Security patch system, and monitoring method and device for protected system

CN119232449BActive Publication Date: 2026-09-08CHINA MOBILE GRP GUANGDONG CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411314828.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-09-20
Publication Date
2026-09-08
Estimated Expiration
2044-09-20

AI Technical Summary

Technical Problem

[0003]为了解决上述技术问题,本公开提供了一种安全贴片系统,及受防护系统的监测方法、装置,有效解决了无法监控蜜罐系统外的状态,同时存在被识别并绕过的可能性,同时由于蜜罐系统对网络行为模拟的复杂性的增加,也会增加蜜罐系统受到攻击的可能性的技术问题

Benefits of technology

[0037] This disclosure provides a security patch system, including a security patch, a traffic monitor, an interaction monitor, a time monitor, and a patch controller. By applying the security patch system provided by this disclosure, multiple network security detection and defense capabilities can be achieved through lightweight deployment and with minimal resource consumption, via corresponding control and interaction steps. This enables more accurate detection and services, and provides platform-based and multi-dimensional security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119232449B_ABST
    Figure CN119232449B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a security patch system, and a monitoring method and device of a protected system, effectively solving the technical problem that the state outside the honeypot system cannot be monitored, and there is a possibility of being identified and bypassed, and as the complexity of the network behavior simulation of the honeypot system increases, the possibility of the honeypot system being attacked also increases, the system comprising a security patch, a traffic monitor, an interaction monitor, a time monitor and a patch controller.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of network security management technology, and in particular to a security patch system, and a monitoring method and apparatus for the protected system. Background Technology

[0002] Cybersecurity is a crucial safeguard for information technology infrastructure development. Cybersecurity technologies and equipment include firewalls, antivirus software and intrusion detection systems (IDS), honeypot systems, VPNs, and security auditing. However, among these technologies, honeypot systems have certain limitations. They cannot monitor the state outside the honeypot system and are susceptible to being identified and bypassed. Furthermore, the increased complexity of network behavior simulation by honeypot systems also increases their vulnerability to attack. Summary of the Invention

[0003] To address the aforementioned technical problems, this disclosure provides a security patch system and a monitoring method and apparatus for the protected system, effectively solving the technical issues of being unable to monitor the state outside the honeypot system, the possibility of being identified and bypassed, and the increased possibility of the honeypot system being attacked due to the increased complexity of the network behavior simulation of the honeypot system.

[0004] In a first aspect, embodiments of this disclosure provide a security patch system, including a security patch, a traffic monitor, an interaction monitor, a time monitor, and a patch controller, wherein:

[0005] Security patches are installed on the protected system to acquire traffic and system resource data of the protected system;

[0006] The time monitor is used to monitor the runtime of the safety patch;

[0007] Flow monitors are used to monitor the flow status of a protected system based on flow data;

[0008] The interaction monitor is used to monitor the interaction status of the protected system based on system resource data;

[0009] The patch controller is used to install safety patches on the protected system and determine the operating status of the safety patches.

[0010] Secondly, embodiments of this disclosure provide a monitoring method for a protected system, the method comprising:

[0011] Obtain traffic data and system resource data of the protected system;

[0012] The operating status of the security patch is determined based on traffic data and system resource data;

[0013] When an abnormal operating status is detected, an alarm message is issued.

[0014] In one possible implementation, the method provided in this embodiment of the invention determines the operating status of the security patch based on traffic data and system resource data, including:

[0015] Monitor the traffic status of the protected system based on traffic data;

[0016] Monitor the interaction status of the protected system based on system resource data;

[0017] The traffic status and interaction status are determined as the operating status of the security patch.

[0018] In one possible implementation, the method provided in this embodiment of the invention further includes:

[0019] If no traffic data or system resource data is received within the preset time period, the system is determined to be in an abnormal operating state and an alarm message is issued.

[0020] Thirdly, embodiments of this disclosure provide a monitoring device for a protected system, the device comprising:

[0021] The acquisition unit is used to acquire traffic data and system resource data of the protected system.

