Cloud platform asset monitoring method and device, medium and equipment

By combining proactive investigation and proxy services, cloud platform asset information is acquired and security audits are conducted, which solves the problem of missing cloud platform asset monitoring and security audits, realizes refined management and security assessment, and improves the security operation capabilities of the cloud platform.

CN118740496BActive Publication Date: 2026-01-23SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411002577.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-25
Publication Date
2026-01-23
Estimated Expiration
2044-07-25

AI Technical Summary

Technical Problem

Existing technologies lack comprehensive management solutions for efficient monitoring and security auditing of cloud platform assets, which could lead to serious consequences if cloud platform assets fall into the hands of hackers.

Method used

Cloud platform assets are acquired through proactive exploration and proactive reporting by agent services deployed on the cloud platform. These assets are then managed in a ledger. Asset information is obtained through deep scanning and stateless scanning. Security event logs are collected by agent services to conduct multi-faceted security audits and risk assessments, and generate security analysis reports.

Benefits of technology

It enables refined management and security auditing of cloud platform assets, real-time detection of asset status changes, improved security operation efficiency and effectiveness of the cloud platform, constructed a digital security base map, and enhanced network security management capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118740496B_ABST
    Figure CN118740496B_ABST
Patent Text Reader

Abstract

The application provides a cloud platform asset monitoring method and device, medium and equipment. The method comprises the following steps: obtaining cloud platform assets by using an active exploration mode and an active reporting mode of a proxy service deployed on the cloud platform, and managing a ledger of the cloud platform assets; monitoring dynamic changes of the cloud platform assets; obtaining running security situation data of the cloud platform assets; performing multi-aspect asset security auditing according to the running security situation data of the cloud platform assets to obtain multi-aspect security risk auditing results of the cloud platform assets; and generating a corresponding security analysis report according to the security risk auditing results. The embodiment of the application effectively supports security operation and management and the like in a network scenario, and improves the efficiency and effect of security operation of an enterprise cloud platform.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of cloud asset management technology, and in particular to a cloud platform asset monitoring method, device, medium, and equipment. Background Technology

[0002] As the integration of cloud, network, edge, and endpoint continues to advance, cloud platforms are gradually becoming the center of data and management. This cloud-based informatization brings many conveniences to enterprises, but it also brings security risks. The asset system within cloud platforms is extremely complex and vast. Once these assets fall into the hands of hackers, it will have very serious consequences. Currently, there is a lack of comprehensive management solutions for efficient monitoring and security auditing of cloud platform assets. Summary of the Invention

[0003] To address at least one of the above technical problems, embodiments of the present invention provide a cloud platform asset monitoring method, apparatus, medium, and equipment.

[0004] In a first aspect, the cloud platform asset monitoring method provided in the embodiments of the present invention includes:

[0005] Cloud platform assets are obtained through proactive exploration and proactive reporting via agent services deployed on the cloud platform, and the ledger of the cloud platform assets is managed.

[0006] Monitor the dynamic changes of the cloud platform assets;

[0007] Obtain operational security status data of the cloud platform assets;

[0008] Based on the operational security status data of the cloud platform assets, a multi-faceted asset security audit is conducted to obtain the audit results of the cloud platform assets in multiple aspects of security risks.

[0009] Based on the security risk audit results, a corresponding security analysis report is generated.

[0010] In one embodiment, acquiring cloud platform assets using proactive probing methods includes at least one of the following:

[0011] Identify the viability of cloud platform assets to obtain cloud platform assets that are in normal operating condition;

[0012] The service ports are scanned using a stateless scanning method to identify those that are open. This stateless scanning method involves sending probe packets to the corrected IP addresses of each service port using coroutine concurrency technology, and determining whether a service port is open based on whether and what the response is from each service port. The corrected IP address is the IP address obtained by hashing the original IP address of the service port.

[0013] The network protocol of a service port is obtained through a deep scanning method. This deep scanning method involves: obtaining a port open service probability table, which records the probability of each service port corresponding to at least one network protocol; selecting the network protocol with the highest probability for each service port from the port open service probability table as the current first network protocol; scanning the current first network protocol; if the current first network protocol is successfully detected, then the current first network protocol is identified as the network protocol used for the service provided by that service port; if the current first network protocol is not detected, then the network protocol with the second highest probability for that service port in the port open service probability table is identified as the current first network protocol, and the process returns to the step of scanning the current first network protocol; this process continues until the network protocol used for the service provided by the service port is determined.

