Domain security detection method, device, equipment, medium and program product

CN119652593BActive Publication Date: 2026-09-04INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411769678.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-04
Publication Date
2026-09-04
Estimated Expiration
2044-12-04

AI Technical Summary

Technical Problem

[0002]随着信息时代的发展,将每台主机独立管理的工作组模式逐渐无法满足业务需求,越来越多的企业和机构使用Windows域搭建办公网络,提供便捷的同时,也带来了巨大的安全隐患

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652593B_ABST
    Figure CN119652593B_ABST
Patent Text Reader

Abstract

The present disclosure provides an intra-domain security detection method, which can be applied to the technical field of network security. The intra-domain security detection method comprises: collecting all data related to an access control policy in a domain; classifying all data according to a subject to obtain a classification result, wherein the subject comprises a user, a computer and a group; and determining whether a security risk exists in the domain according to the classification result according to the classification of the user, the computer and the group respectively. The present disclosure also provides an intra-domain security detection device, equipment, a storage medium and a program product.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of cybersecurity, specifically to a method, apparatus, device, medium, and program product for in-domain security detection. Background Technology

[0002] With the development of the information age, the workgroup model that manages each host independently is gradually unable to meet business needs. More and more enterprises and organizations are using Windows domains to build office networks, which provides convenience but also brings huge security risks.

[0003] Within a Windows domain, all hosts within the domain have the right to interact with the domain controller. Each domain account typically has management access to multiple domain hosts. If a domain is misconfigured, allowing attackers to easily gain access to high-privilege accounts within the domain, attackers can completely penetrate the entire domain. Summary of the Invention

[0004] In view of the above problems, this disclosure provides a domain security detection method, apparatus, equipment, medium and program product.

[0005] According to a first aspect of this disclosure, a domain security detection method is provided, comprising: collecting all data related to access control policies within the domain; classifying all data according to their respective subjects to obtain classification results, wherein the subjects include users, computers, and groups; and determining whether there are security risks within the domain based on the classification results for users, computers, and groups respectively.

[0006] According to embodiments of this disclosure, the collection of all data related to access control policies within the domain includes: collecting lightweight directory access protocol data and domain controller registry data; enumerating machine sessions within the domain, local security policies within the domain, trust relationships between multiple domains, and distributed component object models.

[0007] According to embodiments of this disclosure, the classification result includes the user's attribute information, the computer's attribute information, and the group's attribute information; the user's attribute information includes node information, group member identity information, local administrator permission information, and object control information; the computer's attribute information includes node information, local administrator information, group member identity information, local administrator permission information, and object control information; the group's attribute information includes node information, group member information, group member identity information, local administrator permission information, and object control information.

[0008] According to embodiments of this disclosure, the method includes: determining, based on registry data of the domain controller, the user's node information, the user's group member information, the user's local administrator privilege information, the computer's node information, the computer's group member information, the group's node information, and the group's group member information; determining, based on Lightweight Directory Access Protocol (Light DLTP) data, the user's object control information and the computer's local administrator privilege information; determining, based on the intra-domain machine session and the Lightweight Directory Access Protocol (Light DLTP) data, the computer's local administrator information; determining, based on the local security policy and the Lightweight Directory Access Protocol (Light DLTP) data, the computer's object control information; and determining, based on the trust relationships between the multiple domains, the distributed component object model, and the Lightweight Directory Access Protocol (Light DLTP) data, the group's object control information.

[0009] According to embodiments of this disclosure, determining whether a security risk exists within the domain based on the user classification and the classification result includes: obtaining high-privilege users within the domain, where the operation permissions of the high-privilege users are higher than those of the low-privilege users; determining, based on the classification result, whether there are low-privilege users in the user group to which the high-privilege users belong; if there are no low-privilege users in the user group to which the high-privilege users belong, determining, based on the classification result, whether the device where the high-privilege user account logs in allows low-privilege account login; if the device where the high-privilege user account logs in does not allow low-privilege account login, determining, based on the classification result, whether the object to which the high-privilege user account belongs can be called by the low-privilege account; and if the object to which the high-privilege user account belongs cannot be called by the low-privilege account, determining that the high-privilege account does not pose a security risk.

[0010] According to embodiments of this disclosure, determining whether a security risk exists within the domain based on the classification of the groups and the classification results includes: obtaining high-privilege groups within the domain, where the operation permissions of the high-privilege groups are higher than those of the low-privilege groups; determining, based on the classification results, whether any low-privilege users exist among the members of the high-privilege groups; if no low-privilege users exist among the members of the high-privilege groups, determining, based on the classification results, whether the administrator device to which the high-privilege groups belong allows low-privilege accounts to log in; if the administrator device to which the high-privilege groups belong does not allow low-privilege accounts to log in, determining, based on the classification results, whether any objects belonging to the high-privilege groups can be invoked by low-privilege accounts; and if any objects belonging to the high-privilege groups cannot be invoked by low-privilege users, determining that the high-privilege groups do not pose a security risk.

