Terminal security management system
By designing a terminal security management system that integrates multiple security management functions, the problem of security threat management within the network is solved, multi-in-one and unified management of the terminal is achieved, and more powerful network security protection and management capabilities are provided.
Patent Information
- Application Number
- CN202510298055.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-05-13
AI Technical Summary
It is difficult for the existing technology to effectively manage and prevent terminal security threats from within the network, including system vulnerabilities, mobile storage media management, terminal access management, intranet equipment outreach prevention, terminal asset management, security policy unification, bandwidth occupation monitoring, remote maintenance, sensitive information leakage prevention, terminal application software management, virus location and cut-off problems.
Design a terminal security management system, integrating host monitoring and audit, patch management, desktop application management, information security management, terminal behavior control and other functions, and realize multi-in-one and unified management of the terminal through components such as client, database, area scanner, area manager, management information database, patch download server and intermediate management configuration platform.
It realizes controllable management of internal terminals of the network, provides protection functions that cannot be provided by firewalls, IDSs, and antivirus systems, perceive changes in the network environment in real time, discovers and blocks illegal networking behaviors, prevents information leakage, and improves the efficiency and effectiveness of network security management.
Smart Images

Figure FT_1 
Figure FT_2 
Figure FT_3
Abstract
Description
Technical Field
[0001] The invention belongs to the technical field of terminal management, and in particular relates to a terminal security management system. Background Art
[0002] The rise of terminal desktop security management technology is derived from the increase in the density of network management affairs and the gradual development of network management technology. It is related to the defects of the traditional security defense system. It is a supplement to the traditional network security prevention system and an important part of the future network security prevention system. Therefore, terminal desktop security management technology should be included in the list of basic system network security products, both now and in the future.
[0003] The improvement of modern network security management system has made the demand for network terminal desktop security management strongly highlighted. Correctly and comprehensively understanding the development trend and technical characteristics of terminal management products is a development choice faced by IT R&D manufacturers, and it is also an issue that enterprise and institution IT managers and senior decision-makers must consider when deploying terminal desktop security protection.
[0004] Security defense surveys in the past two years have also shown that more than 80% of management and security issues in government, enterprises, and financial securities units come from terminals. Computer terminals are widely involved in every user. Due to their dispersion, lack of attention, and lack of security measures, terminal security has become a weak link in the information security system. Therefore, network security has shown a new development trend. For various government and enterprise networks, the security battlefield has gradually shifted from the protection of the core and backbone to every terminal within the network.
[0005] When it comes to network security, people naturally think of network boundary security, but the reality is that most of the network security risks come from within. Conventional security defense concepts are often limited to the gateway level, network boundaries (firewalls, IDS, vulnerability scanning), etc., and important security facilities are generally concentrated in the computer room or network entrance. Under the close monitoring of these devices, the security threats from outside the network are greatly reduced. On the contrary, the security threats from computer terminals inside the network are a thorny problem that many security managers generally face.
[0006] In summary, the internal network management of government agencies and corporate units generally faces the following common problems, such as: how to discover system vulnerabilities in terminal devices and automatically distribute patches; how to effectively solve the problem of mobile storage media use management; how to effectively solve the problem of terminals accessing the network at will; how to prevent internal network devices from illegally connecting to the outside world; how to manage terminal assets and ensure the normal operation of network equipment; how to formulate a unified security policy for the entire network; how to promptly discover the terminals that occupy the largest bandwidth in the network; how to conveniently perform remote point-to-point maintenance; how to prevent the leakage of internal sensitive information; how to uniformly monitor and manage the original terminal application software; how to quickly and effectively locate the intrusion points of viruses, worms, and hackers in the network, and promptly and accurately cut off the points where security incidents occur and the network; how to build a powerful unified network security alarm handling platform to respond to security incidents and query events, and comprehensively manage network resources.
[0007] These terminal security risks may threaten the normal operation of user networks at any time and anywhere. In view of the above series of problems, this application provides a terminal security management system.
[0008] The information disclosed in this background technology section is only intended to enhance the understanding of the overall background of the invention and should not be regarded as an acknowledgment or any form of suggestion that the information constitutes the prior art already known to a person skilled in the art. Summary of the invention
[0009] The purpose of the present invention is to provide a terminal security management system, which takes terminal management as the core, forms a management system that integrates host monitoring and auditing, patch management, desktop application management, information security management, terminal behavior control and other security behaviors, and provides enterprise managers with a multi-in-one, unified management solution for terminals, creating a safe, reliable and stable office environment for users.