[0014] In one embodiment, acquiring cloud platform assets using an active probing approach further includes:

[0015] The manufacturer information of the cloud platform assets is obtained by calling the device manufacturer database;

[0016] By calling the component identifier library, the component type and component version of the cloud platform asset can be obtained;

[0017] By calling the operating system type library, the operating system type and operating system version of the cloud platform assets can be obtained;

[0018] The device type of the cloud platform assets is obtained by calling the device type library;

[0019] By calling the product type library, the product type and product version of the cloud platform assets can be obtained;

[0020] The cloud platform assets are marked with information using at least one of the following: the manufacturer information, the component type, the component version, the operating system type, the operating system version, the device type, the product type, and the product version.

[0021] In one embodiment, cloud platform assets are obtained by proactively reporting through an agent service deployed on the cloud platform, including:

[0022] The agent service deployed on the cloud platform is used to collect asset information on the cloud platform host at regular intervals and report the collected asset information.

[0023] Correspondingly, obtaining the operational security status data of the cloud platform assets includes:

[0024] The agent service deployed on the cloud platform periodically collects at least one of the following from the cloud platform host: network security event logs, system alarm logs, and user operation alarm logs, and reports the at least one of them.

[0025] In one embodiment, the management of the ledger of the cloud platform assets includes at least one of the following:

[0026] The cloud platform assets are managed separately according to asset type; wherein, the asset types include cloud servers, web websites, network equipment, security equipment, and operation and maintenance equipment;

[0027] The asset fingerprint information of the cloud platform assets is managed; wherein the asset fingerprint information includes at least one of the following: asset name, group, responsible person, IP address, MAC code, manufacturer, geographical location, usage status, and operating system;

[0028] The business value of the cloud platform assets is managed; wherein the business value includes at least one of confidentiality, integrity, availability, and importance.

[0029] The software information of the cloud platform assets is managed; wherein the software information includes at least one of the following: middleware, application, open source framework version, and application scenario information.

[0030] In one embodiment, the multi-faceted asset security audit based on the operational security posture data of the cloud platform assets includes:

[0031] Based on the operational security status data of the cloud platform assets, at least one of the following is performed on the cloud platform assets: system baseline audit, file integrity audit, unauthorized external connection audit, web application audit, protocol vulnerability audit, and asset vulnerability audit; wherein, the system baseline audit is to audit the configuration baseline of the application; the unauthorized external connection audit is to audit the application that is not on the whitelist and performs external connection operations.

[0032] In one embodiment, the multi-faceted asset security audit based on the operational security posture data of the cloud platform assets includes:

[0033] Low-level operational security posture data is extracted, transformed, and loaded to obtain normalized data. The normalized data is then input into the correlation analysis engine to obtain high-level operational security posture data. The low-level operational security posture data consists of the operational security posture data of individual assets, while the high-level operational security posture data consists of multi-source and multi-step network attack events. The correlation analysis engine performs correlation analysis based on the Apriori correlation rule analysis algorithm.

[0034] According to a second aspect, the cloud platform asset monitoring device provided in the embodiments of the present invention includes:

[0035] The exploration and management module is used to obtain cloud platform assets through proactive exploration and proactive reporting through agent services deployed on the cloud platform, and to manage the ledger of the cloud platform assets.

[0036] The continuous monitoring module is used to monitor the dynamic changes of the cloud platform assets.

[0037] The data acquisition module is used to acquire operational security status data of the cloud platform assets;

[0038] The asset audit module is used to perform multi-faceted asset security audits based on the operational security status data of the cloud platform assets, and obtain audit results of the cloud platform assets in multiple aspects of security risks.

[0039] The report generation module is used to generate a corresponding security analysis report based on the security risk audit results.

[0040] According to a third aspect, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method provided in the first aspect.

[0041] According to a fourth aspect, the computing device provided in the embodiments of the present invention includes a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements the method provided in the first aspect.

[0042] The cloud platform asset monitoring method, apparatus, medium, and equipment provided in this invention utilize active probing and proactive reporting via agent services deployed on the cloud platform to obtain cloud platform assets. They then manage the ledger of these assets and monitor their dynamic changes. During monitoring, operational security status data of the cloud platform assets is acquired. Based on this data, multi-faceted asset security audits are performed to obtain security risk audit results. Finally, a corresponding security analysis report is generated based on these results. Therefore, in a cloud platform network environment, this invention enables the monitoring, tracking, and ledger management of network assets. Furthermore, based on the vulnerabilities and internal / external threats to network assets, it achieves asset security audits and provides security analysis reports. Thus, this invention can monitor asset status, manage asset ledgers, and perform security audits, effectively supporting secure operation and management in network scenarios and improving the efficiency and effectiveness of enterprise cloud platform security operations. Furthermore, by monitoring the status and conducting security audits of enterprise cloud platform assets, this invention enables real-time detection of the current status of assets, helps enterprises organize asset information, establish a trusted asset management database, thereby constructing a digital security base map for critical cloud platform infrastructure and improving cloud platform network security management capabilities. Attached Figure Description