[0011] According to embodiments of this disclosure, the step of determining whether there is a security risk within the domain based on the classification of the computers and the classification result includes: obtaining high-privilege computers within the domain, wherein the access control permissions of the high-privilege computers are higher than those of the low-privilege computers; determining, based on the classification result, whether there are low-privilege users among the users and administrators who can log in on the high-privilege computers; if there are no low-privilege users among the users and administrators who can log in on the high-privilege computers, determining, based on the classification result, whether the local access control list configuration of the high-privilege computers is correct; if the local access control list configuration of the high-privilege computers is correct, determining, based on the classification result, whether the certificate trust of the high-privilege computers is correct; and if the certificate trust of the high-privilege computers is correct, determining that there is no security risk in the high-privilege group.

[0012] A second aspect of this disclosure provides a domain security detection device, comprising: a collection module for collecting all data related to access control policies within the domain; a classification module for classifying all data according to their respective subjects to obtain classification results, wherein the subjects include users, computers, and groups; and a determination module for determining whether a security risk exists within the domain based on the classification results for users, computers, and groups, respectively.

[0013] A third aspect of this disclosure provides an electronic device comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the method described above.

[0014] A fourth aspect of this disclosure also provides a computer-readable storage medium having a computer program or instructions stored thereon, which, when executed by a processor, implement the steps of the above-described method.

[0015] The fifth aspect of this disclosure also provides a computer program product, including a computer program or instructions that, when executed by a processor, implement the steps of the above-described method. Attached Figure Description

[0016] The foregoing contents, as well as other objects, features, and advantages of this disclosure, will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:

[0017] Figure 1 The illustration schematically depicts application scenarios of domain security detection methods, apparatuses, devices, media, and program products according to embodiments of the present disclosure.

[0018] Figure 2 A flowchart illustrating an in-domain security detection method according to an embodiment of the present disclosure is shown.

[0019] Figure 3 A flowchart illustrating a domain-based user classification-based security detection method according to an embodiment of this disclosure is shown.

[0020] Figure 4 A flowchart illustrating a domain-based group classification-based security detection method according to an embodiment of the present disclosure is shown.

[0021] Figure 5 A flowchart illustrating a domain-based computer classification-based security detection method according to an embodiment of the present disclosure is shown.

[0022] Figure 6 A schematic block diagram of a domain security detection device according to an embodiment of the present disclosure is shown.

[0023] Figure 7 A block diagram schematically illustrates an electronic device suitable for implementing domain security detection according to an embodiment of the present disclosure. Detailed Implementation

[0024] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.

[0025] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.

[0026] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.

[0027] When using expressions such as "at least one of A, B and C", they should generally be interpreted in accordance with the meaning that is commonly understood by those skilled in the art (e.g., "a system having at least one of A, B and C" should include, but is not limited to, a system having A alone, a system having B alone, a system having C alone, a system having A and B, a system having A and C, a system having B and C, and / or a system having A, B and C, etc.).

[0028] It should be noted that the domain security detection methods, devices, equipment, media and program products provided in this disclosure can be used in the field of cybersecurity technology in the financial technology field, and can also be used in any field other than the financial technology field. This disclosure does not limit the application field of the provided domain security detection methods, devices, equipment, media and program products.

[0029] In the technical solution disclosed herein, the user information (including but not limited to user personal information, user image information, user device information, such as location information) and data (including but not limited to data used for analysis, stored data, and displayed data) involved are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, storage, use, processing, transmission, provision, disclosure, and application of related data all comply with relevant laws, regulations, and standards, necessary confidentiality measures have been taken, and they do not violate public order and good morals. Corresponding operation entry points are provided for users to choose to authorize or refuse.

[0030] In scenarios involving automated decision-making using personal information, the methods, devices, and systems provided in this disclosure all offer users corresponding entry points for choosing to agree to or reject the automated decision-making results. If the user chooses to reject, the process proceeds to the expert decision-making stage. Here, "automated decision-making" refers to the activity of automatically analyzing and evaluating an individual's behavioral habits, interests, or economic, health, and credit status through computer programs, and then making a decision. Here, "expert decision-making" refers to the activity of making decisions by personnel who specialize in a particular field, possess specialized experience, knowledge, and skills, and have reached a certain level of professional expertise.

