Password security control method and device of springboard machine, electronic equipment and storage medium

By identifying, crawling and detecting the user password of the springboard machine, and automatically generating and applying strong passwords when weak passwords are found, the limitations of manual management and lack of batch scanning functions in the springboard machine password management are solved, and unified password security management and automated repair of the enterprise network is achieved.

CN120017283APending Publication Date: 2025-05-16BEIJING KINGSOFT CLOUD NETWORK TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510162624.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the prior art, the management of springboard passwords has limitations in manual management, lack of batch scanning functions and automated processing, resulting in high risk of weak password leakage and difficult to achieve unified management of the entire enterprise network.

Method used

By identifying the springboard machine in the target network, grab the user password it is configured, perform weak password detection, and when determining that the password is a weak password, a strong password is generated and automatically written into the configuration file, realizing automatic password repair and management of passwords.

Benefits of technology

It realizes automatic management of springboard passwords, improves password security, can quickly batch scan and detect weak springboard passwords in corporate networks, and automatically modify them, reducing security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017283A_ABST
    Figure CN120017283A_ABST
Patent Text Reader

Abstract

The invention provides a password security control method and device for a springboard machine, electronic equipment and a storage medium, and the method comprises the steps: recognizing a springboard machine in a target network; capturing a user password configured by the springboard machine; carrying out weak password detection on the user password, and judging whether the user password is a weak password or not; when it is determined that the user password is the weak password, a strong password corresponding to the springboard machine is generated, the strong password is written into a configuration file of the springboard machine, and the safety of the strong password is higher than that of the weak password. According to the method and the device, the following technical problems in related technologies can be solved: limitation exists in manual management in a password using process; only a password management function of a single machine or a single system is provided, and uniform weak password batch scanning and detection cannot be carried out on the springboard machines in the whole enterprise network; and the problem that the weak password can only be modified manually is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data security technology, and in particular to a method and device for password security management of a jump server, an electronic device, and a storage medium. Background Art

[0002] At present, when using jump servers, relevant personnel often have improper password management. For example, users often rely on weak passwords to use jump servers, which leads to a high risk of password leakage. Once a leak occurs, attackers may obtain access to the jump server and indirectly obtain control over various key business systems of enterprises and institutions, such as virtual machines and servers. Attackers can perform operations such as deleting virtual machines and shutting down servers, which will cause immeasurable losses to corporate property and data. In order to reduce this risk, a tool that can batch scan and manage weak passwords of jump servers is urgently needed to reduce potential security risks.

[0003] In the related art, most of the existing security protection products prevent password leakage by requiring users to manually set password policies and change passwords regularly. However, this method has the following shortcomings:

[0004] Limitations of manual management: User habits are not easy to change, they often rely on weak passwords, and lack sufficient self-vigilance.

[0005] Lack of batch scanning function: Most existing products only provide password management functions for a single machine or a single system, and cannot perform unified batch scanning and detection of weak passwords on jump servers in the entire enterprise network.

[0006] No automated processing: Some products can only modify passwords or perform subsequent processing through manual intervention, making it difficult to achieve automated repair and protection. Summary of the invention

[0007] The present application provides a method and device for password security management of a jump server, an electronic device and a storage medium to at least solve the technical problems existing in the related art.

[0008] According to one aspect of an embodiment of the present application, a method for password security management of a jump server is provided, including:

[0009] Identify jump servers in the target network;

[0010] Capture the user password configured on the jump server;

[0011] Performing weak password detection on the user password and determining whether the user password is a weak password;

[0012] When it is determined that the user password is a weak password, a strong password corresponding to the jump server is generated, and the strong password is written into a configuration file of the jump server, wherein the strong password has higher security than the weak password.

[0013] Optionally, as in the aforementioned method, identifying a jump server in the target network includes:

[0014] The target network is scanned by a preset scanning method, and all jump servers in the target network are identified, wherein the preset scanning method supports at least one of the following protocols: SSH, RDP, and Telnet.

[0015] Optionally, as in the aforementioned method, the capturing and obtaining of the user password configured on the jump server includes:

[0016] Log in to the jump server;

[0017] The user password configured by the jump server is obtained by at least one of the following methods: identifying a file for storing passwords in the target network, identifying a path where the password file is stored in the target network, and obtaining the configuration of a target business system, wherein the target business system is a system used by the jump server to access, and the configuration of the target business system includes a configuration file of the jump server.

