Active safety monitoring methods, devices, equipment, storage media and program products

By constructing entity and behavior fingerprint databases, objects in the network system are authenticated in real time, solving the problem of the inability to identify unknown threats in advance in existing technologies, and achieving efficient security protection and risk control.

CN118646578BActive Publication Date: 2025-12-02INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410837250.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-26
Publication Date
2025-12-02
Estimated Expiration
2044-06-26

AI Technical Summary

Technical Problem

Existing proactive security protection technologies cannot identify unknown security threats in advance, are difficult to avoid missed and false alarms, and can only respond when an attack occurs, thus failing to effectively control network behavior risks.

Method used

By constructing entity fingerprint and behavior fingerprint databases, entities and behavior objects in the network system are authenticated in real time, fingerprints are generated and matched, non-new or unqualified objects are removed, and alarms are issued.

Benefits of technology

It enables accurate risk control and real-time monitoring of network system behavior before an attack occurs, improving the accuracy and efficiency of security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118646578B_ABST
    Figure CN118646578B_ABST
Patent Text Reader

Abstract

This application provides a proactive security monitoring method, apparatus, device, storage medium, and program product, relating to the field of information security. The method includes: acquiring entity objects and behavioral objects within a network system; generating entity fingerprints based on the entity information and management information of the entity objects; determining whether the entity fingerprint matches a target entity fingerprint in a preset entity fingerprint database; if not, clearing the entity object and issuing an alarm; generating behavioral fingerprints based on the memory space, runtime, and target operation object of the behavioral object; determining whether the behavioral fingerprint matches a target entity fingerprint in a preset behavioral fingerprint database; if not, clearing the behavioral object and issuing an alarm; and constructing entity fingerprint databases and behavioral fingerprint databases corresponding to entities and behaviors to perform real-time authentication of the fingerprints of entities and behaviors in the network, thereby accurately and efficiently responding to entity threats and behavioral threats and achieving comprehensive security protection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security, and in particular to an active security monitoring method, device, equipment, storage medium, and program product. Background Technology

[0002] With the widespread adoption of network applications and the rapid expansion of network scale, the network environment has become increasingly complex. While the development of the network brings various conveniences to work, people also face a variety of network threats that are constantly evolving with technological advancements. Existing network security protection technologies include passive security protection technologies and active security protection technologies.

[0003] Passive security protection technologies are characterized by plugging vulnerabilities, building high walls, and preventing external attacks. They employ security protection measures such as intrusion detection devices, firewalls, and network behavior management, combined with address binding or authentication methods based on specific protocols, to detect unauthorized devices connecting to the internal network. However, with increasingly complex network applications and security environments, passive security protection technologies cannot identify dangers in advance, nor can they control internal network behavior risks.

[0004] Currently, proactive security protection technologies primarily rely on establishing a security policy matching library based on common attack patterns. They then monitor and analyze user behavior and system status to detect and prevent network threats. However, existing proactive security protection technologies are all based on security monitoring models built upon intrusion or attack behaviors. Therefore, they can only detect and identify security threats during the intrusion process and respond accordingly, making it difficult to identify unknown security threats before an attack occurs. Furthermore, because the matching rules for detection are abstractions and generalizations of "behavior," existing proactive security protection technologies are also prone to false positives and false negatives. Summary of the Invention

[0005] This application provides an active security monitoring method, device, equipment, storage medium, and program product to solve the problem that existing security protection technologies cannot identify dangers in advance, can only respond to security policies when an attack occurs, and cannot control internal network behavior risks.

[0006] Firstly, this application provides an active security monitoring method, comprising:

[0007] Retrieve entity objects and behavior objects within the network system;

[0008] When the entity object is a newly added entity object, the newly added entity object is sent to the management terminal. If the management terminal authorizes it, a new entity fingerprint is generated based on the entity information and management information of the newly added entity object, and the new entity fingerprint is added to the preset entity fingerprint database.

[0009] When the entity object is not a newly added entity object, an entity fingerprint is generated based on the entity information and management information of the entity object. It is then determined whether the entity fingerprint has a matching target entity fingerprint in the preset entity fingerprint database. If not, the entity object is cleared and an alarm is triggered.