[0031] This disclosure provides a domain security detection method, which includes: collecting all data related to access control policies within the domain; classifying all data according to their respective subjects to obtain classification results; obtaining classification results for subjects including users, computers, and groups; determining whether security risks exist within the domain based on the classification results for users, computers, and groups. This method can detect security risks within Windows domains and protect intranet security.

[0032] Figure 1 The illustration schematically depicts application scenarios of domain security detection methods, apparatuses, devices, media, and program products according to embodiments of the present disclosure.

[0033] like Figure 1As shown, the application scenario according to this embodiment may include a Windows domain 100, which includes a first terminal device 101, a second terminal device 102, a third terminal device 103, a fourth terminal device 104, and a fifth terminal device 105. A network 106 serves as a medium for providing communication links between the first terminal device 101, the second terminal device 102, the third terminal device 103, the fourth terminal device 104, and the fifth terminal device 105. The network 106 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.

[0034] A Windows domain is an independently operating unit in a Windows network; inter-domain access requires establishing a trust relationship. In the Windows network operating system, a domain is a security boundary used by a group of computers to share a common security database.

[0035] The first terminal device 101, the second terminal device 102, the third terminal device 103, the fourth terminal device 104, and the fifth terminal device 105 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0036] It should be noted that the intra-domain security detection method provided in this disclosure embodiment can generally be executed by a server. Correspondingly, the intra-domain security detection device provided in this disclosure embodiment can generally be located in a server. The intra-domain security detection method provided in this disclosure embodiment can also be executed by a server or server cluster that is different from the server and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, the fourth terminal device 104, the fifth terminal device 105, and / or the server. Correspondingly, the intra-domain security detection device provided in this disclosure embodiment can also be located in a server or server cluster that is different from the server and capable of communicating with the first terminal device 101, the second terminal device 102, the third terminal device 103, the fourth terminal device 104, the fifth terminal device 105, and / or the server.

[0037] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices and networks can be included.

[0038] The following will be based on Figure 1 The described scene, through Figures 2-4 The domain security detection method of the disclosed embodiments is described in detail.

[0039] Figure 2 A flowchart illustrating an in-domain security detection method according to an embodiment of the present disclosure is shown.

[0040] like Figure 2 As shown, the domain security detection method of this embodiment includes operations S210 to S230, and the domain security detection method can be executed by the server.

[0041] In operation S210, all data related to access control policies within the domain is collected.

[0042] In operation S220, all data is categorized according to their respective subjects, and the categorization results are obtained. Subjects include users, computers, and groups.

[0043] When operating S230, security risks within the domain are determined based on the classification results, according to the categories of users, computers, and groups.

[0044] In this embodiment of the disclosure, a Windows domain is an independently operating unit within a Windows network. Principals within a Windows domain can include user accounts, computers, printers, and other security principals. All user accounts, computers, printers, and other security principals are registered in a central database located on one or more central computer clusters called a Domain Controller (DC). Authentication is performed on the DC, and each user receives a unique user account, which can then be assigned access permissions to resources within the domain. In this embodiment of the disclosure, the Windows domain is simply referred to as a domain.

[0045] In some embodiments of this disclosure, all data are categorized by user, computer, and group, and the resulting categorization includes user attribute information, computer attribute information, and group attribute information.

[0046] User attribute information includes node information, group member identity information, local administrator permission information, and object control information.

[0047] Node information: A user's unique identifier or location information within the system.

[0048] Group member identity information: One or more organizations or permission groups to which the user belongs.

[0049] Local administrator privileges information: Whether the user has administrator privileges on a certain system node or resource.

[0050] Object control information: User access control permissions for objects or data within the system.

[0051] The computer's attribute information includes node information, local administrator information, group member identity information, local administrator permission information, and object control information.

[0052] Node information: Identification information of a computer in a network or system.

[0053] Local administrator information: Users and groups on the computer who have administrator privileges.

[0054] Group member identity information: The security group or policy group to which the computer belongs.

[0055] Local administrator privileges information: Administrator-level privileges granted on the computer.

[0056] Object control information: A computer's access control over certain resources or objects.

[0057] The group's attribute information includes node information, group member information, group member identity information, local administrator permission information, and object control information.

[0058] Node information: A unique identifier or name for a group within the system.

[0059] Group member information: The user or computer members included in the group.

[0060] Group member identity information: the relationship between the group and other groups or the hierarchical structure of member identities.

[0061] Local administrator privileges information: Administrator privileges granted by members within the group.

[0062] Object control information: Groups have management and access control permissions for objects or data within the system.

