Computer terminal confidentiality inspection method, device, equipment and medium

By deploying a cross-platform confidentiality inspection system, using multiple inspection applications and inspection module libraries, the problem of inconsistent confidentiality inspection methods between different operating systems is solved, efficient and adaptable confidentiality inspection is achieved, and the workload of repeated development is reduced.

CN120012070APending Publication Date: 2025-05-16SHENHUA HOLLYSYS INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510005145.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-02
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the prior art, the confidentiality inspection methods between different operating systems are inconsistent, which increases the difficulty of implementing confidentiality inspection and reduces the efficiency of confidentiality inspection.

Method used

Provide a computer terminal confidentiality inspection method. By deploying a cross-platform confidentiality inspection system, using multiple inspection applications and inspection module libraries, the corresponding inspection applications are called according to the target operating system type of the computer terminal, and the inspection policies are generated and executed to conduct confidentiality inspection.

Benefits of technology

It realizes the use of a unified cross-platform confidentiality inspection system on different operating system platforms for confidentiality inspection, which improves the efficiency and adaptability of confidentiality inspection, and reduces the workload of repeated development of confidentiality inspection systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012070A_ABST
    Figure CN120012070A_ABST
Patent Text Reader

Abstract

The invention provides a computer terminal confidentiality check method, device and equipment and a medium, and relates to the technical field of confidentiality security, the method is applied to a cross-platform confidentiality check system deployed at a computer terminal, the system is configured with a plurality of check application programs, and the method comprises the following steps: based on a target operating system type of the computer terminal, determining a target operating system; calling and executing a corresponding target checking application program; creating an inspection task instance through a front-end management program of the target inspection application program, and generating an inspection strategy according to a setting operation of a user in the inspection task instance; analyzing the checking strategy through a back-end application program of the target checking application program, and calling a corresponding target checking module according to an analysis result to execute a corresponding confidentiality checking function; and generating and displaying a target inspection result according to the inspection result of the target inspection module. According to the method, the problem that the confidentiality check efficiency is reduced due to the fact that existing confidentiality check methods between different operating systems are not unified can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of confidentiality and security technology, and in particular to a computer terminal confidentiality checking method, a computer terminal confidentiality checking device, an electronic device, and a machine-readable storage medium. Background Art

[0002] Some confidential units use Windows operating system, Linux operating system and multiple domestic operating systems in parallel, covering multiple operating system versions, such as Windows XP, Win7, Win10, Win11, Windows Server, as well as domestic operating systems such as Kylin, Kylin, China Science and Technology Fangde, and Tongxin UOS.

[0003] The confidentiality inspection system used by confidentiality units should be compatible with different operating systems at the same time and maintain consistency in functions and inspection methods, so as to better serve the confidentiality inspection work and improve work efficiency and accuracy. However, the existing confidentiality inspection technology cannot be fully adapted to multiple operating system environments, and the confidentiality inspection methods between different operating systems are not unified, which increases the difficulty of implementing confidentiality inspections and reduces the efficiency of confidentiality inspections. Summary of the invention

[0004] The purpose of the embodiments of the present application is to provide a computer terminal confidentiality check method, a computer terminal confidentiality check device, an electronic device and a machine-readable storage medium to solve the problem in the prior art that the confidentiality check methods between different operating systems are not unified, which reduces the efficiency of confidentiality checking.

[0005] In order to achieve the above-mentioned purpose, the first aspect of the present application provides a computer terminal confidentiality check method, which is applied to a cross-platform confidentiality check system deployed on a computer terminal, wherein the system is configured with multiple check applications, and the method comprises:

[0006] Based on the target operating system type of the computer terminal, calling and executing a corresponding target inspection application; wherein the target inspection application includes a front-end management program and a back-end application, the back-end application includes an inspection module library, and the inspection module library includes a plurality of inspection modules;

[0007] Creating an inspection task instance through the front-end management program, and generating an inspection strategy according to the setting operation of the user in the inspection task instance;

[0008] Parsing the inspection strategy through the back-end application, and calling the corresponding target inspection module according to the parsing result to execute the corresponding confidentiality inspection function;

[0009] Generate a target inspection result according to the inspection result of the target inspection module;

[0010] The target inspection result is displayed in a display interface of the system.

