A terminal security detection method and related apparatus
By periodically acquiring basic terminal information and using machine learning models for identity verification and risk analysis, a security assessment report is generated, which solves the shortcomings of terminal hardware trustworthiness detection, realizes comprehensive and accurate security detection and continuous security monitoring of terminals, and improves network security.
Patent Information
- Application Number
- CN202410808686.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-21
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2044-06-21
AI Technical Summary
In existing technologies, hardware trustworthiness detection methods for terminal devices cannot effectively prevent malicious theft and counterfeiting of identifiers, and lack continuous measurement, resulting in insufficient network security.
By periodically acquiring basic information about the terminal, and using machine learning models for identity verification, state risk analysis, and communication risk analysis, a comprehensive terminal security assessment report is generated, enabling comprehensive and accurate security testing of the terminal.
It improves network security, can identify terminal risks, and enables periodic and continuous security testing of terminals, thereby enhancing the security of the access environment.
Smart Images

Figure CN118631546B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and more particularly, to a terminal security detection method and related device. BACKGROUND
[0002] Zero Trust Network (ZTN) is a set of evolving network security paradigms that shift the focus of network defense from static, network-based boundaries to users, devices, and resources. In ZTN, with the globalization of hardware design and supply chain, hardware trustworthiness becomes increasingly important. Device trust is the cornerstone of zero trust, directly affecting the success or failure of the zero trust network architecture. Therefore, how to detect the security of terminal devices and ensure network security has become a technical problem that needs to be solved urgently. SUMMARY
[0003] Therefore, the present application provides a terminal security detection method and related device, which realizes comprehensive and accurate security detection of the terminal and improves network security.
[0004] In order to achieve the above-mentioned application purpose, the specific technical solutions provided by the present application are as follows:
[0005] In a first aspect, the present application provides a terminal security detection method, comprising:
[0006] obtaining the basic information of the terminal within a preset period;
[0007] performing identity verification on the terminal according to the identification information in the basic information to obtain an identity verification result of the terminal;
[0008] inputting the running state information in the basic information into a pre-constructed state risk analysis model to obtain state risk assessment information of the terminal;
[0009] obtaining the communication condition information of the terminal;
[0010] inputting the communication condition information into a pre-constructed communication risk analysis model to obtain communication risk assessment information of the terminal;
[0011] generating a terminal security assessment report according to the identity verification result, the state risk assessment information and the communication risk assessment information.
[0012] In some embodiments, the identity verification on the access terminal according to the identification information in the basic information to obtain the identity verification result of the terminal comprises:
[0013] extracting the identification information in the basic information;
[0014] The identification information includes a device model, a unique identification sequence, a belonging operator, network card information, a secret key, and associated user information.
[0015] If the identification information completely matches the pre-stored identification information of the terminal, the identity verification result of the terminal is obtained as identity verification passing.
[0016] If the identification information does not completely match the pre-stored identification information of the terminal, the identity verification result of the terminal is obtained as identity verification failing.
[0017] In some embodiments, the communication condition information of the terminal is obtained by:
[0018] It is judged whether the terminal has accessed a zero-trust network.
[0019] If the terminal has accessed the zero-trust network, the communication condition information of the terminal is obtained.
[0020] If the terminal has not accessed the zero-trust network, the basic information is input into a pre-constructed device capability analysis model to obtain a device capability analysis result of the terminal.
[0021] If the device capability analysis result meets a preset condition, a pre-communication channel between the terminal and a network server is constructed, and data transmission is performed based on the pre-communication channel to obtain the communication condition information of the terminal.
[0022] In some embodiments, a method for constructing the device capability analysis model comprises:
[0023] A first training sample set is obtained, each training sample in the first training sample set including basic information of a sample terminal and a pre-labeled device capability value label.
[0024] A device capability analysis result output by a first machine learning model approaches the device capability value label as a training target, and the first machine learning model is trained using the first training sample set.
[0025] When a first preset condition is met, the training of the first machine learning model is ended, and the device capability analysis model is obtained.
[0026] In some embodiments, a method for constructing the state risk analysis model comprises:
[0027] A second training sample set is obtained, each training sample in the second training sample set including running state information of a sample terminal and a pre-labeled state risk value label.
[0028] The state risk value output by the second machine learning model approaches the state risk value label as a training target, and the second machine learning model is trained by using the second training sample set;
[0029] When the second preset condition is met, the training of the second machine learning model is ended, and the state risk analysis model is obtained.
[0030] In some embodiments, the method for constructing the communication risk analysis model comprises:
[0031] A third training sample set is obtained, and each training sample in the third training sample set comprises communication condition information of a sample terminal and a pre-labeled communication risk value label;
[0032] The communication risk value output by the third machine learning model approaches the communication risk value label as a training target, and the third machine learning model is trained by using the third training sample set.