[0063] In some embodiments of this disclosure, all data related to access control policies within the domain includes: Lightweight Directory Access Protocol (LDAP) data and DC registry data, domain machine sessions, domain local security policies, trust relationships between multiple domains, and distributed component object models.

[0064] LDAP data provides key functions such as authentication, authorization, centralized management, and directory services, enabling administrators to efficiently manage user and computer accounts within a domain and ensuring users can securely access the resources they need. In some embodiments of this disclosure, LDAP data can be used to determine a user's object control information and the computer's local administrator privileges.

[0065] Within a domain, the Domain Controller (DC) plays a crucial role, managing user and computer accounts and handling tasks such as authentication, authorization, and policy distribution. The Registry, on the other hand, is a vital database in the Windows operating system used to store system and application configuration information. The DC's registry contains configuration information related to domain services, DNS services, certificate services, and more. In some embodiments of this disclosure, the DC's registry data can be used to determine user node information, user group membership information, user local administrator privileges information, computer node information, computer group membership information, group node information, and group member information.

[0066] By obtaining the values ​​of Kdc\StrongCertificateBindingEnforcement and Schannel\CertificateMappingMethods from the DC registry, the allowed certificate mapping methods within the domain can be determined for certificate service authentication.

[0067] In some embodiments of this disclosure, local administrator information for a computer can be determined based on intra-domain machine sessions and LDAP data. Object control information for a computer can be determined based on local security policies and Lightweight Directory Access Protocol (LDP) data. Object control information for a group can be determined based on trust relationships between multiple domains, a distributed component object model, and LDP data.

[0068] Figure 3 A flowchart illustrating a domain-based user classification-based security detection method according to an embodiment of this disclosure is shown.

[0069] like Figure 3 As shown, the domain-based user classification security detection method in this embodiment includes operations S310 to S350.

[0070] When operating S310, obtain high-privilege users within the domain.

[0071] Users with higher privileges have greater operational permissions than users with lower privileges. Operational permissions can include at least one of the following: access permissions, execute permissions, etc.

[0072] Regarding access permissions: High-privilege users typically have broad access to system resources, including but not limited to files, folders, printers, and network devices. They can access and modify system-level settings such as the registry and group policies. In some cases, high-privilege users can even manage and control the entire domain. Low-privilege users have relatively limited access permissions. They can usually only access and manipulate explicitly authorized resources and cannot access or modify system-level settings such as the registry. Performing certain operations may require administrator approval or the entry of an administrator password.

[0073] Regarding execution permissions: High-privilege users can install and uninstall software, drivers, etc.; perform system backup and restore operations; create, delete, and manage user accounts and groups; and perform advanced functions such as remote desktop connection and remote assistance. Low-privilege users can typically only run verified applications, cannot install or uninstall software, and cannot perform system backup and restore operations. They cannot create, delete, or manage user accounts and groups, and their ability to perform functions such as remote desktop connection and remote assistance may be restricted.

[0074] Regarding user management permissions: High-privilege users typically have the ability to manage user accounts, including creating, modifying, and deleting user accounts, as well as assigning or changing user permissions. Low-privilege users typically cannot manage other user accounts. They can only view their own account information and may not be able to change their own permission level.

[0075] When operating S320, based on the classification results, determine whether there are low-privilege users in the group to which the high-privilege user belongs.

[0076] In some implementations, it can be determined whether there are low-privilege users in the group to which the high-privilege user belongs, based on the attribute information of the high-privilege user and the attribute information of the group.

[0077] When operating S330, if there are no low-privilege users in the group of a high-privilege user, determine whether the device logged in by the high-privilege user account should allow the low-privilege account to log in, based on the classification results.

[0078] In some implementations, it can be determined whether a device logged in by a high-privilege user account allows a low-privilege user account to log in, based on the attribute information of the device logged in by the high-privilege user account and the attribute information of the low-privilege user account.

[0079] When operating S340, if a device logged in by a high-privilege user account does not allow low-privilege accounts to log in, the system determines, based on the classification results, whether the object belonging to the high-privilege user account can be accessed by the low-privilege account.

[0080] In some implementations, it can be determined whether an object belonging to a high-privilege user account can be accessed by a low-privilege account based on the attribute information of the high-privilege user and the attribute information of the group.

[0081] When operating S350, if objects belonging to high-privilege user accounts cannot be accessed by low-privilege accounts, it is determined that there is no security risk associated with high-privilege accounts.