[0010] A behavior fingerprint is generated based on the memory space, runtime, and target operation object of the behavior object. It is then determined whether the behavior fingerprint has a matching target entity fingerprint in a preset behavior fingerprint library. If not, the behavior object is cleared and an alarm is triggered. The behavior fingerprint library is used to store the qualified behavior fingerprints of each behavior object.

[0011] Secondly, this application provides an active safety monitoring device, comprising:

[0012] The object acquisition module is used to acquire entity objects and behavior objects within the network system;

[0013] The entity object authorization module is used to send the information of the newly added entity object to the management terminal when the entity object is a newly added entity object. If the management terminal authorizes it, it obtains the authorization information of the newly added entity object, generates a new entity fingerprint based on the entity information, management information and authorization information of the newly added entity object, and adds the new entity fingerprint to the preset entity fingerprint database.

[0014] The entity object matching module is used to generate an entity fingerprint based on the entity information, management information and authorization information of the entity object when the entity object is not a newly added entity object, and to determine whether the entity fingerprint has a matching target entity fingerprint in the preset entity fingerprint database. If not, the entity object is cleared and an alarm is issued.

[0015] The behavior object matching module is used to generate a behavior fingerprint based on the memory space, runtime, and target operation object of the behavior object, and to determine whether the behavior fingerprint has a matching target entity fingerprint in a preset behavior fingerprint library. If not, the behavior object is cleared and an alarm is issued. The behavior fingerprint library is used to store qualified behavior fingerprints of each behavior object.

[0016] Thirdly, this application provides an electronic device including a memory, a processor, and computer-executable instructions stored in the memory and executable on the processor, wherein the processor executes the computer-executable instructions to implement the active security monitoring method described in any one of the first aspects above.

[0017] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the active security monitoring method described in any one of the first aspects above.

[0018] Fifthly, this application provides a computer program product that, when run on a terminal device, causes the terminal device to execute the active security monitoring method described in any of the first aspects above.

[0019] The proactive security monitoring method, apparatus, equipment, storage medium, and program products provided in this application acquire entity objects and behavior objects within the network system by constructing entity fingerprint databases and behavior fingerprint databases corresponding to entities and behaviors. When an entity object is a newly added entity object, it is sent to the management terminal. If the management terminal authorizes it, a new entity fingerprint is generated and added to a preset entity fingerprint database. When the entity object is not a newly added entity object, an entity fingerprint is generated based on the entity information and management information of the entity object. It is then determined whether the entity fingerprint has a matching target entity fingerprint in the preset entity fingerprint database. If not, the entity object is cleared and an alarm is triggered. Similarly, a behavior fingerprint is generated based on the memory space, runtime, and target operation object of a behavior object. It is then determined whether the behavior fingerprint has a matching target entity fingerprint in the preset behavior fingerprint database. If not, the behavior object is cleared and an alarm is triggered. Real-time authentication of entity and behavior fingerprints in the network enables accurate and efficient response to entity and behavior threats. It allows for risk control before the behavior occurs and real-time monitoring of behavior within the network system, achieving comprehensive security protection. Attached Figure Description

[0020] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0021] Figure 1 This is a schematic diagram illustrating an application scenario of the proactive safety monitoring method provided in the embodiments of this application.

[0022] Figure 2 A flowchart of the proactive security monitoring method provided in the embodiments of this application.

[0023] Figure 3 This is a schematic diagram of an active safety monitoring device provided in an embodiment of this application.

[0024] Figure 4 This is a schematic diagram of the electronic device of the active safety monitoring device provided in the embodiments of this application.

[0025] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation

[0026] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.

[0027] It should be noted that the active security monitoring method, device, equipment, storage medium and program product of this application can be used in the field of information security, or in any field other than information security. The application field of the active security monitoring method, device, equipment, storage medium and program product of this application is not limited.

[0028] In related technologies, a security policy matching library can be established in advance based on common attack patterns, and network threats can be discovered and prevented by monitoring and analyzing user behavior and system status. However, existing proactive security protection technologies are all based on security monitoring models built on intrusion or attack behaviors. Therefore, they can only detect and identify security threats during the intrusion process and respond accordingly, making it difficult to identify unknown security threats before an attack occurs.