[0033] When the third preset condition is met, the training of the third machine learning model is ended, and the communication risk analysis model is obtained.
[0034] In some embodiments, the method further comprises:
[0035] The identity verification result, the state risk evaluation information, and the communication risk evaluation information are input into a pre-constructed quantitative scoring model, and a terminal security score output by the quantitative scoring model is obtained.
[0036] According to a correspondence relationship between a pre-configured terminal security score interval and a business security access strategy, a target business security access strategy corresponding to the terminal security score is determined.
[0037] According to the target business security access strategy, access control is performed on the terminal.
[0038] In some embodiments, the method further comprises:
[0039] According to a correspondence relationship between a pre-configured attribute, business, and access control strategy, a target business corresponding to the attribute in the terminal security evaluation report and a target access control strategy are determined.
[0040] According to the target access control strategy, access control is performed on the target business accessed by the terminal.
[0041] In a second aspect, an embodiment of the present application provides a terminal security detection device, comprising:
[0042] A first information acquisition unit is configured to acquire basic information of a terminal in a preset period.
[0043] An identity authentication unit is configured to perform identity authentication on the terminal according to identification information in the basic information, and obtain an identity authentication result of the terminal.
[0044] A state risk analysis unit is configured to input operation state information in the basic information into a pre-constructed state risk analysis model, and obtain state risk assessment information of the terminal.
[0045] A second information acquisition unit is configured to acquire communication condition information of the terminal.
[0046] A communication risk analysis unit is configured to input the communication condition information into a pre-constructed communication risk analysis model, and obtain communication risk assessment information of the terminal.
[0047] An assessment report generation unit is configured to generate a terminal security assessment report according to the identity authentication result, the state risk assessment information and the communication risk assessment information.
[0048] In a third aspect, an electronic device is provided, which includes a memory, a processor and a computer program stored in the memory, and the processor executes the computer program to implement the steps of the terminal security detection method described in any one of the implementation manners of the first aspect.
[0049] Compared with the prior art, the present application has the following advantages:
[0050] The terminal security detection method and related device disclosed in the present application comprehensively collect the basic information of the terminal in a preset period, perform identity authentication on the terminal according to the identification information in the basic information to obtain an identity authentication result, perform state risk analysis according to the operation state information in the basic information to obtain state risk assessment information, acquire the communication condition information of the terminal, perform communication risk analysis according to the communication condition information of the terminal to obtain communication risk assessment information, and finally generate a comprehensive terminal security assessment report according to the identity authentication result, the state risk assessment information and the communication risk assessment information, so as to realize comprehensive and accurate security detection of the terminal. In addition, the periodic acquisition of the basic information of the terminal realizes periodic and continuous security detection of the terminal, and improves the network security. BRIEF DESCRIPTION OF DRAWINGS
[0051] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are only embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of the provided drawings.
[0052] Figure 1A hardware architecture diagram of a terminal security detection method disclosed in an embodiment of the present application;
[0053] Figure 2 A flowchart of a terminal security detection method disclosed in an embodiment of the present application;
[0054] Figure 3 A structural diagram of a terminal security detection device disclosed in an embodiment of the present application;
[0055] Figure 4 A structural diagram of an electronic device disclosed in an embodiment of the present application. DETAILED DESCRIPTION
[0056] The technical solutions in the embodiments of the present application will be clearly and completely described with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the scope of protection of the present application.
[0057] The present application provides a terminal security detection method and related device. Before introducing the technical solutions provided by the present application, an application scenario related to the present application is described.
[0058] For example, in a zero trust network (ZTN), with the globalization of hardware design and supply chain, hardware credibility becomes increasingly important. Device trust is the cornerstone of zero trust, which directly affects the success or failure of the zero trust network architecture. Device trust can be divided into two steps: first, the establishment of initial trust, the degree of which depends on the trust degree of the purchaser to the manufacturer and the supplier. This trust inherited from the supplier is a kind of social trust, which needs to be injected into the terminal device itself to form initial trust. Second, terminal device inventory management, which involves cataloging and managing terminal devices and their attributes, forming an inventory, and based on this, authenticating and integrity checking terminal devices to ensure their security. Currently, the hardware information of the terminal is directly used as the device identifier for authentication and integrity checking of the terminal, without solving the problem of terminal identifier being maliciously stolen or imitated. Moreover, the security measurement of the hardware platform of the terminal in the prior art is often placed in the operating system application layer, which cannot resist security risks caused by operating system vulnerabilities. In addition, the existing measurement method is often only an initial measurement, which cannot be continuously measured. Therefore, how to accurately identify the terminal and accurately measure the security of the terminal access environment to ensure network security has become a problem to be solved.