[0018] Optionally, as in the aforementioned method, performing weak password detection on the user password and determining whether the user password is a weak password includes:

[0019] When it is determined through the weak password detection that the user password satisfies at least one of the following weak password conditions, the user password is determined to be a weak password: the character types of the user password are less than or equal to the preset number of types, the number of characters of the user password is less than or equal to the preset number of characters, the character relationship between the characters in the user password satisfies the preset weak password character relationship, and the user password is one of the preset weak passwords.

[0020] Optionally, as in the aforementioned method, writing the strong password into the configuration file of the jump server includes:

[0021] Obtaining a review result of the strong password;

[0022] When the audit result indicates that the strong password can be applied, the strong password is written into the configuration file of the jump server.

[0023] Optionally, as in the aforementioned method, the method further comprises:

[0024] Recording at least one of the following password management information: a user password configured by the jump server, a password detection result for determining whether the user password is a weak password, and a strong password generated corresponding to the jump server;

[0025] Generate reports and display charts based on the password management information.

[0026] Optionally, as in the aforementioned method, the method further comprises at least one of the following:

[0027] Encrypting the strong password and storing it in a target encryption area, wherein a user who meets a preset identity requirement has access rights to the target encryption area;

[0028] Synchronizing the report and / or the display chart to a security management platform, so that the security management platform responds when determining that the report and / or the display chart does not meet preset security requirements;

[0029] A security detection result of a security detection system is obtained, and when the security of the user password does not meet the security detection result, the user password is updated according to the security detection result.

[0030] According to another aspect of the embodiment of the present application, a jump server password security management and control device is also provided, including:

[0031] Identification module, used to identify the jump server in the target network;

[0032] A capture module, used to capture the user password configured on the jump server;

[0033] A weak password detection module, used to perform weak password detection on the user password and determine whether the user password is a weak password;

[0034] The password management and automatic update module is used to generate a strong password corresponding to the jump server when it is determined that the user password is a weak password, and write the strong password into the configuration file of the jump server, wherein the strong password is more secure than the weak password.

[0035] According to another aspect of the embodiments of the present application, there is also provided an electronic device, including a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; wherein the memory is used to store a computer program; and the processor is used to execute the method steps in any of the above embodiments by running the computer program stored in the memory.

[0036] According to another aspect of the embodiments of the present application, a computer-readable storage medium is provided, in which a computer program is stored, wherein the computer program is configured to execute the method steps in any of the above embodiments when executed.

[0037] In the embodiment of the present application, the security assessment of the user password of the jump board is adopted, by identifying the jump board in the target network; capturing the user password configured by the jump board; performing weak password detection on the user password, and determining whether the user password is a weak password; in the case where it is determined that the user password is a weak password, generating a strong password corresponding to the jump board, and writing the strong password into the configuration file of the jump board, wherein the security of the strong password is higher than that of the weak password. Since the strength of the password of the jump board can be automatically determined, and in the case where the user password is a weak password, a strong password corresponding to the jump board is generated, the purpose of improving the password security of the jump board can be achieved, and the technical effect of being able to quickly batch scan the jump boards in the target network and perform unified password detection, and being able to automatically modify the weak passwords is achieved, thereby solving the following technical problems existing in the related art: there are limitations in manual management during the use of passwords; only providing the password management function of a single machine or a single system, and being unable to perform unified batch scanning and detection of weak passwords on the jump boards in the entire enterprise network; and the problem that weak passwords can only be modified manually. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0039] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0040] Figure 1 It is a schematic diagram of a hardware environment of an optional jump server password security management method according to an embodiment of the present application;

[0041] Figure 2 It is a flow chart of an optional method for password security management and control of a jump server according to an embodiment of the present application;

[0042] Figure 3 It is a structural block diagram of an optional jump server password security management and control device according to an embodiment of the present application;

[0043] Figure 4It is a structural block diagram of an optional electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0044] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.

