Software installation state checking method, device and equipment and readable storage medium
By employing a back-connection verification method, the problem of misjudging the installation status of host software in complex network architectures was resolved, ensuring the accuracy and consistency of the security protection software installation status on each host and improving network security.
Patent Information
- Application Number
- CN202411851591.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-16
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2044-12-16
AI Technical Summary
In complex network architectures, installation status records based on IP addresses cannot accurately reflect the installation status of security software on each host, which may lead to misjudgments, especially in multi-cloud scenarios.
By using a back-connection verification method, the IP address to be verified reported by the scanning node is obtained. If the target software installation record exists, a back-connection verification is performed. If the verification fails, it is determined that the target software is not installed on the device, and the installation package is sent if necessary.
This improved the installation coverage of the target software, ensuring the accuracy and consistency of the security software installation status on each host in the network, and enhancing network security.
Smart Images

Figure CN119697059B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, specifically to a method, apparatus, device, and computer-readable storage medium for verifying software installation status. Background Technology
[0002] Ensuring that every host / device has security software installed is a crucial measure for network security. The coverage of security software installation directly affects whether assets on the network can be effectively protected. Therefore, identifying and accurately determining whether a host has security software installed is particularly important. A typical method is a host security cluster, which scans the network area of its scanning nodes, similar to an NMAP scan, to identify which hosts are present in the network area. By comparing the IP addresses recorded in the known assets table of the host security server with the installation status, it can identify which hosts in the scan results have security software installed and which do not.
[0003] However, in complex network architectures, such as multi-cloud scenarios, multiple hosts in different network zones may have the same IP address. For example, host A in network zone 1 has the IP address 192.168.1.10, and host B in network zone 2 has the IP address 192.168.1.10. Host A has security software installed, so the recorded installation status for 192.168.1.10 is "installed." If the installation record is used for judgment, it would be directly determined that host B also has security software installed, but in reality, host B may not have security software installed. Therefore, recording the installation status based on IP address cannot accurately reflect the security software installation status of each host. Summary of the Invention
[0004] To address the aforementioned technical problems, this application provides a method, apparatus, device, and computer-readable storage medium for verifying software installation status.
[0005] In a first aspect, embodiments of this application provide a method for verifying software installation status, the method comprising:
[0006] Obtain the IP address to be verified reported by the scanning node. The scanning node scans its network area to obtain the IP address to be verified.
[0007] If a target software installation record exists corresponding to the IP address to be verified, then a back-connection verification is performed on the IP address to be verified.
[0008] If the connection verification fails, it is determined that the device with the IP address to be verified in the network area where the scanning node is located does not have the target software installed.
[0009] In conjunction with the first aspect, in one implementation, after receiving a back-connection verification request, the device with the target software installed sends a back-connection signal with the specified IP address contained in the back-connection verification request as the destination address, wherein the specified IP address is the IP address of the scanning node.
[0010] In conjunction with the first aspect, in one implementation, the back-connection verification of the IP address to be verified includes:
[0011] Send a connection verification request to the device whose IP address is the IP address to be verified and which has the target software installed;
[0012] Detect whether the scanning node has received a return connection signal;
[0013] If no follow-up signal is received, the verification is considered to have failed.
[0014] In conjunction with the first aspect, in one implementation, after obtaining the IP address to be verified reported by the scanning node, the method further includes:
[0015] If no installation record for the target software corresponding to the IP address to be verified exists, the installation package of the target software is sent to the device with the IP address to be verified in the network area where the scanning node is located.
[0016] In conjunction with the first aspect, in one implementation, after determining that the device with the IP address to be verified in the network area where the scanning node is located does not have the target software installed if the back-connection verification fails, the method further includes:
[0017] The installation package of the target software is sent to the device with the IP address to be verified in the network area where the scanning node is located.
[0018] Secondly, embodiments of this application provide a software installation status verification device, the software installation status verification device comprising:
[0019] The acquisition module is used to acquire the IP address to be verified reported by the scanning node. The scanning node scans its network area to obtain the IP address to be verified.