[0011] In an embodiment of the present application, the system stores a script; based on the target operating system type of the computer terminal, before calling and executing the corresponding target inspection application, the method further includes:

[0012] In response to a check start instruction initiated by a user, the script is executed, and the target operating system type of the computer terminal is determined by the script.

[0013] In an embodiment of the present application, the system includes a plurality of root directories, each of which corresponds to an operating system type; based on the target operating system type of the computer terminal, calling and executing a corresponding target inspection application program includes:

[0014] Determining a target root directory corresponding to the computer terminal according to a target operating system type of the computer terminal;

[0015] If the target root directory contains subdirectories, the computer architecture type of the computer terminal is determined, and the inspection application stored in the subdirectory corresponding to the computer architecture type under the target root directory is determined as the target inspection application; wherein each subdirectory stores an inspection application;

[0016] If the target root directory does not contain a subdirectory, the inspection application stored in the target root directory is determined as the target inspection application.

[0017] In an embodiment of the present application, the inspection module library includes a basic information inspection module, a software information inspection module, a system security inspection module, a trace inspection module, a file inspection module and a deep inspection module.

[0018] In the embodiment of the present application, the inspection strategy is generated according to the setting operation of the user in the inspection task instance, including:

[0019] In response to a setting completion instruction initiated by a user, obtaining a selection operation and a parameter setting operation of an inspection module by the user in the inspection task instance, and determining a target inspection module and module parameter information;

[0020] Generate an inspection strategy based on the target inspection module and module parameter information.

[0021] In an embodiment of the present application, generating a target inspection result according to the inspection result of the target inspection module includes:

[0022] According to the preset confidentiality check analysis rules, the check result is content-formatted to obtain a formatted result;

[0023] Determining a confidentiality level for the computer terminal;

[0024] Violation items are judged according to the formatting result and the confidentiality level, and a target inspection result is generated.

[0025] In an embodiment of the present application, the method further includes:

[0026] Based on the target inspection result, a confidentiality inspection report of the computer terminal is generated.

[0027] A second aspect of the present application provides a computer terminal confidentiality inspection device, which is configured in a cross-platform confidentiality inspection system deployed on a computer terminal, wherein the system is configured with a plurality of inspection applications, and the device comprises:

[0028] A target program execution module, used to call and execute a corresponding target inspection application based on the target operating system type of the computer terminal; wherein the target inspection application includes a front-end management program and a back-end application, the back-end application includes an inspection module library, and the inspection module library includes a plurality of inspection modules;

[0029] An inspection strategy generation module, used to create an inspection task instance through the front-end management program, and generate an inspection strategy according to the setting operation of the user in the inspection task instance;

[0030] A target module execution module, used to parse the inspection strategy through the back-end application program, and call the corresponding target inspection module according to the analysis result to execute the corresponding confidentiality inspection function;

[0031] An inspection result generating module, used for generating a target inspection result according to the inspection result of the target inspection module;

[0032] The inspection result display module is used to display the target inspection result in the display interface of the system.

[0033] The third aspect of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the computer terminal confidentiality check method described in the first aspect when executing the computer program.

[0034] A fourth aspect of the present application provides a machine-readable storage medium having instructions stored thereon, which, when executed by a processor, configures the processor to execute the computer terminal confidentiality check method described in the first aspect above.

[0035] The computer terminal confidentiality inspection method, apparatus, equipment and medium provided in the present application divide the specific business functions of the confidentiality inspection into multiple inspection modules, and configure multiple inspection applications with multiple inspection modules with different functions in a cross-platform confidentiality inspection system. When the cross-platform confidentiality inspection system is deployed on a computer terminal, based on the target operating system type of the computer terminal, the corresponding target inspection application is called and executed, an inspection task instance is created through the front-end management program of the target inspection application, and an inspection policy is generated according to the user's setting operations in the inspection task instance. The inspection policy is parsed through the back-end application of the target inspection application, and the corresponding target inspection module is called and executed according to the parsing result, and the target inspection result is generated and displayed according to the inspection result of the target inspection module, thereby realizing the use of a unified cross-platform confidentiality inspection system for confidentiality inspection on different operating system platforms, improving the efficiency and adaptability of confidentiality inspection, and reducing the workload of repeated development of confidentiality inspection systems.