[0045] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0046] First, some nouns or terms that appear in the description of the embodiments of the present application are subject to the following interpretation:

[0047] 1. Jump server: An intermediary server used for remote security management, through which enterprise intranet resources can be securely accessed.

[0048] 2. Password management tools: software used to generate, store and manage passwords to help improve password security.

[0049] 3. Weak passwords: Simple passwords that are easy to guess or crack, such as "123456" or "password".

[0050] 4. Multi-factor authentication: Require users to verify their identity through multiple methods, such as passwords and MFA (Multi-Factor Authentication) to enhance security. MFA is usually based on the following three different categories of verification factors: What you know (Knowledge Factors): This is information that the user knows, such as passwords, PIN codes, etc. What you have (Possession Factors): This is an item that the user has, such as a smartphone, hardware token, smart card, etc. Who you are (Inherence Factors): This is the user's biometric characteristics, such as fingerprints, iris scans, facial recognition, etc.

[0051] 5. SIEM (Security Information and Event Management) system: a system that centrally manages and analyzes security events, helps identify threats and responds in a timely manner.

[0052] According to one aspect of an embodiment of the present application, a method for security management of a jump server password is provided. Optionally, in this embodiment, the above-mentioned method for security management of a jump server password can be applied to Figure 1 In the hardware environment composed of terminal 1402 and server 1404 shown in FIG. Figure 1 As shown, server 1404 is connected to terminal 1402 via a network, and can be used to provide services (such as game services, application services, etc.) for the terminal or a client installed on the terminal. A database can be set up on the server or independently of the server to provide data storage services for server 1404.

[0053] The above network may include but is not limited to at least one of the following: wired network, wireless network. The above wired network may include but is not limited to at least one of the following: wide area network, metropolitan area network, local area network, and the above wireless network may include but is not limited to at least one of the following: WIFI (Wireless Fidelity), Bluetooth. The terminal may not be limited to a PC, a mobile phone, a tablet computer, etc.

[0054] The jump board password security control method of the embodiment of the present application can be executed by the server, or by the terminal, or by both the server and the terminal. The terminal can also execute the jump board password security control method of the embodiment of the present application by the client installed thereon.

[0055] Taking the example of the jump server password security management method in this embodiment being executed by the server, Figure 2 A method for controlling password security of a jump server provided in an embodiment of the present application includes the following steps:

[0056] Step S202, identifying a jump server in the target network.

[0057] The method for securely controlling the password of a jump server in this embodiment can be applied to a scenario where the passwords of all jump servers in a certain enterprise or institution network need to be controlled.

[0058] Specifically, with the legal authorization of the target network user, the target network's open ports can be scanned to discover the jump server in the target network.

[0059] The target network may be a network where a business system accessed by at least one jump server is located.

[0060] Step S204, capturing the user password configured on the jump server.

[0061] Specifically, after scanning and obtaining the jump board, the user password configured by the jump board can be obtained by capturing and analyzing the password storage location of each jump board or the configuration of the large path or business system storing the password. In addition, in general, each jump board has a unique corresponding user password.

[0062] Step S206: Perform weak password detection on the user password and determine whether the user password is a weak password.

[0063] Specifically, after obtaining the user password of the jump server, a weak password detection can be performed on the user password. The weak password detection can be a detection for detecting whether the security of the password meets the preset security requirements, such as the number of characters in the password (i.e., password length), the type of characters in the password (e.g., uppercase letters, lowercase letters, numbers, special symbols), the relationship between the characters in the password (e.g., continuous numbers 123456, continuous letters abcdef, etc.), etc. Moreover, if it is determined that the user password does not meet the security requirements, the user password can be determined to be a weak password, that is, a password with low security and easy to be guessed by others.

[0064] Step S208, when it is determined that the user password is a weak password, a strong password corresponding to the jump server is generated, and the strong password is written into the configuration file of the jump server, wherein the strong password is more secure than the weak password.

[0065] Specifically, if it is determined that the user password is a weak password, a strong password corresponding to the jump server is generated, and the strong password is more secure than the weak password, and the strong password is written into the configuration file of the jump server, so that the strong password can be used to log in to the jump server and access the corresponding business system later. If the user password is a strong password, there is no need to generate a strong password corresponding to the jump server and subsequent operations.