[0020] The verification module is used to perform a back-connection verification on the IP address to be verified if there is a target software installation record corresponding to the IP address to be verified.
[0021] The determination module is used to determine, if the back-connection verification fails, that the device with the IP address to be verified in the network area where the scanning node is located does not have the target software installed.
[0022] In conjunction with the second aspect, in one implementation, after receiving a back-connection verification request, the device with the target software installed sends a back-connection signal with the specified IP address contained in the back-connection verification request as the destination address, wherein the specified IP address is the IP address of the scanning node.
[0023] In conjunction with the second aspect, in one implementation, the verification module is used for:
[0024] Send a connection verification request to the device whose IP address is the IP address to be verified and which has the target software installed;
[0025] Detect whether the scanning node has received a return connection signal;
[0026] If no follow-up signal is received, the verification is considered to have failed.
[0027] Thirdly, embodiments of this application provide a software installation status verification device, which includes a processor, a memory, and a software installation status verification program stored in the memory and executable by the processor. When the software installation status verification program is executed by the processor, it implements the steps of the software installation status verification method as described in the first aspect.
[0028] Fourthly, embodiments of this application provide a computer-readable storage medium storing a software installation status verification program, wherein when the software installation status verification program is executed by a processor, it implements the steps of the software installation status verification method as described in the first aspect.
[0029] The beneficial effects of the technical solutions provided in this application include:
[0030] In this embodiment, the scanning node obtains the IP address to be verified reported by the scanning node. The scanning node scans its network area to obtain the IP address to be verified. If a target software installation record corresponding to the IP address to be verified exists, a connection-back verification is performed on the IP address to be verified. If the connection-back verification fails, it is determined that the device with the IP address to be verified in the network area where the scanning node is located does not have the target software installed. Through this embodiment, when a target software installation record corresponding to the IP address to be verified exists, further connection-back verification of the IP address to be verified can more accurately determine the target software installation status of the device with the IP address to be verified in the network area where the scanning node is located. Attached Figure Description
[0031] Figure 1 This is a flowchart illustrating an embodiment of the software installation status verification method of this application;
[0032] Figure 2A schematic diagram of the functional modules of an embodiment of the software installation status verification device of this application;
[0033] Figure 3 This is a schematic diagram of the hardware structure of the software installation status verification device involved in the embodiments of this application. Detailed Implementation
[0034] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present application.
[0035] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0036] In a first aspect, embodiments of this application provide a method for verifying software installation status.
[0037] In one embodiment, reference is made to Figure 1 , Figure 1 This is a flowchart illustrating an embodiment of the software installation status verification method of this application. Figure 1 As shown, the software installation status verification methods include:
[0038] Step S10: Obtain the IP address to be verified reported by the scanning node. The scanning node scans its network area to obtain the IP address to be verified.
[0039] In this embodiment, for ease of explanation, two network regions are used as examples: network region 1 and network region 2. Network isolation exists between these different network regions. Network region 1 includes devices 11, 12, and 13; network region 2 includes devices 21 and 22. For any network region, any one of the devices can be used as a scanning node. For example, device 11 can be used as the scanning node in network region 1, and device 22 can be used as the scanning node in network region 2.
[0040] For any scanning node, it can actively scan to find other devices in its network area and obtain the IP addresses of these other devices as the addresses to be verified, which are then uploaded to the execution entity (e.g., a server) in this embodiment. For example, device 11 actively scans to find devices 12 and 13 and reports the IP addresses of device 12 (IP_12) and 13 (IP_13) as the IP addresses to be verified to the server; similarly, device 22 actively scans to find device 21 and reports the IP address of device 21 (IP_21) as the IP address to be verified to the server.
[0041] Taking the above description as an example, for the server, when the scanning node is device 11, the obtained IP addresses to be verified include: IP_12 and IP_13.
[0042] Step S20: If there is a target software installation record corresponding to the IP address to be verified, then perform a back-connection verification on the IP address to be verified.
[0043] In this embodiment, for any device in each network area, if the target software is installed, a corresponding target software installation record is generated and saved. The target software installation record includes at least the device's IP address, and may also include other information, such as the installation time. The target software is configured according to actual needs and is not limited here.