[0043] Figure 1 This is a flowchart illustrating a cloud platform asset monitoring method according to an embodiment of the present invention;

[0044] Figure 2 This is an overall flowchart of a cloud platform asset monitoring method in one embodiment of the present invention;

[0045] Figure 3 This is an overall flowchart of a cloud platform asset monitoring method in one embodiment of the present invention;

[0046] Figure 4 This is a schematic diagram of the association analysis process in one embodiment of the present invention;

[0047] Figure 5 This is a structural block diagram of a cloud platform asset monitoring device according to an embodiment of the present invention. Detailed Implementation

[0048] In a first aspect, embodiments of the present invention provide a cloud platform asset monitoring method, see [link to relevant documentation]. Figure 1 , Figure 2 and Figure 3 The method includes the following steps S110 to S150:

[0049] S110. Obtain cloud platform assets by actively exploring and actively reporting through agent services deployed on the cloud platform, and manage the ledger of the cloud platform assets.

[0050] Among them, the content detected by active probing methods mainly includes asset viability, service ports, services, network protocols, and basic information.

[0051] In one embodiment, see Figure 3 Obtaining cloud platform assets through proactive exploration can include at least one of the following:

[0052] (1) Identify the liveness of cloud platform assets and obtain cloud platform assets that are in normal operating condition;

[0053] In this context, "survivability" refers to whether an asset is in normal operating condition. In this embodiment of the invention, we need to focus on assets that are in normal operating condition.

[0054] (2) Scan the service ports using a stateless scanning method to obtain the service ports that are in an open state; wherein, the stateless scanning method is: send probe packets to the corrected IP address of each service port based on coroutine concurrency technology, and determine whether the service port is in an open state based on whether each service port responds and the content of the response; wherein, the corrected IP address is the IP address obtained by hashing the original IP address of the service port;

[0055] The service ports are mainly TCP and UDP service ports, especially TCP service ports. Service ports must be open to provide the corresponding services; otherwise, no service can be provided. Therefore, by detecting which service ports are open, we can determine which services are available.

[0056] The stateless scanning method targets TCP service ports, employing an incomplete TCP two-way handshake. The client sends a probe packet containing synchronization information; the service port replies with synchronization information plus an acknowledgment. Whether the service port is operational is determined by whether it responds with both. The probe packets are sent using coroutine concurrency, where a single coroutine simultaneously sends probe packets to various IP addresses within a given IP range. The corrected IP address is obtained by hashing the original IP address of the service port; this avoids triggering the target firewall's filtering rules and blocking the probe packets due to continuous packet sending.

[0057] (3) Obtain the network protocol of the service port through a deep scan method; wherein, the deep scan method is as follows: obtain a port open service probability table, the port open service probability table records the probability of each of multiple service ports corresponding to at least one network protocol, obtain the network protocol with the highest probability corresponding to each service port from the port open service probability table as the current first network protocol; scan for the current first network protocol; if the current first network protocol is successfully scanned, then the current first network protocol is the network protocol used by the service provided by the service port; if the current first network protocol is not scanned, then the network protocol with the second highest probability corresponding to the service port in the port open service probability table is taken as the current first network protocol, and return to the step of scanning the current first network protocol; and so on, until the network protocol used by the service provided by the service port is determined.

[0058] As can be seen, deep scanning is used to interact with cloud platform assets via protocols. Each service port provides one service, but it's uncertain which service it provides. Each service corresponds to a network protocol, but there's a port open service probability table. This table records multiple probabilities for each service port. For example, a service port x might have two probabilities: probability 'a' is the probability that the service port provides the first service (i.e., probability 'a' is the probability that the service port corresponds to the network protocol for the first service); probability 'b' is the probability that the service port provides the second service (i.e., probability 'b' is the probability that the service port corresponds to the network protocol for the second service). Probability 'a' is greater than probability 'b'. During deep scanning, for service port x, the network protocol corresponding to the first service is scanned first. If the network protocol corresponding to the first service is found, service port x is considered to provide the first service and corresponds to the network protocol for the first service. If the network protocol corresponding to the first service is not found, the network protocol corresponding to the second service is scanned. If the network protocol corresponding to the second service is found, service port x is considered to provide the second service and corresponds to the network protocol for the second service.

[0059] For example, for service port 21, the probability of this service port corresponding to the FTP protocol is the highest. Therefore, it is necessary to scan for this protocol first. If it fails, then try the next highest probability protocol, until the detection is completed.

[0060] Among them, the deep scanning method uses coroutine technology similar to the Go language to refine the use of resources and better utilize the concurrency capabilities of multi-core CPUs, thereby improving the scanning speed.