[0059] Based on this, the application aims at a terminal to be accessed into a zero trust network and a terminal in the zero trust network that has been accessed, periodically acquires basic information of the terminal, performs identity authentication on the terminal according to identification information in the basic information to obtain an identity authentication result, performs state risk analysis according to running state information in the basic information to obtain state risk assessment information, and acquires communication condition information of the terminal, performs communication risk analysis according to the communication condition information of the terminal to obtain communication risk assessment information. Finally, a comprehensive terminal security assessment report is generated according to the identity authentication result, the state risk assessment information and the communication risk assessment information, and comprehensive and accurate security detection of the terminal is realized, and even if the terminal identification is maliciously stolen, the terminal risk can also be identified through the state risk analysis and the communication risk analysis. In addition, the periodic and continuous security detection of the terminal is realized by periodically acquiring the basic information of the terminal, and the network security is improved.
[0060] As shown in Figure 1 , after the terminal 11 accesses the zero trust network, the terminal 11 accesses a service system running in the application server 13 by communicating with the network server 12.
[0061] Figure 2 A flowchart of a terminal security detection method disclosed by the embodiment of the application is shown in Figure 2 , and the terminal security detection method disclosed by the embodiment of the application specifically includes the following steps:
[0062] S201: Acquire basic information of the terminal in a preset period.
[0063] The terminal can be a PC (Personal Computer) device, such as a desktop computer, a notebook computer, a small notebook computer, a tablet computer, an ultrabook, etc., and the terminal can also be a smart phone, which is not limited by the application.
[0064] The preset period for security detection of the terminal can be flexibly set in an actual application scenario, such as one hour, one day, etc.
[0065] The basic information of the terminal includes a device model, a unique identification sequence, a belonging operator, network card information, a secret key, associated user information, historical login authentication records, access frequency and time length, a brand, an application name and an application digital signature running on the terminal, an operating system version, etc. Among them, some applications have digital signatures, and some applications do not have digital signatures. The application here is a service system, such as an email, an OA system, etc.
[0066] For example, the basic information of the terminal is acquired by reading a configuration file of the terminal through a data acquisition software running on the terminal device, accessing a task manager running on the terminal, and executing a query command, etc.
[0067] Taking obtaining an application digital signature as an example, different operating systems obtain application digital signatures in different ways. In the Windows operating system, the digital signature in the attribute of the process (i.e., the application) is queried by accessing the task manager. In the Mac operating system, the digital signature is queried by executing a command.
[0068] S202: Identity verification is performed on the terminal according to the identification information in the basic information, and a terminal identity verification result is obtained.
[0069] The identification information is information representing the identity of the terminal.
[0070] Exemplarily, the identification information in the basic information is compared with the identification information of the terminal stored in advance one by one, so as to realize identity verification of the terminal.
[0071] The terminal identity verification result includes identity verification pass and identity verification fail.
[0072] S203: The running state information in the basic information is input into a pre-constructed state risk analysis model, and state risk assessment information of the terminal is obtained.
[0073] The running state information is information representing the running state of the terminal, such as whether to enable, historical login authentication records, access frequency and time length, and the like. The historical login authentication records are authentication records of the terminal logging into a business system, including login authentication success and login authentication failure; the access frequency and time length are access frequency and time length of the terminal accessing the business system.
[0074] The running state information needs to be extracted from the basic information before being input into the state risk analysis model. Exemplarily, the running state information is extracted from the basic information according to a pre-configured running state information type.
[0075] The state risk analysis model is based on a large number of corresponding relationships between historical running state information and state risk values for machine learning, and can quickly analyze the state risk value of the terminal according to the running state information of the terminal. The state risk value corresponding to the historical running state information is obtained by pre-labeling. The higher the frequency of login authentication failure in the historical running state information, the more abnormal the access frequency and access time length, and the greater the state risk value. The abnormality degree of the access frequency is measured according to the degree of deviation of the access frequency from the normal access frequency range, and the abnormality degree of the access time length is measured according to the degree of deviation of the access time length from the normal access time length range.
[0076] The input data of the state risk analysis model is the running state information, and the output data is the running risk value.
[0077] The state risk assessment information includes a state risk value, and can further include information for representing terminal identity such as a unique identification sequence, and can further include running state information of the terminal.
[0078] S204: Obtain communication condition information of the terminal.
[0079] The communication condition information of the terminal is obtained according to data transmission between the terminal and the network server, and includes running state information, data transmission continuity information, data transmission result information, etc., wherein the data transmission result information represents a data transmission result success condition.
[0080] S205: Input the communication condition information into a pre-constructed communication risk analysis model to obtain communication risk assessment information of the terminal.