[0044] Based on the above explanation, for each IP address to be verified, check if there is a corresponding target software installation record. For example, IP_12 is 192.168.1.10, and IP_13 is 192.168.1.20.
[0045] If a target software installation record exists corresponding to 192.168.1.10, then perform a connection verification for IP_12.
[0046] Furthermore, in one embodiment, after receiving a back-connection verification request, the device with the target software installed sends a back-connection signal with the specified IP address contained in the back-connection verification request as the destination address, wherein the specified IP address is the IP address of the scanning node.
[0047] In this embodiment, only devices with the target software installed can receive the connection verification request sent by the server. Taking device 11 as the scanning node, the specified IP address included in the connection verification request is the IP address of device 11, IP_11. After receiving the connection verification request, the device with the target software installed sends a connection signal with IP_11 as the destination address. The target software client of the device with the target software installed can communicate with the server. The server has result data, and the server sends a connection verification request to the target software client so that the target software client can actively connect to the specified IP address.
[0048] Further, in one embodiment, the back-connection verification of the IP address to be verified includes:
[0049] A connection verification request is sent to the device whose IP address is the IP address to be verified and which has the target software installed; the scanning node is checked to see if it receives a connection signal; if no connection signal is received, the verification is determined to have failed.
[0050] In this embodiment, it is assumed that device 21 actually has the target software installed, while device 12 does not. When the scanning node is device 11, and IP_12 and IP_21 = 192.168.1.10, and an installation record exists for 192.168.1.10, the server sends a back-to-back verification request to device 21. This request includes the IP address of device 11, IP_11. Device 21 then needs to send a back-to-back signal with IP_11 as the destination address. Due to network isolation between different network areas, device 11 cannot receive the loopback signal sent by device 21, thus the verification fails.
[0051] Step S30: If the back-connection verification fails, it is determined that the device with the IP address to be verified in the network area where the scanning node is located has not installed the target software.
[0052] In this embodiment, in conjunction with the above description, when device 11 cannot receive the loopback signal sent by device 21, it is determined that the verification has failed, and the back-connection verification for IP_12 has failed. Therefore, it is determined that the device with IP address 192.168.1.10 in network area 1 where device 11 is located has not installed the target software.
[0053] In this embodiment, the scanning node obtains the IP address to be verified reported by the scanning node. The scanning node scans its network area to obtain the IP address to be verified. If a target software installation record corresponding to the IP address to be verified exists, a connection-back verification is performed on the IP address to be verified. If the connection-back verification fails, it is determined that the device with the IP address to be verified in the network area where the scanning node is located does not have the target software installed. Through this embodiment, when a target software installation record corresponding to the IP address to be verified exists, further connection-back verification of the IP address to be verified can more accurately determine the target software installation status of the device with the IP address to be verified in the network area where the scanning node is located.
[0054] Furthermore, in one embodiment, after step S10, the method further includes:
[0055] If no installation record for the target software corresponding to the IP address to be verified exists, the installation package of the target software is sent to the device with the IP address to be verified in the network area where the scanning node is located.
[0056] In this embodiment, taking the IP addresses to be verified obtained by the server as including IP_12 and IP_13 as an example, if there is no target software installation record corresponding to IP_13, it means that the target software has not been installed on device 13. Then, the installation package of the target software is sent to the device with IP address IP_13 in network area 1 where device 11 is located, so that device 13 can install the target software, thereby improving the target software installation coverage and enhancing network security.
[0057] Furthermore, in one embodiment, after step S30, the method further includes:
[0058] The installation package of the target software is sent to the device with the IP address to be verified in the network area where the scanning node is located.
[0059] In this embodiment, referring to the above description, after determining that the device with IP address 192.168.1.10 in network area 1 where device 11 is located has not installed the target software, the installation package of the target software is sent to the device with IP address 192.168.1.10 in network area 1 so that it can install the target software, thereby improving the target software installation coverage and enhancing network security.
[0060] Secondly, embodiments of this application also provide a software installation status verification device.