[0010] In order to achieve the above object, the present invention provides the following technical solutions:
[0011] A terminal security management system, comprising:
[0012] Client, used to install client program;
[0013] A database for storing network client device information;
[0014] Area scanner, used to detect the network connection behavior of the computer, find and block the illegal behavior defined in the database;
[0015] The regional manager is used to register, verify, manage and obtain patches for clients in the network, and to exchange data and issue instructions with the regional scanner;
[0016] Management information base, used for command, policy acquisition and status, data reporting, and data exchange with the patch analysis module;
[0017] A patch download server, used to obtain patches from the Internet and import patch increments into the patch analysis module;
[0018] The intermediate management configuration platform exchanges data and issues instructions with the management information base, is used to configure and manage the entire computer equipment information system, and sets the IP addresses of the regional manager and regional scanner within the network.
[0019] As a preferred option, it has multiple terminal desktop management functions, including: process running black and white list control, process execution summary, terminal service management, software black and white list control, software installation summary, terminal message push, remote assistance, terminal real-time monitoring management, system automatic shutdown management and terminal time synchronization management.
[0020] Preferably, the terminal real-time monitoring and management is a real-time viewing and control of the client's operation status by the system administrator through the system terminal in a point-to-point manner, specifically including the following contents: hardware asset inventory, installed software query, terminal process management, terminal service management, terminal port management, system operation resource view, patch query, terminal time query, terminal security audit, shared directory query, current execution policy, message notification, remote running process, modifying network configuration, terminal uninstallation, remote disconnection / restore of network terminal, locking mouse and keyboard, shutting down computer and remote support.
[0021] As a preferred option, it has multiple terminal security management functions, including: desktop password permission management, terminal network access control, terminal antivirus software management, registry check, IP / MAC binding policy management and hardware control policy management.
[0022] As a preference, it has the function of managing illegal external connections, including: monitoring of illegal external Internet connections of internal network terminals, monitoring of illegal access of internal network terminals to other networks, monitoring of illegal external Internet connections of off-network terminals, alarms for illegal external connection behaviors, network locking, and evidence collection for illegal external connection behaviors.
[0023] Preferably, the illegal external connection function is completed by the cooperation of several modules, specifically including: an external network detection module, a routing information detection module, an alarm module, a blocking module and a network middle layer driver.
[0024] As a preferred method, an illegal external connection strategy is adopted to perceive changes in the network environment in real time to prevent illegal networking behaviors, which specifically includes the following steps:
[0025] S71. Report external evidence collection records and route tracking records;
[0026] S72, by detecting the URL, determine whether there is an external connection behavior; if so, proceed to S76; if not, proceed to S73;
[0027] S73, by detecting the URL, determine whether it is a regular URL; if so, send a detection packet to other URLs and enter S76; if not, enter S74;
[0028] S74, when external connection is not possible, close the routing detection, load the middle layer driver module, send the detection data packet, and start the subnet detection logic;
[0029] S75, determine whether the machine is within the set subnet range; if so, proceed to S78; if not, report external alarm information, process it and proceed to S78;
[0030] S76, enable route tracking and force detection of cascade URLs;
[0031] S77, when it is detected that the cascade URL is in the external network state or the internal network + external network state, enter S78, and perform external connection processing at the same time, communicate with the blocking module, and notify the driver to block the middle layer network driver;
[0032] S78. End the detection of illegal external connections.
[0033] As a preference, it has patch distribution management functions, including: patch indexing, patch download detection and incremental import, automatic patch security testing, automatic classification of patch libraries, cascading and synchronization of patch libraries, patch installation detection and automatic distribution, patch strategy formulation, patch download flow control, server-side patch query and client-side web page patch installation information query.
[0034] As a preferred method, an anti-virus software operation monitoring strategy is adopted to perform regular detection, and automatically prompt or block the virus that has not been updated within a time limit, which specifically includes the following steps:
[0035] S91, obtaining anti-virus software logic, determining whether the anti-virus software is installed; if so, proceeding to S42; if not, performing violation processing;
[0036] S92, determining whether the antivirus software database is updated; if so, terminating antivirus software monitoring; if not, performing violation processing.
[0037] Preferably, a process protection module is included; the process protection module adopts SSDT HOOK technology to monitor dangerous operations of the process in real time to prevent malicious termination.
[0038] Compared with the prior art, the present invention has the following beneficial effects:
[0039] (1) The terminal security management system of the present invention adheres to the concept of giving equal importance to network protection and endpoint protection, and provides solutions to various problems faced by network security managers in the process of network management and terminal management. It can realize controllable management of internal network terminals and support multi-level cascaded wide area network architecture to achieve the best management effect.
