Terminal security problem rectification system, method, device and computer equipment
By classifying and repairing terminals through the terminal security issue rectification system, the problem of isolated information in terminal security management software in large organizations has been solved, enabling timely detection and efficient repair of terminal security issues.
Patent Information
- Application Number
- CN202410500741.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-24
- Publication Date
- 2025-12-16
- Estimated Expiration
- 2044-04-24
AI Technical Summary
In large organizations, endpoint security management software is isolated, configuration and management are labor-intensive, the number of endpoint devices is large and geographically dispersed, manual inspection is inefficient, and it is difficult to detect and handle security anomalies in a timely manner, resulting in severe endpoint security risks.
The endpoint security issue rectification system uses management units to classify endpoint information, determine whether it complies with security rules, identify abnormal endpoints, and form a digital rectification plan through collaborative repair between institutional clients and operation and maintenance terminals.
It enables timely detection and efficient remediation of terminal security issues, solves the problem of low efficiency in manual investigation, and forms a complete digital rectification solution for terminal anomalies.
Smart Images

Figure CN118368115B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present specification relates to the technical field of computer, in particular to a terminal security problem rectification system, method, device and computer equipment. BACKGROUND
[0002] Currently, various types of security management software (such as antivirus software, watermark software, domain control software, document encryption software, network access software, etc.) are installed on terminals to achieve terminal security management, which is a mature technology.
[0003] However, in the current technology, various types of terminal security management software information is isolated and does not form a unified organic whole. The security measures, protection mechanisms and other strategies of different software need to be configured independently. In the application scenario of financial units such as large institutions, there are various terminal devices such as office terminals, financial equipment, and special terminals in large institutions. The configuration management workload is large, and unexpected normal operation often occurs. In addition, the number of terminal devices in large institutions such as finance is large and the region is scattered, and there is a lack of complete terminal problem list. Manual on-site investigation and rectification is costly, inefficient and difficult to ensure quality, and terminal security anomalies cannot be discovered and handled in a timely manner. The terminal security protection risk is serious, and it is easy to become a security management and data security protection risk point. SUMMARY
[0004] To solve the problem that the security management in the prior art cannot cope with the large number of large institutions and the low efficiency of manual terminal security investigation, the embodiments of the present specification provide a terminal security problem rectification system, method, device and computer equipment.
[0005] The embodiments of the present specification provide a terminal security problem rectification method, which comprises: classifying a plurality of terminals of each institution according to terminal information received from each institution client to obtain a terminal type of each terminal; determining whether each terminal meets a security rule according to the terminal type and the terminal information; if the security rule is not met, determining that the terminal is abnormal and sending it to the institution client; receiving a repair result fed back after the institution client repairs the abnormal terminal; and recording and displaying the repair result.
[0006] According to an aspect of the embodiments of the present specification, the classification of the terminals of each institution according to the terminal information received from each institution client to obtain the terminal type of each institution comprises: determining whether the field attributes of each terminal in the terminal information include a preset access method, a preset operating system and a preset security software; and determining the terminal type of the terminal according to the determination result.
[0007] According to an aspect of the embodiments of the present disclosure, the method further includes: determining that the terminal corresponds to a first terminal type if the field attribute of the terminal includes the preset access mode, the preset operating system and the first preset security software; determining that the terminal corresponds to a second terminal type if the field attribute of the terminal does not include the preset access mode, but includes the preset operating system, the network type and the first preset security software, or includes the preset operating system, the network type and the second preset software; determining that the terminal corresponds to a third terminal type if the field attribute of the terminal includes the preset access mode, the preset operating system and the second preset security software; and determining that the terminal corresponds to a fourth terminal type when it is judged that the field attribute of the terminal includes the preset access mode and does not include the preset operating system.
[0008] According to an aspect of the embodiments of the present disclosure, if the terminal type cannot be determined according to the field attribute in the terminal information, the terminal whose terminal type cannot be determined is a second terminal, and the method further includes: counting the MAC address prefixes of the terminals whose terminal types have been determined, and the terminals are first terminals; determining the terminal type to which the first terminals with a MAC address prefix belong, from the first terminals with the same MAC address prefix, and the first terminals are greater than a preset proportion; matching the first terminals with the same MAC address prefix for the MAC address prefix of the terminal whose terminal type cannot be determined; and taking the type of the first terminal as the type of the second terminal.
