Detection method and system
By responding to target task messages on the first server, pulling the running environment mirror to create a container, loading the detection program and obtaining task files from the cloud storage side for detection, it solves the problems of large resource occupation, impact on detection effects and high pressure on detection engine construction in cloud security detection, and achieves efficient and stable cloud security detection.
Patent Information
- Application Number
- CN202311473003.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-06
- Publication Date
- 2025-05-06
AI Technical Summary
The existing technology has problems in cloud security detection, such as large resource usage, impact on detection effects, threatening user system stability, and high pressure to build detection engines.
By responding to target task messages on the first server, pulling the running environment image to create a container, loading the detection program, and obtaining task files from the cloud storage side for detection, the need to install a client on the user host and build a detection engine is avoided.
It realizes detection without occupancy of user resources, avoids the impact of resource preemption and system stability, reduces the cost of detection engine construction, and solves the problem of detection engine expansion during peak periods.
Smart Images

Figure CN119938418A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present specification relate to the field of computer technology, and in particular to a detection method. Background Art
[0002] With the promotion and application of cloud services, cloud security faces continuous challenges. In order to ensure cloud security, it is usually necessary to detect user hosts related to cloud services. Traditional detection methods require the installation and deployment of clients on user hosts, and the execution of corresponding detection tasks by controlling the clients on the hosts. This method requires a large amount of user resources, and the mutual influence between resource-preemptive detection tasks will greatly reduce the detection effect, and even affect the stability of the user system, causing users to worry about data security, service stability, system performance, etc.
[0003] The other detection method requires the deployment of a large amount of resources to build a detection engine. Due to the differences in user machine system types, it is difficult to cover all systems and all tasks. At the same time, the diversity of various types of detection tasks requires real-time updates of the detection engine. During peak service periods, a large number of detection tasks require the detection engine to have the ability to urgently expand capacity to ensure concurrency, which will put tremendous pressure on the construction of the detection engine. Therefore, a detection method is urgently needed to solve the above problems. Summary of the invention
[0004] In view of this, the embodiments of this specification provide two detection methods. One or more embodiments of this specification also relate to a detection system, a computing device, a computer-readable storage medium and a computer program to solve the technical defects existing in the prior art.
[0005] According to a first aspect of an embodiment of the present specification, a detection method is provided, which is applied to a first server, and includes: responding to a target task message, wherein the target task message carries attribute information of a task to be detected; pulling a corresponding operating environment image according to the attribute information of the task to be detected, and creating a target container using the operating environment image; loading a detection program of the task to be detected in the target container according to the attribute information of the task to be detected, and obtaining a task file corresponding to the task to be detected from a cloud storage terminal, wherein the files stored in the cloud storage terminal include a task file corresponding to the target task message obtained from a user host; and detecting the task file using the detection program to obtain a target detection result.
[0006] According to the second aspect of the embodiments of this specification, a detection method is provided, which is applied to a second server, including: performing file collection on the operating system information and file system information of the user host to obtain a task file related to the task to be detected; sending the task file to a cloud storage end for storage, so that the first server obtains the task file corresponding to the task to be detected from the cloud storage end, the task to be detected is obtained from the target task message by the first server in response to the target task message, the task to be detected is used to enable the first server to pull the corresponding operating environment image according to the attribute information of the task to be detected, and create a target container using the operating environment image, load the detection program of the task to be detected in the target container according to the attribute information of the task to be detected, and use the detection program to detect the task file to obtain a target detection result.
[0007] According to the third aspect of the embodiment of this specification, a detection system is provided, including: a first server end applying the detection method, a second server end applying the detection method, and a cloud storage end; the cloud storage end is used to store a task file corresponding to the target task message obtained from the user host.
[0008] According to the fourth aspect of the embodiments of this specification, a computing device is provided, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which implement the steps of the above-mentioned detection method when executed by the processor.
[0009] According to a fifth aspect of the embodiments of this specification, a computer-readable storage medium is provided, which stores computer-executable instructions, and when the instructions are executed by a processor, the steps of the above-mentioned detection method are implemented.
[0010] According to a sixth aspect of the embodiments of this specification, a computer program is provided, wherein when the computer program is executed in a computer, the computer is caused to execute the steps of the above-mentioned detection method.