[0022] The determination unit is used to determine the operating status of the security patch based on traffic data and system resource data;

[0023] The alarm unit is used to issue alarm information when an abnormal operating status is detected.

[0024] In one possible implementation, the determining unit in the apparatus provided by the embodiments of the present invention is specifically used for:

[0025] Monitor the traffic status of the protected system based on traffic data;

[0026] Monitor the interaction status of the protected system based on system resource data;

[0027] The traffic status and interaction status are determined as the operating status of the security patch.

[0028] In one possible implementation, the alarm unit in the apparatus provided by the embodiments of the present invention is further configured to:

[0029] If no traffic data or system resource data is received within the preset time period, the system is determined to be in an abnormal operating state and an alarm message is issued.

[0030] Fourthly, embodiments of this disclosure provide an electronic device, including:

[0031] Memory;

[0032] Processor; and

[0033] Computer programs;

[0034] The computer program is stored in memory and configured to be executed by a processor to implement the monitoring method for the protected system as described above.

[0035] Fifthly, embodiments of this disclosure provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the monitoring method for the protected system as described above.

[0036] Sixthly, embodiments of this disclosure also provide a computer program product, including a computer program that, when executed by a processor, implements a monitoring method for any of the protected systems described above.

[0037] This disclosure provides a security patch system, including a security patch, a traffic monitor, an interaction monitor, a time monitor, and a patch controller. By applying the security patch system provided by this disclosure, multiple network security detection and defense capabilities can be achieved through lightweight deployment and with minimal resource consumption, via corresponding control and interaction steps. This enables more accurate detection and services, and provides platform-based and multi-dimensional security protection. Attached Figure Description

[0038] The accompanying drawings, which are incorporated in and form a part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure.

[0039] To more clearly illustrate the technical solutions in the embodiments of this disclosure or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0040] Figure 1 This is a schematic diagram of the structure of a security patch system provided in an embodiment of the present disclosure;

[0041] Figure 2 A schematic flowchart illustrating a monitoring method for a protected system provided in an embodiment of this disclosure;

[0042] Figure 3 An interactive schematic diagram of a monitoring method for a protected system provided in an embodiment of this disclosure;

[0043] Figure 4 A schematic diagram of the structure of a monitoring device for a protected system provided in an embodiment of this disclosure;

[0044] Figure 5This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure. Detailed Implementation

[0045] To better understand the above-mentioned objectives, features, and advantages of this disclosure, the solutions disclosed herein will be further described below. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.

[0046] Numerous specific details are set forth in the following description in order to provide a full understanding of this disclosure, but this disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only some, and not all, of the embodiments of this disclosure.

[0047] 1. In the embodiments of this invention, the term "and / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.

[0048] Cybersecurity is a crucial safeguard for information technology infrastructure development. Cybersecurity technologies and equipment include firewalls, antivirus software and intrusion detection systems (IDS), honeypot systems, VPNs, and security auditing. Because network technologies and services are constantly evolving, the number and types of security vulnerabilities related to network and host hardware and software are also constantly changing. Therefore, continuous improvement and upgrading of cybersecurity protection technologies and methods are necessary. Cybersecurity honeypot systems are a commonly used security protection method. Based on risk vulnerability camouflage technology, they deploy detectable vulnerabilities along the critical paths of attacker intrusion, making it easy for attackers to target these vulnerabilities and launch attacks. This allows for timely and effective monitoring of attack behavior, improving network and system security and stability. Taking commonly used cybersecurity honeypot systems as an example, deploying information exchange strategies with varying degrees of interaction within the honeypot system can attract and prevent various network attack behaviors.

