Network security configuration verification and reinforcement method and system based on agentless architecture
Through the agentless architecture network security configuration verification and reinforcement method, using remote connection and dynamic risk assessment, the deployment complexity and security risk issues of traditional technologies are solved, and efficient and secure system reinforcement and operation and maintenance management are achieved, as well as convenient network security protection.
Patent Information
- Application Number
- CN202411631576.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-15
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2044-11-15
AI Technical Summary
Traditional security configuration verification and reinforcement technologies have shortcomings such as complex deployment, high security risks, difficult operation and maintenance, and difficult updates and maintenance. They are unable to effectively respond to the increasingly severe network security challenges.
It adopts an agentless architecture and establishes a remote connection with the target host system through a preset network protocol to obtain configuration information and operating environment information, identify security risks and configuration defects, generate reports, and perform reinforcement operations. It dynamically calculates the reinforcement risk value and avoids installing agent software on the target host system.
It achieves lightweight, high-security, and low-performance-loss security configuration verification and reinforcement, reduces the complexity of system deployment and maintenance, avoids the security risks of agent software, and improves the convenience and security protection capabilities of operation and maintenance management.
Smart Images

Figure CN119484103B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network technology, and in particular to a method and system for verifying and reinforcing network security configuration based on an agentless architecture. Background Art
[0002] Security configuration verification refers to the systematic inspection and verification of various configuration information of network systems, devices or applications to ensure that they comply with industry security standards, best practices and relevant laws and regulations; security hardening is to further enhance its security, stability and performance by modifying and optimizing system configurations on the basis of security configuration verification, such as shutting down unnecessary services, restricting user permissions, deploying security patches, etc.; security configuration verification and hardening can effectively reduce security risks and configuration defects in the system, reduce the possibility of network attacks and data leaks, and are an important part of building a deep defense system.
[0003] However, traditional security configuration verification and reinforcement technologies face many challenges in practical applications: First, traditional security configuration verification tools usually rely on agent programs and predefined configuration dictionaries. This approach requires the installation of additional agent software on the target host system, which not only consumes system resources and increases system load, but may also reduce system stability and even introduce incompatible or incorrect configurations, bringing new security risks; second, the implementation process of traditional security reinforcement technology is relatively complex and requires high technical capabilities of operation and maintenance personnel. That is, operation and maintenance personnel need to have an in-depth understanding of various security policies and configuration parameters to effectively use these tools, which undoubtedly increases the difficulty of operation and the possibility of errors; in addition, traditional security configuration verification tools rely on preset configuration dictionaries, which are difficult to update and maintain. That is, as network security threats and compliance requirements continue to evolve, preset dictionaries are difficult to update in a timely manner and cannot effectively respond to emerging new security threats, resulting in lagging security protection capabilities.
[0004] In summary, traditional security configuration verification and reinforcement technologies suffer from numerous shortcomings, including complex deployment, high security risks, difficult operations and management, and challenges with updates and maintenance. These shortcomings make it difficult to meet the growing demands of network security. Therefore, a more efficient, secure, and flexible network security configuration verification and reinforcement solution is urgently needed to address the increasingly severe network security challenges and build a more reliable security protection system. Summary of the Invention
[0005] In order to solve the above problems, the present invention provides a network security configuration verification and reinforcement method and system based on an agentless architecture, which can efficiently, safely and flexibly improve the security protection capabilities of servers and application systems, while taking into account system stability, performance optimization and convenient operation and maintenance management.