[0081] The communication risk analysis model is based on a large number of corresponding relationships between historical communication condition information and communication risk values for machine learning, and can quickly analyze the communication risk value of the terminal according to the communication condition information of the terminal, wherein the communication risk value corresponding to the historical communication condition information is obtained in advance according to communication stability, communication transmission data integrity and other indicators of the historical communication condition information.
[0082] The communication risk assessment information includes a communication risk value, and can further include information for representing terminal identity such as a unique identification sequence, and can further include communication condition information of the terminal.
[0083] S206: Generate a terminal security assessment report according to the identity verification result, the state risk assessment information and the communication risk assessment information.
[0084] The terminal security assessment report includes the identity verification result, the state risk assessment information and the communication risk assessment information.
[0085] For example, the identity verification result, the state risk assessment information and the communication risk assessment information are filled into a pre-configured report template to generate the terminal security assessment report.
[0086] For example, the identity verification result, the state risk assessment information and the communication risk assessment information are spliced according to a preset format to generate the terminal security assessment report.
[0087] The above is only an example, and the present application is not limited thereto.
[0088] The terminal security detection method disclosed in the embodiment comprehensively collects the basic information of the terminal in a preset period, performs identity verification on the terminal according to the identification information in the basic information to obtain an identity verification result, performs state risk analysis according to the running state information in the basic information to obtain state risk assessment information, and obtains the communication condition information of the terminal, and performs communication risk analysis according to the communication condition information of the terminal to obtain communication risk assessment information. Finally, a comprehensive terminal security assessment report is generated according to the above identity verification result, state risk assessment information and communication risk assessment information, realizing comprehensive and accurate security detection of the terminal. In addition, by periodically obtaining the basic information of the terminal, periodic and continuous security detection of the terminal is realized, and the network security is improved.
[0089] Among them, the implementation mode of S202 in the above embodiment has multiple modes, one of which includes the following steps:
[0090] A1: extracting identification information in the basic information;
[0091] Specifically, the identification information is extracted from the basic information according to the pre-configured identification information type.
[0092] A2: one-to-one comparison of the identification information with the pre-stored identification information of the terminal, the identification information including device model, unique identification sequence, operator, network card information, secret key and associated user information;
[0093] Among them, the network card information includes IP address (Internet Protocol Address) and MAC address (Media Access Control Address).
[0094] The associated user information is the user information associated with the terminal.
[0095] A3: if the identification information completely matches the pre-stored identification information of the terminal, the identity verification result of the terminal is identity verification passed;
[0096] A4: if the identification information does not completely match the pre-stored identification information of the terminal, the identity verification result of the terminal is identity verification failed.
[0097] By using multi-dimensional identification information to verify the identity of the terminal, accurate identity authentication is realized, and the verification effect is improved.
[0098] Since the terminal can be a terminal to be connected to a zero-trust network or a terminal already connected to a zero-trust network, the way of obtaining the communication condition information of the terminal is different for the above two cases. The following will be illustrated by a specific example, which specifically includes the following steps:
[0099] B1: judging whether the terminal has accessed the zero-trust network;
[0100] The terminal is judged to have accessed the zero-trust network according to the communication state between the terminal and the network server. Specifically, if the terminal and the network server are in a communication state, the terminal has accessed the zero-trust network; if the terminal and the network server are in a disconnected state, the terminal has not accessed the zero-trust network.
[0101] B2: if the terminal has accessed the zero-trust network, obtaining the communication condition information of the terminal;
[0102] Specifically, the communication condition information of the terminal is obtained according to the data transmission between the terminal and the network server.
[0103] B3: if the terminal has not accessed the zero-trust network, inputting the basic information into a pre-constructed device capability analysis model to obtain the device capability analysis result of the terminal;
[0104] In order to only access the zero-trust network for the terminal whose device capability meets the preset condition, and avoid the problem of affecting the network transmission speed and occupying network resources caused by too many terminals accessing the zero-trust network, the device capability of the terminal needs to be analyzed before the terminal accesses the zero-trust network. Only the terminal whose device capability meets the preset condition accesses the zero-trust network. For example, the device capability of the terminal is measured by the use of the terminal to the business system. The higher the access frequency of the terminal to the business system, the longer the access time, and the greater the device capability value.
[0105] The device capability analysis model is based on the correspondence between the basic information of a large number of sample terminals and the device capability value for machine learning, and can quickly analyze the device capability value of the terminal according to the basic information of the terminal. The device capability value corresponding to the basic information of the sample terminal is obtained by pre-marking.
[0106] The input data of the device capability analysis model is the basic information of the terminal, and the output data is the device capability value.
[0107] B4: if the device capability analysis result meets the preset condition, a pre-communication channel between the terminal and the network server is constructed, and data transmission is performed based on the pre-communication channel to obtain the communication condition information of the terminal.