[0009] According to an aspect of the embodiments of the present disclosure, determining whether each terminal meets the security rule according to the terminal type and the terminal information includes: matching the corresponding security rule for each terminal according to the terminal type; and checking the terminal information of each terminal according to the security rule to determine whether each terminal meets the security rule.
[0010] The present disclosure provides a terminal security problem rectification system, which includes: a management and control unit configured to classify a plurality of terminals of each institution according to terminal information received from each institution client, to obtain a terminal type of each terminal; determine whether each terminal meets a security rule according to the terminal type and the terminal information; determine that the terminal is abnormal if the terminal does not meet the security rule; receive a repair result fed back by the institution client after repairing the abnormal terminal; record and display the repair result; and a plurality of institution clients, each of which is deployed in a corresponding institution and is in communication connection with the management and control unit, and is configured to: collect terminal information of the institution to which the institution client belongs; and send the terminal information of the institution to the management and control unit.
[0011] According to an aspect of the embodiment of the present specification, when determining an abnormal terminal, the abnormal terminal corresponding to the organization client is further used for: when receiving the terminal abnormal information sent by the management unit, sending the terminal abnormal information to the operation and maintenance end; downloading the repair script provided by the operation and maintenance end from the application space of the organization to which the abnormal terminal belongs; repairing the abnormal terminal based on the repair script; and feeding back the repair result to the management unit.
[0012] The present specification also provides a terminal security problem rectification device, which comprises: a classification unit, configured to classify a plurality of terminals of each organization according to terminal information received from each organization client, to obtain terminal types of each terminal of each organization; a judgment unit, configured to judge whether each terminal meets a security rule according to the terminal types and the terminal information; an abnormality determination unit, configured to determine that a terminal is abnormal and send it to an organization client if it does not meet the security rule; a receiving unit, configured to receive a repair result fed back by the organization client after repairing an abnormal terminal; and a recording unit, configured to record and display the repair result.
[0013] The embodiment of the present specification provides a computer device, which comprises a memory, a processor and a computer program stored in the memory and capable of running on the processor, and the processor implements the terminal security problem rectification method when executing the computer program.
[0014] The embodiment of the present specification also provides a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the terminal security problem rectification method.
[0015] The present specification realizes terminal security abnormal problem rectification through the cooperation of the terminal security digital management unit and the organization client, can timely find abnormal problems existing in each terminal, forms a complete terminal abnormal problem digital rectification scheme, and solves the problems of low efficiency and difficulty in ensuring quality of artificial on-site investigation. BRIEF DESCRIPTION OF DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present specification or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment or prior art description. Obviously, the drawings in the following description are only some embodiments of the present specification, and for those skilled in the art, other drawings can also be obtained without creative labor based on these drawings.
[0017] Figure 1 The flowchart of the terminal security problem rectification system is shown.
[0018] Figure 2Fig. 1 shows a flow chart of a method for classifying terminals of each organization to obtain terminal types according to an embodiment of the present specification;
[0019] Figure 3 Fig. 2 shows a flow chart of another method for classifying terminals to obtain terminal types according to an embodiment of the present specification;
[0020] Figure 4 Fig. 3 shows a flow chart of a method for determining terminal types according to an embodiment of the present specification;
[0021] Figure 5 Fig. 4 shows a schematic diagram of a terminal security problem rectification system according to an embodiment of the present specification;
[0022] Figure 6 Fig. 5 shows a structural schematic diagram of a terminal security problem rectification device according to an embodiment of the present specification;
[0023] Figure 7 Fig. 6 shows a flow chart of a method for repairing abnormal terminals according to an embodiment of the present specification;
[0024] Figure 8 Fig. 7 shows a structural schematic diagram of a computer device according to an embodiment of the present specification.