[0006] To achieve the above objectives, in a first aspect, embodiments of the present application provide a method for verifying and reinforcing network security configurations based on an agentless architecture, comprising the following steps:
[0007] S1. Obtain preset and user-defined verification baselines, security risk assessment baselines, and hardening baselines;
[0008] S2. Establish a remote connection with the target host system using a pre-defined network protocol through an agentless architecture, and remotely obtain the target host system's configuration information and operating environment information;
[0009] S3. Analyze the remotely acquired configuration information based on the verification baseline, identify security risks and configuration flaws in the target host system, and generate a configuration verification report;
[0010] S4. Based on the collected configuration information and operating environment information, as well as the security risk assessment baseline, determine the security risk factor of the hardening operation and generate a security risk assessment report;
[0011] S5. Based on the security risk assessment report, you can selectively adjust the target reinforcement items and the corresponding reinforcement scope;
[0012] S6. Based on a preset or user-defined reinforcement test strategy, select some target reinforcement items and corresponding reinforcement ranges for reinforcement testing, and generate a reinforcement test report.
[0013] S7. Based on the reinforcement test report, you can selectively adjust the target reinforcement items and the corresponding reinforcement scope;
[0014] S8. Determine the final target reinforcement items and corresponding reinforcement scopes, and remotely execute reinforcement operations in batches. During the reinforcement operation, dynamically calculate the reinforcement risk value based on the preset risk strategy.
[0015] S9. If the reinforcement risk value reaches the preset risk threshold, the reinforcement operation is interrupted and the reinforcement is deemed to have failed. In the event of a reinforcement failure, the state is automatically rolled back to the state before the reinforcement. After the reinforcement failure, the target reinforcement items and the corresponding reinforcement scope are readjusted, and the reinforcement operation is continued in batches until all target reinforcement items have been reinforced.
[0016] S10. Collect reinforcement result data and generate a reinforcement report.
[0017] Optionally, the verification baseline includes but is not limited to access control policy, password policy, data encryption policy, and log audit policy.
[0018] Optionally, the agentless architecture means that no agent program or client software needs to be installed in the target host system, but communication with the target host system is performed directly through a network protocol.
[0019] Optionally, the network protocol includes but is not limited to SSH, SFTP, and WMI.
[0020] Optionally, the configuration information of the target host system includes at least the operating system version and patch level, network configuration, database configuration, and middleware configuration; the operating environment information of the target host system includes at least running processes and services, open network ports, system resource usage, and security logs.
[0021] Optionally, the security risk assessment baseline includes:
[0022] a) Asset Value: Determine the asset value of the target host system based on its configuration information and operating environment information. Parameters for asset value assessment include operating system version and patch level, network configuration, database configuration, middleware configuration, running processes and services, open network ports, system resource usage, and security logs.
[0023] b) Hardening dependencies: Identify the software associated with the hardening items and the target host system configuration information and operating environment information, and analyze the degree of correlation;
[0024] c) Assessment criteria: Based on the asset value and reinforcement dependency, a quantitative or qualitative risk assessment method is used to conduct a risk assessment of the reinforcement operation.
[0025] Optionally, the reinforcement operation includes at least modifying the system configuration, installing security patches, disabling unnecessary services and ports, enabling security features, restricting user permissions, data encryption, and security logging; and before performing each reinforcement operation, the target host system or related data is backed up.
[0026] Optionally, in step S6, the reinforcement test strategy includes:
[0027] a) Determine whether the number of hosts that need to be reinforced has reached the preset minimum threshold;
[0028] b) If the number of hosts that need to be reinforced is lower than the minimum threshold, the reinforcement test is skipped and the remote batch reinforcement operation in step S8 is directly executed;
[0029] c) If the number of hosts that need to be reinforced reaches or exceeds the minimum number threshold, a reinforcement test is performed according to a preset or user-defined strategy, which includes at least one of the following: selecting the scope of the test reinforcement items, specifying the hosts that must be tested, specifying the hosts that do not need to be tested, and specifying the number of hosts that need to be tested.
[0030] Optionally, in step S8, the risk strategy includes:
[0031] a) During the reinforcement operation, collect the reinforcement results of each reinforcement item;
[0032] b) grouping and sorting the reinforcement results based on unit time;
[0033] c) Calculate the reinforcement failure rate of each reinforcement item in each unit time group to determine the reinforcement risk value corresponding to each reinforcement item.