[0082] In some implementations, if a low-privilege user exists within the same group as a high-privilege user, operation S360 is executed, and a security warning is issued. If a device logged into by a high-privilege user account allows low-privilege accounts to log in, operation S360 is executed, and a security warning is issued. If an object belonging to a high-privilege user account can be accessed by a low-privilege account, operation S360 is executed, and a security warning is issued.

[0083] In some embodiments of this disclosure, configuration modifications can be made based on the assessment results after a security warning is received. For example, if a low-privilege user exists within the same group as a high-privilege user, group policies can be enhanced. Another example is that if an object belonging to a high-privilege user account can be accessed by a low-privilege user, the permissions of the low-privilege user can be changed.

[0084] Figure 4 A flowchart illustrating a domain-based group classification-based security detection method according to an embodiment of the present disclosure is shown.

[0085] like Figure 4 As shown, the domain-based group classification security detection method of this embodiment includes operations S410 to S450.

[0086] When operating S410, obtain high-privilege groups within the domain.

[0087] Higher-privilege groups have higher operation permissions than lower-privilege groups. Operation permissions can include at least one of the following: access permissions, execute permissions, etc.

[0088] When operating S420, based on the classification results, determine whether there are low-privilege users among the members of the high-privilege group.

[0089] In some implementations, it can be determined whether there are low-privilege users among the members of a high-privilege group based on the user's attribute information and the group's attribute information.

[0090] When operating S430, if there are no low-privilege users among the members of the high-privilege group, determine whether the administrator device of the high-privilege group should allow low-privilege accounts to log in based on the classification results.

[0091] In some implementations, it can be determined whether the administrator device to which the high-privilege group belongs allows low-privilege accounts to log in based on the user's attribute information, the computer's attribute information, and the group's attribute information.

[0092] When operating S440, if the administrator device belonging to the high-privilege group does not allow low-privilege accounts to log in, determine whether the objects belonging to the high-privilege group can be accessed by low-privilege accounts based on the classification results.

[0093] In some implementations, it can be determined whether an object belonging to a high-privilege group can be accessed by a low-privilege account based on the user's attribute information, the computer's attribute information, and the group's attribute information.

[0094] When operating S450, if objects belonging to a high-privilege group cannot be accessed by low-privilege users, it is determined that there is no security risk to the high-privilege group.

[0095] In some implementations, if a low-privilege user exists within the group of a high-privilege user, operation S460 is executed, and a security warning is issued. If the administrator device of the high-privilege group allows low-privilege accounts to log in, operation S460 is executed, and a security warning is issued. If an object belonging to the high-privilege group can be accessed by a low-privilege user, operation S460 is executed, and a security warning is issued.

[0096] In some embodiments of this disclosure, configuration modifications can be made based on the assessment results after receiving a security warning. For example, if a low-privilege user exists within the group of a high-privilege user, group policies can be enhanced to strengthen the account security of the high-privilege account. Another example is that if the administrator device of the high-privilege group allows a low-privilege account to log in, excessive privileges of the low-privilege user can be removed.

[0097] Figure 5 A flowchart illustrating a domain-based computer classification-based security detection method according to an embodiment of the present disclosure is shown.

[0098] like Figure 5 As shown, the domain-based computer classification security detection method of this embodiment includes operations S510 to S550.

[0099] When operating S510, obtain high-privilege computers within the domain.

[0100] Computers with higher privileges have higher access control privileges than computers with lower privileges.

[0101] A high-privilege computer can centrally manage and control other computers and users in the domain. It can create, modify, and delete user accounts and groups. It can enforce and manage group policies to control the behavior of computers and users in the domain. It can access and modify sensitive data and configurations within the domain.

[0102] Low-privilege computers typically only have access to and use the network resources and services assigned to them. They cannot manage or control other computers and users in the domain. User accounts on them can usually only perform limited operations, such as accessing files and printing documents. Access to sensitive data and configurations is restricted.

[0103] When operating S520, based on the classification results, determine whether there are low-privilege users among the users and administrators who can log in on the high-privilege computer.

[0104] In some implementations, it can be determined whether there are low-privilege users among the members of a high-privilege group based on the computer's attributes, the user's attribute information, and the group's attribute information.

[0105] When operating S530, if there are no low-privilege users among the users and administrators who can log in on the high-privilege computer, determine whether the local access control list configuration of the high-privilege computer is correct based on the classification results.

[0106] In some implementations, the correctness of the local access control list configuration of a high-privilege computer can be determined based on the computer's attributes.

[0107] When operating S540, if the local access control list configuration of the high-privilege computer is incorrect, determine whether the high-privilege computer's certificate trust is correct based on the classification results.

[0108] In some implementations, the validity of a high-privilege computer certificate trust can be determined based on the computer's attributes.