[0061] In one embodiment, reference is made to Figure 3 , Figure 3 This is a functional module diagram of an embodiment of the software installation status verification device of this application. Figure 3 As shown, the software installation status verification device includes:
[0062] The acquisition module 10 is used to acquire the IP address to be verified reported by the scanning node, wherein the scanning node scans its network area to obtain the IP address to be verified.
[0063] The verification module 20 is used to perform back-connection verification on the IP address to be verified if there is a target software installation record corresponding to the IP address to be verified.
[0064] The determination module 30 is used to determine, if the back-connection verification fails, that the device with the IP address to be verified in the network area where the scanning node is located does not have the target software installed.
[0065] Furthermore, in one embodiment, after receiving a back-connection verification request, the device with the target software installed sends a back-connection signal with the specified IP address contained in the back-connection verification request as the destination address, wherein the specified IP address is the IP address of the scanning node.
[0066] Furthermore, in one embodiment, the verification module 20 is used for:
[0067] Send a connection verification request to the device whose IP address is the IP address to be verified and which has the target software installed;
[0068] Detect whether the scanning node has received a return connection signal;
[0069] If no follow-up signal is received, the verification is considered to have failed.
[0070] Furthermore, in one embodiment, the software installation status verification device further includes a sending module, used for:
[0071] If no installation record for the target software corresponding to the IP address to be verified exists, the installation package of the target software is sent to the device with the IP address to be verified in the network area where the scanning node is located.
[0072] Furthermore, in one embodiment, the software installation status verification device further includes a sending module, used for:
[0073] The installation package of the target software is sent to the device with the IP address to be verified in the network area where the scanning node is located.
[0074] The functions of each module in the software installation status verification device correspond to the steps in the software installation status verification method embodiment, and their functions and implementation processes will not be described in detail here.
[0075] Thirdly, embodiments of this application provide a software installation status verification device, which can be a personal computer (PC), laptop computer, server, or other device with data processing capabilities.
[0076] Reference Figure 3 , Figure 3 This is a schematic diagram of the hardware structure of the software installation status verification device involved in the embodiments of this application. In the embodiments of this application, the software installation status verification device may include a processor, a memory, a communication interface, and a communication bus.
[0077] The communication bus can be of any type and is used to interconnect the processor, memory, and communication interface.
[0078] The communication interface includes input / output (I / O) interfaces, physical interfaces, and logical interfaces used for interconnecting internal components of the software installation status verification device, as well as interfaces used for interconnecting the software installation status verification device with other devices (such as other computing devices or user equipment). Physical interfaces can be Ethernet interfaces, fiber optic interfaces, ATM interfaces, etc.; user equipment can be displays, keyboards, etc.
[0079] Memory can be various types of storage media, such as random access memory (RAM), read-only memory (ROM), non-volatile RAM (NVRAM), flash memory, optical storage, hard disk, programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), etc.
[0080] The processor can be a general-purpose processor, which can call a software installation status verification program stored in memory and execute the software installation status verification method provided in the embodiments of this application. For example, the general-purpose processor can be a central processing unit (CPU). The method executed when the software installation status verification program is called can be referred to in various embodiments of the software installation status verification method of this application, and will not be repeated here.
[0081] Those skilled in the art will understand that Figure 3The hardware structure shown does not constitute a limitation of this application and may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0082] Fourthly, embodiments of this application also provide a computer-readable storage medium.
[0083] The present application provides a computer-readable storage medium storing a software installation status verification program, wherein when the software installation status verification program is executed by a processor, it implements the steps of the software installation status verification method described above.
[0084] The method implemented when the software installation status verification program is executed can be referred to in various embodiments of the software installation status verification method of this application, and will not be repeated here.
[0085] It should be noted that the sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0086] The terms "comprising" and "having," and any variations thereof, in the specification, claims, and accompanying drawings of this application are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus. The terms "first," "second," and "third," etc., are used to distinguish different objects, etc., and do not indicate a sequence, nor do they limit "first," "second," and "third" to different types.
[0087] In the description of the embodiments of this application, terms such as "exemplary," "for example," or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplary," "for example," or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of terms such as "exemplary," "for example," or "for instance" is intended to present the relevant concepts in a concrete manner.