[0061] Furthermore, the method of obtaining cloud platform assets through proactive exploration may also include:

[0062] The manufacturer information of the cloud platform assets is obtained by calling the device manufacturer database;

[0063] By calling the component identifier library, the component type and component version of the cloud platform asset can be obtained;

[0064] By calling the operating system type library, the operating system type and operating system version of the cloud platform assets can be obtained;

[0065] The device type of the cloud platform assets is obtained by calling the device type library;

[0066] By calling the product type library, the product type and product version of the cloud platform assets can be obtained;

[0067] The cloud platform assets are marked with information using at least one of the following: the manufacturer information, the component type, the component version, the operating system type, the operating system version, the device type, the product type, and the product version.

[0068] As can be seen, by calling the corresponding database, relevant data information can be obtained, and then this data information can be used to mark the cloud platform assets.

[0069] Understandably, the advantages of proactive asset exploration are: better real-time asset exploration, higher degree of automation, and higher accuracy.

[0070] In one embodiment, obtaining cloud platform assets by actively reporting through an agent service deployed on the cloud platform may include: periodically collecting asset information on the cloud platform host using the agent service deployed on the cloud platform, and reporting the collected asset information.

[0071] Among them, the agent service is deployed on the host of the cloud platform. The agent collects asset information on the host of the cloud platform in real time and then reports the collected asset information.

[0072] Understandably, while the agent collects and reports asset information, it can also collect and report other information, such as network security event logs, system alarm logs, and user operation alarm logs, as described in S130 below. Compared to proactive probing, the agent-based monitoring and reporting method has the advantage of obtaining higher-quality and richer host system security data and effectively pushing it to the analysis platform. At the same time, it can alleviate firewall blocking issues to some extent.

[0073] As can be seen, two methods are used for acquiring and monitoring assets on the cloud platform: proactive exploration and agent-based monitoring and reporting. Assets on the cloud platform are complex, involving management node layers, compute node layers, storage node layers, and hyperconverged node layers, with assets at each layer having coupling relationships and mutual access. Due to the control policies of perimeter security systems such as firewalls and cloud WAFs, some assets cannot be externally probed and scanned. In such cases, the approach is to deploy agents within the cloud platform, which collect security logs, system logs, and operation logs from the hosts and then report this data.

[0074] In one embodiment, the management of the ledger of the cloud platform assets may include at least one of the following:

[0075] (1) The cloud platform assets are managed separately according to asset type; wherein, the asset type includes cloud host, WEB website, network equipment, security equipment and operation and maintenance equipment;

[0076] That is, to classify and manage cloud platform assets.

[0077] (2) Manage the asset fingerprint information of the cloud platform assets; wherein the asset fingerprint information includes at least one of the following: asset name, group, responsible person, IP address, MAC code, manufacturer, geographical location, usage status and operating system;

[0078] Among them, asset fingerprint information refers to the core attribute information of cloud platform assets.

[0079] (3) Manage the business value of the cloud platform assets; wherein the business value includes at least one of confidentiality, integrity, availability and importance;

[0080] Importance refers to the importance of the business systems running on the cloud platform assets.

[0081] (4) Manage the software information of the cloud platform assets; wherein the software information includes at least one of the following: middleware, application, open source framework version and application scenario information.

[0082] As can be seen, ledger management is essentially the operation of managing various information about cloud platform assets. After managing the detailed information of cloud platform assets, more effective security risk assessments can be conducted. When a vulnerability is discovered and disclosed on the internet in a particular version of a certain type of asset, an assessment can be made based on the managed information, combined with the importance of the asset, the severity of the vulnerability, the likelihood of external attacks, and collected alert data. Simultaneously, ledger management also provides a basis for monitoring illegal assets within the cloud platform's security domain.

[0083] Understandably, ledger management helps to identify the exposure of cloud platform assets, clarify asset management responsibilities, refine the details of asset management, and promptly rectify security issues.

[0084] S120. Monitor the dynamic changes of the cloud platform assets;

[0085] Understandably, cloud platform assets are dynamic, and asset information can be changed manually or automatically. Therefore, after acquiring and marking the asset information of each cloud platform asset through S110, continuous monitoring is performed through S120 to determine the specific changes that have occurred. Changes in cloud platform assets and their information may alter the operational security posture of the cloud platform assets; therefore, monitoring the dynamic changes of cloud platform assets is a crucial operation for ensuring their security.

[0086] S130. Obtain the operational security status data of the cloud platform assets;

[0087] The operational security posture data may include log data related to alarms, faults, and vulnerabilities. That is, if alarms, faults, or vulnerabilities are generated during the monitoring of dynamic changes in the cloud platform assets, the relevant log data will be reported.

[0088] In one embodiment, obtaining the operational security status data of the cloud platform assets may include: periodically collecting at least one of the network security event logs, system alarm logs, and user operation alarm logs on the cloud platform host using an agent service deployed on the cloud platform, and reporting the at least one of them.