[0049] Honeypot systems have certain limitations. (1) Existing technical solutions mainly focus on the deployment of honeypot systems in various scenarios, as well as the optimization of honeypot functions and the enhancement of protection functions. Although honeypot network security technology will help discover network threats, honeypots will not see everything that is happening, but only the activities targeting the honeypot. (2) Although the goal of honeypots is to deceive attackers into believing that they have gained access to the real system, if an attacker successfully identifies it as a fake honeypot, the attacker will continue to attack other systems without contacting the honeypot. (3) Once a honeypot is identified by an attacker, the attacker can launch a deceptive attack to divert attention and actually attack the production system. They will also provide the honeypot with incorrect information. (4) Attackers may use honeypots as a way to enter the system. Honeypots may be used as a stepping stone for further intrusion. As the complexity of the network behavior simulation of honeypot systems increases, the possibility of honeypot systems being attacked also increases.

[0050] Figure 1 This is a schematic diagram of the structure of a security patch system provided in an embodiment of the present disclosure, as shown below. Figure 1As shown, in practical use, this includes the protected system and the applications running on it, network security patches, traffic monitors, interaction monitors, time monitors, and patch controllers. A network security patch is a lightweight, isolated, dynamically generated, and managed hardware and software integrated module that includes honeypot decoys, risk identification, security protection, security monitoring, content security, vulnerability scanning, security penetration testing, threat intelligence, situational awareness, capability orchestration, and physical security functions. The honeypot decoy function of network security patches can be customized to simulate the protected system. Common simulation system types include those with various common network services and applications related to the protected system, such as email systems, office systems, and other network security assets with high attack value. When it is necessary to customize honeypot simulation functions for a target protected system, network security patches can be deployed on the corresponding protected system. Security patches with network monitoring capabilities can then monitor the target system's traffic, analyze its interaction protocols and traffic characteristics, and learn its characteristic behaviors. (2) The patch controller, as the central control system, possesses general-purpose simulation software and logic for various network services. It can customize and generate corresponding decoy functions according to protection needs and deliver them to the network security patches for execution. The protected system first obtains information on the network and system resources used by each application within the system. Then, it submits data on the applications within the registered system and their network and system resource usage to the network security patch controller. The network security patch controller needs to verify the validity of the relevant data with the protected system. Based on this data and scenario, the network security patch controller creates dynamic network security patches and installs them in the protected system. After the network security patches are installed, the traffic monitor detects the network security patch traffic and reports to the network security patch controller; the interaction monitor monitors the network security patch interaction behavior and reports to the network security patch controller; the time monitor monitors the network security patch runtime and reports to the network security patch controller; and the network security patch controller notifies the network security patches to execute corresponding strategies based on the operating status.

[0051] Figure 2 A flowchart illustrating a monitoring method for a protected system provided in this disclosure embodiment is shown, specifically including as follows: Figure 2 The following steps S201 to S203 are shown:

[0052] S201. Obtain traffic data and system resource data of the protected system.

[0053] In practice, the first step is to install a security patch on the protected system. During installation, the network and system resources used by the application should be obtained. The protected system should provide information on the network and system resources used by the system, including the name of each application, the IP address it occupies, the protocol, the port, the network interface, the file directory, and the protection requirements.

[0054] The following are examples of network and system resources.

[0055]

[0056]

[0057] The protected system submits application data to the network security patch controller to request the installation of network security patches in the system. The following is an example of requesting the installation of network security patches for two applications (webserver and dbserver).

[0058]

[0059] At this point, the patch controller can confirm the application data list with the protected system. Then, the patch controller creates and installs dynamic network security patches for the protected system. The steps involved include analyzing application scenarios, developing protection strategies, creating network security patches, and deploying network security patches. The steps for installing dynamic network security patches (hereinafter referred to as: Patch Startup Method A) are as follows:

[0060] (1) Copy or download the basic module of Dynamic Network Security Patch (hereinafter referred to as DCSPROC) to the corresponding directory of the protected system.