[0034] d) Intervene in the reinforcement work based on the reinforcement risk value, interrupt the high-risk reinforcement task, and no longer perform the work on the reinforcement item, but it will not affect the work of other reinforcement items:
[0035] e) Confirm whether the failed items need to be rolled back based on the reinforcement work records and logs.
[0036] In a second aspect, an embodiment of the present application provides a network security configuration verification and reinforcement system based on an agentless architecture, applicable to a network security configuration verification and reinforcement method based on an agentless architecture described in any embodiment of the first aspect, including:
[0037] Baseline module, used to store preset and user-defined verification baselines, security risk assessment baselines, and hardening baselines;
[0038] A remote execution module is used to establish a remote connection with the target host system through a preset network protocol to collect system configuration and operation status information;
[0039] The configuration verification module is used to analyze configuration information based on the verification baseline, identify security risks and configuration defects, and generate configuration verification reports;
[0040] The security risk assessment module is used to determine the risk of the reinforcement operation based on the security risk assessment baseline and the system configuration and operating status information of the target host system, and generate a security risk assessment report;
[0041] The reinforcement test module is used to select some targets for reinforcement testing according to the reinforcement test strategy and generate a reinforcement test report;
[0042] Automatic hardening module, used to perform hardening operations according to the hardening baseline, including data backup, hardening execution, failure rollback and interruption functions;
[0043] The control center is used to centrally dispatch the above modules.
[0044] The network security configuration verification and reinforcement method and system based on the agentless architecture designed by the present invention adopts an agentless architecture and directly communicates and operates with the target host system through a preset network protocol. There is no need to install any agent program or client software on the target host system, which significantly reduces the complexity of system deployment and maintenance, avoids the security vulnerability risk of the agent software itself, and eliminates the impact of the agent software on the performance of the target host system, thereby realizing lightweight, high-security, and low-performance loss security configuration verification and reinforcement. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1 This is a flowchart of a network security configuration verification and reinforcement method based on an agentless architecture provided in an embodiment of the present application. DETAILED DESCRIPTION
[0046] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.
[0047] Example 1
[0048] like Figure 1 As shown, in the first aspect, the embodiments of the present application provide a network security configuration verification and reinforcement method based on an agentless architecture, which aims to automatically set, check, and verify various configuration information of systems, devices, or applications to ensure that they comply with preset security policies, performance standards, and business requirements, thereby ensuring the normal operation and security of the system. At the same time, the method enhances the security, stability, and performance of the system by modifying and optimizing the system configuration, reducing potential security vulnerabilities and attack surfaces, and improving the overall protection capabilities of the system.
[0049] The method specifically comprises the following steps:
[0050] S1. Obtain preset and user-defined verification baselines, security risk assessment baselines, and hardening baselines.
[0051] Optionally, in an implementation of an embodiment of the present invention, the verification baseline includes but is not limited to access control policy, password policy, data encryption policy, and log audit policy.
[0052] Specifically, the verification baseline is a set of predefined security rules and standards used to check whether the security configuration of the target host system meets the security requirements. It can cover various security aspects, such as: operating system security configuration (such as account management, password policy, file permissions), network security configuration (such as firewall rules, access control lists), application security configuration (such as database security configuration, server security configuration), compliance requirements (such as PCI DSS, GDPR). The security risk assessment baseline is used to assess the security risks in the target host system. It can include: known security vulnerability information, common attack means and methods, industry best practices and security standards. The hardening baseline is a set of predefined security hardening measures used to improve the security of the target host system. It can include: modifying configuration files, installing security patches, disabling unnecessary services, and enabling security audit functions.
[0053] In addition to pre-set baselines, the system also allows users to customize baselines, allowing them to add, modify, or delete baseline items based on their specific needs and security policies. For example, users can add additional security rules for specific applications or services, or select different security reinforcement measures based on their operational experience.