[0011] An embodiment of the present specification provides a detection method, which is applied to a first server, by responding to a target task message, wherein the target task message carries attribute information of a task to be detected; pulling a corresponding operating environment image according to the attribute information of the task to be detected, and creating a target container using the operating environment image; loading a detection program of the task to be detected in the target container according to the attribute information of the task to be detected, and obtaining a task file corresponding to the task to be detected from a cloud storage terminal; detecting the task file using the detection program to obtain a target detection result; the method does not need to occupy user resources, avoids the problem of resource preemption between different tasks, reduces the impact on the stability of the user system, and avoids the cost of building a detection engine, solving the problem of emergency expansion of the detection engine during task peak periods. BRIEF DESCRIPTION OF THE DRAWINGS
[0012] Figure 1 is a network architecture diagram of a detection system provided by an embodiment of this specification;
[0013] Figure 2 is a flow chart of a detection method applied to a first server provided by an embodiment of this specification;
[0014] Figure 3 is a flow chart of a detection method applied to a second server provided in an embodiment of this specification;
[0015] Figure 4 is a processing flow chart of a detection method provided by an embodiment of this specification;
[0016] Figure 5 It is a scene schematic diagram of a detection method provided by an embodiment of this specification;
[0017] Figure 6 It is a structural schematic diagram of a detection system provided by an embodiment of this specification;
[0018] Figure 7 It is a structural block diagram of a computing device provided by an embodiment of this specification. DETAILED DESCRIPTION
[0019] Many specific details are described in the following description to facilitate a full understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar generalizations without violating the connotation of this specification, so this specification is not limited to the specific implementation disclosed below.
[0020] The terms used in one or more embodiments of this specification are only for the purpose of describing specific embodiments, and are not intended to limit one or more embodiments of this specification. The singular forms of "a", "said" and "the" used in one or more embodiments of this specification and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.
[0021] It should be understood that although the terms first, second, etc. may be used to describe various information in one or more embodiments of this specification, this information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of this specification, the first may also be referred to as the second, and similarly, the second may also be referred to as the first. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".
[0022] In addition, it should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in one or more embodiments of this specification are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0023] First, the terms involved in one or more embodiments of this specification are explained.
[0024] Agent: Agent monitoring, the so-called Agent monitoring method, is to install a small Agent software on the host where the monitored application is located, through which data collection and management are realized; Agent monitoring agent software on the market can generally monitor the host and its applications on one host.
[0025] Agentless: Agentless monitoring refers to the so-called agentless monitoring method. On the host where the monitored application is located, no agent software is installed to collect the corresponding information. Instead, the collection is achieved through some standard protocols.
[0026] API: Application Programming Interface (API), also known as application programming interface, is an agreement for connecting different components of a software system.
[0027] At present, one detection method requires the installation and deployment of a client on the user's host. The cloud server controls the client on the host to execute the corresponding detection task by issuing control commands, which causes users to worry about data security, service stability, system performance, etc. Another detection method requires the deployment of a large number of resources to build a detection engine, which is difficult to cover all systems and all tasks; at the same time, the diversity of various types of detection task scripts requires real-time updates to the detection engine; during service peaks, a large number of detection tasks require the detection engine to have the ability to expand capacity urgently to ensure concurrency. These factors have caused tremendous pressure on the construction of the detection engine.
[0028] In view of this, the embodiments of this specification propose a detection method, which builds an execution task environment in an agentless manner, first avoiding the impact of deploying the client on the user host, and can download task files from the cloud storage end through function computing, solving the real-time update, task coverage, and emergency capacity expansion problems faced by building a detection engine.
[0029] In this specification, a detection method is provided. This specification also relates to a detection system, a computing device, and a computer-readable storage medium, which are described in detail one by one in the following embodiments.
[0030] See also Figure 1 , Figure 1 A network architecture diagram of a detection system provided according to an embodiment of this specification is shown. Figure 1 As shown, the detection system includes a first server 106, a second server 102 and a cloud storage 104; the detection method provided in the embodiment of this specification is applied to the detection system.
[0031] The first server 106 is used to respond to a target task message carrying attribute information of the task to be detected, pull the corresponding operating environment image according to the attribute information of the task to be detected, create a target container using the operating environment image, load the detection program of the task to be detected in the target container, and obtain the task file corresponding to the task to be detected from the cloud storage terminal 104, detect the task file using the detection program, and obtain the target detection result.
[0032] The second server 102 is used to collect the operating system information and file system information of the user host to obtain the task file related to the task to be detected; and send the task file to the cloud storage end 104 for storage, so that the first server 106 detects the task file.
[0033] The cloud storage terminal 104 is used to store the task file corresponding to the target task message obtained from the user host.
[0034] Specifically, the task to be detected can be understood as a task for performing detection on the user's host system, such as vulnerability scanning, baseline checking and other tasks; the first server end 106 can be understood as a function computing unit (FC, Function Compute, an event-driven fully managed computing service), the second server end 102 can be understood as a server related to the task to be detected; the cloud storage end 104 can be understood as a storage end that stores task files corresponding to the task to be detected.