[0029] To address the aforementioned technical problems, this application aims to propose an active security monitoring method, apparatus, device, storage medium, and program product. The core concept of this method is to actively monitor entities and behaviors in the network by constructing entity fingerprint databases and behavior fingerprint databases corresponding to entities and behaviors, and to authenticate their fingerprints in real time. This enables accurate and efficient response to entity and behavior threats, allowing for risk control before the behavior occurs and real-time monitoring of behaviors within the network system, thus achieving comprehensive security protection.

[0030] The data transmission method provided in this application is intended to solve the above-mentioned technical problems of the prior art.

[0031] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0032] To better understand the solutions of the embodiments of this application, an application scenario involved in the embodiments of this application will be introduced below.

[0033] Please see Figure 1 , Figure 1This is a schematic diagram illustrating an application scenario of the proactive security monitoring method provided in the embodiments of this application, such as... Figure 1 As shown, it includes a management terminal 100 and a server 200. The management terminal 100 can be used to send instructions related to network security protection requirements to the server 200, and to perform operations such as reviewing information returned by the server 200. The management terminal 100 may include a personal computer, tablet computer, smart panel, etc., and is not limited thereto in this embodiment.

[0034] Server 200 can be used to actively acquire entity objects and behavior objects within the network system, determine whether an entity object or behavior object is a newly added entity / behavior object, and send the newly added entity / behavior object to management terminal 100. After authorization and verification by management terminal 100, a fingerprint is generated for the newly added entity / behavior object, and the fingerprint is added to a preset entity / behavior fingerprint database. If management terminal 100 does not authorize it, the newly added entity / behavior object is deleted. For non-new entity objects or non-new behavior objects, their corresponding entity / behavior fingerprints are generated and compared with existing fingerprints in the preset entity / behavior fingerprint database. If they do not match, the non-new entity object or non-new behavior object is deleted, and an alarm is triggered.

[0035] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.

[0036] Figure 2 A flowchart illustrating the proactive security monitoring method provided in this application embodiment. Figure 2 As shown, the method in this embodiment includes:

[0037] S201: Obtain entity objects and behavior objects within the network system.

[0038] The execution entity of this application embodiment can be a server or a proactive security monitoring system within the server, wherein the proactive security monitoring system can be implemented through software.

[0039] Understandably, in a network system, entity objects can include files, directories, free storage areas, and I / O devices, while behavioral objects can include processes, procedures, and operations. In this step, entity objects and behavioral objects can be obtained by detecting all entities and behaviors (i.e., processes) in the network system.

[0040] S202: When the entity object is a newly added entity object, the newly added entity object is sent to the management terminal. If the management terminal authorizes it, a new entity fingerprint is generated based on the entity information and management information of the newly added entity object, and the new entity fingerprint is added to the preset entity fingerprint database.

[0041] Understandably, when a new entity is detected, its relevant information, such as its content, device control, and status information, can be sent to the management system. The administrator can then determine whether authorization is warranted. If authorization is granted, the new entity's fingerprint can be added to the entity fingerprint database. This expands the database and reduces false alarms. Furthermore, identifying new entities allows for proactive security risk mitigation before attacks occur, enhancing the responsiveness of proactive security detection.

[0042] S203: When the entity object is not a newly added entity object, an entity fingerprint is generated based on the entity information and management information of the entity object. It is determined whether the entity fingerprint has a matching target entity fingerprint in the preset entity fingerprint database. If not, the entity object is cleared and an alarm is issued.

[0043] It is understandable that, similar to how fingerprints in real life are information representations that indicate the authenticity, uniqueness, integrity, and provability of an object, the fingerprints described in this application are information digests corresponding to entity objects or behavioral objects obtained through information digest processing technology, which can accurately identify each entity object or behavioral object.