[0054] In this way, the method steps provide necessary security rules and standards for subsequent steps by obtaining preset baselines and user-defined baselines, and enhance the automation and flexibility of the system.
[0055] S2. Through the agentless architecture, a preset network protocol is used to establish a remote connection with the target host system, and the configuration information and operating environment information of the target host system are remotely obtained.
[0056] The agentless architecture refers to a system that communicates directly with the target host system via network protocols, without requiring any agent or client software to be installed on the target host system. In this embodiment, the network protocols include, but are not limited to, SSH (Secure Shell), SFTP (Secure File Transfer Protocol), and WMI (Windows Management Instrumentation). For example, if the target host system is a server running the Linux operating system, the SSH protocol can be used to establish a remote connection with it.
[0057] Specifically, through the established remote connection, the system can execute specific commands or scripts to obtain the configuration information and operating environment information of the target host system. In this embodiment, the configuration information of the target host system includes at least the operating system version and patch level, network configuration (such as IP address, subnet mask, gateway), database configuration, and middleware configuration (such as firewall rules and password policy); the operating environment information of the target host system includes at least running processes and services, open network ports, system resource usage (such as CPU usage, memory usage), and security logs.
[0058] In this way, the method steps utilize the agentless architecture and preset network protocols to achieve remote access and information collection of the target host system, laying the foundation for subsequent analysis and reinforcement operations. At the same time, it also avoids the deployment complexity, security risks and performance impact brought by agent software, thereby improving efficiency and security.
[0059] S3. Analyze the remotely acquired configuration information based on the verification baseline, identify security risks and configuration defects in the target host system, and generate a configuration verification report.
[0060] Specifically, by comparing the acquired configuration information with the verification baseline, security risks and configuration flaws in the target host system can be identified. For example, if the verification baseline requires a password length of at least 8 characters, but the target host system password length is set to 6 characters, the system will identify that the configuration item does not meet the requirement; or if the verification baseline requires the firewall to be enabled, but the target host system does not have the firewall enabled, the system will identify that the security configuration is missing; or if the verification baseline requires the disabling of unnecessary services, but the target host system has unnecessary services enabled, the system will identify that the configuration poses a security risk.
[0061] In this way, after accurately identifying the security risks and configuration defects in the target host system, the analysis results are summarized into a configuration verification report for the user's reference and to guide the user in subsequent reinforcement operations. In this embodiment, the report generally includes the following: basic information of the target host system (such as operating system version, IP address, host name), verification baseline information (such as verification baseline name, version, description), security risk list (such as risk description, risk level, affected system components, and repair suggestions), and configuration defect list (such as defect description, defect level, affected configuration items, and repair suggestions).
[0062] S4. Based on the collected configuration information and operating environment information, as well as the security risk assessment baseline, determine the security risk factor of the reinforcement operation and generate a security risk assessment report.
[0063] Optionally, the security risk assessment baseline includes:
[0064] a) Asset Value: Determine the asset value of the target host system based on its configuration information and operating environment information. Parameters for asset value assessment include operating system version and patch level, network configuration, database configuration, middleware configuration, running processes and services, open network ports, system resource usage, and security logs.
[0065] b) Hardening dependencies: Identify the software associated with the hardening items and the target host system configuration information and operating environment information, and analyze the degree of correlation;
[0066] c) Assessment criteria: Based on the asset value and reinforcement dependency, a quantitative or qualitative risk assessment method is used to conduct a risk assessment of the reinforcement operation.
[0067] Specifically, by performing a risk assessment on each reinforcement operation, users can better understand and manage the risks of reinforcement operations, thereby improving the security of reinforcement operations. For example:
[0068] Assuming that step S3 identifies the target server as having a security risk of "limiting the number of account authentication failures," a risk assessment is performed on the "enabling the limit on the number of account authentication failures" reinforcement operation in step S4:
[0069] First, the system analyzes the potential impact of enabling the "limit on account authentication failures" operation on the server. For example, this operation may require modifying server configuration files, which can lead to potential risks such as configuration errors, service interruptions, and account authentication failures.