[0061] (2) The resources that the dynamic network security patch dcsproc can occupy are limited by the protection system, including CPU (C), memory (M), hard disk resources (H), directory (D), and network bandwidth (B), so as to prevent it from being used as a springboard after being attacked by third-party applications; since the availability of resources is constantly changing, these resource restrictions need to be constantly updated for the patch.

[0062] (3) Modify the corresponding configuration of the protected system to hide dcsproc. For example, modify commonly used process viewing tools such as ps, pslist, and Task Manager to prevent them from displaying any information about dcsproc, thereby hiding the dcsproc process.

[0063] (4) The protected system starts dcsproc with the system management privileges to enable it to monitor network traffic.

[0064] (5) dcsproc, which has system management privileges, can monitor the traffic of each network card of the protected system and send data directly at the network card level without calling other library functions in the protected system, thereby reducing the possibility of being discovered and intercepted by third-party processes.

[0065] (6) After completing the above steps, the dcsproc process will reside in the protected system as a dynamic network security patch, and will have extremely high concealment, isolation and security.

[0066] S202. Determine the operating status of the security patch based on traffic data and system resource data.

[0067] In practice, after the network security patch resides in the protected system, it dynamically realizes various honeypot decoy forms and capabilities, and provides corresponding simulation responses and traps according to the simulated business type; it performs functions such as risk identification, security protection, security monitoring, content security, security vulnerability scanning, security penetration, threat intelligence, situational awareness, capability orchestration, and physical security as required.

[0068] The traffic monitor tracks network security patch traffic by having the network security patch listen to network interface card (NIC) packets and send traffic statistics to the traffic monitor via the NIC. For various network protocols and service primitives, the patch listens for the {request, response} characteristic pairs of their interactions and feeds them directly back to the patch controller via the NIC. This allows for the learning of the target system's behavior without affecting business operations. The learning result is a series of interaction {request, response} characteristic pairs, which are reported to the patch controller as the interaction logic characteristics of the protected system. The proposal defines the following representation for a request (req): {IP version, protocol, source port, destination port, request packet}; and the proposal defines the following representation for a response (res): {IP version, protocol, source port, destination port, response packet}.

[0069] The traffic monitor reports network security patch traffic to the network security patch controller as follows: Upon receiving the traffic information from the patch report, the patch controller first learns and adjusts the {response} information. For this series of {requests, responses}, such as {request 1, response 1}, {request 2, response 2}, {request 3, response 3},..., the patch controller can determine the threat level of each {request, response} based on the characteristics of the protected system. This can be based on sensitive keywords or action characteristics contained in the request or response information, or on commonly used intrusion detection mechanisms. The patch controller assigns a value to the {request, response} based on its threat level. The higher the threat, the higher the value. The threat value ranges from 0 to 100, resulting in a decoy simulation logic triple (Decoy3): {request, response, threat value}. The patch controller can further formulate decoy actions based on the {request, response}, resulting in a decoy simulation logic quadruple (Decoy4): {request, response, threat value, decoy action}. The decoy action is defined as the action information sent to the attacker, which may include {bait information, delay, social media account interception, fingerprinting}, etc. This information can be sent to the attacker by the patch via IP packets to obtain feedback and take further action based on the feedback. It should be noted that the above-described process of interactive learning, threat assignment, and decoy strategy formulation is also applicable to other general network services, thus enabling the patch controller to achieve more comprehensive simulation and decoy capabilities. The network security patch monitors network traffic, analyzes potential security attacks, and feeds back the behavioral sequence, i.e., {request 1, request 2,...}, to the patch controller in real time. The patch controller combines its own decoy simulation logic with the newly learned logic to analyze the behavioral sequence and find the business decoy simulation logic quadruple (Decoy4) most similar to the behavior. Then, it sends a series of corresponding decoy simulation logic quadruples (Decoy4) to the network security patch.

[0070] The cybersecurity patch provides a corresponding response to the attack based on this dataset.

