive patch installation. Upon completion of the CYTR, the administrator is granted an Administrator Certificate ISDL. Based on this ISDL, a password signature is added to the administrator account as an administrator signature, authorizing the administrator to act as the administrator of Server 30.
[0041] Simultaneously, server 30 itself must meet security requirements, which are combined in the System Target Configuration (SYSOPC). This SYSOPC means that all software installed on server 30, in this case, the operating system and the project coordination software, are up-to-date. After verifying that server 30's configuration meets the SYSOPC, a Server License ISLP for network 10 is granted to server 30. Based on the ISLP, server 30 is granted another cryptographic signature in the form of a server signature, which proves that server 30 at least initially meets the SYSOPC. With the aid of this server signature, server 30 is allowed to integrate into network 10.
[0042] In the illustrated embodiment, the administrator logs into network 10 to manage server 30 as follows:
[0043] First, the administrator authenticates with UACREQ relative to Network 10 in a manner known to them. To do this, the administrator transmits a unique identifier to Network 10 using their administrator account. The access control server 60 checks whether the administrator possesses an administrator certificate based on the administrator signature assigned to that identifier. If so, the administrator account is determined based on the administrator signature, and the score account assigned to that administrator account is identified. It is then checked whether the score value recorded in that score account exceeds a first threshold. If the score value is below the first threshold, the administrator continues logging into Network 10. If the score value is above the first threshold, the administrator is denied access by Network 10.
[0044] Next, the administrator selects the project coordination software running on server 30, which he manages. Server 30 checks whether the administrator has previously registered with UREGSYS to manage server 30. If not, server 30 rejects the administrator. If the administrator is registered to manage server 30, the administrator login process continues.
[0045] Finally, the access control server 60 checks whether server 30 currently meets the system target configuration SYSOPC based on its server signature. If so, the administrator is granted permission to OPALL to manage server 30. If server 30 does not currently meet the system target configuration SYSOPC, the server license ISLP is revoked.
[0046] In the illustrated embodiment, the server license ISLP of server 30 and the administrator certificate ISDL for managing server 30 are verified not only for the initial permission for the administrator and server 30 to access network 10. More specifically, the maintenance of the administrator certificate ISDL depends on the score value of the administrator account to which the administrator belongs, and the server license ISLP depends on the score value of the server 30's account. Thus, the observation unit 70 periodically or continuously checks the update status of the operating system of server 30. If the score value of the administrator account to which the administrator belongs exceeds the first threshold, the administrator is excluded from further management of server 30 by the access control server 60. Furthermore, server 30 is decoupled from network 10. In other embodiments not specifically shown, the administrator is not excluded from further management of server 30, but a corresponding message is sent to the security officer of network 10 indicating that the first threshold has been exceeded. Furthermore, instead of decoupling server 30 from network 10, a message is sent to the security officer of network 10, allowing the security officer to examine the situation more closely.
[0047] If the administrator of server 30 on network 10 exceeds the score account assigned to him, the administrator can be trained via the access control server 60, and after the training, the administrator certificate ISDL is reissued to the administrator. Specifically, the score can be determined in multiple dimensions, such as the software configured by the administrator on server 30, for example, project coordination software and the operating system of server 30. If it is found that the excess is largely attributable to a defective update of the operating system of server 30 when the score of the score account assigned to the administrator exceeds the first threshold, the training can automatically provide a higher weighting for content related to the operating system of server 30. For this purpose, it is appropriate to record the score for those dimensions, i.e., categories, where the training content can be used modularly. In the illustrated embodiment, this training content exists modularly in 5 to 10 categories, for example, these categories are incorporated into the training of the administrator when entries are filled in when the score exceeds the threshold. Categories that are not assigned non-zero scores are either completely ignored when weighting the training or considered with standard content that differs from the post-training content. When categories are filled with non-zero scores, this post-training content is incorporated into the administrator training. In the illustrated embodiment, the training module is automatically compiled using the software of the permissions management server 60.
Claims
1. A method for operating a network having at least one endpoint for managing at least one network resource, the method comprising the following steps: - Define a set of rules with at least one rule for the at least one endpoint; - Observe the compliance of at least one endpoint with the rule set; - Scores are assigned based on the aforementioned compliance; and - Determine at least one measure based on the score. -The endpoints described therein form the administrator interface, and -The rule set having at least one rule is a rule set used to manage at least one network resource through at least one endpoint, and - Each of the at least one network resource is physically separated from the at least one endpoint that manages the network resource, and - Not only can the at least one endpoint managing the network resource access the network resource, but one or more other endpoints of the network can also access the network resource, and wherein - The at least one network resource is formed using hardware and / or software, and The rule set specifies the regularity and / or timeliness of updates to the software and / or the software on the hardware, and The score depends on the time period during which at least one update was missed and / or on the number of missed updates and / or the criticality of the missed updates to IT security.
2. The method according to claim 1, wherein the hardware is a server.
3. The method of claim 1, wherein the software is an operating system and / or an application for use via the network.
4. The method according to claim 1, wherein the at least one measure comprises: The privileges of the endpoint in the network are restricted based on the score.
5. The method of claim 4, wherein restricting the privileges means restricting the privileges used to manage the network resources.
6. The method according to any one of claims 1 to 5, wherein the at least one measure includes interrupting the operation of the network.
7. The method according to any one of claims 1 to 5, wherein each of the at least one endpoint is formed using at least one network resource and / or at least one administrator hardware and / or at least one hardware interface.
8. The method of claim 7, wherein the at least one administrator hardware is a client computer and / or authentication hardware.
9. The method of claim 7, wherein the at least one hardware interface is a user account.
10. The method according to any one of claims 1 to 5, wherein the measure comprises: Change or restrict administrative privileges.
11. The method according to any one of claims 1 to 5, wherein the measures include: Connect the endpoint to the network; Alternatively, change the connection between the endpoint and the network.
12. The method according to any one of claims 1 to 5, wherein the measure comprises: training an administrator connected to the endpoint.
13. The method of any one of claims 1 to 5, wherein the scores are assigned in at least two categories, and the training is adjusted according to the scores in the categories; and / or wherein the administrator is only allowed access to the network after training.
14. The method of claim 13, wherein the training is adjusted by means of a module based on the score in the category.
15. The method of claim 13, wherein the training is adjusted based on the occupancy of the category and / or based on the absolute and / or relative weight of the category.
16. The method according to any one of claims 1 to 5, wherein the score is given, maintained, or changed based on training and / or inspection.
17. The method of claim 16, wherein the training is repeated.
18. The method of claim 16, wherein the check is repeated.
19. A computer program product designed for application in the method according to any one of claims 1 to 18, further designed for storing a rule set having at least one rule for the at least one endpoint, for receiving observation data regarding the compliance of the at least one endpoint with respect to the rule set, and for assigning scores based on the compliance.
Citation Information
Patent Citations
Enterprise security measures
US10084809B1
Health-based access to network resources
US20100192196A1