[0025] Explanation of symbols in the drawings:
[0026] 100, management and control unit;
[0027] 200, organization client;
[0028] 300, operation and maintenance end;
[0029] 601, classification unit;
[0030] 602, judgment unit;
[0031] 603, abnormality determination unit;
[0032] 604, receiving unit;
[0033] 605, recording unit;
[0034] 802, computer device;
[0035] 804, processor;
[0036] 806, memory;
[0037] 808, driving mechanism;
[0038] 810, input / output module;
[0039] 812, input device;
[0040] 814, output device;
[0041] 816, presentation device;
[0042] 818, graphical user interface;
[0043] 820, network interface;
[0044] 822, communication link;
[0045] 824, communication bus. DETAILED DESCRIPTION
[0046] In order to make the technical personnel in the technical field better understand the technical solutions in the specification, the technical solutions in the specification will be described clearly and completely in the specification, and obviously, the described embodiments are only part of the embodiments of the specification, not all. Based on the embodiments in the specification, all other embodiments obtained by those of ordinary skill in the art without creative labor belong to the scope of protection of the specification.
[0047] It should be noted that the terms "first", "second" and the like in the specification and claims of the specification and the above-described drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the specification described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, device, product or equipment including a series of steps or units does not have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or equipment.
[0048] The specification provides method operation steps as described in the embodiments or flowcharts, but can include more or less operation steps based on conventional or non-creative labor. The order of steps listed in the embodiments is only one of the many step execution orders, and does not represent the only execution order. When the system or device product is executed in practice, it can be executed in sequence or in parallel according to the method order shown in the embodiments or drawings.
[0049] It should be noted that the terminal security problem rectification method of the specification can be used in the computer field, and can also be used in the financial field, and the application field of the terminal security problem rectification method and device of the specification is not limited.
[0050] Figure 1A flowchart of a terminal security problem rectification method is shown. The method is applied to a management and control unit and specifically includes the following steps.
[0051] In step 101, the terminals of each institution are classified according to the terminal information received from the institution clients, to obtain the terminal types of each terminal.
[0052] In the embodiments of the present specification, the institution client is a management and control client deployed in each institution. The institution client can be installed on different platforms and operating systems and communicates with the management and control unit. The institution client deployed in each institution is used to collect specific information of the terminals in the institution to which the institution client belongs. For example, a branch of a bank has 20 terminal devices of different types. The institution client of the branch collects the terminal device information of the 20 devices to obtain terminal information.
[0053] In this step, the management and control unit classifies the terminals of each institution after receiving the terminal information of each institution from the institution clients, to obtain the types of each terminal of each institution. Further, after obtaining the terminal types of each terminal in each institution, the management and control unit sorts the high-end information and stores it in a terminal data table.
[0054] The main fields in the terminal data table include: MAC address, IP address, terminal name, terminal device belonging institution, latest login time, latest login username, latest login user belonging institution, antivirus client version, virus library client version, access client version, Tian Xiang client version, terminal operating system version, belonging network segment, whether to install access client, whether to install antivirus client, whether to install Tian Xiang client, etc.
[0055] In step 102, it is judged whether each terminal meets the security rules according to the terminal type and the terminal information. In this step, different security management and control strategies are set in advance according to different terminal types. The terminal types include but are not limited to: ordinary terminal, special terminal and financial equipment. If the terminal type is an ordinary terminal, the security rules include: determining whether the ordinary terminal is enabled with watermark, domain control, network input, antivirus client, U port disabled, BIOS password authentication enabled. If the terminal type is a special terminal, the security rules include: whether to enable watermark, domain control, antivirus client, MAC address binding, U port disabled, BIOS password authentication enabled. If the terminal type is a financial equipment, the security rules include: whether to bind MAC address, disable U port and enable BIOS password authentication.
[0056] In the present specification, the security rules are derived from the security management and control requirements proposed by internal and external regulatory agencies, and comprehensively cover all terminal devices to avoid detection blind spots.
[0057] Step 103, if the security rules are not met, determine the terminal exception and send to the institution client. In this step, if a terminal type does not meet any of the corresponding security rules, the terminal does not meet the security control strategy, and the terminal exception is determined, and the information of the terminal exception is sent to the institution client, and the institution client is further fed back to the institution operation and maintenance personnel.