[0044] In this step, fingerprints are generated for entity objects in the network system. Based on the identifiability of the entity fingerprint, the entity fingerprint is matched using a preset entity fingerprint database. Specifically, if there is a matching target entity fingerprint, it proves that the entity fingerprint is in a secure state. However, if there is no matching target entity fingerprint in the entity fingerprint database, it means that the entity fingerprint is no longer in a secure state. At this time, an alarm is sent to the management end to achieve proactive security protection.

[0045] S204: Generate a behavior fingerprint based on the memory space, runtime, and target operation object of the behavior object. Determine whether the behavior fingerprint has a matching target entity fingerprint in the preset behavior fingerprint library. If not, clear the behavior object and issue an alarm. The behavior fingerprint library is used to store qualified behavior fingerprints of each behavior object.

[0046] In this step, fingerprints are generated for behavioral objects in the network system. Based on the identifiability of the behavioral fingerprint, the behavioral fingerprint is matched using a preset behavioral fingerprint database. Specifically, if there is a matching target behavioral fingerprint, it proves that the behavioral fingerprint is in a secure state. However, if there is no matching target behavioral fingerprint in the behavioral fingerprint database, it means that the behavioral fingerprint is no longer in a secure state. At this time, an alarm is sent to the management end to achieve proactive security protection.

[0047] The proactive security monitoring method provided in this embodiment acquires entity objects and behavior objects within the network system by constructing entity fingerprint databases and behavior fingerprint databases corresponding to entities and behaviors. When an entity object is a newly added entity object, it is sent to the management terminal. If the management terminal authorizes it, a new entity fingerprint is generated and added to the preset entity fingerprint database. When the entity object is not a newly added entity object, an entity fingerprint is generated based on the entity information and management information of the entity object. It is then determined whether the entity fingerprint has a matching target entity fingerprint in the preset entity fingerprint database. If not, the entity object is cleared and an alarm is triggered. Similarly, a behavior fingerprint is generated based on the memory space, runtime, and target operation object of the behavior object. It is then determined whether the behavior fingerprint has a matching target entity fingerprint in the preset behavior fingerprint database. If not, the behavior object is cleared and an alarm is triggered. Real-time authentication of entity and behavior fingerprints in the network enables accurate and efficient response to entity and behavior threats. This allows for risk control before the behavior occurs and real-time monitoring of behaviors within the network system, achieving comprehensive security protection.

[0048] The technical solution of the above-mentioned active safety monitoring method will be described in detail below.

[0049] In one possible implementation, the proactive security monitoring method provided in this embodiment processes relevant information of entity objects using two different cryptographic hash functions and combines them with a random factor to generate entity fingerprints.

[0050] Specifically, generating an entity fingerprint based on the entity information and management information of the entity object includes: using the MD5 message digest algorithm to calculate the message digests of the entity information and management information respectively to obtain entity information digests and management information digests, and using the entity information digests and management information digests as X factors and Y factors respectively; randomly generating a Z factor according to a preset security information generation rule; concatenating the X factor, the Y factor and the Z factor and then performing a cryptographic hash function calculation, and using the calculation result as the entity fingerprint of the entity object.

[0051] Understandably, a cryptographic hash function is a one-way hash function that compresses a message of arbitrary length into a message digest of a fixed length. For any given message, it is easy to calculate the hash value. However, it is difficult to deduce the original message from a known hash value. In this application, using a cryptographic hash function to generate a fingerprint can effectively ensure the accuracy of identifying entities or behaviors. The MD5 algorithm (Message Digest Algorithm) is a widely used cryptographic hash function that produces a 128-bit (16-byte) hash value to ensure the integrity and consistency of transmitted information. Its principle is as follows: MD5 codes process the input information in 512-bit blocks, and each block is further divided into 16 32-bit sub-blocks. After a series of processing steps, the algorithm's output consists of four 32-bit blocks. Concatenating these four 32-bit blocks generates a 128-bit hash value.

[0052] Specifically, entity information may include file content information, device control and status information; management information may include file control blocks, empty space allocation tables and device allocation tables.

[0053] Therefore, after calculating the message digest using the MD5 algorithm on the entity information and the management information respectively, two different hash values ​​are obtained. These two hash values ​​can be used as the X factor and Y factor of the fingerprint respectively.