[0071] When the threat value corresponding to a requested action reaches a preset threshold, triggering the corresponding alarm threshold, the patch sends an alarm to the patch controller and initiates the decoy function locally. In the above steps, the request information req0 provided by the patch includes {IP version, protocol, source port, destination port, request data packet}. The patch controller relies on its own stored database of request signatures. Based on the request information provided by the patch, the following methods are used to find and identify the attack most similar to that request.

[0072] (a) For all requests reqx stored in the patch controller, calculate the similarity distance with req0 respectively:

[0073] Dx = |IP version difference| + |protocol difference| + |destination port difference| + |request packet difference| + |source port difference| * alpha

[0074] (b) The difference value is the edit distance of the string, and alpha is the matching degree of the source port, with a default value of 0. If two reqx values ​​are the same, it is necessary to further determine whether the data was sent from the same source port. In this case, the alpha value can be set to 1 and the Dx value can be recalculated.

[0075] (c) If the Dx request with the smallest distance is identified as the target of the current attack, the corresponding simulation logic quadruple series can be returned to the patch.

[0076] The interaction monitor tracks the interaction behavior of network security patches as follows: it intercepts and records read and write operations on the file directory corresponding to the network security patch.

[0077] S203. When an abnormal operating status is determined, an alarm message is issued.

[0078] In practice, the interaction monitor reports the network security patch interaction behavior to the network security patch controller.

[0079] The time monitor tracks the runtime of the network security patch by monitoring the process of the network security patch from the start of execution to the current moment and periodically reporting the running status to the patch controller.

[0080] The following is a monitoring example of the network security patch (tiepian1).

[0081]

[0082]

[0083] The time monitor reports the network security patch runtime to the network security patch controller. Upon receiving the network security patch runtime report, the patch controller can determine the running status of the corresponding patch. If no report is received for an extended period, it is determined that the patch is running abnormally, and intervention should be initiated. If the honeypot decoy function's runtime exceeds a certain threshold, to prevent the honeypot decoy function from being identified by the attacker, the patch controller can dynamically and randomly generate a new decoy simulation logic (Decoy4) based on the application service information simulated by the patch, and send it to the patch to replace its execution. If other security functions encounter abnormalities, the patch controller will perform functional repair based on the abnormality information.

[0084] The network security patch controller analyzes the operational status of network security patches and needs to execute corresponding policies based on the operational status. Since the resources that network security patches can use are limited, this proposal needs to limit the resources that dynamic network security patches (dcsproc) can occupy in the aforementioned steps, including CPU (C), memory (M), hard disk resources (H), and directories (D). On the other hand, the patches also need to run various programs on the protected system according to policy requirements, so it is necessary to plan the deployment and operation of these programs and formulate corresponding execution policies.

[0085] Let the resources that the network security patch dcsproc can occupy be: CPU (C), memory (M), hard disk resources (H), directories (D), and network bandwidth (B).

[0086] Let the program P = {p1, p2, ..., pi, ...} that the patch controller can run according to the patch protection requirements be denoted by. Here, pi corresponds to the security protection capabilities such as risk identification, security protection, security monitoring, content security, security vulnerability scanning, security penetration, threat intelligence, situational awareness, capability orchestration, and physical security.

[0087] (1) First, calculate the CPU, memory, hard disk and directory usage of the program P = {p1, p2, ..., pi, ...} corresponding to various protection requirements, and record them as (ci, mi, hi, di, bi);

[0088] (2) When formulating policies, network security patch controllers need to load and run programs on patches according to security requirements, given the available resources.

[0089] (3) Based on these conditions, the following planning algorithm can be set to calculate the list of applications that the patch controller can plan to run. Due to resource constraints, the scheduling frequency of each application also needs to be considered during scheduling. If an application has already been scheduled, its CPU and memory usage can be temporarily increased to transfer its scheduling priority to other applications with less frequent scheduling, thus ensuring that each application can be patched and executed within a certain period. The increased CPU and memory usage needs to be restored to their original values ​​in the next period.