[0066] In the embodiment of the present application, a method of performing a security assessment on the user password of a jump machine is adopted. Since the strength of the password of the jump machine can be automatically determined, and when the user password is a weak password, a strong password corresponding to the jump machine is generated, the purpose of improving the password security of the jump machine can be achieved, and the technical effect of quickly scanning the jump machines in the target network in batches and performing unified password detection, and automatically modifying weak passwords is achieved, thereby solving the following technical problems existing in the related art: there are limitations in manual management during the use of passwords; only password management functions for a single machine or a single system are provided, and unified weak password batch scanning and detection cannot be performed on the jump machines in the entire enterprise network; and the problem that weak passwords can only be modified manually.

[0067] As an optional embodiment, as in the aforementioned method, the jump board in the target network can be identified by the following steps: scanning in the target network by a preset scanning method, and identifying all the jump boards in the target network, wherein the preset scanning method supports at least one of the following protocols: SSH (Secure Shell), RDP (Remote Desktop Protocol), Telnet (Teletype Network). Specifically, the jump board can be scanned in the target network by protocols such as SSH, RDP, Telnet, and all the jump boards in the target network can be identified by scanning the open ports. The public key can be captured in the ~ / .ssh / authorized_keys file of the business system. The private key can be captured in the ~ / .ssh directory of the user access terminal (client). The basic information of all local users can also be scanned in the / etc / passwd directory, including user name, user ID (UID), group ID (GID), user home directory path, and default Shell, etc., and each field is separated by a colon.

[0068] As an optional embodiment, as in the aforementioned method, the user password configured by the jump board can be captured by the following steps: log in to the jump board; obtain the user password configured by the jump board by at least one of the following methods: identify a file for storing passwords in the target network, identify a path where the password file is stored in the target network, and obtain the configuration of the target business system, wherein the target business system is the system used by the jump board to access, and the configuration of the target business system includes the configuration file of the jump board. That is to say, after logging in to the jump board, the data in the file can be identified, and when it is determined that the data belongs to a password, it can be determined as a file for storing passwords, or the path where the password file is stored can be identified in the target network, for example: the public key and private key configuration files in the ~ / .ssh directory, / etc / passwd, etc. The configuration of the business system can also be obtained through management tools (such as Puppet, Ansible, etc.) to determine the large path that may be used to store the password file, and then the user password configured by the jump board can be captured in the large path. Furthermore, in the case where multiple jump servers are obtained through scanning, the multiple jump servers may be scanned concurrently. Optionally, the scanning efficiency of the concurrent scanning may be improved through a queue mechanism and multi-threading technology.

[0069] As an optional embodiment, as in the aforementioned method, weak password detection can be implemented on the user password through the following steps to determine whether the user password is a weak password: when it is determined through weak password detection that the user password meets at least one of the following weak password conditions, the user password is determined to be a weak password: the character types of the user password are less than or equal to the preset number of types, the number of characters of the user password is less than or equal to the preset number of characters, the character relationship between the characters in the user password satisfies the preset weak password character relationship, and the user password is one of the preset weak passwords. Among them, the character types of the user password are less than or equal to the preset number of types, and the character types may include but are not limited to: uppercase letters (for example, A, B, etc.), lowercase letters (for example, a, b, etc.), numbers (i.e., 1, 2, 3, etc.), special symbols (for example,!, @, #, etc.), etc. The preset number of types can be a pre-set number of the minimum number of character types that need to be met, for example, 3 types, 4 types, etc. The number of characters is the length of the password, and the preset number of characters can be a pre-set number of the minimum number of characters that need to be met, for example, 8, 10, etc. The character relationship between each character is the order of different characters. The preset weak password character relationship may include but is not limited to: a numerical ascending relationship (for example: 123456, etc.), an alphabetical ascending relationship (for example: abcdef, etc.). The preset weak password may be a password stored in a weak password dictionary (for example, 123456, password, etc.), and whether it is a preset weak password can be determined by comparing the user password with the preset weak password.