[0036] Other features and advantages of the embodiments of the present application will be described in detail in the subsequent specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] The accompanying drawings are used to provide a further understanding of the embodiments of the present application and constitute a part of the specification. Together with the following specific implementations, they are used to explain the embodiments of the present application, but do not constitute a limitation on the embodiments of the present application. In the accompanying drawings:

[0038] Figure 1 The following is a schematic diagram showing a flow chart of a computer terminal confidentiality checking method according to an embodiment of the present application;

[0039] Figure 2 The following is a schematic diagram showing the application of the computer terminal confidentiality checking method according to an embodiment of the present application;

[0040] Figure 3 The structure block diagram of the computer terminal confidentiality checking device according to the embodiment of the present application is schematically shown;

[0041] Figure 4 The internal structure diagram of the computer device according to the embodiment of the present application is schematically shown.

[0042] Description of Reference Numerals

[0043] A01-processor; A02-network interface; A03-internal memory; A04-display screen; A05-input device; A06-non-volatile storage medium; B01-operating system; B02-computer program. DETAILED DESCRIPTION

[0044] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the specific implementation methods described herein are only used to illustrate and explain the embodiments of the present application, and are not used to limit the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.

[0045] It should be noted that if the embodiments of the present application involve directional indications (such as up, down, left, right, front, back, etc.), such directional indications are only used to explain the relative position relationship, movement status, etc. between the components under a certain specific posture (as shown in the accompanying drawings). If the specific posture changes, the directional indication will also change accordingly.

[0046] In addition, if there are descriptions involving "first", "second", etc. in the embodiments of the present application, the descriptions of "first", "second", etc. are only used for descriptive purposes and cannot be understood as indicating or suggesting their relative importance or implicitly indicating the number of technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include at least one of the features. In addition, the technical solutions between the various embodiments can be combined with each other, but they must be based on the ability of ordinary technicians in the field to implement them. When the combination of technical solutions is contradictory or cannot be implemented, it should be deemed that such combination of technical solutions does not exist and is not within the scope of protection required by this application.

[0047] In view of the problem that the confidentiality checking methods between different operating systems in the related art are not unified, which reduces the efficiency of confidentiality checking, the present application provides a computer terminal confidentiality checking method, device, equipment and medium. The computer terminal confidentiality checking method, device, equipment and medium provided by the present application are described in detail below in conjunction with the accompanying drawings through specific embodiments and implementation methods.

[0048] Figure 1 The flowchart of the computer terminal confidentiality checking method of the embodiment of the present application is schematically shown. Figure 1 As shown, in one embodiment of the present application, a computer terminal confidentiality check method is provided, which is applied to a cross-platform confidentiality check system deployed on a computer terminal, the system is configured with multiple check applications, and the method may include the following steps.

[0049] Step 100: Based on the target operating system type of the computer terminal, call and execute a corresponding target inspection application.

[0050] The target inspection application includes a front-end management program and a back-end application. The back-end application includes an inspection module library. The inspection module library includes a plurality of inspection modules.

[0051] Specifically, each inspection application stored in the system includes a front-end management program and a back-end application including an inspection module library.

[0052] In the embodiment of the present application, the system fully abstracts and packages the confidentiality inspection service and adapts the confidentiality inspection service of different operating systems at the service level. Specifically, the specific service functions of confidentiality inspection are divided into multiple inspection modules to form an inspection module library, and the confidentiality inspection work on different operating systems is carried out in accordance with the inspection module library.

[0053] Among them, the inspection module library includes a basic information inspection module, a software information inspection module, a system security inspection module, a trace inspection module, a file inspection module and a deep inspection module. Each inspection module is further subdivided into several basic function sub-modules. The functions of each basic function sub-module are independent and there is no direct coupling between them. Local modifications within the basic function sub-module will not lead to the spread of modifications, which improves the system's anti-modification ability and reduces the risk of repeated system development.

[0054] In addition, before forming the inspection module library, the basic functional submodules can be flexibly and dynamically combined according to user needs during system design. The embodiment of the present application improves the maintainability of the system by adopting modular and structured program design. When an inspection module with a new function needs to be introduced, it does not affect other existing inspection modules, and has good scalability.