[0070] Next, the system determines the risk level of the "Enable account authentication failure limit" operation based on the security risk assessment baseline and the actual situation of the target server. For example, because "Enable account authentication failure limit" requires modifying system configuration, there is a certain probability of causing configuration errors or service interruption, so the system may determine it as medium risk.
[0071] Finally, the system will generate a security risk assessment report, which will list the risk level of the "Enable Account Authentication Failure Limit" operation and a detailed risk description. In other embodiments, to help users better understand and address risks, the report can also provide some risk mitigation suggestions. For example, before performing a hardening operation, it is recommended to back up the server's configuration files and data so that they can be restored in time if problems occur. Alternatively, it is recommended to refer to official documentation or seek professional technical support to ensure that the "Account Authentication Failure Limit" is correctly enabled to avoid configuration errors.
[0072] S5. Based on the security risk assessment report, you can selectively adjust the target reinforcement items and the corresponding reinforcement scope.
[0073] Specifically, after completing the security risk assessment and generating a report in step S4, the target reinforcement items and the corresponding reinforcement scope can be selectively adjusted according to the content of the security risk assessment report. For example, for high-risk reinforcement operations, users can choose not to perform the operation, or take additional risk mitigation measures, such as performing a more comprehensive data backup before performing the operation, or seeking professional technical support; for medium and low-risk reinforcement operations, users can choose to perform the operation, but need to carefully read the risk description and risk mitigation recommendations.
[0074] S6. Combine the preset or user-defined reinforcement test strategy, select some target reinforcement items and corresponding reinforcement ranges for reinforcement testing, and generate a reinforcement test report.
[0075] Optionally, the reinforcement test strategy includes:
[0076] a) Determine whether the number of hosts that need to be reinforced reaches the preset minimum threshold; for example, the system default minimum threshold is 5.
[0077] b) If the number of hosts requiring hardening is below the minimum threshold, the hardening test is skipped and the remote batch hardening operation in step S8 is performed directly. For example, if only three hosts are selected for hardening, since the number is below the threshold of five, the system will directly perform the hardening operation on these three hosts without performing the hardening test.
[0078] c) If the number of hosts that need to be reinforced reaches or exceeds the minimum number threshold, the reinforcement test will be performed according to a preset or user-defined policy, which policy includes at least one of the following: selecting the scope of the reinforcement items to be tested (for example, testing reinforcement items that are determined to be medium risk or high risk by the security risk assessment module, or testing all selected reinforcement items), specifying the hosts that must be tested (for example, hosts running critical business applications), specifying the hosts that do not need to be tested (for example, hosts in the test environment), and specifying the number of hosts that need to be tested.
[0079] S7. Based on the reinforcement test report, you can selectively adjust the target reinforcement items and the corresponding reinforcement scope. In this way, if the reinforcement test report shows that a reinforcement operation failed or had a negative impact on system performance or functionality, you can choose to abandon the reinforcement operation. For some reinforcement operations with higher risks or greater impacts, you can choose other reinforcement solutions with lower risks or smaller impacts. For example, if the "disable default account" operation is considered too risky, you can choose to change the default account password and strengthen account permission management instead of directly disabling the account.
[0080] S8. Determine the final target reinforcement items and the corresponding reinforcement scope, and remotely execute the reinforcement operations in batches. During the reinforcement operation, dynamically calculate the reinforcement risk value based on the preset risk strategy.
[0081] Optionally, the reinforcement operation includes at least modifying the system configuration, installing security patches, disabling unnecessary services and ports, enabling security features, restricting user permissions, data encryption, and security logging; and before performing each reinforcement operation, the target host system or related data is backed up.