[0108] For example, the device capability analysis result meeting the preset condition is that the device capability value is greater than the preset value.
[0109] The pre-communication channel between the terminal and the network server includes the following steps:
[0110] B41: Realize TCP (Transmission Control Protocol) port opening between the terminal and the network server by UDP (User Datagram Protocol) port knocking;
[0111] B42: After the TCP port is opened, the network server judges the authority of the terminal;
[0112] B43: After the authority judgment is completed, the TAP (Trusted Application Proxy) agent in the network server starts the SSL (Secure Socket Layer) encryption tunnel;
[0113] B44: The terminal accesses the business system published by the application server through the TAP agent.
[0114] The construction methods of the device capability analysis model, the state risk analysis model, and the communication risk analysis model involved in the above embodiments are introduced respectively as follows.
[0115] The method for constructing the device capability analysis model includes the following steps:
[0116] C1: Obtain a first training sample set, each training sample in the first training sample set including the basic information of a sample terminal and a pre-labeled device capability value label;
[0117] The first training sample set can be derived from historical data. The basic information of the terminal in the historical data and the device capability value corresponding to the basic information are used as training samples, and the terminal in the training sample is used as a sample terminal.
[0118] The device capability value label corresponding to the basic information of the sample terminal is labeled in advance according to the business system usage in the basic information of the sample terminal. For example, the higher the business system access frequency and the longer the access time, the greater the device capability value.
[0119] C2: Use the first training sample set to train the first machine learning model, with the training target being that the device capability analysis result output by the first machine learning model approaches the device capability value label;
[0120] The first machine learning model can be a model based on CNN (Convolutional Neural Networks), a model based on DNN (Deep Neural Network) and a regression prediction method, etc.
[0121] C3: when the first preset condition is met, ending the training of the first machine learning model to obtain the device capability analysis model.
[0122] For example, the first preset condition met by the training result is that the accuracy of the model output result is greater than a first preset value.
[0123] The method for constructing the state risk analysis model comprises the following steps:
[0124] D1: obtaining a second training sample set, each training sample in the second training sample set comprising running state information of a sample terminal and a pre-labeled state risk value label;
[0125] The second training sample set can be derived from historical data, and the running state information of the terminal in the historical data and the state risk value corresponding to the running state information are taken as training samples, and the terminal in the training sample is taken as a sample terminal.
[0126] The state risk value corresponding to the running state information of the sample terminal is pre-labeled, for example, the higher the login authentication failure frequency in the running state information, the more abnormal the access frequency and access duration, and the greater the state risk value. The abnormality degree of the access frequency is measured according to the degree of deviation of the access frequency from the normal access frequency range, and the abnormality degree of the access duration is measured according to the degree of deviation of the access duration from the normal access duration range.
[0127] D2: taking the state risk value output by the second machine learning model approaching the state risk value label as a training target, and training the second machine learning model by using the second training sample set;
[0128] The second machine learning model can be a model based on CNN (Convolutional Neural Networks), a model based on DNN (Deep Neural Network) and a model based on a regression prediction method.
[0129] D3: when the second preset condition is met, ending the training of the second machine learning model to obtain the state risk analysis model.
[0130] For example, the second preset condition met by the training result is that the accuracy of the model output result is greater than a second preset value.
[0131] The method for constructing the communication risk analysis model comprises the following steps:
[0132] E1: obtaining a third training sample set, each training sample in the third training sample set comprising communication condition information of a sample terminal and a pre-labeled communication risk value label;
[0133] The third training sample set can be derived from historical data, and the communication condition information of the terminal in the historical data and the communication risk value corresponding to the communication condition information are taken as training samples, and the terminal in the training samples is taken as a sample terminal.
[0134] The communication risk value corresponding to the communication condition information of the sample terminal is obtained according to the communication stability, communication transmission data integrity and other indicators of the communication condition information, for example, the higher the communication stability and the higher the communication transmission data integrity, the lower the communication risk value.
[0135] E2: Taking the communication risk value output by the third machine learning model approaching the communication risk value label as a training target, the third machine learning model is trained by using the third training sample set.
[0136] The third machine learning model can be a model based on CNN (Convolutional Neural Networks), a model based on DNN (Deep Neural Network), a model based on a regression prediction method, etc.
[0137] E3: When the third preset condition is met, the training of the third machine learning model is ended, and a communication risk analysis model is obtained.
[0138] For example, the training result meets the third preset condition, that is, the accuracy of the model output result is greater than the third preset value.
[0139] Further, in order to improve the control of the terminal risk, after obtaining the identity verification result, the state risk evaluation information and the communication risk evaluation information, the terminal risk can be quantified, and the risk level can be intuitively displayed, so that the terminal is accessed according to the risk level, and the business access security is ensured.