[0089] S140. Based on the operational security status data of the cloud platform assets, conduct multi-faceted asset security audits to obtain the audit results of the cloud platform assets in multiple aspects of security risks.

[0090] Understandably, security risk audit results can be obtained in two ways: one is a security assessment based on vulnerability databases, which uses asset characteristics to match operating systems, middleware, application services, etc., and has the characteristics of being secure, lossless, and efficient; the other is an agent service running on cloud platform assets, which collects information such as security logs, baseline configurations, system file integrity, and unauthorized external connections on the assets.

[0091] The step of conducting multi-faceted asset security audits based on the operational security status data of the cloud platform assets may include: performing at least one of the following on the cloud platform assets based on the operational security status data: system baseline audit, file integrity audit, unauthorized external connection audit, web application audit, protocol vulnerability audit, and asset vulnerability audit; wherein the system baseline audit is an audit of the configuration baseline of the application; and the unauthorized external connection audit is an audit of applications that are not on the whitelist and are performing external connection operations.

[0092] System baseline auditing refers to auditing whether the configuration baseline of the application is reasonable. File integrity auditing refers to auditing the integrity of files on cloud platform assets. Unauthorized external connection auditing refers to auditing whether any applications not on the whitelist are performing external connection operations. Whitelisted applications are allowed to perform external connection operations. Applications not on the whitelist are not allowed to perform external connection operations; if they do, it indicates an unauthorized operation. Web application auditing refers to auditing web applications. Protocol vulnerability auditing refers to auditing whether network protocols are vulnerable, and asset vulnerability auditing refers to auditing whether cloud platform assets have vulnerabilities.

[0093] In one embodiment, see Figure 4 The step of conducting multi-faceted asset security audits based on the operational security posture data of the cloud platform assets may include: extracting, transforming, and loading low-level operational security posture data to obtain normalized data, and inputting the normalized data into a correlation analysis engine to obtain high-level operational security posture data; wherein, the low-level operational security posture data is the operational security posture data of each individual asset, and the high-level operational security posture data is multi-source and multi-step network attack events; the correlation analysis engine performs correlation analysis based on the Apriori correlation rule analysis algorithm.

[0094] Extraction, transformation, and loading processes constitute ETL technology.

[0095] It is evident that low-level operational security posture data, such as various alarms from a single cloud platform asset, can be processed by ETL to form normalized data, which can mask the differences in data from external devices. The normalized data, together with existing assets, vulnerabilities, and correlation rules, is then processed by a correlation analysis engine to obtain high-level operational security posture data. This data is more accurate and effective, and is used to support subsequent security assessments and security report generation.

[0096] The high-level operational security situation data refers to multi-source, multi-step network attack events.

[0097] The association analysis engine performs association analysis based on the Apriori association rule analysis algorithm.

[0098] Most attacks on cloud platform networks, especially those with significant impact (such as APTs, ransomware, and cryptocurrency mining), are typically multi-source and multi-step attacks. The low-level operational security posture data detected by network security neural devices are often discrete and isolated. Therefore, identifying the various stages of multi-source, multi-step attacks from numerous security incidents and linking them to establish attack chains is a crucial research area in security incident correlation analysis. Correlation analysis of complex attacks primarily studies the relationships between attack steps, providing technical support for attack scenario construction and security auditing.

[0099] During association analysis, the engine employs the Apriori association rule analysis algorithm. Apriori is a commonly used association rule algorithm in data mining, primarily used to find frequently occurring sets of associations within a dataset, thereby aiding in security analysis. A deeper analysis of the Apriori association rule analysis algorithm reveals its application in network intrusion behavior analysis. By establishing associations between assets, vulnerabilities, security events, and alerts, the algorithm uncovers abnormal access behaviors to cloud hosts within the network, enabling the discovery of multi-source, multi-step network attack events and enhancing the system's security analysis capabilities.

[0100] S150. Based on the security risk audit results, generate a corresponding security analysis report.

[0101] As can be seen, the embodiments of this invention mainly involve several stages, including asset monitoring, ledger management, and security auditing. The asset monitoring stage involves asset viability detection, deep asset scanning, and asset tagging. The ledger management stage manages the classification, attributes, value, and various middleware and applications running on the assets. In the security auditing stage, by associating the asset ledger with information such as vulnerabilities, security events, and security alarms, the security auditing of cloud platform assets is achieved, and corresponding security reports and security assessments are provided. The embodiments of this invention are primarily aimed at asset monitoring and security auditing of cloud platforms, and can effectively support secure operation and management in network scenarios.