[0088] In the description of the embodiments of this application, unless otherwise stated, " / " means "or". For example, A / B can mean A or B. The "and / or" in the text is merely a description of the relationship between related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of this application, "multiple" means two or more.
[0089] In some processes described in the embodiments of this application, multiple operations or steps are included in a specific order. However, it should be understood that these operations or steps may not be executed in the order they appear in the embodiments of this application, or they may be executed in parallel. The sequence number of the operation is only used to distinguish different operations, and the sequence number itself does not represent any execution order. In addition, these processes may include more or fewer operations, and these operations or steps may be executed sequentially or in parallel, and these operations or steps may be combined.
[0090] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) as described above, and includes several instructions to cause a terminal device to execute the methods described in the various embodiments of this application.
[0091] The above are merely preferred embodiments of this application and do not limit the patent scope of this application. Any equivalent structural or procedural transformations made using the content of this application's specification and drawings, or direct or indirect applications in other related technical fields, are similarly included within the patent protection scope of this application.
Claims
1. A method for verifying software installation status, characterized in that, The software installation status verification method includes: Obtain the IP address to be verified reported by the scanning node. The scanning node scans its network area to obtain the IP address to be verified. If a target software installation record exists corresponding to the IP address to be verified, then a back-connection verification is performed on the IP address to be verified. If the connection verification fails, it is determined that the device with the IP address to be verified in the network area where the scanning node is located does not have the target software installed.
2. The software installation status verification method as described in claim 1, characterized in that, After receiving the reconnection verification request, the device with the target software installed sends a reconnection signal with the specified IP address contained in the reconnection verification request as the destination address. The specified IP address is the IP address of the scanning node.
3. The software installation status verification method as described in claim 2, characterized in that, The back-connection verification of the IP address to be verified includes: Send a connection verification request to the device whose IP address is the IP address to be verified and which has the target software installed; Detect whether the scanning node has received a return connection signal; If no follow-up signal is received, the verification is considered to have failed.
4. The software installation status verification method as described in claim 1, characterized in that, After obtaining the IP address to be verified reported by the scanning node, the process also includes: If no installation record for the target software corresponding to the IP address to be verified exists, the installation package of the target software is sent to the device with the IP address to be verified in the network area where the scanning node is located.
5. The software installation status verification method as described in any one of claims 1 to 4, characterized in that, After determining that the device with the IP address to be verified in the network area where the scanning node is located does not have the target software installed if the back-connection verification fails, the method further includes: The installation package of the target software is sent to the device with the IP address to be verified in the network area where the scanning node is located.
6. A software installation status verification device, characterized in that, The software installation status verification device includes: The acquisition module is used to acquire the IP address to be verified reported by the scanning node. The scanning node scans its network area to obtain the IP address to be verified. The verification module is used to perform a back-connection verification on the IP address to be verified if there is a target software installation record corresponding to the IP address to be verified. The determination module is used to determine, if the back-connection verification fails, that the device with the IP address to be verified in the network area where the scanning node is located does not have the target software installed.
7. The software installation status verification device as described in claim 6, characterized in that, After receiving the reconnection verification request, the device with the target software installed sends a reconnection signal with the specified IP address contained in the reconnection verification request as the destination address. The specified IP address is the IP address of the scanning node.
8. The software installation status verification device as described in claim 7, characterized in that, The verification module is used for: Send a connection verification request to the device whose IP address is the IP address to be verified and which has the target software installed; Detect whether the scanning node has received a return connection signal; If no follow-up signal is received, the verification is considered to have failed.
9. A software installation status verification device, characterized in that, The software installation status verification device includes a processor, a memory, and a software installation status verification program stored in the memory and executable by the processor, wherein when the software installation status verification program is executed by the processor, it implements the steps of the software installation status verification method as described in any one of claims 1 to 5.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a software installation status verification program, wherein when the software installation status verification program is executed by a processor, it implements the steps of the software installation status verification method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Self-signed SSL certificate processing system and method
CN108810163A
Application installation method and device and terminal
CN110022340A