[0055] It should be noted that in the embodiment of the present application, in the inspection module libraries contained in different back-end application programs, the inspection modules with the same name have the same inspection functions.

[0056] In an embodiment of the present application, the system stores a script. Before executing step 100, the method further includes: executing the script in response to a check start instruction initiated by a user, and determining the target operating system type of the computer terminal through the script.

[0057] The user may initiate the inspection start instruction by manually starting the system or by other methods, which are not limited in the embodiments of the present application. After executing the script, the script automatically determines the type of the operating system of the computer terminal. The embodiments of the present application first determine the operating system type of the computer terminal so as to accurately match the corresponding inspection application program in the subsequent step, thereby ensuring the feasibility of performing a confidentiality inspection on the computer terminal.

[0058] In a specific example, the system is aggregated in a CD, and the script is run to automatically execute the inspection application that matches the currently running operating system platform. This application method enables a CD with the cross-platform confidentiality inspection system burned on it to be adapted to run on multiple platform operating systems in common confidentiality inspection scenarios, eliminating the need to bring multiple CDs for on-site inspections and the need to manually determine which CD to use.

[0059] In the embodiment of the present application, step 100 includes the following steps.

[0060] Step 110: Determine a target root directory corresponding to the computer terminal according to the target operating system type of the computer terminal.

[0061] Wherein, the system includes multiple root directories, each of which corresponds to a type of operating system. In addition, some root directories also contain subdirectories, such as the root directory corresponding to the Linux operating system. It can be understood that whether each root directory contains subdirectories can be set according to actual needs.

[0062] Step 120: If the target root directory contains a subdirectory, determine the computer architecture type of the computer terminal, and determine the inspection application stored in the subdirectory corresponding to the computer architecture type under the target root directory as the target inspection application.

[0063] Each subdirectory stores a check application.

[0064] Step 130: If the target root directory does not contain a subdirectory, the inspection application stored in the target root directory is determined as the target inspection application.

[0065] Specifically, for each root directory, when the root directory does not include a subdirectory, only one inspection application is stored in the root directory; when the root directory includes a subdirectory, each subdirectory of the root directory stores an inspection application.

[0066] In a specific example, the root directory corresponding to the Windows operating system does not contain subdirectories, and the root directory corresponding to the Linux operating system contains multiple subdirectories, which are the subdirectories corresponding to the X86 architecture, the arm architecture, and the Loongson architecture. In this case, if it is determined that the target operating system type of the computer terminal is the Windows operating system, the executable program (i.e., the target inspection application) contained in the root directory corresponding to the Windows operating system will be automatically executed; if it is determined that the target operating system type of the computer terminal is the Linux operating system, it will be further determined which type of computer architecture the computer terminal belongs to, and then the executable program in the corresponding subdirectory will be automatically executed according to the computer architecture type.

[0067] The embodiment of the present application accurately matches the corresponding inspection application based on the operating system type of the computer terminal and the directory information contained in the system, thereby ensuring the feasibility of performing confidentiality inspection on the computer terminal.

[0068] Step 200: Create an inspection task instance through the front-end management program, and generate an inspection strategy according to the setting operation of the user in the inspection task instance.

[0069] In the embodiment of the present application, step 200 includes the following steps.

[0070] Step 210, in response to a setting completion instruction initiated by the user, obtaining the user's selection operation and parameter setting operation on the inspection module in the inspection task instance, and determining the target inspection module and module parameter information.

[0071] Step 220: Generate an inspection strategy based on the target inspection module and module parameter information.

[0072] Among them, the selection operation of the inspection module refers to selecting some or all inspection modules in the inspection module library as inspection items in the front-end page, and the parameter setting operation of the inspection module refers to setting the module parameter information of the selected inspection module in the front-end page. For example, for the file inspection module, the set module parameter information includes inspection keywords, inspection paths, and inspection file types. In addition, the user can initiate the setting completion instruction by clicking the submit button in the inspection task instance, or other methods, which are not limited in the embodiments of the present application.