[0102] Understandably, with the continuous development of the internet industry, more and more enterprises are shifting their businesses towards "digitalization" and "cloudification," resulting in more diverse, complex, and large-scale enterprise cloud platform assets. Enterprise cloud platform assets involve management node layers, computing node layers, storage node layers, and hyper-converged node layers, with coupling and mutual access relationships between assets at each layer. These relationships give rise to increasingly complex and serious security issues related to various assets such as networks, hosts, data, and applications. Addressing the urgent need for cloud platform network asset monitoring and security auditing, this invention, through status monitoring and security auditing of enterprise cloud platform assets, can detect the current status of assets in real time, such as additions, disappearances, attribute adjustments, vulnerability changes, configuration changes, security events, and alarms. This helps enterprises organize asset information, establish a trusted asset management database, thereby constructing a digital security foundation for critical cloud platform infrastructure and improving cloud platform network security management capabilities.

[0103] Understandably, cloud platform asset monitoring is fundamental to vulnerability and threat management. Without robust real-time monitoring and auditing measures for network assets, it's difficult to effectively integrate business operations with security efforts. When vulnerabilities and threats emerge, it's challenging to quickly assess the impact on the enterprise's cloud platform and implement timely and effective protective measures. This invention addresses the complexity of cloud platform asset security monitoring by providing a cloud platform asset monitoring and security auditing solution. Within the cloud platform network environment, it enables monitoring, tracking, and ledger management of network assets. Simultaneously, based on the vulnerabilities and internal / external threats to network assets, it performs security audits and provides security analysis reports. Therefore, this invention effectively monitors asset status, manages asset ledgers, and conducts security audits, demonstrating significant application value.

[0104] Through the embodiments of the present invention, users can monitor assets in the enterprise cloud platform in real time, promptly discover asset exposure, vulnerabilities, complex attacks, etc., and generate corresponding security analysis reports, thereby improving the efficiency and effectiveness of the enterprise cloud platform's security operation.

[0105] The embodiments of the present invention have the following effects:

[0106] (1) It has enabled refined management of cloud platform assets.

[0107] Establish a detailed ledger for cloud platform asset management, and monitor various types of assets in the enterprise cloud platform in real time, including cloud servers, websites, network devices, and security devices. By continuously monitoring assets, detect asset changes, and promptly identify the exposure surface and scope of asset vulnerabilities, when new vulnerabilities emerge, the tagged asset information helps to quickly locate potentially affected assets, assisting users in identifying and fixing vulnerabilities.

[0108] (2) The asset monitoring has a high degree of automation and high accuracy.

[0109] By combining proactive exploration with agent-based monitoring and reporting, it features a high degree of automation and accuracy in network asset detection.

[0110] (3) Provide strong security audit capabilities to improve the efficiency and effectiveness of security operations. Through core technologies such as data normalization and correlation analysis, audit asset vulnerabilities, security incidents and alarms, guide on-site personnel to carry out security operations, and provide network security reports for security operations.

[0111] Secondly, embodiments of the present invention provide a cloud platform asset monitoring device, see [link to relevant documentation]. Figure 5 The device 100 includes:

[0112] The exploration and management module 110 is used to obtain cloud platform assets by means of active exploration and active reporting by proxy services deployed on the cloud platform, and to manage the ledger of the cloud platform assets.

[0113] The continuous monitoring module 120 is used to monitor the dynamic changes of the cloud platform assets;

[0114] The data acquisition module 130 is used to acquire the operational security status data of the cloud platform assets;

[0115] The asset audit module 140 is used to perform multi-faceted asset security audits based on the operational security status data of the cloud platform assets, and obtain the audit results of the cloud platform assets in multiple aspects of security risks.

[0116] The report generation module 150 is used to generate a corresponding security analysis report based on the security risk audit results.

[0117] In one embodiment, the exploration management module is specifically configured to perform at least one of the following:

[0118] Identify the viability of cloud platform assets to obtain cloud platform assets that are in normal operating condition;

[0119] The service ports are scanned using a stateless scanning method to identify those that are open. This stateless scanning method involves sending probe packets to the corrected IP addresses of each service port using coroutine concurrency technology, and determining whether a service port is open based on whether and what the response is from each service port. The corrected IP address is the IP address obtained by hashing the original IP address of the service port.

[0120] The network protocol of a service port is obtained through a deep scanning method. This deep scanning method involves: obtaining a port open service probability table, which records the probability of each service port corresponding to at least one network protocol; selecting the network protocol with the highest probability for each service port from the port open service probability table as the current first network protocol; scanning the current first network protocol; if the current first network protocol is successfully detected, then the current first network protocol is identified as the network protocol used for the service provided by that service port; if the current first network protocol is not detected, then the network protocol with the second highest probability for that service port in the port open service probability table is identified as the current first network protocol, and the process returns to the step of scanning the current first network protocol; this process continues until the network protocol used for the service provided by the service port is determined.