[0040] (2) The terminal security management system of the present invention strengthens the management of the status, behavior and events of network computer terminals, provides protection functions that firewalls, IDS, anti-virus systems and professional network management software cannot provide, monitors the blind spots of their management, and expands into a real-time controllable intranet management platform, and can be integrated with other security devices for security and alarm linkage.
[0041] (3) The terminal security management system of the present invention uses unique network detection technology, which can sense in real time whether the network environment has changed, promptly discover illegal networking behaviors, and save external evidence collection records, route detection, report alarms, and block the current network of the terminal, which is conducive to preventing terminal information leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 is a system logic diagram of the present invention;
[0043] Figure 2 It is a schematic diagram of the patch monitoring function;
[0044] Figure 3 This is the automatic test image of this patch;
[0045] Figure 4 It is a flowchart of illegal external connection functions;
[0046] Figure 5 It is the anti-virus software monitoring flow chart. DETAILED DESCRIPTION
[0047] The following is a clear and complete description of the technical solution of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by technicians in this field without creative work are within the scope of protection of the present invention.
[0048] See attached Figure 1 , a terminal security management system, comprising:
[0049] Client, used to install client program;
[0050] A database for storing network client device information;
[0051] Area scanner, used to detect the network connection behavior of the computer, find and block the illegal behavior defined in the database;
[0052] The regional manager is used to register, verify, manage and obtain patches for clients in the network, and to exchange data and issue instructions with the regional scanner;
[0053] Management information base, used for command, policy acquisition and status, data reporting, and data exchange with the patch analysis module;
[0054] A patch download server, used to obtain patches from the Internet and import patch increments into the patch analysis module;
[0055] The intermediate management configuration platform exchanges data and issues instructions with the management information base, is used to configure and manage the entire computer equipment information system, and sets the IP addresses of the regional manager and regional scanner within the network.
[0056] In this embodiment, the system takes terminal management as the core, forming a management system that integrates host monitoring audit, patch management, desktop application management, information security management, terminal behavior control and other security behaviors, providing enterprise managers with a multi-in-one, unified management solution for terminals, and creating a safe, reliable and stable office environment for users. The terminal security management system adopts a C / S and B / S hybrid mode design, supports distributed deployment, and has the advantages of modular software customization, support for standard APIs, seamless function expansion and upgrades, etc.
[0057] This system installs a database in the network to store network client device information. When the above system database, web management platform, and regional manager are installed, the client in the network can be registered. After the user obtains the registration program and executes it, he / she adds computer usage information, such as the user's name, unit, contact information, etc. The registration program automatically collects the system's hardware device information, which is stored in the database after being processed by the regional manager. At the same time, the regional manager sends the agent resident program to the computer terminal and runs it in real time. The computer's network connection behavior is detected through probes, regional scanners, etc., and relevant system patches, security policies, commands or files that are missing from the local machine are sent as needed. When illegal behaviors defined in the database are encountered, they are blocked.
[0058] After the system is running normally, the entire computer equipment information system is mainly configured and managed through the web management platform, and the regional manager and scanner IP addresses are set in the network. For general networks (such as a LAN range of one Class C address or several Class C addresses), one set of this system is applicable to centrally manage the equipment in the area. For large-scale multiple LANs or cross-regional WANs, a multi-region centralized management mode is provided, that is, the lower-level management system can pass all the equipment information at this level to the upper-level management database, so that the upper-level management personnel can fully grasp the equipment status of the entire network.
[0059] The configuration of the device management information system should be selected according to the scale of network clients and the actual situation of network management. Multiple regional managers can be installed in the network. The regional manager is only responsible for clients within a certain range and does not process clients outside the range. Each regional manager has multiple scanners under it to provide segmented scanning of the network in the area and timely check the registration status of the network clients.
[0060] The terminal security management system of the present invention has multiple terminal desktop management functions, including: process running black and white list control, process execution summary, terminal service management, software black and white list control, software installation summary, terminal message push, remote assistance, terminal real-time monitoring management, system automatic shutdown management, terminal time synchronization management, etc.
[0061] Blacklist and whitelist control of process operation: Blacklist and whitelist control of process execution, that is, setting prohibited and mandatory processes according to policies. For clients violating the rules, corresponding measures such as client prompts and network disconnection are taken, and audit reports are conducted for backend query management.
[0062] Process execution summary: It can summarize and monitor the processes of each terminal in the network. It can incrementally display the new processes in the network and count the most frequently run processes in the network, so as to count the usage of network client software. This system can locate and alarm abnormal processes (most likely virus processes) in the network and directly block them when necessary.
[0063] Terminal service management: Query the services currently running on the terminal and start or stop the services remotely.