[0073] After detecting that the inspection strategy is generated, a confidentiality inspection task is sent to the back-end application, and the back-end application can start to execute the specific confidentiality inspection task, that is, execute step 300.

[0074] The embodiment of the present application provides the front-end management program so that the user can make relevant settings in the inspection task instance created based on the front-end management program, which makes it easy for the user to customize the confidentiality inspection task of the computer terminal according to his own needs, thereby improving the user experience.

[0075] Step 300: parse the inspection strategy through the back-end application, and call the corresponding target inspection module according to the analysis result to execute the corresponding confidentiality inspection function.

[0076] The target inspection module is at least part of the inspection modules in the inspection module library included in the target inspection application.

[0077] In the embodiment of the present application, the back-end application can decompose the confidentiality inspection task into specific confidentiality inspection functions by parsing the inspection strategy, and then execute the underlying inspection modules in sequence, that is, call the inspection modules adapted to the target operating system type in sequence. Among them, the call of the underlying inspection module provides a unified interface and specification to the upper layer, and at the same time shields the differences between different operating systems and devices, so that the system can ignore the differences in the underlying platforms and realize cross-platform operation.

[0078] In the embodiment of the present application, after the target inspection module is executed, its inspection result is fed back / pushed to the front-end management program so that the front-end management program can perform subsequent analysis and summary processing.

[0079] Step 400: Generate a target inspection result according to the inspection result of the target inspection module.

[0080] In the embodiment of the present application, step 400 includes the following steps.

[0081] Step 410: Format the content of the inspection result according to the preset confidentiality inspection analysis rules to obtain a formatted result.

[0082] Step 420, determining the confidentiality level of the computer terminal.

[0083] Step 430: determine the violation item based on the formatting result and the confidentiality level, and generate a target inspection result.

[0084] In a specific example, the formatting results include inspection results of USB storage devices, network connections, file hierarchical storage, system security and security settings, etc. The confidentiality level of the computer terminal can be selected in the inspection task instance, and the confidentiality level of the computer terminal is one of public, internal, secret, confidential, and top secret.

[0085] In the embodiment of the present application, the front-end management program summarizes and analyzes the inspection results of each inspection module included in the target inspection module, and the purpose of formatting the content of the inspection results is to meet the confidentiality inspection analysis requirements (corresponding to the preset confidentiality inspection analysis rules) and facilitate interface display. After the content is formatted, combined with the confidentiality level of the computer terminal, it is automatically determined whether there are any violations, and then the final inspection result, that is, the target inspection result, is generated.

[0086] Step 500: Display the target inspection result in the display interface of the system.

[0087] In a specific example, the structural diagram of the cross-platform confidentiality check system is as follows: Figure 2 As shown in the left part of the figure, the computer terminal deployed by the system includes common components and system layers, such as Figure 2 The system includes UI layer, business layer, function layer, data layer and system layer. The system adopts C / S architecture to separate the front and back ends. The front end uses QT+QML development mode, the business function layer is fully abstracted, and horizontal dependencies are removed. The back end is written in C / C++ language, shielding the differences in operating systems, and supports running on Windows, Linux and domestic operating systems.

[0088] Specifically, the UI layer is used to receive user commands and pass them to the business layer, so as to use the function layer connected to the business layer to perform confidentiality inspection and display the final inspection results; the business scheduling module of the business layer is used to manage all business interfaces; the function layer is used to check the module library (corresponding to Figure 2 The product function module in the system) performs confidentiality inspection on the system layer of the computer terminal; the data layer is used to store the log data and rule base (such as the preset confidentiality inspection analysis rules corresponding to different operating system types) of the system for confidentiality inspection. In addition, in addition to the aforementioned inspection module, the back-end application of the system also includes a host-type general function module, which has resource monitoring, permission control, login authentication, user management, and log management functions.

[0089] Optionally, the method may further include the following steps:

[0090] Step 600: Generate a confidentiality inspection report for the computer terminal based on the target inspection result.

[0091] In a specific example, after generating the target inspection result, a confidentiality inspection report of the computer terminal is generated according to a preset report generation rule, and the confidentiality inspection report is displayed through the front-end management program so that the user can clearly know the confidentiality inspection result of the computer terminal.