[0058] Step 104, receiving the repair result fed back by the institution client after repairing the abnormal terminal. Based on the above step, the security operation and maintenance personnel receive the terminal exception information sent by the institution client, and trigger the rectification task. Wherein, the security operation and maintenance personnel develop scripts, program packages for automatic implementation of abnormal problems in advance, and place them in the application space of each institution after testing. In this step, the institution client installed on the terminal device receives the rectification task, downloads the automatic implementation scripts, program packages from the application space to the terminal local, automatically executes the scripts, program packages to repair abnormal problems, and repairs the security abnormal problems of the abnormal terminal on the target terminal. When the institution client completes the repair of the abnormal terminal, the repair result is sent to the control unit.
[0059] Step 105, record and display the repair result. The control unit records and statistics the execution results of each type of task.
[0060] Figure 2 The method flow chart for classifying terminals of each institution to obtain terminal types is shown in the embodiment of the present specification, which specifically includes the following steps:
[0061] Step 201, determine whether the field attributes of each terminal in the terminal information include the preset access method, the preset operating system and the preset security software. In the embodiment of the specification, the terminal type is determined by determining whether the operating system of the terminal is a windows system, whether the terminal is installed with a tianjiong software, whether the terminal is installed with an antivirus software, whether the terminal is installed with a network access software, etc.
[0062] Step 202, according to the determination result, determine the terminal type of the terminal. In the embodiment of the present specification, the terminal type mainly includes three types of ordinary terminal, special terminal and financial equipment. Because the access configuration, operating system and software installation of each type of terminal are different, the type of the terminal can be determined according to the terminal information.
[0063] Figure 3 The method flow chart for classifying terminals to obtain terminal types is shown in another embodiment of the present specification, which specifically includes the following steps:
[0064] Step 301, if the field attributes of the terminal include the preset access method, the preset operating system and the first preset security software, determine that the terminal corresponds to the first terminal type.
[0065] Specifically, the terminal type is determined by judging whether the terminal binds the MAC address, and whether the terminal type corresponds to the first terminal type, the second terminal type, the third terminal type or the fourth terminal type.
[0066] In step 302, if the field attribute of the terminal does not include the preset network access mode, but includes the preset operating system, the network type and the first preset security software, or includes the preset operating system, the network type and the second preset security software, it is determined that the terminal corresponds to the second terminal type.
[0067] In this step, if it is determined that the terminal does not bind the MAC address, the preset operating system is windows, the network type is test network or security network, and the access software is installed, it is determined that the terminal type is the second terminal type, which is a common terminal.
[0068] In this step, if it is determined that the terminal does not bind the MAC address, the preset operating system is windows, the network type is test network or security network, and the access software is installed, it is determined that the terminal type is the second terminal type, which is a common terminal.
[0069] In step 303, if the field attribute of the terminal includes the preset network access mode, the preset operating system and the second preset security software, it is determined that the terminal corresponds to the third terminal type. In this step, if it is determined that the terminal binds the MAC address, the operating system is windows, and the access software is installed, it is determined that the terminal type is the third terminal type, which is a special terminal.
[0070] In step 304, when it is determined that the field attribute of the terminal includes the preset network access mode and does not include the preset operating system, it is determined that the terminal corresponds to the fourth terminal type. In this step, if it is determined that the terminal binds the MAC address, but the operating system is not the windows system, it is determined that the terminal type is the fourth terminal type, which is an external device.
[0071] Figure 4 The method for determining the terminal type is shown in the flow chart of the embodiment of the present specification, which specifically includes the following steps:
[0072] In step 401, the MAC address prefix of each terminal whose type has been determined is counted, and the terminal is the first terminal. In this step, based on the fact that the types of some terminals have been determined in the foregoing step 301, the MAC address prefix of each terminal whose type has been determined is counted. Figure 3 In step 401, the MAC address prefix of each terminal whose type has been determined is counted, and the terminal is the first terminal. In this step, based on the fact that the types of some terminals have been determined in the foregoing step 301, the MAC address prefix of each terminal whose type has been determined is counted. Figure 3 In step 401, the MAC address prefix of each terminal whose type has been determined is counted, and the terminal is the first terminal. In this step, based on the fact that the types of some terminals have been determined in the foregoing step 301, the MAC address prefix of each terminal whose type has been determined is counted.