[0035] During specific implementation, the second server 102 can obtain a hard disk snapshot of the user host through a snapshot interface, mount the hard disk corresponding to the hard disk snapshot in the sandbox environment, and obtain the operating system information and file system information corresponding to the hard disk snapshot; analyze the operating system information and file system information, such as filtering through file size, file type, prefix and other matching methods to obtain task files related to the task to be detected, and upload them to the cloud storage terminal 104 for storage.
[0036] After the first server 106 responds to the target task message, it pulls the corresponding operating environment image according to the attribute information of the task to be detected carried in the target task message, creates a target container, loads the detection program of the task to be detected in the target container, and obtains the task file corresponding to the task to be detected from the cloud storage 104; uses the detection program to detect the task file to obtain the target detection result.
[0037] For example, the attribute information of the task to be detected may include information such as the system type of the system to be detected, the task type, the task name, and the file system directory of the user host; the first server end 106 can pull the corresponding operating environment image A according to the system type of the system to be detected (such as an operating system) and the task type (such as vulnerability scanning), and use the operating environment image A to create a target container A; according to the attribute information of the task to be detected such as the task name and the file system directory of the user host, load the detection program (such as the operating environment) of the task to be detected in the target container A, and obtain the task file (such as script file A) corresponding to the task to be detected from the cloud storage end 104; execute script file A in the operating environment, complete the detection of script file A, and obtain the target detection result.
[0038] The server described in the embodiments of this specification can be implemented as a distributed server cluster composed of multiple servers, or as a single server. The server can also be a server of a distributed system, or a server combined with a blockchain. The server can also be a cloud server for basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content distribution networks (CDN, Content Delivery Network), and big data and artificial intelligence platforms, or an intelligent cloud computing server or intelligent cloud host with artificial intelligence technology.
[0039] The detection system provided in the embodiments of this specification achieves the effect of not occupying user resources, avoids the problem of resource grabbing between different tasks, reduces the impact on user system stability, avoids the cost of building a detection engine, and solves the problem of emergency expansion of the detection engine during task peak periods.
[0040] The following combination Figure 2 , further describing the detection method applied to the first server, wherein: Figure 2 A flow chart of a detection method applied to a first server provided by an embodiment of the present specification is shown, which specifically includes the following steps.
[0041] Step 202: Respond to a target task message, wherein the target task message carries attribute information of the task to be detected.
[0042] Among them, the first server can be understood as a function computing unit that provides computing services under the drive of the target task message; the target task message can be understood as a task message for detecting the task to be detected; the attribute information of the task to be detected may include the system type of the system to be detected, the task type, the task name, the file system directory of the user host and other information.
[0043] Specifically, there may be a trigger in the function computing unit for monitoring a message queue, in which there may be a detection task message. The detection task message may be a detection task message of different task types for the same user host, or a detection task message of different task files of the same task type for the same user host. This specification does not limit this. The target task message is any one of the detection task messages.
[0044] Specifically, the trigger in the function computing unit responds to the target task message by monitoring the message queue. The target task message carries the attribute information of the task to be detected, so that the corresponding task file can be detected using the corresponding detection program according to the attribute information of the task to be detected.
[0045] Step 204: Pull the corresponding operating environment image according to the attribute information of the task to be detected, and create a target container using the operating environment image.
[0046] Among them, the operating environment image can be understood as a container image, which is a file system package composed of an encapsulated file system and metadata describing the image, containing the system, environment, configuration, etc. required to execute the task to be detected, and providing the necessary files for starting the container; the target container can be understood as the container corresponding to the task to be detected. The container is an instantiation of the above-mentioned operating environment image, and the task to be detected can be executed in the container.
[0047] Specifically, the corresponding operating environment image can be pulled according to the system type and task type of the system to be detected, and the target container corresponding to the task to be detected can be created using the operating environment image. The operating environment corresponding to the task to be detected can be quickly simulated through the container to execute the task to be detected, and the task to be detected is executed in the target container to avoid abnormal execution of the task to be detected or the inability to execute the task to be detected due to different operating environments.
[0048] In one or more embodiments of this specification, the operating environment image corresponding to the task to be detected can be pulled from the image warehouse, so as to use the operating environment image to build the target container, wherein the image warehouse can pre-store the operating environment image corresponding to the task to be detected, and in this way, the execution efficiency of the task to be detected can be improved; and the image warehouse can be conveniently shared between multiple operating environments, thereby improving the applicability of the detection method provided in the embodiments of this specification. The specific implementation method is as follows:
[0049] The step of pulling the corresponding operating environment image according to the attribute information of the task to be detected includes:
[0050] Pull the corresponding operating environment image from the image repository according to the attribute information of the task to be detected, wherein the operating environment image is an image pre-packaged and constructed based on the basic environment image and dependent files of the detection program.