[0054] Furthermore, a Z-factor is randomly generated according to a preset security information generation rule, including: obtaining authorization information for the entity object from the management end; calculating the message digest value of the authorization information through a cryptographic hash function, and using the message digest value as the Z-factor.

[0055] In this process, the MD5 algorithm can be used as the cryptographic hash function for this step, and the authorization information processed by the MD5 algorithm can be used as the Z factor of the fingerprint.

[0056] For the concatenated X, Y, and Z factors, a Secure Hash Algorithm 1 (SHA-1), different from MD5, can be used as the cryptographic hash function for this step. SHA-1 can generate a 160-bit (20-byte) hash value called a message digest. Using different cryptographic hash functions to generate fingerprints can avoid data collisions, that is, avoid the possibility of different information generating the same fingerprint, thereby ensuring the uniqueness and identifiability of the fingerprint.

[0057] In this embodiment, two different cryptographic hash functions are used to process the relevant information of the entity object, and a random factor is combined to generate an entity fingerprint. This reduces the possibility of data conflicts during the calculation process, is suitable for complex data situations with multiple factors, and improves the accuracy of fingerprint matching.

[0058] In one possible implementation, the proactive security monitoring method provided in this embodiment processes the relevant information of the behavioral object through two different cryptographic hash functions and combines them with a random factor to generate a behavioral fingerprint.

[0059] Specifically, generating a behavioral fingerprint based on the memory space, runtime, and target operation object of the behavioral object includes: using the MD5 message digest algorithm to calculate message digests for the memory space, runtime, and target operation object respectively, obtaining a memory space message digest, a runtime message digest, and a target operation object message digest; using the memory space message digest, the runtime message digest, and the target operation object message digest as factors A, B, and C respectively; randomly generating an M factor according to a preset security information generation rule; concatenating factors A, B, C, and M and then performing a cryptographic hash function calculation, using the calculation result as the behavioral fingerprint of the entity object.

[0060] The memory space can include the memory space occupied by each application process during runtime, the runtime can include the start time, end time and runtime of each application process, and the target operation object can include the operation target object of each application process.

[0061] It is understandable that the principle for generating specific behavioral fingerprints in this embodiment is similar to the principle for generating entity fingerprints in the previous embodiment. However, since the content of behavioral objects and entity objects is inconsistent, the processing details of the cryptographic hash function differ. For behavioral objects, the establishment of behavioral fingerprints requires three aspects of data information: the memory space occupied by each application process during runtime, the start time, end time, and runtime of each application process, and the target object of the application process's operation. It should be noted that the selection of data information can also be different in the specific calculation of factors A, B, and C.

[0062] In this embodiment, the M factor can be randomly generated according to the random hash value generation rules preset by the manager, or it can be generated according to the authorization information or verification information of the manager for the behavior object.

[0063] In this embodiment, two different cryptographic hash functions are used to process the relevant information of the behavior object. Combined with a random factor, a behavior fingerprint is generated, which reduces the possibility of data conflicts during the calculation process. It is suitable for complex data situations with multiple factors and improves the accuracy of fingerprint matching.

[0064] In one possible implementation, the entity objects include files, directories, free storage areas, and I / O devices in the network system. After obtaining the entity objects in the network system, the proactive security monitoring method provided in this embodiment further includes: determining whether the entity object is a newly added entity object.

[0065] Specifically, determining whether the entity object is a newly added entity object includes: obtaining the address and device number of the entity object; determining whether the address or device number of the entity object exists in a preset entity object monitoring list, wherein the entity object monitoring list includes the address and device number information of each entity object authorized by the management terminal; if not, confirming that the entity object is a newly added entity object; if yes, confirming that the entity object is not a newly added entity object.

[0066] It is understandable that the address or device number of an entity object is usually fixed. In other words, the entity object can be initially identified by its address or device number.

[0067] In this embodiment, the entity object is determined to be a newly added entity object by its address or device number. This proactive monitoring of entity objects in the network system is beneficial for building a security protection system with different layers and improving security.