[0073] In this step, the MAC address prefix of the terminal whose type has been determined and which is bound with the MAC address is counted. The MAC address field of the terminal is a 12-bit string, and the first several bits are the vendor number of the terminal, i.e., the MAC address prefix.
[0074] In step 402, the type of the terminal to which a first terminal with the same MAC address prefix belongs is determined, the first terminal being greater than a preset proportion. In this step, the MAC address prefix of different terminals can be the same or different. For example, an institution has 50 terminals bound with the MAC address, and the types of the 50 terminals are known. The institution also has 8 terminals whose types cannot be determined. The 50 terminals are the first terminals, and the 8 terminals whose types cannot be determined are the second terminals. Among the first terminals, the MAC address prefixes of 40 terminals are the same, and all correspond to the same vendor.
[0075] In step 403, the MAC address prefix of the terminal whose type cannot be determined is matched with the first terminal with the same MAC address prefix. The MAC address prefix of the terminal whose type cannot be determined in the processing step in step 401 is queried, and the terminal whose type cannot be determined is referred to as the second terminal. According to the 12-bit string form of the MAC address of the second terminal, the MAC address prefix is further determined. The MAC address prefix of the second terminal is matched with the address prefix of the terminal greater than the preset proportion in the first terminal in step 402, and it is determined whether the MAC address prefix of part of the terminals in the second terminal is the same as the MAC address prefix of the terminal greater than the preset proportion in the first terminal. Figure 3
[0076] In step 404, the type of the first terminal is taken as the type of the second terminal. If there is the second terminal with the same MAC address prefix as the first terminal greater than the preset proportion in the first terminal in step 403, the type of the corresponding first terminal is taken as the type of the second terminal.
[0077] For example, based on the embodiment in step 402, if there are 50 first terminals whose types have been determined and 8 second terminals whose types have not been determined in an institution, the MAC address prefixes of 40 terminals in the first terminals are the same, and the device types of the 40 first terminals are the same, i.e., ordinary terminals. Among the 8 second terminals, the MAC address prefixes of 2 terminals are the same as the MAC address prefixes of the 40 first terminals, and thus the terminal type of the first terminal can be taken as the terminal type of the second terminal, i.e., ordinary terminal.
[0078] In some other embodiments of the present specification, if there is no MAC address information in the terminal information, determining the terminal type further includes: parsing the IP address in the terminal information of the terminal;
[0079] According to the range where the IP address is located and the system preset network structure, the type of the terminal is determined.
[0080] In the present specification, if the second terminal is a newly networked terminal, the newly networked terminal information can not have MAC address information, or the MAC address information is not the same as the MAC address prefix of the first terminal, and the newly networked terminal information cannot be matched to the corresponding first terminal supplier information through the MAC address prefix, the IP address of the newly networked terminal needs to be obtained, and the type of the newly networked device is determined according to the range where the IP address segment is located and the system preset network architecture. Specifically, the system preset network architecture records the mapping relationship between the physical space and the IP address. According to the IP address of the newly networked device, the range where the IP address is located is determined, and according to the range where the IP address is located and the mapping relationship, the terminal type of the newly networked terminal can be determined. For example, the IP address of the newly networked device falls into the IP address range recorded in the preset network architecture, and the corresponding physical space is a restaurant, so the terminal type of the newly networked terminal can be determined as a normal device. The embodiments of the present specification are exemplary, and other forms can also be provided, and the present specification does not limit the content recorded in the network architecture.
[0081] Figure 5 The present specification is a schematic diagram of a terminal security problem rectification system, the system includes: a control unit 100, a plurality of agency clients 200 and an operation and maintenance end. Among them, the control unit 100 is used to classify the terminals of each agency according to the terminal information received from each agency client, the terminal type of each terminal; according to the terminal type and the terminal information, it is judged whether each terminal meets the safety rules; if it does not meet the safety rules, it is determined that the terminal is abnormal; receiving the repair result feedback by the agency client 200 after repairing the abnormal terminal; record and display the repair result.