[0109] When operating the S550, assuming the high-privilege computer certificate is correctly trusted, it is determined that there are no security risks in the high-privilege group.

[0110] In some implementations, if a low-privilege user exists among the users and administrators who can log in on the high-privilege computer, operation S560 is executed, and a security warning is issued. If the local access control list configuration on the high-privilege computer is incorrect, operation S560 is executed, and a security warning is issued. If the certificate trust on the high-privilege computer is incorrect, operation S560 is executed, and a security warning is issued.

[0111] Based on the above-described intra-domain security detection method, this disclosure also provides an intra-domain security detection device. The following will be combined with... Figure 6 The device is described in detail.

[0112] Figure 6 A schematic block diagram of a domain security detection device according to an embodiment of the present disclosure is shown.

[0113] like Figure 6As shown, the domain security detection device 600 of this embodiment includes a collection module 610, a classification module 620, and a determination module 630.

[0114] The collection module 610 is used to collect all data related to access control policies within the domain. In one embodiment, the collection module 610 can be used to perform the operation S210 described above, which will not be repeated here.

[0115] The classification module 620 is used to classify all data according to their respective subjects to obtain classification results. Subjects include users, computers, and groups. In one embodiment, the classification module 620 can be used to perform the operation S220 described above, which will not be repeated here.

[0116] The determination module 630 is used to determine whether there are security risks within the domain based on the classification results, according to users, computers, and groups. In one embodiment, the determination module 630 can be used to perform the operation S230 described above, which will not be repeated here.

[0117] According to embodiments of this disclosure, collecting all data related to access control policies within a domain includes: collecting lightweight directory access protocol data and domain controller registry data; enumerating machine sessions within the domain, local security policies within the domain, trust relationships between multiple domains, and distributed component object models.

[0118] According to embodiments of this disclosure, the classification results include user attribute information, computer attribute information, and group attribute information; user attribute information includes node information, group member identity information, local administrator permission information, and object control information; computer attribute information includes node information, local administrator information, group member identity information, local administrator permission information, and object control information; group attribute information includes node information, group member information, group member identity information, local administrator permission information, and object control information.

[0119] According to embodiments of this disclosure, the domain security detection device 600 further includes: a first determining submodule, configured to determine user node information, user group member identity information, user local administrator privilege information, computer node information, computer group member identity information, group node information, and group group member information based on registry data of the domain controller; a second determining submodule, configured to determine user object control information and computer local administrator privilege information based on Lightweight Directory Access Protocol (Light DLTP) data; a third determining submodule, configured to determine computer local administrator information based on domain machine session and Lightweight Directory Access Protocol (Light DLTP) data; a fourth determining submodule, configured to determine computer object control information based on local security policies and Lightweight Directory Access Protocol (Light DLTP) data; and a fifth determining submodule, configured to determine group object control information based on trust relationships between multiple domains, a distributed component object model, and Lightweight Directory Access Protocol (Light DLTP) data.

[0120] According to embodiments of this disclosure, based on user classification, determining whether a security risk exists within a domain includes: acquiring high-privilege users within the domain, where the operation permissions of high-privilege accounts are higher than those of low-privilege accounts; determining, based on the classification results, whether there are low-privilege users in the user group to which the high-privilege user belongs; if there are no low-privilege users in the user group to which the high-privilege user belongs, determining, based on the classification results, whether the device where the high-privilege user account logs in allows the low-privilege account to log in; if the device where the high-privilege user account logs in does not allow the low-privilege account to log in, determining, based on the classification results, whether the object belonging to the high-privilege user account can be called by the low-privilege account; and if the object belonging to the high-privilege user account cannot be called by the low-privilege account, determining that the high-privilege account does not pose a security risk.

[0121] According to embodiments of this disclosure, based on group classification, determining whether a security risk exists within a domain based on the classification results includes: obtaining high-privilege groups within the domain, where the operation permissions of high-privilege groups are higher than those of low-privilege groups; determining, based on the classification results, whether any low-privilege users exist among the members of the high-privilege groups; if no low-privilege users exist among the members of the high-privilege groups, determining, based on the classification results, whether the administrator device to which the high-privilege groups belong allows low-privilege accounts to log in; if the administrator device to which the high-privilege groups belong does not allow low-privilege accounts to log in, determining, based on the classification results, whether objects belonging to the high-privilege groups can be invoked by low-privilege accounts; and if objects belonging to the high-privilege groups cannot be invoked by low-privilege users, determining that the high-privilege groups do not pose a security risk.