[0051] Among them, the image warehouse can be understood as a warehouse that provides a centralized storage and distribution service for images. It is the location where the operating environment images are stored and is also one of the important channels for obtaining the operating environment images. The detection program can be understood as the operating environment corresponding to the task to be detected.
[0052] Specifically, after the runtime environment image is built, it is uploaded to the image warehouse so that the user can directly obtain the runtime environment image from the image warehouse, and then use the runtime environment image to build the target container.
[0053] For example, in order to build a runtime environment for executing Python scripts (a high-level scripting language that combines interpretation, compilation, interactivity, and object-orientedness), use the basic image of the Python 2.7 environment, install the required external dependencies, add the basic script files that one operating system or another depends on, and package them into a Python runtime environment image and upload it to the image repository.
[0054] In actual applications, when it is necessary to pull the Python runtime environment image according to the attribute information of the task to be detected, the Python runtime environment image can be directly obtained from the image repository, and then the corresponding container can be built using the Python runtime environment image.
[0055] The detection method provided in the embodiments of this specification is pre-packaged into an image based on the basic environment image and dependent files of the detection program, and uploaded to the image warehouse, so as to pull the operating environment image corresponding to the task to be detected from the image warehouse, thereby improving the execution efficiency of the task to be detected.
[0056] Step 206: Based on the attribute information of the task to be detected, the detection program of the task to be detected is loaded into the target container, and the task file corresponding to the task to be detected is obtained from the cloud storage end, wherein the files stored in the cloud storage end include the task file corresponding to the target task message obtained from the user host.
[0057] The cloud storage end may be object storage OSS (Object Storage Service), file storage, etc., which is not limited here; the task file may be understood as a script file corresponding to the task to be detected.
[0058] Specifically, in the target container, the running environment of the task to be detected can be loaded according to the task name (script file name) of the task to be detected, the file system directory of the user host, etc., and the script file corresponding to the task to be detected can be downloaded from the cloud storage end to execute the script file corresponding to the task to be detected in the running environment of the task to be detected.
[0059] In actual applications, the task files stored in the cloud storage end can be collected by the second server from the operating system information and file system information of the user host, and sent to the cloud storage end for storage.
[0060] In one or more embodiments of the present specification, before pulling the corresponding operating environment image according to the attribute information of the task to be detected, it is also possible to pre-determine whether there is a reusable container in the created container. If a reusable container is determined, the detection program of the task to be detected is loaded in the reusable container, and the task file corresponding to the task to be detected is obtained from the cloud storage end. The specific implementation method is as follows:
[0061] Before pulling the corresponding operating environment image according to the attribute information of the task to be detected, the method further includes:
[0062] Determine whether the number of created containers reaches a preset threshold;
[0063] If the preset threshold is reached, determining whether there is an idle container in the created containers;
[0064] If there is an idle container, matching the task to be detected with the idle container;
[0065] Determine a reuse container from the containers in the idle state according to the matching result obtained by matching;
[0066] Loading the detection program of the task to be detected in the reuse container, and obtaining the task file corresponding to the task to be detected from the cloud storage end;
[0067] If the preset threshold is not reached or there is no idle container, the step of pulling the corresponding operating environment image according to the attribute information of the task to be detected is entered.
[0068] The preset threshold value may be understood as a preset threshold value of the number of containers, which may be set according to actual needs; and the reused container may be understood as a container that may execute different batches of tasks to be detected multiple times.
[0069] In actual applications, a container A is in an idle state after executing task A to be detected, and the system type of the system to be detected corresponding to task A to be detected is system A; after responding to the target task message, the first server obtains the attribute information of task B to be detected carried in the target task message, and when the number of created containers reaches a preset container number threshold, task B to be detected can be matched with container A in an idle state.
[0070] When the system type of the system to be detected corresponding to the task to be detected B is also system A, the matching result can be determined to be a successful match, and container A can be determined as a reused container; at this time, there is no need to pull the corresponding operating environment image according to the attribute information of the task to be detected, and the detection program of the task to be detected can be directly loaded in the reused container, and the task file corresponding to the task to be detected can be obtained from the cloud storage end.
[0071] It should be noted that, when the number of created containers does not reach a preset threshold, or there is no idle container among the created containers, it is necessary to proceed to step 204 .
[0072] Furthermore, containers that have been idle for longer than a preset time can be destroyed to save space resources.
[0073] The detection method provided in the embodiment of the present specification determines whether there is a reused container. If it is determined that there is a reused container, the detection program of the task to be detected is loaded into the reused container, and the task file corresponding to the task to be detected is obtained from the cloud storage end, thereby saving the time of creating a new container and improving the efficiency of executing the detection task.