[0082] The agency client 200 includes a plurality of agency clients, and the agency client 200 is usually deployed in the branch or subordinate agency of the headquarters agency. Each agency client corresponds to a branch or subordinate agency. For example, the agency client 200 can be deployed in the branch or branch of the bank headquarters, the branch or subordinate hospital of the hospital headquarters, the branch of the school headquarters, the subsidiary or subordinate unit of the enterprise headquarters group, etc.
[0083] The agency client 200 is used to collect the terminal information of the agency, and sends the terminal information of the agency to the control unit 100. Each agency client is respectively deployed in the corresponding agency, and each agency client is respectively connected with the control unit 100.
[0084] When the agency client 200 receives the terminal exception information sent by the management and control unit, the terminal exception information is sent to the operation and maintenance end 300. The operation and maintenance end 300 pushes the corresponding repair script or program package to the application space of the agency to which the abnormal terminal belongs. The agency client 200 downloads the repair script provided by the operation and maintenance end 300 from the application space of the respective agency, repairs the abnormal terminal, and feeds back the repair result to the management and control unit 100. The management and control unit 100 displays the task execution result.
[0085] As Figure 6 The figure shows the structure of a terminal security problem rectification device according to an embodiment of the present specification. The basic structure of the terminal security problem rectification device is described in the figure. The functional units and modules in the figure can be implemented in software, or can be implemented by using general-purpose chips or special-purpose chips to rectify terminal security problems. The device specifically includes:
[0086] The classification unit 601 is configured to classify a plurality of terminals of each agency according to terminal information received from each agency client, to obtain a terminal type of each terminal of each agency.
[0087] The judgment unit 602 is configured to judge whether each terminal meets a security rule according to the terminal type and the terminal information.
[0088] The exception determination unit 603 is configured to determine that a terminal is abnormal and send it to an agency client if it does not meet the security rule.
[0089] The receiving unit 604 is configured to receive a repair result fed back by the agency client after repairing an abnormal terminal.
[0090] The recording unit 605 is configured to record and display the repair result.
[0091] The present specification realizes terminal security exception problem rectification through the cooperation of the terminal security digital management and control unit and the agency client, can timely find the abnormal problems existing in each terminal, forms a complete terminal exception problem digital rectification scheme, and solves the problem of low efficiency and difficulty in ensuring quality of manual on-site investigation.
[0092] Figure 7 The figure shows a method flowchart for repairing an abnormal terminal according to an embodiment of the present specification, specifically including the following steps:
[0093] Step 701, when receiving the terminal exception information sent by the management and control unit, send the terminal exception information to the operation and maintenance end. In the embodiment of the present application, when the agency client receives the exception information sent by the management and control unit, the agency client interacts with the operation and maintenance end, and sends the terminal exception information to the operation and maintenance personnel. The operation and maintenance end configures scripts and program packages for automatic implementation for the abnormal problems, and places them in the application space of each agency after passing the test. The operation and maintenance end sends the instruction of script release to the agency client.
[0094] Step 702, download the repair script provided by the operation and maintenance end from the application space of the agency to which the abnormal terminal belongs. When the agency client receives the instruction sent by the operation and maintenance end, it downloads the corresponding repair script from the application space to which it belongs or the abnormal terminal belongs.
[0095] Step 703, repair the abnormal terminal based on the repair script. In this step, the agency client automatically executes the script and program package to repair the abnormal problem.
[0096] Step 704, feed back the repair result to the management and control unit. The management and control unit records and displays the repair result or the abnormal execution result. Among them, the repair result includes the abnormal terminal which is not repaired successfully. The operation and maintenance end is fed back to the operation and maintenance end through the agency client through the management and control unit, and the operation and maintenance end optimizes the script and program package with low success rate after executing the script and program package for various types, and then pushes them to the agency client to execute the repair task, so as to gradually iterate the security problem of the terminal.