[0121] In one embodiment, the exploration management module is further configured to perform the following steps: obtaining the vendor information of the cloud platform asset by calling the device vendor library; obtaining the component type and component version of the cloud platform asset by calling the component identifier library; obtaining the operating system type and operating system version of the cloud platform asset by calling the operating system type library; obtaining the device type of the cloud platform asset by calling the device type library; obtaining the product type and product version of the cloud platform asset by calling the product type library; and marking the cloud platform asset with information using at least one of the vendor information, component type, component version, operating system type, operating system version, device type, product type, and product version.

[0122] In one embodiment, the exploration management module is specifically used to perform the following steps: periodically collect asset information on the cloud platform host using the agent service deployed on the cloud platform, and report the collected asset information; correspondingly, the data acquisition module is specifically used to: periodically collect at least one of the network security event logs, system alarm logs, and user operation alarm logs on the cloud platform host using the agent service deployed on the cloud platform, and report the at least one.

[0123] In one embodiment, the exploration and management module is specifically used for: managing the cloud platform assets according to asset type; wherein the asset types include cloud hosts, web websites, network devices, security devices, and maintenance devices; managing the asset fingerprint information of the cloud platform assets; wherein the asset fingerprint information includes at least one of asset name, group, responsible person, IP address, MAC code, manufacturer, geographical location, usage status, and operating system; managing the business value of the cloud platform assets; wherein the business value includes at least one of confidentiality, integrity, availability, and importance; and managing the software information of the cloud platform assets; wherein the software information includes at least one of middleware, application, open source framework version, and application scenario information.

[0124] In one embodiment, the asset audit module is specifically used to: perform at least one of the following on the cloud platform assets based on the operational security status data of the cloud platform assets: system baseline audit, file integrity audit, unauthorized external connection audit, web application audit, protocol vulnerability audit, and asset vulnerability audit; wherein, the system baseline audit is to audit the configuration baseline of the application; and the unauthorized external connection audit is to audit applications that are not on the whitelist and are performing external connection operations.

[0125] In one embodiment, the asset audit module is specifically used to: extract, transform, and load low-level operational security posture data to obtain normalized data, and input the normalized data into a correlation analysis engine to obtain high-level operational security posture data; wherein, the low-level operational security posture data is the operational security posture data of each individual asset, and the high-level operational security posture data is multi-source, multi-step network attack events; the correlation analysis engine performs correlation analysis based on the Apriori correlation rule analysis algorithm.

[0126] It is understood that explanations, specific implementation methods, beneficial effects, examples, etc. of the contents of the apparatus provided in the embodiments of the present invention can be found in the corresponding parts of the method provided in the first aspect, and will not be repeated here.

[0127] Thirdly, embodiments of the present invention provide a computer-readable medium storing computer instructions, which, when executed by a processor, cause the processor to perform the method provided in the first aspect.

[0128] Specifically, a system or apparatus equipped with a storage medium may be provided, on which software program code implementing the functions of any of the embodiments described above is stored, and the computer (or CPU or MPU) of the system or apparatus may read and execute the program code stored in the storage medium.

[0129] In this case, the program code read from the storage medium can itself implement the function of any of the above embodiments, and therefore the program code and the storage medium storing the program code constitute part of the present invention.

[0130] Examples of storage media used to provide program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Alternatively, program code can be downloaded from a server computer via a communication network.

[0131] Furthermore, it should be clear that not only can the program code read by the computer be executed, but also the operating system or other components operating on the computer can be instructed based on the program code to perform some or all of the actual operations, thereby realizing the function of any of the embodiments described above.

[0132] Furthermore, it is understood that the program code read from the storage medium is written to the memory set in the expansion board inserted into the computer or to the memory set in the expansion module connected to the computer. Then, based on the instructions of the program code, the CPU or other components installed on the expansion board or expansion module execute some and all of the actual operations, thereby realizing the function of any of the above embodiments.

[0133] It is understood that explanations, specific implementation methods, beneficial effects, examples, etc. of the contents in the computer-readable medium provided in the embodiments of the present invention can be found in the corresponding parts of the method provided in the first aspect, and will not be repeated here.

[0134] Fourthly, one embodiment of this specification provides a computing device including a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements the method of any embodiment of the specification.

[0135] It is understood that explanations, specific implementation methods, beneficial effects, examples, etc. of the computing device provided in the embodiments of the present invention can be found in the corresponding parts of the method provided in the first aspect, and will not be repeated here.

[0136] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the apparatus embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0137] Those skilled in the art will recognize that, in one or more of the examples above, the functions described in this invention can be implemented using hardware, software, widgets, or any combination thereof. When implemented in software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or code on a computer-readable medium.