[0074] Step 208: Utilize the detection program to detect the task file and obtain a target detection result.
[0075] Specifically, in the target container, or in the reused container when a reused container is determined, a task file corresponding to the task to be detected is detected by using a detection program to obtain a target detection result of the task to be detected.
[0076] In one or more embodiments, after obtaining the target detection result, the target detection result may also be sent to the sender of the target task message, so that the sender of the target task message obtains the target detection result of the task to be detected. The specific implementation method is as follows:
[0077] After obtaining the target detection result, the method further includes:
[0078] The target detection result is sent to the sending end of the target task message.
[0079] The detection method provided in the embodiment of this specification sends the target detection result to the sender of the target task message after obtaining the target detection result, so that the sender of the target task message can accurately obtain the target detection result of the task to be detected.
[0080] See also Figure 3 , Figure 3 A flow chart of a detection method applied to a second server provided by an embodiment of the present specification is shown, which specifically includes the following steps.
[0081] Step 302: Collect the operating system information and file system information of the user host to obtain task files related to the task to be detected.
[0082] Specifically, by collecting files of the operating system information and file system information of the user host, the system type, file system directory, etc. of the user host are obtained, and the task file related to the task to be detected can be obtained by matching methods such as file size, type, prefix, etc.
[0083] In one or more embodiments, before collecting files of the operating system information and file system information of the user host, the operating system information and file system information of the user host can be obtained by obtaining a hard disk snapshot of the user host through a snapshot interface. The specific implementation method is as follows:
[0084] Before collecting files from the operating system information and the file system information of the user host, the method further includes:
[0085] Obtaining a hard disk snapshot of the user host through a snapshot interface;
[0086] Mount the hard disk corresponding to the hard disk snapshot in the sandbox environment;
[0087] Obtain operating system information and file system information corresponding to the hard disk snapshot.
[0088] Among them, the snapshot interface can be understood as an API for obtaining snapshots; the hard disk snapshot can be understood as a disk snapshot for data backup; and the sandbox environment can be understood as a network programming virtual execution environment.
[0089] Specifically, the second server obtains a disk snapshot of the user host through an API for obtaining snapshots, mounts the disk corresponding to the disk snapshot in the sandbox environment, and analyzes and collects operating system information and file system information corresponding to the disk snapshot after mounting the disk in the sandbox environment.
[0090] The detection method provided in the embodiment of this specification obtains the operating system information and file system information of the second server by obtaining the hard disk snapshot of the user host through the snapshot interface, so as to obtain the task file related to the task to be detected from the second server.
[0091] Step 304: Send the task file to the cloud storage end for storage, so that the first server end obtains the task file corresponding to the task to be detected from the cloud storage end, the task to be detected is obtained by the first server end from the target task message in response to the target task message, and the task to be detected is used to enable the first server end to pull the corresponding operating environment image according to the attribute information of the task to be detected, and create a target container using the operating environment image, load the detection program of the task to be detected in the target container according to the attribute information of the task to be detected, and use the detection program to detect the task file to obtain the target detection result.
[0092] Specifically, after the second server obtains the task file related to the task to be detected, it sends the task file to the cloud storage end for storage. Subsequently, the first server end can directly obtain the task file related to the task to be detected from the cloud storage end, avoiding the problem of occupying user resources and reducing detection effects during task peak periods.
[0093] See also Figure 4 , Figure 4 A processing flow chart of a detection method provided by an embodiment of this specification is shown, which specifically includes the following steps.
[0094] Step 402: Receive a detection request sent by a user.
[0095] Among them, the detection request may include multiple tasks to be detected, and the tasks to be detected can be understood as tasks such as vulnerability scanning and baseline checking; such as task A to be detected and task B to be detected, task A to be detected is a vulnerability detection for file A, and task B to be detected is a vulnerability detection for file B; multiple detection task messages can be generated based on multiple tasks to be detected.
[0096] Specifically, the cloud management platform can provide a user operation interface to facilitate users to perform interactive operations or display information through the user operation interface. For example, users can select the task type of the task to be detected (such as vulnerability scanning, baseline checking, file detection) in the cloud management platform, and the cloud server (which can be understood as the second server in the above embodiment) can receive the detection request sent by the user through the cloud management platform.
[0097] Step 404: Obtain operating system information and file system information of the user host.
[0098] Specifically, when the cloud server receives a detection request, the cloud server can obtain a snapshot of the user's host disk through the snapshot API (or create a disk snapshot in the cloud management platform), and after mounting the disk in the sandbox environment, analyze and collect the operating system information and file system information corresponding to the snapshot.
[0099] Step 406: Upload to the cloud storage for storage.