[0068] In one possible implementation, the proactive security monitoring method provided in this embodiment further includes, before generating an entity fingerprint based on the memory space, runtime, and target operation object of the behavior object: determining whether the behavior object is a newly added behavior object; if so, sending the information of the newly added behavior object to the management terminal; if the management terminal reports that the newly added behavior object is an unqualified behavior object, clearing the newly added behavior object.

[0069] It's understandable that the same entity object might generate different behavior objects. Therefore, when a new behavior object appears, it can be sent to the management terminal for the administrator to determine its validity. If the new behavior object is valid, a fingerprint can be generated for it and added to the behavior fingerprint database. If the new behavior object is invalid, it indicates that the behavior object is in an insecure state and needs to be removed.

[0070] In this embodiment, by judging newly added behavioral objects, the active monitoring of behavioral objects in the network system is beneficial to building a security protection system with different layers and improving security.

[0071] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.

[0072] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0073] Figure 3 This is a schematic diagram of the active safety monitoring device provided in an embodiment of this application. Figure 3 As shown, the active safety monitoring device includes:

[0074] Object acquisition module 31 is used to acquire entity objects and behavior objects within the network system;

[0075] The entity object authorization module 32 is used to send the information of the newly added entity object to the management terminal when the entity object is a newly added entity object. If the management terminal authorizes it, it obtains the authorization information of the newly added entity object, generates a new entity fingerprint based on the entity information, management information and authorization information of the newly added entity object, and adds the new entity fingerprint to the preset entity fingerprint database.

[0076] The entity object matching module 33 is used to generate an entity fingerprint based on the entity information, management information and authorization information of the entity object when the entity object is not a newly added entity object, and to determine whether the entity fingerprint has a matching target entity fingerprint in the preset entity fingerprint database. If not, the entity object is cleared and an alarm is issued.

[0077] The behavior object matching module 34 is used to generate a behavior fingerprint based on the memory space, running time and target operation object of the behavior object, and to determine whether the behavior fingerprint has a matching target entity fingerprint in the preset behavior fingerprint library. If not, the behavior object is cleared and an alarm is issued. The behavior fingerprint library is used to store the qualified behavior fingerprints of each behavior object.

[0078] In one possible design, the entity object matching module 33 is specifically used for:

[0079] The MD5 message digest algorithm is used to calculate message digests for the entity information and management information respectively, and the entity information digest and the management information digest are used as the X factor and the Y factor respectively.

[0080] The Z-factor is randomly generated according to the preset security information generation rules;

[0081] The X factor, Y factor, and Z factor are concatenated and then subjected to a cryptographic hash function calculation. The result is used as the entity fingerprint of the entity object.

[0082] In one possible design, the entity object matching module 33 is specifically used for:

[0083] Obtain the authorization information for the entity object from the management terminal;

[0084] The message digest value of the authorization information is calculated using a cryptographic hash function, and the message digest value is used as the Z factor.

[0085] In one possible design, the entity information includes file content information, device control and status information, and the management information includes a file control block, a space allocation table and a device allocation table.

[0086] In one possible design, the behavior object matching module 34 is specifically used for:

[0087] The MD5 message digest algorithm is used to calculate message digests for the memory space, runtime, and target operation object, respectively, to obtain a memory space message digest, a runtime message digest, and a target operation object message digest. The memory space message digest, the runtime message digest, and the target operation object message digest are then used as factors A, B, and C, respectively.

[0088] M-factors are randomly generated according to preset security information generation rules;

[0089] Factor A, factor B, factor C, and factor M are concatenated and then subjected to a cryptographic hash function calculation. The calculation result is used as the behavioral fingerprint of the entity object.

[0090] In one possible design, the memory space includes the memory space occupied by each application process during runtime, the runtime includes the start time, end time and runtime of each application process, and the target operation object includes the operation target object of each application process.

[0091] In one possible design, entity objects include files, directories, free storage areas, and I / O devices in the network system. The entity object authorization module 32 is also specifically used for:

[0092] Determine whether the entity object is a newly added entity object.

[0093] In one possible design, the entity object authorization module 32 is also specifically used for:

[0094] Obtain the address and device number of the entity object, and determine whether the address or device number of the entity object exists in the preset entity object monitoring list. The entity object monitoring list includes the address and device number information of each entity object authorized by the management terminal.