[0097] As Figure 8 The schematic diagram of a computer device provided by the embodiment of the present application is shown. The computer device can execute the terminal security problem rectification method of the present application. The computer device 802 can include one or more processors 804, such as one or more central processing units (CPUs), each of which can implement one or more hardware threads. The computer device 802 can also include any memory 806 for storing any kind of information, such as code, settings, data, etc. Without limitation, for example, the memory 806 can include any one or combination of the following: any type of RAM, any type of ROM, flash memory device, hard disk, optical disk, etc. More generally, any memory can store information using any technology. Further, any memory can provide volatile or non-volatile retention of information. Further, any memory can represent a fixed or removable component of the computer device 802. In one case, the computer device 802 can perform any operation of the associated instructions when the processor 804 executes the associated instructions stored in any memory or combination of memories. The computer device 802 also includes one or more drive mechanisms 808 for interacting with any memory, such as a hard disk drive mechanism, an optical disk drive mechanism, etc.
[0098] The computer device 802 can also include input / output module(s) 810 (I / O) for receiving various input (via input device(s) 812) and for providing various output (via output device(s) 814). One particular output mechanism can include a presentation device 816 and associated graphical user interface (GUI) 818. In other embodiments, the input / output module(s) 810 (I / O), input device(s) 812, and output device(s) 814 can not be included, and the computer device 802 can be a computer device in a network that only receives input and only provides output (sends and receives data, respectively).
[0099] The communication links 822 can be implemented in any manner, such as through a local area network, a wide area network (e.g., the Internet), a point-to-point connection, etc., or any combination thereof. The communication links 822 can include any combination of hardwired links, wireless links, routers, gateway functionality, name servers, etc., governed by any protocol or combination of protocols.
[0100] Corresponding to the method in Figures 1 to 4 The computer program is stored in the computer readable storage medium, and the computer program is run by the processor to execute the steps of the method.
[0101] The computer readable instructions are executed by the processor, and the program in the computer readable instructions causes the processor to execute the method as shown in Figures 1 to 4 .
[0102] It should be understood that the size of the sequence number of each process described above in various embodiments of the present specification does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present specification.
[0103] It should also be understood that in the embodiments of the present specification, the term "and / or" is only a description of the association relationship between the associated objects, which means that there can be three relationships. For example, A and / or B can represent three cases: A exists alone, A and B exist together, and B exists alone. In addition, the character " / " in the present specification generally represents an "or" relationship between the associated objects before and after it.
[0104] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.
[0105] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be repeated here.
[0106] In several embodiments provided in the present specification, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the device embodiments described above are merely schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interfaces, devices or units, and can also be electrical, mechanical or other forms of connection.
[0107] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiments of the present specification.
[0108] In addition, each functional unit in each embodiment of the present specification can be integrated in one processing unit, or each unit can exist physically independently, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0109] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer readable storage medium. Based on such understanding, the technical solutions of the specification or the entire or part of the technical solutions that essentially contribute to the prior art can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the various embodiments of the specification. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk or an optical disk, and various media that can store program codes.
[0110] The principles and implementation manners of the specification are described by using specific embodiments in the specification. The above embodiment description is only used to help understand the method of the specification and its core idea; meanwhile, for those skilled in the art, according to the idea of the specification, the specific implementation manners and application ranges will have changes. In summary, the content of the specification should not be understood as a limitation of the specification.
Claims
1. A method for rectifying a terminal security problem, characterized by, The method comprises: According to the terminal information received from each agency client, classifying the multiple terminals of each agency to obtain the terminal type of each terminal, which comprises: Judging whether the field attribute of each terminal in the terminal information includes the preset access mode, the preset operating system and the preset security software; If the field attribute of the terminal includes the preset access mode, the preset operating system and the first preset security software, it is determined that the terminal corresponds to the first terminal type; If the field attribute of the terminal does not include the preset access mode, but includes the preset operating system, the network type and the first preset security software, or includes the preset operating system, the network type and the second preset software, it is determined that the terminal corresponds to the second terminal type; If the field attribute of the terminal includes the preset access mode, the preset operating system and the second preset security software, it is determined that the terminal corresponds to the third terminal type; When it is judged that the field attribute of the terminal includes the preset access mode and does not include the preset operating system, it is determined that the terminal corresponds to the fourth terminal type; According to the terminal type and the terminal information, judging whether each terminal meets the security rules; If it does not meet the security rules, determining that the terminal is abnormal and sending it to the agency client; Receiving the repair result fed back by the agency client after repairing the abnormal terminal; Recording and displaying the repair result.