[0082] Specifically, the remote connection established in step S2 allows for remote execution of reinforcement operations without manual intervention. To mitigate risk, the targeted reinforcement items and corresponding scopes are divided into multiple batches, each of which is executed sequentially. This prevents the potential for widespread failures caused by operating all target host systems at once. Furthermore, during the reinforcement process, the risk value of each reinforcement operation is dynamically calculated based on a pre-set risk strategy.
[0083] Optionally, the risk strategy includes:
[0084] a) During the execution of the reinforcement operation, the reinforcement results of each reinforcement item are collected; that is, during the execution of the reinforcement operation, the execution results of each reinforcement item on each target host are collected in real time, including status information such as success, failure, and partial success.
[0085] b) Grouping and sorting the reinforcement results based on unit time; grouping the reinforcement results according to unit time, for example, the reinforcement operations completed within every 20 seconds can be grouped together. This can more accurately reflect the execution status of the reinforcement items in different time periods and avoid inaccurate risk assessment due to abnormal conditions in certain specific time periods.
[0086] c) Calculate the failure rate of each hardening item within each time period to determine the corresponding hardening risk value. For example, if the "Disable unnecessary services" hardening item is executed on 10 servers within 20 seconds and fails on 2 of them, the failure rate (risk value) of the "Disable unnecessary services" hardening item within that time period is 20%.
[0087] S9. If the reinforcement risk value reaches the preset risk threshold, the reinforcement operation is interrupted and determined to be a reinforcement failure; in which, when the reinforcement fails, it automatically rolls back to the state before reinforcement, and after the reinforcement fails, the target reinforcement items and the corresponding reinforcement range are readjusted and the reinforcement operation is continued in batches until all target reinforcement items have completed the reinforcement operation.
[0088] Specifically, before executing each reinforcement operation, the target host system or related data is backed up. If the risk value reaches the preset risk threshold, the system will immediately interrupt the reinforcement operation and determine that the reinforcement has failed. It will also start the automatic rollback mechanism to restore the target host system to the state before the reinforcement operation was executed. Subsequently, based on the cause of the failure, the reinforcement plan can be adjusted again until all target reinforcement items are completed.
[0089] In this embodiment, the preset risk threshold is a security boundary set based on experience and security policies, that is, when the dynamically calculated reinforcement risk value reaches or exceeds the threshold, the system will consider that the reinforcement operation has a high risk and may cause serious impact on the target host system. At this time, the system will immediately interrupt the current reinforcement operation and determine that the reinforcement has failed to avoid further expansion of the risk. For example, it can be set that when the number of hosts that have completed reinforcement reaches 10% of the total number of hosts, a risk determination is made, or it can be determined by judging whether the risk value of the reinforcement item reaches or exceeds the preset threshold: for example, the risk threshold can be set to 10% (assuming the risk value range is 0-100%), that is, if the risk value of a reinforcement item reaches or exceeds 10%, a risk interruption is triggered.
[0090] S10. Collect reinforcement result data and generate a reinforcement report. During implementation, the reinforcement result data is summarized into a detailed reinforcement report for users to review and analyze. In this embodiment, the reinforcement report typically includes the following: the execution time range of the reinforcement operation, the number of target hosts, the number of hosts successfully reinforced, the number of hosts failed to be reinforced, etc.; the execution status statistics, average risk value, common error messages, etc. of each reinforcement operation; the execution status, execution time, risk value, error message, rollback status, etc. of each operation.