[0090] As described above, the network security patch controller instructs the network security patch to execute corresponding policies based on the operational status. The overall process is as follows: Figure 3 As shown, after various application functions are executed on the patch, the relevant execution results need to be fed back to the patch controller through the patch so that further protective measures can be taken.

[0091] It should be noted that since different patches have different available resources and varying protection requirements, the patch controller needs to plan an application list for each patch separately. Even for the same patch, its protection requirements and resource availability change dynamically at different times, so the patch controller needs to continuously plan and update applications for patches and publish them to the corresponding patches.

[0092] Figure 4 This is a schematic diagram of the structure of a monitoring device for a protected system provided in an embodiment of this disclosure. The monitoring device 400 for a protected system provided in this embodiment of the disclosure can execute the processing flow provided in the above-described embodiments of the monitoring method for a protected system, such as… Figure 4 As shown, the monitoring device 400 of the protected system includes an acquisition unit 401, a determination unit 402, and an alarm unit 403, wherein:

[0093] Acquisition unit 401 is used to acquire traffic data and system resource data of the protected system;

[0094] The determining unit 402 is used to determine the operating status of the security patch based on traffic data and system resource data;

[0095] Alarm unit 403 is used to issue alarm information when an abnormal operating status is detected.

[0096] In one possible implementation, the determining unit 402 in the apparatus provided by the embodiments of the present invention is specifically used for:

[0097] Monitor the traffic status of the protected system based on traffic data;

[0098] Monitor the interaction status of the protected system based on system resource data;

[0099] The traffic status and interaction status are determined as the operating status of the security patch.

[0100] In one possible implementation, the alarm unit 403 in the apparatus provided by the embodiments of the present invention is further configured to:

[0101] If no traffic data or system resource data is received within the preset time period, the system is determined to be in an abnormal operating state and an alarm message is issued.

[0102] Figure 4 The monitoring device for the protected system shown in the embodiment can be used to execute the technical solution of the above method embodiment. Its implementation principle and technical effect are similar, and will not be repeated here.

[0103] In addition, combined Figures 1-4 The monitoring method and apparatus for the protected system described in this application can be implemented by an electronic device. Figure 5A schematic diagram of the hardware structure of the electronic device provided in an embodiment of this application is shown.

[0104] like Figure 5 As shown, the electronic device 800 may include a processing device (e.g., a central processing unit, a graphics processor, etc.) 801, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 802 or a program loaded from a storage device 808 into a random access memory (RAM) 803 to implement the monitoring method of the protected system as described in the embodiments of this disclosure. The RAM 803 also stores various programs and data required for the operation of the electronic device 800. The processing device 801, ROM 802, and RAM 803 are interconnected via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.

[0105] Typically, the following devices can be connected to I / O interface 805: input devices 806 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 807 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 808 including, for example, magnetic tapes, hard disks, etc.; and communication devices 809. Communication device 809 allows electronic device 800 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 5 An electronic device 800 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.

[0106] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts, thereby implementing the voice control method as described above. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 809, or installed from a storage device 808, or installed from a ROM 802. When the computer program is executed by the processing device 801, it performs the functions defined in the methods of embodiments of this disclosure.

[0107] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0108] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.

[0109] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.

[0110] The aforementioned computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to:

[0111] Obtain traffic data and system resource data of the protected system;

[0112] The operating status of the security patch is determined based on traffic data and system resource data;

[0113] When an abnormal operating status is detected, an alarm message is issued.

[0114] Optionally, when one or more of the above-described procedures are executed by the electronic device, the electronic device may also perform other steps described in the above embodiments.

[0115] Computer program code for performing the operations of this disclosure can be written in one or more programming languages ​​or a combination thereof, including but not limited to object-oriented programming languages ​​such as Java, Smalltalk, and C++, as well as conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0116] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0117] The units described in the embodiments of this disclosure can be implemented in software or hardware. The names of the units are not, in some cases, intended to limit the specific unit.