[0064] Software blacklist and whitelist control: Blacklist and whitelist control of software installation, that is, setting the software that is prohibited from installation and the software that must be installed according to the policy. For illegal software, you can execute prompt information, disconnect from the network, silently uninstall, log off, and shut down.
[0065] Software installation summary: The system can summarize the installed software and generate reports based on the summary statistics, supporting multiple report export methods.
[0066] Terminal message push: Messages can be accurately sent to selected objects or individuals without relying on the messenger service function of Windows itself. The system also provides a variety of strategy modes for sending messages.
[0067] Remote assistance: When client users and server users encounter difficult-to-solve problems when using computers, they can visit specific web pages and proactively make concurrent assistance requests to multiple network management workstations (optional) to call the network management for remote assistance. When the administrator receives the client's request, he or she can call the remote client's desktop to help the client user solve the corresponding problem; after the terminal receives the request, the system will automatically call the remote computer's desktop, just like the administrator personally goes to the site to perform software installation, software debugging, system maintenance, printer installation, etc., saving the administrator's time traveling back and forth between the site and the office, and improving the efficiency of system maintenance and the administrator's work efficiency.
[0068] Real-time terminal monitoring and management: System administrators can view and control the operation of the client in real time through the system terminal point-to-point mode, including the following:
[0069] (1) Hardware asset list: Automatically collects information including CPU, memory, total hard disk partitions, device ID size and other detailed information, as well as other hardware information such as motherboard, optical drive, floppy drive, graphics card, keyboard, mouse, monitor, infrared device, keyboard, etc.; network administrators can add relevant additional information on their own;
[0070] (2) Installed software query: query all software installed on the device;
[0071] (3) Terminal process management: query all running processes of the current terminal, and close non-system processes through the system;
[0072] (4) Terminal service management: query the services currently running on the terminal and remotely turn off or on the services;
[0073] (5) Terminal port management: check the occupied ports of the current terminal process;
[0074] (6) Check system operation resources: including: CPU frequency and usage rate, memory size and usage rate, and the size and usage of each hard disk partition of the system;
[0075] (7) Patch query: check the patches that the system has missed;
[0076] (8) Terminal time query: view the terminal's system log, security log, and application log;
[0077] (9) Terminal security audit: Check user login, history, download information and other information;
[0078] (10) Shared directory query: view the terminal shared directory;
[0079] (11) Current execution strategy: View the strategy executed by the terminal, including synchronized and unsynchronized strategies;
[0080] (12) Message notification: Send messages to users and ask them to provide feedback;
[0081] (13) Remote running process: can remotely load the process in the terminal specified directory;
[0082] (14) Modify network configuration: You can view the IP, MAC, subnet mask and gateway information of the network terminal, and remotely modify the user's IP address;
[0083] (15) Terminal uninstallation: Remotely uninstall the client without the need for an uninstall code, and uninstall silently in the terminal background;
[0084] (16) Remotely disconnect / restore the network of the network terminal: use the recovery network to restore the terminal after it is permanently blocked;
[0085] (17) Lock the mouse and keyboard: The terminal mouse and keyboard are locked and cannot be operated;
[0086] (18) Re-registration: The terminal pops up a registration interface where you need to re-fill in the registration information. After registration, the information is re-reported;
[0087] (19) Shut down the computer: shut down the terminal;
[0088] (20) Remote support: remotely assist the terminal.
[0089] System automatic shutdown management: Setting the shutdown time of the client to achieve automatic scheduled shutdown, locking the screen or shutting down the computer when it is idle for too long, monitoring whether the terminal startup is within the allowed range, and generating audit logs for administrators to query and manage in the background.
[0090] Terminal time synchronization management: All client times are automatically synchronized with server time to solve the time difference problem between the client and the server, and the terminal is supported to prohibit time modification.
[0091] The terminal security management system of the present invention also has multiple terminal security management functions, including: desktop password authority management, terminal network access control, terminal antivirus software management, registry check, IP / MAC binding policy management, hardware control policy management, etc.
[0092] Desktop password authority management: Audit and check the changes in the terminal's password management authority and usage status (including password length, security, weak passwords, password modification cycle, etc.), and issue alerts or force modifications to terminals that do not meet the requirements to prevent viruses and hacker intrusions. Audit the increase, decrease, and authority changes of terminal accounts or account groups, and support locking terminal accounts and groups, prohibiting the creation of accounts without permission; it can realize the functions of raising and lowering the rights of terminal login users, and automatically add users to the specified user group.
[0093] Terminal network access control: Administrators can set up unified firewalls for terminals in the Web console, restrict network IP and protocol access, establish virtual terminal isolation zones within the network, and support control over IP and domain names, protocol types, port ranges, applications, and inbound and outbound directions.