[0091] In a second aspect, an embodiment of the present application provides a network security configuration verification and reinforcement system based on an agentless architecture, applicable to a network security configuration verification and reinforcement method based on an agentless architecture described in any embodiment of the first aspect, including:
[0092] Baseline module, used to store preset and user-defined verification baselines, security risk assessment baselines, and hardening baselines;
[0093] A remote execution module is used to establish a remote connection with the target host system through a preset network protocol to collect system configuration and operation status information;
[0094] The configuration verification module is used to analyze configuration information based on the verification baseline, identify security risks and configuration defects, and generate configuration verification reports;
[0095] The security risk assessment module is used to determine the risk of the reinforcement operation based on the security risk assessment baseline and the system configuration and operating status information of the target host system, and generate a security risk assessment report;
[0096] The reinforcement test module is used to select some targets for reinforcement testing according to the reinforcement test strategy and generate a reinforcement test report;
[0097] Automatic hardening module, used to perform hardening operations according to the hardening baseline, including data backup, hardening execution, failure rollback and interruption functions;
[0098] The control center is used to centrally dispatch the above modules.
[0099] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system described above can refer to the corresponding process in the aforementioned embodiment of the network security configuration verification and reinforcement method based on the agentless architecture, and will not be repeated here.
[0100] The network security configuration verification and reinforcement method and system based on the agentless architecture provided in this embodiment adopts an agentless architecture and directly communicates and operates with the target host system through a preset network protocol. There is no need to install any agent program or client software on the target host system, which significantly reduces the complexity of system deployment and maintenance, avoids the security vulnerability risk of the agent software itself, and eliminates the impact of the agent software on the performance of the target host system, thereby realizing lightweight, high-security, and low-performance loss security configuration verification and reinforcement.
[0101] In the description of the present invention, it should be noted that the terms "vertical", "up", "down", "horizontal", etc., indicating orientations or positional relationships, are based on the orientations or positional relationships shown in the accompanying drawings. They are only for the convenience of describing the present invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, they cannot be understood as limiting the present invention.
[0102] In the description of the present invention, it should also be noted that, unless otherwise expressly specified or limited, the terms "disposed," "installed," "connected," and "connected" should be understood in a broad sense. For example, they may refer to fixed connections, detachable connections, or integral connections; they may refer to mechanical connections or electrical connections; they may refer to direct connections or indirect connections through an intermediate medium; and they may refer to internal communication between two components. Those skilled in the art will understand the specific meanings of the above terms in the present invention based on specific circumstances.
[0103] Finally, it should be noted that the above descriptions are merely preferred embodiments of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art will be able to modify the technical solutions described in the aforementioned embodiments or substitute equivalents for some of the technical features. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the scope of protection of the present invention.
Claims
1. A network security configuration verification and reinforcement method based on an agentless architecture, characterized in that: The following steps are involved: S1. Obtain preset and user-defined verification baselines, security risk assessment baselines, and hardening baselines; S2. Establish a remote connection with the target host system using a pre-defined network protocol through an agentless architecture, and remotely obtain the target host system's configuration information and operating environment information; S3. Analyze the remotely acquired configuration information based on the verification baseline, identify security risks and configuration flaws in the target host system, and generate a configuration verification report; S4. Based on the collected configuration information and operating environment information, as well as the security risk assessment baseline, determine the security risk factor of the hardening operation and generate a security risk assessment report; S5. Based on the security risk assessment report, you can selectively adjust the target reinforcement items and the corresponding reinforcement scope; S6. Based on a preset or user-defined reinforcement test strategy, select some target reinforcement items and corresponding reinforcement ranges for reinforcement testing, and generate a reinforcement test report. S7. Based on the reinforcement test report, you can selectively adjust the target reinforcement items and the corresponding reinforcement scope; S8. Determine the final target reinforcement items and corresponding reinforcement scope, and remotely execute the reinforcement operations in batches; During the reinforcement operation, the reinforcement risk value is dynamically calculated based on the preset risk strategy; S9. If the reinforcement risk value reaches the preset risk threshold, the