[0140] For example, the identity verification result, the state risk evaluation information and the communication risk evaluation information are input into a pre-constructed quantitative scoring model to obtain a terminal security score output by the quantitative scoring model, according to a pre-configured corresponding relationship between the terminal security score interval and the business security access strategy, a target business security access strategy corresponding to the terminal security score is determined, and the terminal is accessed according to the target business security access strategy.
[0141] The quantification scoring model is a mathematical model, such as quantifying the identity verification result as an identity verification risk value, the identity verification risk value being 0 if the identity verification is passed, and the identity verification risk value being a positive value if the identity verification is failed. Then, the state risk value in the state risk assessment information is extracted, and the communication risk value in the communication risk assessment information is extracted. The quantification scoring model sets weights for the identity verification risk value, the state risk value, and the communication risk value. The identity verification risk value, the state risk value, and the communication risk value are summed by weighting. Then, the reciprocal of the sum value is taken as the terminal security score, and the terminal security score output by the quantification scoring model is obtained.
[0142] According to different application scenarios, the types of business security access policies are different. For example, the business security access policy includes an access policy and an access policy. The access policy is a terminal that meets the most basic security baseline before access, such as the terminal security score reaching the security baseline value, and can access. The access policy is a control policy for the terminal in the access process. The terminal security score interval corresponding to the access policy is lower than the terminal security score interval corresponding to the access policy.
[0143] Further, in order to improve the security control of the terminal access business in a more fine-grained manner, the attributes in the terminal security assessment report can also be combined to control the access of the corresponding business. All businesses can be based on specific attributes in the terminal security assessment report to perform fine-grained business access control, and realize fine security control of terminal access business.
[0144] For example, according to the correspondence between the pre-configured attributes, businesses, and access control policies, the target business corresponding to the attribute in the terminal security assessment report and the target access control policy are determined; and the target business accessed by the terminal is controlled according to the target access control policy.
[0145] The attribute can be any type of value in the terminal basic information, or any type of value in the terminal communication status information, and the invention does not make specific limitations.
[0146] For example, the attribute is that the terminal fails to log in to the business system for three consecutive times. The access control policy corresponding to this attribute for different business systems can be different. For example, the terminal security assessment report shows that the terminal fails to log in to the A business system for three consecutive times. The corresponding access control policy is that the terminal is not allowed to log in to the A business system within 1 day. If the terminal fails to log in to the B business system for three consecutive times, the corresponding access control policy is that the terminal is not allowed to log in to the B business system within 1 hour.
[0147] For another example, the attribute is that the terminal is infected with a virus, and the corresponding access control policy of the C business system is business access blocking.
[0148] The above several cases are only examples, and the application is not limited thereto.
[0149] Based on the terminal security detection method disclosed in the above embodiment, the present embodiment discloses a terminal security detection device. Please refer to Figure 3 The device comprises:
[0150] A first information acquisition unit 301 is configured to acquire the basic information of the terminal in a preset period.
[0151] An identity verification unit 302 is configured to perform identity verification on the terminal according to the identification information in the basic information, and obtain the identity verification result of the terminal.
[0152] A state risk analysis unit 303 is configured to input the running state information in the basic information into a pre-constructed state risk analysis model, and obtain the state risk assessment information of the terminal.
[0153] A second information acquisition unit 304 is configured to acquire the communication condition information of the terminal.
[0154] A communication risk analysis unit 305 is configured to input the communication condition information into a pre-constructed communication risk analysis model, and obtain the communication risk assessment information of the terminal.
[0155] An evaluation report generation unit 306 is configured to generate a terminal security evaluation report according to the identity verification result, the state risk assessment information and the communication risk assessment information.
[0156] In some embodiments, the identity verification unit 302 is specifically configured to extract the identification information in the basic information; compare the identification information with the pre-stored identification information of the terminal one by one, the identification information including device model, unique identification sequence, operator, network card information, secret key and associated user information; if the identification information is completely matched with the pre-stored identification information of the terminal, the identity verification result of the terminal is obtained as identity verification passed; if the identification information is not completely matched with the pre-stored identification information of the terminal, the identity verification result of the terminal is obtained as identity verification failed.
[0157] In some embodiments, the second information obtaining unit 304 is specifically configured to determine whether the terminal has accessed a zero-trust network; if the terminal has accessed the zero-trust network, obtain the communication condition information of the terminal; if the terminal has not accessed the zero-trust network, input the basic information into a pre-constructed device capability analysis model to obtain a device capability analysis result of the terminal; if the device capability analysis result meets a preset condition, construct a pre-communication channel between the terminal and a network server, and perform data transmission based on the pre-communication channel to obtain the communication condition information of the terminal.