[0122] According to embodiments of this disclosure, determining whether a security risk exists within a domain based on computer classification and classification results includes: acquiring high-privilege computers within the domain, where the access control permissions of high-privilege computers are higher than those of low-privilege computers; determining, based on the classification results, whether there are low-privilege users among the users and administrators who can log in on the high-privilege computers; if there are no low-privilege users among the users and administrators who can log in on the high-privilege computers, determining, based on the classification results, whether the local access control list configuration of the high-privilege computers is correct; if the local access control list configuration of the high-privilege computers is correct, determining, based on the classification results, whether the certificate trust of the high-privilege computers is correct; and if the certificate trust of the high-privilege computers is correct, determining that there is no security risk in the high-privilege group.

[0123] According to embodiments of this disclosure, any plurality of modules among the collection module 610, classification module 620, and determination module 630 may be combined into one module, or any one of these modules may be split into multiple modules. Alternatively, at least a portion of the functionality of one or more of these modules may be combined with at least a portion of the functionality of other modules and implemented in one module. According to embodiments of this disclosure, at least one of the collection module 610, classification module 620, and determination module 630 may be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the collection module 610, classification module 620, and determination module 630 may be at least partially implemented as a computer program module, which, when run, can perform corresponding functions.

[0124] Figure 7 A block diagram schematically illustrates an electronic device suitable for implementing an in-domain security detection method according to an embodiment of the present disclosure.

[0125] like Figure 7As shown, an electronic device 700 according to an embodiment of the present disclosure includes a processor 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage portion 708 into a random access memory (RAM) 703. The processor 701 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 701 may also include onboard memory for caching purposes. The processor 701 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.

[0126] RAM 703 stores various programs and data required for the operation of electronic device 700. Processor 701, ROM 702, and RAM 703 are interconnected via bus 704. Processor 701 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 702 and / or RAM 703. It should be noted that programs may also be stored in one or more memories other than ROM 702 and RAM 703. Processor 701 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in one or more memories.

[0127] According to embodiments of this disclosure, the electronic device 700 may further include an input / output (I / O) interface 705, which is also connected to a bus 704. The electronic device 700 may also include one or more of the following components connected to the input / output (I / O) interface 705: an input section 706 including a keyboard, mouse, etc.; an output section 707 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 708 including a hard disk, etc.; and a communication section 709 including a network interface card such as a LAN card, modem, etc. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the input / output (I / O) interface 705 as needed. A removable medium 711, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 710 as needed so that computer programs read from it can be installed into the storage section 708 as needed.

[0128] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.

[0129] According to embodiments of this disclosure, the computer-readable storage medium can be a non-volatile computer-readable storage medium, such as including, but not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to embodiments of this disclosure, the computer-readable storage medium may include ROM 702 and / or RAM 703 and / or one or more memories other than ROM 702 and RAM 703 described above.

[0130] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods shown in the flowchart. When the computer program product is run on a computer system, the program code enables the computer system to implement the domain security detection method provided in embodiments of this disclosure.

[0131] When the computer program is executed by the processor 701, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0132] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 709, and / or installed from a removable medium 711. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.

[0133] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 709, and / or installed from the removable medium 711. When the computer program is executed by the processor 701, it performs the functions defined in the system of this disclosure embodiment. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.

[0134] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on a user's computing device, partially on a user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).

[0135] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0136] Those skilled in the art will understand that the features described in the various embodiments of this disclosure can be combined and / or combined in various ways, even if such combinations or combinations are not explicitly described in this disclosure. In particular, the features described in the various embodiments of this disclosure can be combined and / or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.

[0137] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.

Claims

1. A method for intra-domain security detection, characterized in that, The method includes: Collect all data related to access control policies within the domain. This collection includes: collecting lightweight directory access protocol data and domain controller registry data; enumerating machine sessions within the domain, local security policies within the domain, trust relationships between multiple domains, and distributed component object models. All the data is categorized according to their respective subjects to obtain the categorization results. The subjects include users, computers, and groups. Based on the classification of users, computers, and groups, determine whether there are security risks within the domain according to the classification results. Based on the classification of the groups, determine whether there are security risks within the domain according to the classification results, including: Obtain the high-privilege group within the domain, where the operation privileges of the high-privilege group are higher than those of the low-privilege group; Based on the classification results, it is determined whether there are low-privilege users among the members of the high-privilege group. The members of the high-privilege group are the user or computer members included in the member information of the high-privilege group. The low-privilege users are used to emphasize the user entity itself. If there are no low-privilege users among the members of the high-privilege group, determine whether the administrator device of the high-privilege group allows low-privilege accounts to log in based on the classification results. When the administrator device of the high-privilege group does not allow low-privilege accounts to log in, the classification result determines whether the object of the high-privilege group can be called by a low-privilege account, where the low-privilege account is used to emphasize the account's behavior. If the objects belonging to the high-privilege group cannot be accessed by low-privilege users, it is determined that the high-privilege group does not pose a security risk. The method includes: Based on the registry data of the domain controller, determine the user's node information, the user's group member identity information, the user's local administrator privilege information, the computer's node information, the computer's group member identity information, the group's node information, and the group's group member information; Based on the Lightweight Directory Access Protocol data, determine the user's object control information and the computer's local administrator privileges information; Based on the intra-domain machine sessions and the Lightweight Directory Access Protocol (Light DLAP) data, determine the local administrator information of the computer; Based on the local security policy and the lightweight directory access protocol data, the object control information of the computer is determined; Based on the trust relationships between the multiple domains, the distributed component object model, and the lightweight directory access protocol data, the object control information of the group is determined.