[0094] Terminal anti-virus software management: can uniformly audit the installation and use of anti-virus software (from mainstream manufacturers) on terminals within the network, and can force the client to install anti-virus programs when necessary; for terminals that do not have anti-virus software installed or do not have trusted anti-virus software installed, it can automatically prompt, restart, block, prompt, and automatically download specified anti-virus software; supports unified configuration of the enabling and disabling of the terminal Windows firewall.
[0095] Registry check: The system provides a registry check function. For registry modified by virus behavior, it can be operated through mandatory registry policies, and can automatically create, delete, and modify the corresponding registry key values to achieve registry security management. The system can block the use of the registry by some program processes on the selected user's computer. This policy can effectively prevent illegal processes from damaging the user's registry.
[0096] IP / MAC binding policy management: supports locking terminal IP, and can also prohibit modifying IP, gateway, etc. to prevent ARP attacks and IP conflicts; after detecting IP or MAC changes, supports automatic recovery, blocking, prompts and other processing methods; audits terminal IP / mac changes; audits terminal host name, IP and MAC changes, can record changes in terminal host name, IP, MAC, and generate corresponding alarm event information to report to the server, helping users to promptly discover illegal modifications to computer configurations; can audit change time, content before and after changes, and distinguish changes with significantly different colors; supports querying terminal host name, IP, MAC changes based on time range, department, IP address, host name, MAC address, etc.
[0097] Hardware control policy management: supports disabling and enabling of all hardware devices; hardware control operations are divided into three items: enable, disable, and do not process; supports enabling or disabling control of optical drives, floppy drives, USB mobile storage, USB non-mobile storage devices, printers, print services, modems, serial ports, parallel ports, 1394 controllers, infrared devices, Bluetooth devices, PCMCIA, redundant hard disks, tape drives, redundant SCSI devices, wireless network cards, wired network cards, image devices, and mobile devices; various types of devices can be set to not process, then the original control mode is maintained without control; supports exception configuration of devices. Judge through device description or device hardware ID, and make exceptions to the specified device; supports custom device control, users can add specified device names or device IDs, enable and disable states, and control this device.
[0098] It should be noted that the terminal security management system of the present invention has the function of managing illegal external connections, specifically including: monitoring the illegal external Internet connections of terminals within the network, monitoring the illegal access of terminals within the network to other networks, monitoring the illegal external Internet connections of terminals off-network, alarming and network locking of illegal external connection behaviors, and evidence collection of illegal external connection behaviors.
[0099] The system monitors the illegal external Internet connection behavior of internal network terminals. For registered devices that communicate with the Internet through different methods (such as dual network cards, proxies, etc.), the system can automatically block their connection behavior and issue an alarm.
[0100] Monitor the illegal access of terminals within the network to other networks. For registered devices, monitor their network connection behavior and determine whether they have illegally accessed other networks based on the access network environment factors.
[0101] The system monitors illegal external Internet connection behavior of off-grid terminals. It monitors the illegal behavior of registered computers being taken out of another network. When external Internet connection behavior is detected, it can take actions such as warning, blocking, and automatic shutdown.
[0102] Illegal external connection behavior alarm and network lock. For terminals that illegally access the network, information can be obtained on the alarm platform and alarm query, and the terminal can be prompted, automatically shut down, blocked from the Internet, etc.
[0103] Forensics of illegal external connection behavior, real-time alarm function is provided for illegal external connection behavior, and relevant information such as the event, IP address, MAC address, user, etc. are recorded and reported to the server for record collection; if the terminal sends an illegal external connection after leaving the network, the illegal external connection record generated before will be automatically reported to the server after the terminal is connected to the intranet.
[0104] The illegal external connection strategy uses a unique network detection technology to sense in real time whether the network environment has changed, promptly discover illegal networking behaviors, save external connection evidence records, detect routes, report connection alarms, block the current terminal network, and prevent terminal information leakage. The illegal external connection function is completed by the cooperation of several major modules, including: external network detection module, routing information detection module, alarm module, blocking module, and network middle layer driver. First, the application layer module communicates with the regional manager and requests the server to issue an illegal external connection strategy; after receiving the strategy, the application layer loads the strategy to monitor changes in the network card, and uses unique network detection technology and middle layer network driver technology to sense in real time whether the network environment has changed; if network changes are found, the external connection detection logic is started to detect whether the Internet is connected and the external connection route is detected; if it is found that the external connection is possible, the external connection evidence records and route detection are saved locally, and the external connection alarm is reported to the server at the same time, the inter-process notification blocks the process, and the underlying firewall driver is triggered to block the terminal network. Please refer to the attached for the flowchart of the illegal external connection function. Figure 4 .