[0092] In another specific example, after generating the target inspection result, the modification operations performed by a technician (who has the authority to operate the system) on the target inspection result (such as inspection results in terms of network connection, file hierarchical storage, and system security configuration) are also obtained, and based on the modification results of the technician and according to the preset report generation rules, a confidentiality inspection report for the computer terminal is generated, and the confidentiality inspection report is displayed through the front-end management program.

[0093] This specific example avoids the problem of misjudgment of the back-end application causing the confidentiality inspection results to differ from the actual situation by granting the technician the authority to operate the target inspection results, thereby further ensuring the accuracy of the confidentiality inspection work.

[0094] In addition, before generating the confidentiality inspection report of the computer terminal, the front-end management program can also obtain the rectification suggestions proposed by the technical personnel based on the feedback from the on-site comprehensive inspection, and finally generate the confidentiality inspection report of the computer terminal based on the target retrieval results and the rectification suggestions, so as to facilitate the inspected unit to carry out rectification work and improve the confidentiality level of the inspected unit.

[0095] It can be seen that the computer terminal confidentiality check method provided in the embodiment of the present application uses a unified cross-platform confidentiality check system to perform confidentiality checks on different operating system platforms, thereby improving the efficiency and adaptability of confidentiality checks and reducing the workload of repeated development of confidentiality check systems. Specifically, the cross-platform confidentiality check system abstracts and encapsulates confidentiality check services based on the differences between different operating systems and devices, and provides a unified interface and specification, so that it can ignore the differences in the underlying platforms and achieve cross-platform operation, that is, it can perform confidentiality checks on different operating systems and hardware platforms. The constructed cross-platform confidentiality check system can be deployed on multiple platforms without the need for a large number of platform-specific code modifications.

[0096] Specifically, the embodiment of the present application divides the specific business functions of confidentiality inspection into six modules: basic information inspection module, software information inspection module, system security inspection module, trace inspection module, file inspection module and deep inspection module. Confidentiality inspections on different operating systems are carried out in accordance with these six modules, forming a standardized, unified and convenient cross-platform confidentiality inspection method, improving the efficiency of confidentiality inspection, and is suitable for confidentiality inspection work scenarios of computer terminals where multiple operating systems coexist, such as Windows, Linux, Kylin, Kylin, Zhongke Fangde and Tongxin UOS.

[0097] Figure 1 FIG. 1 is a flow chart of a computer terminal confidentiality check method in one embodiment. It should be understood that although Figure 1The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, Figure 1 At least part of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.

[0098] Figure 3 The structure block diagram of the computer terminal privacy check device according to the embodiment of the present application is schematically shown. Figure 3 As shown, in one embodiment of the present application, a computer terminal confidentiality check device is provided, which is configured in a cross-platform confidentiality check system deployed on a computer terminal. The system is configured with multiple check applications, and the device may include the following functional modules.

[0099] A target program execution module is used to call and execute a corresponding target inspection application based on the target operating system type of the computer terminal. The target inspection application includes a front-end management program and a back-end application, and the back-end application includes an inspection module library, and the inspection module library includes multiple inspection modules;

[0100] The inspection strategy generation module is used to create an inspection task instance through the front-end management program and generate an inspection strategy according to the setting operation of the user in the inspection task instance.

[0101] The target module execution module is used to parse the inspection strategy through the back-end application program and call the corresponding target inspection module according to the analysis result to execute the corresponding confidentiality inspection function.

[0102] The inspection result generating module is used to generate a target inspection result according to the inspection result of the target inspection module.

[0103] The inspection result display module is used to display the target inspection result in the display interface of the system.

[0104] In the embodiment of the present application, the system stores a script; the device may further include:

[0105] The system type determination module is used to execute the script in response to a check start instruction initiated by a user, and determine the target operating system type of the computer terminal through the script.

[0106] In the embodiment of the present application, the system includes multiple root directories, each of which corresponds to an operating system type; the target program execution module includes:

[0107] The root directory determining unit is used to determine the target root directory corresponding to the computer terminal according to the target operating system type of the computer terminal.

[0108] The first target program determination unit is used to determine the computer architecture type of the computer terminal if the target root directory contains subdirectories, and determine the inspection application stored in the subdirectory corresponding to the computer architecture type under the target root directory as the target inspection application, wherein each subdirectory stores an inspection application.