[0095] If not, confirm that the entity object is a newly added entity object;

[0096] If so, confirm that the entity object is not a newly added entity object.

[0097] In one possible design, the behavior object matching module 34 is also specifically used for:

[0098] Determine whether the behavior object is a newly added behavior object;

[0099] If so, send the information of the newly added behavior object to the management terminal;

[0100] If the management system reports that the newly added behavior object is an unqualified behavior object, the newly added behavior object will be deleted.

[0101] It should be noted that, for the sake of simplicity, the foregoing method embodiments are all described as a series of actions. However, those skilled in the art should understand that this application is not limited to the described order of actions, as some steps may be performed in other orders or simultaneously according to this application. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all optional embodiments, and the actions and modules involved are not necessarily essential to this application.

[0102] It should be further noted that although the steps in the flowchart are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowchart may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0103] It should be understood that the above-described device embodiments are merely illustrative, and the device of this application can also be implemented in other ways. For example, the division of units / modules in the above embodiments is only a logical functional division, and there may be other division methods in actual implementation. For example, multiple units, modules, or components may be combined, or integrated into another system, or some features may be ignored or not executed.

[0104] Furthermore, unless otherwise specified, the functional units / modules in the various embodiments of this application can be integrated into one unit / module, or each unit / module can exist physically separately, or two or more units / modules can be integrated together. The integrated units / modules described above can be implemented in hardware or as software program modules.

[0105] Figure 4 This is a schematic diagram of the electronic device used in the active safety monitoring device provided in an embodiment of this application. Figure 4 As shown, the electronic device of this embodiment includes: at least one processor 40 ( Figure 4 (Only one is shown) a processor, a memory 41, and a computer program stored in the memory 41 that can run on at least one processor 40, which executes the computer program to implement the steps in any of the above method embodiments.

[0106] The electronic device may include, but is not limited to, a processor 40 and a memory 41. Those skilled in the art will understand that... Figure 4 This is merely an example of an electronic device and does not constitute a limitation on electronic devices. It may include more or fewer components than shown in the illustration, or combinations of certain components, or different components. For example, it may also include input / output devices, network access devices, etc.

[0107] The processor 40 may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.

[0108] The specific implementation process of processor 401 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.

[0109] In some embodiments, memory 41 may be an internal storage unit of an electronic device, such as the memory of the electronic device. In other embodiments, memory 41 may be an external storage device of the electronic device, such as a plug-in hard drive, smart media card (SMC), secure digital (SD) card, flash card, etc. Furthermore, memory 41 may include both internal and external storage units of the electronic device. Memory 41 is used to store operating systems, applications, bootloaders, data, and other programs, such as program code for computer programs. Memory 41 can also be used to temporarily store data that has been output or will be output.

[0110] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps described in the various method embodiments above.

[0111] The aforementioned computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.

[0112] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an application-specific integrated circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the aforementioned electronic device.

[0113] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.

[0114] In the above embodiments, the descriptions of each embodiment have their own emphasis. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments. The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combination of these technical features does not contradict each other, it should be considered within the scope of this specification.

[0115] Other embodiments of this application will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and embodiments are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims. It should be understood that this application is not limited to the precise structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.

Claims

1. A proactive safety monitoring method, characterized in that, include: Retrieve entity objects and behavior objects within the network system; When the entity object is a newly added entity object, the newly added entity object is sent to the management terminal. If the management terminal authorizes it, a new entity fingerprint is generated based on the entity information and management information of the newly added entity object, and the new entity fingerprint is added to the preset entity fingerprint database. When the entity object is not a newly added entity object, an entity fingerprint is generated based on the entity information and management information of the entity object. It is then determined whether the entity fingerprint has a matching target entity fingerprint in the preset entity fingerprint database. If not, the entity object is cleared and an alarm is triggered. A behavior fingerprint is generated based on the memory space, runtime, and target operation object of the behavior object. It is then determined whether the behavior fingerprint has a matching target entity fingerprint in a preset behavior fingerprint library. If not, the behavior object is cleared and an alarm is triggered. The behavior fingerprint library is used to store the qualified behavior fingerprints of each behavior object.