reinforcement operation is interrupted and the reinforcement is deemed to have failed. In the event of a reinforcement failure, the state is automatically rolled back to the state before the reinforcement. After the reinforcement failure, the target reinforcement items and the corresponding reinforcement scope are readjusted, and the reinforcement operation is continued in batches until all target reinforcement items have been reinforced. S10. Collect reinforcement result data and generate a reinforcement report; The verification baseline includes but is not limited to access control policy, password policy, data encryption policy, and log audit policy; The agentless architecture means that no agent program or client software needs to be installed on the target host system, but the target host system is communicated directly through the network protocol; The security risk assessment baseline includes: a) Asset Value: Determine the asset value of the target host system based on its configuration information and operating environment information. Parameters for asset value assessment include operating system version and patch level, network configuration, database configuration, middleware configuration, running processes and services, open network ports, system resource usage, and security logs. b) Hardening dependencies: Identify the software associated with the hardening items and the target host system configuration information and operating environment information, and analyze the degree of correlation; c) Assessment criteria: Based on the asset value and reinforcement dependency, use quantitative or qualitative risk assessment methods to assess the risk of reinforcement operations; In step S8, the risk strategy includes: a) During the reinforcement operation, collect the reinforcement results of each reinforcement item; b) grouping and sorting the reinforcement results based on unit time; c) Calculate the reinforcement failure rate of each reinforcement item in each unit time group to determine the reinforcement risk value corresponding to each reinforcement item.
2. The network security configuration verification and reinforcement method based on agentless architecture according to claim 1 is characterized in that: The network protocols include but are not limited to SSH, SFTP, and WMI.
3. The network security configuration verification and reinforcement method based on agentless architecture according to claim 1 is characterized in that: The configuration information of the target host system includes at least the operating system version and patch level, network configuration, database configuration, and middleware configuration; the operating environment information of the target host system includes at least running processes and services, open network ports, system resource usage, and security logs.
4. The network security configuration verification and reinforcement method based on agentless architecture according to claim 1 is characterized in that: The reinforcement operations at least include modifying system configuration, installing security patches, disabling unnecessary services and ports, enabling security features, restricting user permissions, data encryption, and security logging; and before performing each reinforcement operation, the target host system or related data shall be backed up.
5. The network security configuration verification and reinforcement method based on agentless architecture according to claim 1 is characterized in that: In step S6, the reinforcement test strategy includes: a) Determine whether the number of hosts that need to be reinforced has reached the preset minimum threshold; b) If the number of hosts that need to be reinforced is lower than the minimum threshold, the reinforcement test is skipped and the remote batch reinforcement operation in step S8 is directly executed; c) If the number of hosts that need to be reinforced reaches or exceeds the minimum number threshold, a reinforcement test is performed according to a preset or user-defined strategy, which includes at least one of the following: selecting the scope of the test reinforcement items, specifying the hosts that must be tested, specifying the hosts that do not need to be tested, and specifying the number of hosts that need to be tested.
6. A network security configuration verification and reinforcement system based on an agentless architecture, applicable to a network security configuration verification and reinforcement method based on an agentless architecture according to any one of claims 1 to 5, characterized in that: include: Baseline module, used to store preset and user-defined verification baselines, security risk assessment baselines, and hardening baselines; A remote execution module is used to establish a remote connection with the target host system through a preset network protocol to collect system configuration and operation status information; The configuration verification module is used to analyze configuration information based on the verification baseline, identify security risks and configuration defects, and generate configuration verification reports; The security risk assessment module is used to determine the risk of the reinforcement operation based on the security risk assessment baseline and the system configuration and operating status information of the target host system, and generate a security risk assessment report; The reinforcement test module is used to select some targets for reinforcement testing according to the reinforcement test strategy and generate a reinforcement test report; Automatic hardening module, used to perform hardening operations according to the hardening baseline, including data backup, hardening execution, failure rollback and interruption functions; The control center is used to centrally dispatch the above modules.
Citation Information
Patent Citations
An application system oriented risk processing method and device
CN109214192A
Network security protection security method and system based on unit cell
CN114978584A
Real-time self-learning security reinforcement method for operating system
CN117349802A