[0158] In some embodiments, the method further comprises:
[0159] The first model constructing unit is configured to obtain a first training sample set, each training sample in the first training sample set comprising basic information of a sample terminal and a pre-labeled device capability value label; a training target is that a device capability analysis result output by a first machine learning model approaches the device capability value label, and the first training sample set is used to train the first machine learning model; when a first preset condition is met, the training of the first machine learning model is ended, and the device capability analysis model is obtained.
[0160] In some embodiments, the method further comprises:
[0161] The second model constructing unit is configured to obtain a second training sample set, each training sample in the second training sample set comprising running state information of a sample terminal and a pre-labeled state risk value label; a training target is that a state risk value output by a second machine learning model approaches the state risk value label, and the second training sample set is used to train the second machine learning model; when a second preset condition is met, the training of the second machine learning model is ended, and the state risk analysis model is obtained.
[0162] In some embodiments, the method further comprises:
[0163] The third model constructing unit is configured to obtain a third training sample set, each training sample in the third training sample set comprising communication condition information of a sample terminal and a pre-labeled communication risk value label; a training target is that a communication risk value output by a third machine learning model approaches the communication risk value label, and the third training sample set is used to train the third machine learning model; when a third preset condition is met, the training of the third machine learning model is ended, and the communication risk analysis model is obtained.
[0164] In some embodiments, the method further comprises:
[0165] The first access control unit is configured to input the identity verification result, the state risk assessment information and the communication risk assessment information into a pre-constructed quantitative scoring model to obtain a terminal security score output by the quantitative scoring model, determine a target business security access strategy corresponding to the terminal security score according to a pre-configured correspondence between terminal security score intervals and business security access strategies, and perform access control on the terminal according to the target business security access strategy.
[0166] In some embodiments, the method further comprises:
[0167] The second access control unit is configured to determine a target business and a target access control strategy corresponding to an attribute in the terminal security assessment report according to a pre-configured correspondence among attributes, businesses and access control strategies, and perform access control on the target business accessed by the terminal according to the target access control strategy.
[0168] The terminal security detection device disclosed in the embodiment comprehensively collects the basic information of the terminal in a preset period, performs identity verification on the terminal according to the identification information in the basic information to obtain an identity verification result, performs state risk analysis according to the running state information in the basic information to obtain state risk assessment information, and obtains the communication condition information of the terminal, performs communication risk analysis according to the communication condition information of the terminal to obtain communication risk assessment information. Finally, a comprehensive terminal security assessment report is generated according to the identity verification result, the state risk assessment information and the communication risk assessment information, so that comprehensive and accurate security detection of the terminal is realized. In addition, the periodic and continuous security detection of the terminal is realized by periodically collecting the basic information of the terminal, and the network security is improved.
[0169] The embodiment further discloses an electronic device, for example, referring to Figure 4 The electronic device includes a memory 401, a processor 402 and a computer program stored in the memory, and the processor 402 executes the computer program to implement the steps of the terminal security detection method described in any one of the above embodiments.
[0170] The embodiment further discloses a computer readable storage medium, which stores a computer program, and the computer program is executed by a processor to implement the steps of the terminal security detection method described in any one of the above embodiments.
[0171] The embodiment further discloses a computer program product, which includes a computer program, and the computer program is executed by a processor to implement the steps of the terminal security detection method described in any one of the above embodiments.
[0172] It should be noted that the terminal security detection method and the related device provided by the present application can be applied to the field of network security or the field of finance.
[0173] The embodiments in the specification are described in progressive manner, and each embodiment focuses on the difference from other embodiments, and the same or similar parts between the embodiments can be mutually referred to. For the device disclosed by the embodiments, since it corresponds to the method disclosed by the embodiments, the description is relatively simple, and the related parts can be referred to the method part.
[0174] It should be noted that, in this document, the terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply that there is any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variants thereof are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device. Without more limitations, the element defined by the statement "including a" does not exclude the presence of another identical element in the process, method, article or device including the element.
[0175] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein can be directly implemented by hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0176] The above-described embodiments can be combined arbitrarily, and the above-described description of the disclosed embodiments can be replaced by each feature described in the embodiments in the specification, so as to enable or use the present application by those skilled in the art.
[0177] The above-described description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to the embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A terminal security detection method, characterized by, The method comprises the following steps: acquiring basic information of the terminal within a preset period; performing identity verification on the terminal according to identification information in the basic information to obtain an identity verification result of the terminal; inputting running state information in the basic information into a pre-constructed state risk analysis model to obtain state risk assessment information of the terminal; acquiring communication condition information of the terminal; inputting the communication condition information into a pre-constructed communication risk analysis model to obtain communication risk assessment information of the terminal; generating a terminal security assessment report according to the identity verification result, the state risk assessment information and the communication risk assessment information; wherein the step of acquiring the communication condition information of the terminal comprises: judging whether the terminal has accessed a zero-trust network; if the terminal has accessed the zero-trust network, acquiring the communication condition information of the terminal; if the terminal has not accessed the zero-trust network, inputting the basic information into a pre-constructed device capability analysis model to obtain a device capability analysis result of the terminal; if the device capability analysis result meets a preset condition, constructing a pre-communication channel between the terminal and a network server and performing data transmission based on the pre-communication channel to acquire the communication condition information of the terminal.