2. The method according to claim 1, wherein If the terminal type cannot be determined according to the field attribute in the terminal information, the terminal whose terminal type cannot be determined is the second terminal, and the method further comprises: Statistically analyzing the MAC address prefix of each terminal whose terminal type has been determined, and the terminal is the first terminal; From the first terminals with the same MAC address prefix, determining the terminal type to which the first terminals with a proportion greater than a preset proportion belong; Matching the first terminals with the same MAC address prefix for the MAC address prefix of the terminal whose terminal type cannot be determined; Taking the type of the first terminal as the type of the second terminal.
3. The method according to claim 1, wherein According to the terminal type and the terminal information, judging whether each terminal meets the security rules comprises: According to the terminal type, matching the corresponding security rules for each terminal; According to the security rules, investigating the terminal information of each terminal to judge whether each terminal meets the security rules.
4. A terminal security problem rectification system characterized by comprising: The system adopts the method of any one of claims 1 to 3, comprising: A management unit for classifying the multiple terminals of each agency according to the terminal information received from each agency client to obtain the terminal type of each terminal; judging whether each terminal meets the security rules according to the terminal type and the terminal information; determining that the terminal is abnormal if it does not meet the security rules; receiving the repair result fed back by the agency client after repairing the abnormal terminal; and recording and displaying the repair result; Multiple agency clients, each of which is deployed in a corresponding agency and is in communication connection with the management unit, and each of which is used for collecting the terminal information of the agency to which it belongs and sending the terminal information of the agency to the management unit.
5. The terminal security issue remediation system of claim 4, wherein, When it is determined that there is an abnormal terminal, the agency client corresponding to the abnormal terminal is further used for: After receiving the terminal abnormal information sent by the management unit, sending the terminal abnormal information to the operation and maintenance end. Download a repair script provided by an operation and maintenance terminal from an application space of an organization to which the abnormal terminal belongs; Repair the abnormal terminal based on the repair script; Feed back a repair result to the management and control unit.
6. A terminal security problem rectification apparatus characterized by comprising: The device comprises: A classification unit for classifying a plurality of terminals of each organization according to terminal information received from each organization client, obtaining a terminal type of each terminal of each organization, comprising: judging whether field attributes of each terminal in the terminal information include a preset access mode, a preset operating system and a preset security software; if the field attributes of the terminal include the preset access mode, the preset operating system and the first preset security software, determining that the terminal corresponds to a first terminal type; if the field attributes of the terminal do not include the preset access mode, but include the preset operating system, a network type and the first preset security software, or include the preset operating system, the network type and the second preset software, determining that the terminal corresponds to a second terminal type; if the field attributes of the terminal include the preset access mode, the preset operating system and the second preset security software, determining that the terminal corresponds to a third terminal type; when judging that the field attributes of the terminal include the preset access mode and do not include the preset operating system, determining that the terminal corresponds to a fourth terminal type; A judging unit for judging whether each terminal meets a security rule according to the terminal type and the terminal information; An abnormality determining unit for determining that the terminal is abnormal and sending to the organization client if the terminal does not meet the security rule; A receiving unit for receiving a repair result fed back by the organization client after repairing the abnormal terminal; A recording unit for recording and displaying the repair result.
7. A computer device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the computer program to realize the method in any one of claims 1 to 3.
8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, and the computer program is executed by the processor to realize the method in any one of claims 1 to 3.
Citation Information
Patent Citations
Terminal anomaly detection method and device, detection equipment and machine readable storage medium
CN110381090A
Network connectivity detection method and device and storage medium
CN116684323A