[0105] The terminal security management system of the present invention also includes a patch distribution management system, which has a patch distribution management function. The system supports automatic downloading of patches in both push and pull modes. Figure 2 The entire patch management operation platform architecture is: obtain the latest patches from the patch vendor website in a timely manner through the Beixinyuan external network patch download server; after the patch security test, distribute and install it to network users through the patch distribution management center server. Patch installation supports both automatic and manual methods.
[0106] The patch distribution management system can monitor and manage the status of network patches. Its specific functions are as follows:
[0107] Patch index: The intranet security management system has good compatibility and supports mainstream operating systems such as Windows XP, Windows 7, Windows 8, Windows 10, etc. Because the patch index file is independently developed by Beixinyuan, the structure of the patch index is scalable and editable. In addition to supporting Microsoft patches, the structure and definition of the index can also support non-Microsoft system patches, various database patches, and even update patches for various user applications.
[0108] Patch download detection and incremental import: For physically isolated internal networks, the patch data in the internal patch upgrade server must be imported from the outside. The huge patch database makes each patch import quite cumbersome. For this reason, Beixinyuan uses incremental patch separation technology. When exporting patches to the external network, it can separate the patches that have been installed on the internal network and only import the system patches that have not been installed on the internal network, that is, only perform "incremental" upgrades on the patches on the internal network to improve efficiency. When a new computer patch is released for download, Beixinyuan Company will have dedicated personnel to obtain it as soon as possible, conduct corresponding analysis, and update the patch index file. The system has a dedicated external patch download server that can automatically download new computer patches based on the index. The patch verification function verifies the downloaded patches to ensure the reliability, integrity, and security of the computer patches. The patch has a virus detection function when it is imported to ensure that the patches imported into the patch library are not infected by viruses.
[0109] Automatic patch security testing: The user's real environment may contain special applications or special software versions. In these environments, sometimes the system or application will be abnormal after the patch is applied. Therefore, it is necessary to conduct real environment patch testing before large-scale patch distribution. BeiXinYuan System has created a real environment closed-loop testing technology. For the specific process, please refer to the attached Figure 3 First, the network administrator selects certain computers as test computers as a test group. After each patch is imported into the intranet, it is automatically distributed to these selected computers for installation testing of the new patch, thereby automatically performing non-simulation automatic testing. If the patch installation has no impact on the test computer and the tested computer can run normally, the network administrator can push it to the computers in the network on a large scale according to the corresponding strategy. This technology can greatly reduce the testing workload of the network administrator and improve the security of patch installation.
[0110] Automatic classification of patch library: The system can analyze computer system patches stored on the server, automatically obtain patch attributes, types and related patch descriptions, and display them clearly on the web page, which can facilitate managers to define patch distribution strategies efficiently and quickly according to corresponding needs, and distribute computer patches in a timely manner for different systems and needs. The system also provides a patch management method for administrators to customize patch categories. If necessary, relevant managers can also set corresponding customized patch categories to meet their management needs.
[0111] Cascading and synchronization of patch libraries: The system can distribute and manage patches in a cascaded manner, with no limit on the number of cascade levels and seamless and smooth expansion based on three levels; it can perform synchronization verification regularly, and can also set the synchronization verification cycle and time independently; when new patches are imported, it can also automatically trigger synchronization operations with lower-level servers. All synchronization processes can be completed automatically, and the upper-level server can understand whether the patch library of the lower-level server is synchronized successfully.
[0112] Patch installation detection and automatic distribution: Based on its own registered client advantages, Beixinyuan Patch Management provides network users with powerful remote control functions such as system patch detection, distribution, and installation. Network administrators can use this module to comprehensively detect the installation status of network system terminal patches, and through this module, remotely install patches for devices that have not installed patches. The latest patch upgrade packages can be distributed to terminal computers in a timely manner, and prompts to install patches are displayed. There are obvious prompts on the client to notify users to apply patches. The system can automatically detect and maintain the version of the system installed on the client and the patch installation status of the IE version (the patch installation status of the client computer includes Windows, Office, IE, Microsoft Media Player, etc.), automatically collect client system information and installation patch information, and automatically distribute the required patches according to the actual status of the client system.
[0113] Client program installation detection: The client in the network accesses the local WEB website to automatically register; after registration, the client detection program will run in real time in the system to detect the patch installation status and report it to the patch management center. The user WEB page automatically detects prompts to support rapid installation for a large number of users.
[0114] Client deployment: In the system's internal network, when an unregistered client accesses a local website or a parent website, a window prompting the user to register will appear.