2. The method according to claim 1, characterized in that, The generation of entity fingerprints based on the entity information and management information of the entity object includes: The MD5 message digest algorithm is used to calculate message digests for the entity information and management information respectively, and the entity information digest and the management information digest are used as the X factor and the Y factor respectively. The Z-factor is randomly generated according to the preset security information generation rules; The X factor, Y factor, and Z factor are concatenated and then subjected to a cryptographic hash function calculation. The result is used as the entity fingerprint of the entity object.

3. The method according to claim 2, characterized in that, The step of randomly generating the Z factor according to the preset security information generation rules includes: Obtain the authorization information for the entity object from the management terminal; The message digest value of the authorization information is calculated using a cryptographic hash function, and the message digest value is used as the Z factor.

4. The method according to claim 2, characterized in that, The entity information includes file content information, device control and status information, and the management information includes file control blocks, empty space allocation tables and device allocation tables.

5. The method according to claim 1, characterized in that, The process of generating a behavior fingerprint based on the memory space, runtime, and target operation object of the behavior object includes: The MD5 message digest algorithm is used to calculate message digests for the memory space, runtime, and target operation object, respectively, to obtain a memory space message digest, a runtime message digest, and a target operation object message digest. The memory space message digest, the runtime message digest, and the target operation object message digest are then used as factors A, B, and C, respectively. M-factors are randomly generated according to preset security information generation rules; Factor A, factor B, factor C, and factor M are concatenated and then subjected to a cryptographic hash function calculation. The calculation result is used as the behavioral fingerprint of the entity object.

6. The method according to claim 5, characterized in that, The memory space includes the memory space occupied by each application process during runtime, the runtime includes the start time, end time and runtime of each application process, and the target operation object includes the operation target object of each application process.

7. The method according to claim 1, characterized in that, The entity objects include files, directories, free storage areas, and I / O devices in the network system. After obtaining the entity objects within the network system, the system further includes: Determine whether the entity object is a newly added entity object.

8. The method according to claim 7, characterized in that, The step of determining whether the entity object is a newly added entity object includes: Obtain the address and device number of the entity object, and determine whether the address or device number of the entity object exists in the preset entity object monitoring list. The entity object monitoring list includes the address and device number information of each entity object authorized by the management terminal. If not, confirm that the entity object is a newly added entity object; If so, confirm that the entity object is not a newly added entity object.

9. The method according to claim 1, characterized in that, Before generating an entity fingerprint based on the memory space, runtime, and target operation object of the behavior object, the process also includes: Determine whether the behavior object is a newly added behavior object; If so, send the information of the newly added behavior object to the management terminal; If the management system reports that the newly added behavior object is an unqualified behavior object, the newly added behavior object will be deleted.

10. An active safety monitoring device, comprising: The object acquisition module is used to acquire entity objects and behavior objects within the network system; The entity object authorization module is used to send the information of the newly added entity object to the management terminal when the entity object is a newly added entity object. If the management terminal authorizes it, it obtains the authorization information of the newly added entity object, generates a new entity fingerprint based on the entity information, management information and authorization information of the newly added entity object, and adds the new entity fingerprint to the preset entity fingerprint database. The entity object matching module is used to generate an entity fingerprint based on the entity information, management information and authorization information of the entity object when the entity object is not a newly added entity object, and to determine whether the entity fingerprint has a matching target entity fingerprint in the preset entity fingerprint database. If not, the entity object is cleared and an alarm is issued. The behavior object matching module is used to generate a behavior fingerprint based on the memory space, runtime, and target operation object of the behavior object, and to determine whether the behavior fingerprint has a matching target entity fingerprint in a preset behavior fingerprint library. If not, the behavior object is cleared and an alarm is issued. The behavior fingerprint library is used to store qualified behavior fingerprints of each behavior object.

11. An electronic device, characterized in that, include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 9.

12. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 9.

13. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method of any one of claims 1-9.

Citation Information

Patent Citations

  • Network fingerprint-based software dynamic credible authentication method

    CN102891752A

  • Data processing method and related device

    CN114297735A