[0100] In actual applications, the cloud storage end can be object storage (OSS). After obtaining the operating system information and file system information of the user's host, the file list related to the task to be detected can be filtered out by file size, file type, prefix, etc., and uploaded to the object storage for storage, while still retaining the file directory structure.
[0101] By storing data on the cloud storage side, maximum flexibility can be achieved during peak service periods. By collecting the operating system information and file system information from the user host at one time, multiple tasks to be detected on the same user host can benefit from it. That is, when executing different task files on the same user host, the relevant file list can be read from the object storage, avoiding the need to seize resources on the same user host to execute tasks to be detected, greatly shortening the detection cycle, and reducing the impact on the user system.
[0102] Step 408: In response to the target task message, pull the image and start the container.
[0103] Among them, the target task message is any one of the above-mentioned detection task messages; the image can be understood as the operating environment image in the above-mentioned embodiment; and the container can be understood as the target container or reused container in the above-mentioned embodiment.
[0104] Specifically, the execution process of the task to be detected is dispersed in different function computing units. There is a trigger in the function computing unit in the above embodiment, which can monitor the message queue, and the message queue contains the above-mentioned multiple detection task messages; the function computing unit responds to any detection task message (i.e., target task message) in the detection task message through the trigger; and can pull the operating environment image corresponding to the target task message according to the system type, task type (such as vulnerability check, baseline check, etc.) and other attribute information of the task to be detected carried by the target task message, and create a corresponding target container to load the operating environment of the task to be detected in the target container.
[0105] Through this detection method, different types of tasks to be detected, such as vulnerability scanning, baseline detection, file detection, etc., are distributed in the function computing unit for execution, which greatly improves the concurrency and execution efficiency of the tasks.
[0106] In another embodiment, before pulling the image, it can be determined whether there is a reusable container. If so, the running environment of the task to be detected can be loaded into the reusable container.
[0107] Step 410: Download the task file and execute it.
[0108] Specifically, in the target container or reused container, according to the task name, file system directory and other attribute information of the task to be detected carried in the target task message, the task file corresponding to the task to be detected is downloaded from the cloud storage end and executed to obtain the target detection result of the task to be detected.
[0109] Step 412: Send the target detection result to the user.
[0110] Finally, the obtained target detection result can be sent to the user's client via a message to display the target detection result to the user.
[0111] The detection method provided in the embodiments of this specification does not need to occupy user resources, avoids the problem of resource grabbing between different tasks, reduces the impact on user system stability, avoids the cost of building a detection engine, and solves the problem of emergency expansion of the detection engine during task peak periods.
[0112] See also Figure 5 , Figure 5 A schematic diagram of a scene of a detection method provided by an embodiment of this specification is shown.
[0113] In one embodiment of the present specification, the cloud server can send multiple tasks to be detected, such as vulnerability scanning and baseline checking, to the function computing unit for execution; specifically, the cloud server can obtain a snapshot of the user's host disk through an API for obtaining snapshots, and after mounting the disk in a sandbox environment, analyze and collect the operating system information and file system information corresponding to the snapshot; after obtaining the operating system information and file system information of the user's host, the list of files related to the task to be detected can be filtered out by file size, file type, prefix, etc., and uploaded to the object storage for storage.
[0114] The function computing unit pulls the operating environment image corresponding to the task to be detected according to the attribute information of the task to be detected, and creates a corresponding target container to load the operating environment of the task to be detected in the target container, downloads the task file corresponding to the task to be detected from the cloud storage end and executes it to obtain the target detection result of the task to be detected.
[0115] Taking a specific scenario as an example, for vulnerability scanning of system A, it is mainly necessary to collect system registry files to determine the installed system patches, and compare them with vulnerability rules to determine the system A vulnerabilities in the current system. For the detection method of deploying Agent, the task to be detected is sent, and the client executes to read the local registry file and compares it with the vulnerability rules, and directly reports the vulnerability results; but for the Agentless scenario, after mounting the disk to analyze the file system, it is necessary to solve the cross-platform problem and parse the system A registry in the system B environment, which brings great trouble to the construction of the detection engine. By introducing the function computing unit, different tasks to be detected are dispersed in the function computing unit for execution, the image is pulled to start the container, and the corresponding task file is downloaded from the cloud storage end, shielding the impact of different operating systems.
[0116] The detection method provided in the embodiments of this specification avoids the impact of deploying a client on the user's machine, and instead uses an API to collect data, avoiding the direct execution of the task to be detected in the user environment, eliminating the impact on the user environment, and also eliminating the user's concerns about data security, service stability, system performance, etc.
[0117] Moreover, by pulling the image to start the container, the influence of different operating systems can be shielded. The execution process of the task to be detected is dispersed in different function computing units, which solves the problems of real-time update, task coverage, and emergency expansion faced in building the detection engine.