2. The method of claim 1, wherein, The step of performing identity verification on the terminal according to identification information in the basic information to obtain an identity verification result of the terminal comprises: extracting the identification information in the basic information; comparing the identification information with pre-stored identification information of the terminal one by one, wherein the identification information comprises device model, unique identification sequence, operator to which the terminal belongs, network card information, secret key and associated user information; if the identification information is completely matched with the pre-stored identification information of the terminal, obtaining an identity verification result of the terminal as identity verification passed; if the identification information is not completely matched with the pre-stored identification information of the terminal, obtaining an identity verification result of the terminal as identity verification failed.
3. The method of claim 1, wherein the terminal security detection method is characterized by, The method for constructing the device capability analysis model comprises: acquiring a first training sample set, wherein each training sample in the first training sample set comprises basic information of a sample terminal and a pre-labeled device capability value label; training a first machine learning model by taking the device capability analysis result output by the first machine learning model approaching the device capability value label as a training target; when a first preset condition is met, ending the training of the first machine learning model to obtain the device capability analysis model.
4. The method of claim 1, wherein the terminal security detection method is characterized by, The method for constructing the state risk analysis model comprises: acquiring a second training sample set, wherein each training sample in the second training sample set comprises running state information of a sample terminal and a pre-labeled state risk value label; training a second machine learning model by taking the state risk value output by the second machine learning model approaching the state risk value label as a training target; when a second preset condition is met, ending the training of the second machine learning model to obtain the state risk analysis model.
5. The method of claim 1, wherein, The method for constructing the communication risk analysis model comprises: obtaining a third training sample set, each training sample in the third training sample set comprising communication condition information of a sample terminal and a pre-labeled communication risk value label; training a third machine learning model by taking the communication risk value output by the third machine learning model as a training target and using the third training sample set to train the third machine learning model; when a third preset condition is met, ending the training of the third machine learning model to obtain the communication risk analysis model.
6. The method of claim 1, wherein, Further comprising: inputting the identity verification result, the state risk assessment information and the communication risk assessment information into a pre-constructed quantitative scoring model to obtain a terminal security score output by the quantitative scoring model; determining a target business security access strategy corresponding to the terminal security score according to a pre-configured correspondence between terminal security score intervals and business security access strategies; controlling access to the terminal according to the target business security access strategy.
7. The method of claim 1, wherein the terminal security detection method is characterized by, Further comprising: determining a target business and a target access control strategy corresponding to an attribute in the terminal security assessment report according to a pre-configured correspondence among attributes, businesses and access control strategies; controlling access to the target business accessed by the terminal according to the target access control strategy.
8. A terminal security detection apparatus characterized by comprising: Comprise: a first information acquisition unit configured to acquire basic information of a terminal within a preset period; an identity verification unit configured to perform identity verification on the terminal according to identification information in the basic information to obtain an identity verification result of the terminal; a state risk analysis unit configured to input running state information in the basic information into a pre-constructed state risk analysis model to obtain state risk assessment information of the terminal; a second information acquisition unit configured to acquire communication condition information of the terminal; a communication risk analysis unit configured to input the communication condition information into a pre-constructed communication risk analysis model to obtain communication risk assessment information of the terminal; an assessment report generation unit configured to generate a terminal security assessment report according to the identity verification result, the state risk assessment information and the communication risk assessment information; the second information acquisition unit is specifically configured to determine whether the terminal has accessed a zero-trust network; if the terminal has accessed the zero-trust network, the communication condition information of the terminal is acquired; if the terminal has not accessed the zero-trust network, the basic information is input into a pre-constructed device capability analysis model to obtain a device capability analysis result of the terminal; if the device capability analysis result meets a preset condition, a pre-communication channel between the terminal and a network server is constructed, and data transmission is performed based on the pre-communication channel to acquire the communication condition information of the terminal.
9. An electronic device comprising a memory, a processor, and a computer program stored on the memory, wherein the computer program, when executed by the processor, is arranged to perform the method of any one of claims 1 to 8. The processor executes the computer program to implement the steps of the terminal security detection method in any one of claims 1-7.
Citation Information
Patent Citations
Internet of Things trust evaluation method
CN113487218A
Zero-trust secure trusted access method of 5G dual-domain private network
CN117750467A