[0109] The second target program determining unit is configured to determine the inspection application stored in the target root directory as the target inspection application if the target root directory does not contain a subdirectory.

[0110] In an embodiment of the present application, the inspection module library includes a basic information inspection module, a software information inspection module, a system security inspection module, a trace inspection module, a file inspection module and a deep inspection module.

[0111] In an embodiment of the present application, the inspection strategy generation module includes:

[0112] The relevant information determination unit is used to respond to the setting completion instruction initiated by the user, obtain the user's selection operation and parameter setting operation on the inspection module in the inspection task instance, and determine the target inspection module and module parameter information.

[0113] The inspection strategy generating unit is used to generate an inspection strategy according to the target inspection module and module parameter information.

[0114] In the embodiment of the present application, the inspection result generating module includes:

[0115] The content formatting unit is used to format the content of the inspection result according to the preset confidentiality inspection analysis rules to obtain a formatted result.

[0116] The confidentiality level determination unit is used to determine the confidentiality level of the computer terminal.

[0117] The inspection result generating unit is used to judge the violation items according to the formatting result and the confidentiality level, and generate a target inspection result.

[0118] In the embodiment of the present application, the device may further include:

[0119] A report generation module is used to generate a confidentiality inspection report of the computer terminal based on the target inspection result.

[0120] Since the computer terminal confidentiality check device provided in the embodiment of the present application is a virtual device corresponding to the computer terminal confidentiality check method of the above embodiment, it can also solve the problem of inconsistent confidentiality check methods between different operating systems in the prior art, which reduces the efficiency of confidentiality check.

[0121] An embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer terminal confidentiality check method described in the above embodiment is implemented when the processor executes the computer program.

[0122] The electronic device provided in the embodiment of the present application includes a processor capable of running the computer terminal confidentiality check method of the aforementioned embodiment, and therefore can also solve the problem in the prior art that the confidentiality check methods between different operating systems are not unified, thereby reducing the efficiency of confidentiality check.

[0123] An embodiment of the present application provides a machine-readable storage medium, on which instructions are stored. When the instructions are executed by a processor, the processor is configured to execute the computer terminal confidentiality checking method described in the above embodiment.

[0124] The machine-readable storage medium provided in the embodiment of the present application stores instructions for causing the machine to execute the computer terminal confidentiality check method of the above embodiment, and can therefore also solve the problem in the prior art that the confidentiality check methods between different operating systems are not unified, thereby reducing the efficiency of confidentiality checks.

[0125] Figure 4 The internal structure diagram of the computer device of the embodiment of the present application is schematically shown. Figure 4As shown, in one embodiment of the present application, a computer device is provided, which can be a terminal. The computer device includes a processor A01, a network interface A02, a display screen A04, an input device A05 and a memory (not shown in the figure) connected through a system bus. Among them, the processor A01 of the computer device is used to provide computing and control capabilities. The memory of the computer device includes an internal memory A03 and a non-volatile storage medium A06. The non-volatile storage medium A06 stores an operating system B01 and a computer program B02. The internal memory A03 provides an environment for the operation of the operating system B01 and the computer program B02 in the non-volatile storage medium A06. The network interface A02 of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor A01, a computer terminal confidentiality check method is implemented. The display screen A04 of the computer device can be a liquid crystal display or an electronic ink display, and the input device A05 of the computer device can be a touch layer covered on the display screen, or a key, trackball or touchpad set on the computer device housing, or an external keyboard, touchpad or mouse.

[0126] Those skilled in the art will understand that Figure 4 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0127] In one embodiment, the computer terminal privacy check device provided by the present application can be implemented in the form of a computer program. The computer program can be Figure 4 The computer device is run on the computer device shown. The memory of the computer device can store various program modules constituting the computer terminal confidentiality check device, and the computer program composed of various program modules enables the processor to execute the steps of the computer terminal confidentiality check method of each embodiment of the present application described in this specification.

[0128] Figure 4 The computer device shown can be Figure 3 The target program execution module in the computer terminal confidentiality inspection device shown executes step 100, the inspection strategy generation module executes step 200, the target module execution module executes step 300, the inspection result generation module executes step 400 and the inspection result display module executes step 500.