[0115] Patch push installation: When the system detects that a client has not installed a patch, it can push the missed patch to install. At the same time, through push installation, you can also install application software for the client. Patch push distribution can cross network segments and VLANs, and patch distribution supports breakpoint resume function. During the patch distribution process, if a special event causes a network interruption, the next time the network is connected, the transmitted data and breakpoint position are verified and resumed.
[0116] System patch report: The monitoring program reports the network client patch information to the management center and writes it into the database. The patch report can be viewed on the WEB management platform to count the network client patch installation status.
[0117] Patch strategy formulation: including patch application strategy formulation, patch strategy distribution and patch file distribution task formulation. It can be divided into different areas according to requirements. It can be divided into areas according to IP addresses, departments, operating systems, user customization, etc.
[0118] Patch application strategy formulation: specifically supports timing, fixed period, classification, department, range, client status and user-defined strategies.
[0119] Patch distribution strategy: With a detailed patch distribution strategy, patches can be distributed on a regular basis, periodically, by category, by range, by department, by scope, by client status, and by user customization.
[0120] Patch file task formulation: Automatically distribute and install a specific patch or multiple patches on a specified computer or computer network.
[0121] The patch center classifies network clients and sets up test clients. After the patches are strictly tested on test machines, they are officially distributed to other types of network machines. In addition, the intranet security management system also provides patch download flow control function. The regional management module of the patch management center can control the flow and quantity of terminal patch upgrades in different network segments and different areas of the network to avoid affecting the network flow and reasonably control the network bandwidth.
[0122] Patch download traffic control: The system can use a variety of methods to control download traffic, including: (1) the system can automatically adjust the network bandwidth and concurrent connections used when distributing patches according to the network load; (2) manually set the allowed bandwidth or the number of concurrent server connections and the bandwidth allowed for each connection; (3) the system also supports client forwarding proxy patch downloads to reduce network bandwidth traffic and improve efficiency.
[0123] Proxy forwarding technology description: When distributing patches, some clients first download server patches through the patch distribution system, and other computers can download the corresponding patches through the clients that have downloaded the patches instead of the servers. When downloading, the client can automatically search for nearby IP addresses, select the client that has the patch file and has the fastest download speed, and obtain the relevant patches issued by the system server from this client to ensure network utilization and improve patch distribution efficiency.
[0124] Server-side patch query: The client software monitors the client system vulnerabilities and patch installation status in real time. The server-side patch query can query the patch installation status of computer terminals within the regional network based on the patch name, IP range to be queried, operating system, area to be queried, query time or other conditions. Through the query conditions set by the network administrator, the installation status of the queried patch can be quickly obtained (such as whether the patch is sent successfully, whether the patch is installed successfully, whether the patch has been installed, etc.) to ensure timely installation of the patch.
[0125] Client web page patch installation information query: Because many users are accustomed to visiting Microsoft's Update web page to check for patches they have missed and download and install them. As a physically isolated network, users in the intranet cannot access this web page. Therefore, from the perspective of user habits, there should also be a similar web page in the intranet so that users can access and learn about the local patch installation status and download and install patches. Computers with the system client installed can query the computer patches that are missing by accessing a specific web page in the intranet. The query results are displayed on the web page, and computer users can install them as needed.
[0126] The terminal security management system of the present invention adopts an anti-virus software operation monitoring strategy to ensure the security of the terminals connected to the network. It performs regular detection on the anti-virus software information installed on the terminal and the update time of the anti-virus software virus database. If it is found that the virus database has not been updated for more than a specified number of days, it will automatically prompt or block the system.
[0127] Usually, anti-virus software will save version information in the registry, but now many anti-virus software have abandoned this processing method and instead register their own version information in specific files or specific locations in the operating system. Through the interface provided by Microsoft, you can obtain these important information such as anti-virus product version and virus database version. For anti-virus software manufacturers that write version information to specific locations, we will use our unique acquisition method according to different manufacturers to obtain anti-virus software information. Please refer to the attached anti-virus software operation monitoring strategy flow chart Figure 5 .
[0128] The terminal security management system of the present invention also includes a process protection module. In order to protect the host audit function from being interrupted or closed by malicious programs and to ensure the audit and management of user operations, HOOK protection is performed for our product process in the kernel. Using HOOK technology, dangerous operations of our process will be monitored in real time to prevent malicious termination. SSDT HOOK is used in 32-bit systems. Since Patch Guard is used in WIN7 64-bit and later systems, SSDT HOOK cannot be used. We use the callback interface method provided by the system.