[0138] The specific embodiments described above further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solution of the present invention should be included within the scope of protection of the present invention.

Claims

1. A cloud platform asset monitoring method, characterized in that, include: Cloud platform assets are obtained through proactive exploration and proactive reporting via agent services deployed on the cloud platform, and the ledger of the cloud platform assets is managed. Monitor the dynamic changes of the cloud platform assets; Obtain operational security status data of the cloud platform assets; Based on the operational security status data of the cloud platform assets, a multi-faceted asset security audit is conducted to obtain the audit results of the cloud platform assets in multiple aspects of security risks. Based on the security risk audit results, a corresponding security analysis report will be generated; The management of the ledger of the cloud platform assets includes at least one of the following: The cloud platform assets are managed separately according to asset type; wherein, the asset types include cloud servers, web websites, network equipment, security equipment, and operation and maintenance equipment; The asset fingerprint information of the cloud platform assets is managed; wherein the asset fingerprint information includes at least one of the following: asset name, group, responsible person, IP address, MAC code, manufacturer, geographical location, usage status, and operating system; The business value of the cloud platform assets is managed; wherein the business value includes at least one of confidentiality, integrity, availability, and importance. The software information of the cloud platform assets is managed; wherein the software information includes at least one of the following: middleware, application, open-source framework version, and application scenario information; The aforementioned asset security audit, based on the operational security status data of the cloud platform assets, involves multiple aspects, including: Based on the operational security status data of the cloud platform assets, at least one of the following is performed on the cloud platform assets: system baseline audit, file integrity audit, unauthorized external connection audit, web application audit, protocol vulnerability audit, and asset vulnerability audit; wherein, the system baseline audit is an audit of the configuration baseline of the application; the unauthorized external connection audit is an audit of applications that are not on the whitelist and are performing external connection operations; The aforementioned asset security audit, based on the operational security status data of the cloud platform assets, involves multiple aspects, including: Low-level operational security posture data is extracted, transformed, and loaded to obtain normalized data. The normalized data is then input into the correlation analysis engine to obtain high-level operational security posture data. The low-level operational security posture data consists of the operational security posture data of individual assets, while the high-level operational security posture data consists of multi-source and multi-step network attack events. The correlation analysis engine performs correlation analysis based on the Apriori correlation rule analysis algorithm.

2. The method according to claim 1, characterized in that, Acquiring cloud platform assets through proactive exploration methods, including at least one of the following: Identify the viability of cloud platform assets to obtain cloud platform assets that are in normal operating condition; The service ports are scanned using a stateless scanning method to identify those that are open. This stateless scanning method involves sending probe packets to the corrected IP addresses of each service port using coroutine concurrency technology, and determining whether a service port is open based on whether and what the response is from each service port. The corrected IP address is the IP address obtained by hashing the original IP address of the service port. The network protocol of a service port is obtained through a deep scanning method. This deep scanning method involves: obtaining a port open service probability table, which records the probability of each service port corresponding to at least one network protocol; selecting the network protocol with the highest probability for each service port from the port open service probability table as the current first network protocol; scanning the current first network protocol; if the current first network protocol is successfully detected, then the current first network protocol is identified as the network protocol used for the service provided by that service port; if the current first network protocol is not detected, then the network protocol with the second highest probability for that service port in the port open service probability table is identified as the current first network protocol, and the process returns to the step of scanning the current first network protocol; this process continues until the network protocol used for the service provided by the service port is determined.

3. The method according to claim 1, characterized in that, Acquiring cloud platform assets through proactive exploration also includes: The manufacturer information of the cloud platform assets is obtained by calling the device manufacturer database; By calling the component identifier library, the component type and component version of the cloud platform asset can be obtained; By calling the operating system type library, the operating system type and operating system version of the cloud platform assets can be obtained; The device type of the cloud platform assets is obtained by calling the device type library; By calling the product type library, the product type and product version of the cloud platform assets can be obtained; The cloud platform assets are marked with information using at least one of the following: the manufacturer information, the component type, the component version, the operating system type, the operating system version, the device type, the product type, and the product version.

4. The method according to claim 1, characterized in that, Cloud platform assets are obtained by proactively reporting through agent services deployed on the cloud platform, including: The agent service deployed on the cloud platform is used to collect asset information on the cloud platform host at regular intervals and report the collected asset information. Correspondingly, obtaining the operational security status data of the cloud platform assets includes: The agent service deployed on the cloud platform periodically collects at least one of the following from the cloud platform host: network security event logs, system alarm logs, and user operation alarm logs, and reports the at least one of them.

Citation Information

Patent Citations

  • A security situation assessment system for a multi-source heterogeneous information cloud platform

    CN109873786A

  • Method, device and equipment for monitoring cloud security and computer storage medium

    CN109962891A