[0129] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0130] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0131] These computer program instructions may also be stored in a computer readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0132] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0133] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0134] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0135] Computer readable media include permanent and non-permanent, removable and non-removable media, and can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0136] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0137] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.

Claims

1. A computer terminal confidentiality checking method, characterized in that: A cross-platform confidentiality inspection system is applied to a computer terminal, wherein the system is configured with multiple inspection applications, and the method comprises: Based on the target operating system type of the computer terminal, calling and executing a corresponding target inspection application; wherein the target inspection application includes a front-end management program and a back-end application, the back-end application includes an inspection module library, and the inspection module library includes a plurality of inspection modules; Creating an inspection task instance through the front-end management program, and generating an inspection strategy according to the setting operation of the user in the inspection task instance; Parsing the inspection strategy through the back-end application, and calling the corresponding target inspection module according to the parsing result to execute the corresponding confidentiality inspection function; Generate a target inspection result according to the inspection result of the target inspection module; The target inspection result is displayed in a display interface of the system.

2. The method according to claim 1, characterized in that The system stores a script; based on the target operating system type of the computer terminal, before calling and executing the corresponding target inspection application, the method further includes: In response to a check start instruction initiated by a user, the script is executed, and the target operating system type of the computer terminal is determined by the script.

3. The method according to claim 1, characterized in that The system includes a plurality of root directories, each of which corresponds to a type of operating system; Based on the target operating system type of the computer terminal, calling and executing a corresponding target inspection application program includes: Determining a target root directory corresponding to the computer terminal according to a target operating system type of the computer terminal; If the target root directory contains subdirectories, the computer architecture type of the computer terminal is determined, and the inspection application stored in the subdirectory corresponding to the computer architecture type under the target root directory is determined as the target inspection application; wherein each subdirectory stores an inspection application; If the target root directory does not contain a subdirectory, the inspection application stored in the target root directory is determined as the target inspection application.

4. The method according to claim 1, characterized in that: The inspection module library includes a basic information inspection module, a software information inspection module, a system security inspection module, a trace inspection module, a file inspection module and a depth inspection module.

5. The method according to claim 1, characterized in that Generate an inspection strategy based on the user's setting operation in the inspection task instance, including: In response to a setting completion instruction initiated by a user, obtaining a selection operation and a parameter setting operation of an inspection module by the user in the inspection task instance, and determining a target inspection module and module parameter information; Generate an inspection strategy based on the target inspection module and module parameter information.

6. The method according to claim 1, characterized in that Generating a target inspection result according to the inspection result of the target inspection module includes: According to the preset confidentiality check analysis rules, the check result is content-formatted to obtain a formatted result; Determining a confidentiality level for the computer terminal; Violation items are judged according to the formatting result and the confidentiality level, and a target inspection result is generated.

7. The method according to any one of claims 1 to 6, characterized in that The method further comprises: Based on the target inspection result, a confidentiality inspection report of the computer terminal is generated.

8. A computer terminal confidentiality checking device, characterized in that: A cross-platform confidentiality inspection system is configured and deployed on a computer terminal, wherein the system is configured with a plurality of inspection applications, and the device comprises: A target program execution module, used to call and execute a corresponding target inspection application based on the target operating system type of the computer terminal; wherein the target inspection application includes a front-end management program and a back-end application, the back-end application includes an inspection module library, and the inspection module library includes a plurality of inspection modules; An inspection strategy generation module, used to create an inspection task instance through the front-end management program, and generate an inspection strategy according to the setting operation of the user in the inspection task instance; A target module execution module, used to parse the inspection strategy through the back-end application program, and call the corresponding target inspection module according to the analysis result to execute the corresponding confidentiality inspection function; An inspection result generating module, used for generating a target inspection result according to the inspection result of the target inspection module; The inspection result display module is used to display the target inspection result in the display interface of the system.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the computer terminal confidentiality checking method according to any one of claims 1 to 7 is implemented.

10. A machine-readable storage medium having instructions stored thereon, characterized in that: When the instruction is executed by a processor, the processor is configured to execute the computer terminal privacy checking method according to any one of claims 1 to 7.