[0129] The foregoing description of specific exemplary embodiments of the present invention is for the purpose of illustration and demonstration. These descriptions are not intended to limit the present invention to the precise form disclosed, and it is clear that many changes and variations can be made based on the above teachings. The purpose of selecting and describing the exemplary embodiments is to explain the specific principles of the present invention and its practical application, so that those skilled in the art can realize and utilize various different exemplary embodiments of the present invention and various different selections and changes. The scope of the present invention is intended to be limited by the claims and their equivalents.
Claims
1. A terminal security management system, characterized in that: include: Client, used to install client program; A database for storing network client device information; Area scanner, used to detect the network connection behavior of the computer, find and block the illegal behavior defined in the database; The regional manager is used to register, verify, manage and obtain patches for clients in the network, and to exchange data and issue instructions with the regional scanner; Management information base, used for command, policy acquisition and status, data reporting, and data exchange with the patch analysis module; A patch download server, used to obtain patches from the Internet and import patch increments into the patch analysis module; The intermediate management configuration platform exchanges data and issues instructions with the management information base, is used to configure and manage the entire computer equipment information system, and sets the IP addresses of the regional manager and regional scanner within the network.
2. The terminal security management system according to claim 1, characterized in that: It has multiple terminal desktop management functions, including: process running black and white list control, process execution summary, terminal service management, software black and white list control, software installation summary, terminal message push, remote assistance, terminal real-time monitoring management, system automatic shutdown management and terminal time synchronization management.
3. The terminal security management system according to claim 2, characterized in that: The terminal real-time monitoring management is a point-to-point way for the system administrator to view and control the operation of the client in real time through the system terminal, which specifically includes the following contents: Hardware asset inventory, installed software query, terminal process management, terminal service management, terminal port management, system operation resource view, patch query, terminal time query, terminal security audit, shared directory query, current execution policy, message notification, remote process operation, network configuration modification, terminal uninstallation, remote disconnection / restore of network terminals, locking mouse and keyboard, shutting down computers and remote support.
4. The terminal security management system according to claim 1, characterized in that: It has multiple terminal security management functions, including: desktop password permission management, terminal network access control, terminal antivirus software management, registry check, IP / MAC binding policy management and hardware control policy management.
5. The terminal security management system according to claim 1, characterized in that: It has the function of managing illegal external connections, including: monitoring of illegal external Internet connections of internal network terminals, monitoring of illegal access to other networks by internal network terminals, monitoring of illegal external Internet connections of off-network terminals, alarms for illegal external connection behaviors, network locking, and evidence collection for illegal external connection behaviors.
6. The terminal security management system according to claim 5, characterized in that: The illegal external connection function is completed by the cooperation of several major modules, including: external network detection module, routing information detection module, alarm module, blocking module and network middle layer driver.
7. The terminal security management system according to claim 6, characterized in that: Adopt illegal external connection strategies to perceive changes in the network environment in real time to prevent illegal network behavior. The specific steps include: S71. Report external evidence collection records and route tracking records; S72, by detecting the URL, determine whether there is an external connection behavior; if so, proceed to S76; if not, proceed to S73; S73, by detecting the URL, determine whether it is a regular URL; if so, send a detection packet to other URLs and enter S76; if not, enter S74; S74, when external connection is not possible, close the routing detection, load the middle layer driver module, send the detection data packet, and start the subnet detection logic; S75, determine whether the machine is within the set subnet range; if so, proceed to S78; if not, report external alarm information, process it and proceed to S78; S76, enable route tracking and force detection of cascade URLs; S77, when it is detected that the cascade URL is in the external network state or the internal network + external network state, enter S78, and perform external connection processing at the same time, communicate with the blocking module, and notify the driver to block the middle layer network driver; S78. End the detection of illegal external connections.
8. The terminal security management system according to claim 1, characterized in that: It has patch distribution management functions, including: patch indexing, patch download detection and incremental import, automatic patch security testing, automatic classification of patch libraries, cascading and synchronization of patch libraries, patch installation detection and automatic distribution, patch strategy formulation, patch download flow control, server-side patch query and client-side web page patch installation information query.
9. The terminal security management system according to claim 1, characterized in that: Adopt anti-virus software operation monitoring strategy, conduct regular detection, and automatically prompt or block viruses that have not been updated within a certain period of time. The specific steps include: S91, obtaining anti-virus software logic, determining whether the anti-virus software is installed; if so, proceeding to S42; if not, performing violation processing; S92, determining whether the antivirus software database is updated; if so, terminating antivirus software monitoring; if not, performing violation processing.
10. The terminal security management system according to claim 1, characterized in that: It includes a process protection module; the process protection module adopts SSDT HOOK technology to monitor dangerous operations of the process in real time to prevent malicious termination.
Citation Information
Cited By
Domestic substitution-based credential terminal asset management and control method and system
CN120765205A