[0118] Corresponding to the above method embodiment, this specification also provides a detection system embodiment, Figure 6 A schematic diagram of the structure of a detection system 600 provided in one embodiment of the present specification is shown. The system includes: a first server 606, a second server 602 and a cloud storage 604.
[0119] The first server 606 is used to respond to a target task message, wherein the target task message carries attribute information of the task to be detected; pull the corresponding operating environment image according to the attribute information of the task to be detected, and create a target container using the operating environment image; load the detection program of the task to be detected in the target container according to the attribute information of the task to be detected, and obtain the task file corresponding to the task to be detected from the cloud storage end, wherein the files stored in the cloud storage end include the task file corresponding to the target task message obtained from the user host; use the detection program to detect the task file to obtain the target detection result.
[0120] The second server 602 is used to collect the operating system information and file system information of the user host to obtain the task file related to the task to be detected; and send the task file to the cloud storage end for storage, so that the first server can detect the task file.
[0121] The cloud storage terminal 604 is used to store the task file corresponding to the target task message obtained from the user host.
[0122] Specifically, after the second server 602 collects the operating system information and file system information of the user host, it obtains the task file related to the task to be detected, and sends the task file related to the task to be detected to the cloud storage end 604 for storage; after the first server 606 responds to the target task message, it pulls the corresponding operating environment image according to the attribute information of the task to be detected carried in the target task message, and creates a target container using the operating environment image; loads the detection program of the task to be detected in the target container, and obtains the task file corresponding to the task to be detected from the cloud storage end 604; uses the detection program to detect the task file to obtain the target detection result.
[0123] The detection system provided in the embodiments of this specification does not need to occupy user resources, avoids the problem of resource grabbing between different tasks, reduces the impact on user system stability, avoids the cost of building a detection engine, and solves the problem of emergency expansion of the detection engine during task peak periods.
[0124] The above is a schematic scheme of a detection system of this embodiment. It should be noted that the technical scheme of the detection system and the technical scheme of the above detection method belong to the same concept, and the details of the technical scheme of the detection system that are not described in detail can all be referred to the description of the technical scheme of the above detection method.
[0125] Figure 7 The block diagram of a computing device 700 according to an embodiment of the present specification is shown. The components of the computing device 700 include but are not limited to a memory 710 and a processor 720. The processor 720 is connected to the memory 710 via a bus 730, and the database 750 is used to store data.
[0126] The computing device 700 also includes an access device 740 that enables the computing device 700 to communicate via one or more networks 760. Examples of these networks include a public switched telephone network (PSTN), a local area network (LAN), a wide area network (WAN), a personal area network (PAN), or a combination of communication networks such as the Internet. The access device 740 may include one or more of any type of network interface (e.g., a network interface card (NIC)) that is wired or wireless, such as an IEEE 802.11 wireless local area network (WLAN) wireless interface, a world-wide interoperability for microwave access (Wi-MAX) interface, an Ethernet interface, a universal serial bus (USB) interface, a cellular network interface, a Bluetooth interface, and a near field communication (NFC).
[0127] In one embodiment of the present specification, the above components of the computing device 700 and Figure 7 Other components not shown in the figure may also be connected to each other, for example, via a bus. It should be understood that Figure 7 The computing device structure block diagram shown is only for the purpose of illustration, and is not intended to limit the scope of this specification. Those skilled in the art can add or replace other components as needed.
[0128] The computing device 700 may be any type of stationary or mobile computing device, including a mobile computer or mobile computing device (e.g., a tablet computer, a personal digital assistant, a laptop computer, a notebook computer, a netbook, etc.), a mobile phone (e.g., a smart phone), a wearable computing device (e.g., a smart watch, smart glasses, etc.), or other types of mobile devices, or a stationary computing device such as a desktop computer or a personal computer (PC). The computing device 700 may also be a mobile or stationary server.
[0129] The processor 720 is used to execute the following computer executable instructions, which implement the steps of the above detection method when executed by the processor.
[0130] The above is a schematic scheme of a computing device of this embodiment. It should be noted that the technical scheme of the computing device and the technical scheme of the above detection method belong to the same concept, and the details not described in detail in the technical scheme of the computing device can be referred to the description of the technical scheme of the above detection method.
[0131] An embodiment of the present specification further provides a computer-readable storage medium storing computer-executable instructions, which can implement the steps of the above-mentioned detection method when executed by a processor.
[0132] The above is a schematic scheme of a computer-readable storage medium of this embodiment. It should be noted that the technical scheme of the storage medium and the technical scheme of the above detection method belong to the same concept, and the details not described in detail in the technical scheme of the storage medium can be referred to the description of the technical scheme of the above detection method.