2. The method according to claim 1, characterized in that, The collection of all data related to access control policies within the domain includes: Collect Lightweight Directory Access Protocol data and domain controller registry data; It enumerates intra-domain machine sessions, intra-domain local security policies, trust relationships between multiple domains, and distributed component object models.

3. The method according to claim 1, characterized in that, The classification results include the user's attribute information, the computer's attribute information, and the group's attribute information; The user's attribute information includes node information, group member identity information, local administrator permission information, and object control information; The computer's attribute information includes node information, local administrator information, group member identity information, local administrator permission information, and object control information; The group's attribute information includes node information, group member information, group member identity information, local administrator permission information, and object control information.

4. The method according to claim 3, characterized in that, The step of determining whether there is a security risk within the domain based on the user's classification and the classification result includes: Obtain high-privilege users within the domain, whose operation privileges are higher than those of low-privilege users; Based on the classification results, determine whether there are any low-privilege users in the group to which the high-privilege user belongs; If there are no low-privilege users in the group of the high-privilege user, determine whether the device logged in by the high-privilege user account allows low-privilege account login based on the classification result; If a device logged in by a high-privilege user account does not allow low-privilege accounts to log in, the classification result is used to determine whether the object belonging to the high-privilege user account can be accessed by a low-privilege account. If the object belonging to the high-privilege user account cannot be accessed by the low-privilege account, it is determined that the high-privilege account does not pose a security risk.

5. The method according to claim 1, characterized in that, The step of determining whether there is a security risk within the domain based on the classification of the computers includes: Obtain high-privilege computers within the domain, wherein the access control permissions of the high-privilege computers are higher than those of the low-privilege computers; Based on the classification results, determine whether there are any low-privilege users among the users and administrators who can log in on the high-privilege computer; If there are no low-privilege users among the users and administrators who can log in on the high-privilege computer, determine whether the local access control list configuration of the high-privilege computer is correct based on the classification results. If the local access control list of the high-privilege computer is configured correctly, determine whether the high-privilege computer certificate trust is correct based on the classification result. If the high-privilege computer certificate is correctly trusted, it is determined that there is no security risk to the high-privilege group.

6. A domain security detection device, characterized in that, The apparatus, applied to the domain security detection method of claim 1, comprises: The collection module is used to collect all data related to access control policies within the domain; the collection of all data related to access control policies within the domain includes: collecting lightweight directory access protocol data and domain controller registry data; enumerating machine sessions within the domain, local security policies within the domain, trust relationships between multiple domains, and distributed component object models; The classification module is used to classify all the data according to their respective subjects to obtain classification results. The subjects include users, computers, and groups. The determination module is used to determine whether there are security risks within the domain based on the classification results of users, computers, and groups, respectively. The method includes: Based on the registry data of the domain controller, determine the user's node information, the user's group member identity information, the user's local administrator privilege information, the computer's node information, the computer's group member identity information, the group's node information, and the group's group member information; Based on the Lightweight Directory Access Protocol data, determine the user's object control information and the computer's local administrator privileges information; Based on the intra-domain machine sessions and the Lightweight Directory Access Protocol (Light DLAP) data, determine the local administrator information of the computer; Based on the local security policy and the lightweight directory access protocol data, the object control information of the computer is determined; Based on the trust relationships between the multiple domains, the distributed component object model, and the lightweight directory access protocol data, the object control information of the group is determined.

7. An electronic device, comprising: One or more processors; Memory, used to store one or more computer programs. The characteristic feature is that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program or instructions stored thereon, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 5.

9. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by a processor, they implement the steps of the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Secure access method, system, equipment and medium

    CN114268494A

  • Network domain security detection method and device based on domain environment

    CN116208368A