[0118] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0119] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0120] This disclosure provides a security patch system, including a security patch, a traffic monitor, an interaction monitor, a time monitor, and a patch controller. By applying the security patch system provided by this disclosure, multiple network security detection and defense capabilities can be achieved through lightweight deployment and with minimal resource consumption, via corresponding control and interaction steps. This enables more accurate detection and services, and provides platform-based and multi-dimensional security protection.

[0121] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0122] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0123] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0124] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0125] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0126] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.

Claims

1. A safety patch system, characterized in that, The system includes a security patch, a flow monitor, an interaction monitor, a time monitor, and a patch controller, wherein: The security patch is used to be installed on the protected system and to acquire the traffic data and system resource data of the protected system; The time monitor is used to monitor the running time of the security patch; The flow monitor is used to monitor the flow status of the protected system based on the flow data; The interaction monitor is used to monitor the interaction status of the protected system based on the system resource data. The patch controller is used to install the safety patch on the protected system and determine the operating status of the safety patch; The process involves the following steps: The patch controller creates a security patch based on the traffic data, system resource data, and scenario of the protected system, and installs the security patch in the protected system. After installation, the traffic monitor detects the traffic of the security patch and reports to the patch controller. The interaction monitor monitors the interaction behavior of the security patch and reports to the patch controller. The time monitor monitors the runtime of the security patch and reports to the patch controller. The patch controller notifies the security patch to execute corresponding policies based on its operating status. The steps for installing the dynamic network security patch include: modifying the corresponding configuration of the protected system to hide the dynamic network security patch; and the dynamic network security patch with system management privileges monitoring the traffic of each network interface card (NIC) of the protected system and sending data directly at the NIC level without calling other library functions in the protected system.

2. A monitoring method for a protected system, characterized in that, The method, applied to the security patch system of claim 1, comprises: Obtain the traffic data and system resource data of the protected system; The operating status of the security patch is determined based on the traffic data and the system resource data; When the abnormal operating status is determined, an alarm message is issued.

3. The method according to claim 2, characterized in that, Determining the operating status of the security patch based on the traffic data and the system resource data includes: Monitor the traffic status of the protected system based on the traffic data; Monitor the interaction status of the protected system based on the system resource data; The traffic status and the interaction status are determined as the operating status of the security patch.

4. The method according to claim 3, characterized in that, The method further includes: If the traffic data and system resource data are not received within a preset time period, the operating status is determined to be abnormal, and an alarm message is issued.

5. A monitoring device for a protected system, employing the monitoring method for a protected system as described in any one of claims 2-4, characterized in that, The device includes: The acquisition unit is used to acquire the traffic data and system resource data of the protected system; A determining unit is configured to determine the operating status of the security patch based on the traffic data and the system resource data; An alarm unit is used to issue an alarm message when the operating status is found to be abnormal.

6. The apparatus according to claim 5, characterized in that, The determining unit is specifically used for: Monitor the traffic status of the protected system based on the traffic data; Monitor the interaction status of the protected system based on the system resource data; The traffic status and the interaction status are determined as the operating status of the security patch.

7. The apparatus according to claim 6, characterized in that, The alarm unit is also used for: If the traffic data and system resource data are not received within a preset time period, the operating status is determined to be abnormal, and an alarm message is issued.

8. An electronic device, characterized in that, include: Memory; processor; as well as Computer programs; The computer program is stored in the memory and configured to be executed by the processor to implement the monitoring method for the protected system as described in any one of claims 2 to 4.

9. A computer-readable storage medium having computer program instructions stored thereon, characterized in that, When the computer program instructions are executed by the processor, the monitoring method for the protected system as described in any one of claims 2-4 is implemented.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the monitoring method for the protected system as described in any one of claims 2-4.

Citation Information

Patent Citations

  • Method for realizing 5G equipment CPE fault alarm real-time reporting based on SLA

    CN113573352A

  • Safe honeypot system and implementation method thereof

    CN116760558A