[0133] An embodiment of the present specification further provides a computer program, wherein when the computer program is executed in a computer, the computer is caused to execute the steps of the above detection method.
[0134] The above is a schematic scheme of a computer program of this embodiment. It should be noted that the technical scheme of the computer program and the technical scheme of the above detection method belong to the same concept, and the details not described in detail in the technical scheme of the computer program can be referred to the description of the technical scheme of the above detection method.
[0135] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0136] The computer instructions include computer program codes, which may be in source code form, object code form, executable files or some intermediate forms, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the content contained in the computer-readable medium may be appropriately increased or decreased according to the requirements of patent practice. For example, in some regions, according to patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.
[0137] It should be noted that, for the convenience of description, the aforementioned method embodiments are all described as a series of action combinations, but those skilled in the art should be aware that the embodiments of this specification are not limited by the order of the actions described, because according to the embodiments of this specification, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the embodiments of this specification.
[0138] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0139] The preferred embodiments of this specification disclosed above are only used to help explain this specification. The optional embodiments do not describe all the details in detail, nor do they limit the invention to only the specific implementation methods described. Obviously, many modifications and changes can be made according to the content of the embodiments of this specification. This specification selects and specifically describes these embodiments in order to better explain the principles and practical applications of the embodiments of this specification, so that technicians in the relevant technical field can well understand and use this specification. This specification is only limited by the claims and their full scope and equivalents.
Claims
1. A detection method, applied to a first server, comprising: Responding to a target task message, wherein the target task message carries attribute information of the task to be detected; Pulling a corresponding operating environment image according to the attribute information of the task to be detected, and creating a target container using the operating environment image; According to the attribute information of the task to be detected, a detection program of the task to be detected is loaded in the target container, and a task file corresponding to the task to be detected is obtained from a cloud storage end, wherein the files stored in the cloud storage end include a task file corresponding to the target task message obtained from a user host; The task file is detected using the detection program to obtain a target detection result.
2. According to the detection method of claim 1, the first server is a function computing unit that provides computing services driven by a target task message.
3. According to the detection method described in claim 1, the task file stored in the cloud storage end is collected by the second server end from the operating system information and file system information of the user host, and sent to the cloud storage end for storage.
4. The detection method according to claim 1, wherein the corresponding operating environment image is pulled according to the attribute information of the task to be detected, comprising: Pull the corresponding operating environment image from the image warehouse according to the attribute information of the task to be detected, wherein: The operating environment image is an image that is pre-packaged and constructed based on the basic environment image and dependent files of the detection program.
5. The detection method according to claim 1, before pulling the corresponding operating environment image according to the attribute information of the task to be detected, further comprising: Determine whether the number of created containers reaches a preset threshold; If the preset threshold is reached, determining whether there is an idle container in the created containers; If there is an idle container, matching the task to be detected with the idle container; Determine a reuse container from the containers in the idle state according to the matching result obtained by matching; Loading the detection program of the task to be detected in the reuse container, and obtaining the task file corresponding to the task to be detected from the cloud storage end; If the preset threshold is not reached or there is no idle container, the step of pulling the corresponding operating environment image according to the attribute information of the task to be detected is entered.
6. The detection method according to claim 1, after obtaining the target detection result, further comprising: The target detection result is sent to the sending end of the target task message.
7. A detection method, applied to a second server, comprising: Collect the operating system information and file system information of the user host to obtain the task files related to the task to be detected; The task file is sent to a cloud storage end for storage, so that the first server end obtains the task file corresponding to the task to be detected from the cloud storage end, the task to be detected is obtained by the first server end from the target task message in response to the target task message, and the task to be detected is used to enable the first server end to pull the corresponding operating environment image according to the attribute information of the task to be detected, and create a target container using the operating environment image, load the detection program of the task to be detected in the target container according to the attribute information of the task to be detected, and use the detection program to detect the task file to obtain a target detection result.
8. The detection method according to claim 7, before collecting files from the operating system information and file system information of the user host, further comprising: Obtaining a hard disk snapshot of the user host through a snapshot interface; Mount the hard disk corresponding to the hard disk snapshot in the sandbox environment; Obtain operating system information and file system information corresponding to the hard disk snapshot.
9. A detection system comprising: A first server end applying the detection method according to any one of claims 1 to 6, a second server end applying the detection method according to claim 7 or 8, and a cloud storage end; The cloud storage end is used to store the task file corresponding to the target task message obtained from the user host.
10. A computing device comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the detection method according to any one of claims 1 to 8 are implemented.
11. A computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions, when executed by a processor, implement the steps of the detection method according to any one of claims 1 to 8.