[0070] As an optional embodiment, as in the aforementioned method, the strong password can be written into the configuration file of the jump board through the following steps, including: obtaining the audit result of the strong password audit; when the audit result indicates that the strong password can be applied, the strong password is written into the configuration file of the jump board. Specifically, once the user password is found to be a weak password, the password update mechanism will be triggered, and the system will automatically generate a random strong password that meets the security requirements. Optionally, the strong password will contain uppercase letters, lowercase letters, numbers and special symbols to meet the security policy of the enterprise. After the strong password is generated, the new strong password can be automatically written into the jump board configuration, and the unified platform for enterprise user management corresponding to the transmission of the new password through a secure channel (such as SSH key authentication, Kerberos authentication, etc.) is supported, so that the administrator in the unified platform for enterprise user management can choose to review the recommended new strong password and generate the corresponding audit result. If the audit result indicates that the strong password is applied, the strong password is written into the configuration file of the jump board. Through this administrator approval mode, it can be ensured that changes to important systems will not be wrong due to automated operations.

[0071] As an optional embodiment, as in the above method, the method further includes:

[0072] At least one of the following password management information is recorded: the user password configured for the jump server, the password detection result for determining whether the user password is a weak password, and the strong password generated corresponding to the jump server; that is, log recording can be implemented, for example, each password scan is recorded by the password detection result for determining whether the user password is a weak password; the time and operator of the password update can be determined based on the password detection result for determining whether the user password is a weak password, the time of generating the strong password corresponding to the jump server, and the operator who applied the strong password; detailed information such as the password before and after the update can be obtained based on the user password and the generated strong password.

[0073] Generate reports and display charts based on password management information. After obtaining the above password management information, you can generate reports by day, week, or month. The reports can include statistics on weak passwords in the target network, the security status of each jump server, etc. In addition, the report can be displayed through display charts to help administrators quickly and intuitively understand the overall password security status.

[0074] As an optional embodiment, as in the above method, the method further includes at least one of the following:

[0075] The strong password is encrypted and stored in the target encryption area, wherein users who meet the preset identity requirements have access rights to the target encryption area; that is, the strong password is stored in the target encryption area to prevent the strong password from being stolen, and only users who meet the preset identity requirements can access the target encryption area. For example, the password management system can be integrated with the enterprise's LDAP, Active Directory and other identity authentication systems to achieve the above-mentioned identity authentication management and password synchronization.

[0076] The report and / or display chart are synchronized to the security management platform so that the security management platform responds when it determines that the report and / or display chart do not meet the preset security requirements. Specifically, after the report is generated, the report can be synchronized to the security management platform so that the security management platform responds when it determines that the report does not meet the preset security requirements. After the display chart is generated, the display chart can be synchronized to the security management platform so that the security management platform responds when it determines that the display chart does not meet the preset security requirements. After the report and the display chart are generated, the report and the display chart can be synchronized to the security management platform so that the security management platform responds when it determines that the report and the display chart do not meet the preset security requirements. For example, the system implementing the above-mentioned embodiment method can be integrated with a SIEM (such as Splunk, ArcSight, etc.) system, and the report and / or display chart can be synchronized to the SIEM platform for unified security monitoring and incident response.

[0077] Obtain the security detection result of the security detection system, and update the user password according to the security detection result when the security of the user password does not meet the security detection result. For example, the system implementing the above-mentioned embodiment method can provide a RESTful API interface so that the system supports integration with other security detection systems (for example, security vulnerability scanning, intrusion detection, etc.), and when the security of the user password does not meet the security detection result, such as when there is a security vulnerability or intrusion, the user password is updated to improve the security of the password.

[0078] As described below, an application example of applying any of the above embodiments is provided:

[0079] User login: The user logs in through a Web console or an APP to implement the system of the method described in any of the preceding embodiments.

[0080] Scan trigger: The system administrator triggers a batch scan task, and the system connects to the jump server and scans the user password of each jump server.

[0081] Password Assessment: Each jump server user password is assessed and marked as strong or weak.

[0082] Automatic update: If a weak password is detected, the system will automatically generate a strong password for the corresponding jump server and deploy a new strong password for the jump server, or notify the administrator to change the password.

[0083] Report generation: After the scan is completed, the system generates a report and / or displays a chart, and displays the report and / or displays a chart through the web interface.

[0084] It should be noted that, for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.

[0085] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM (Read-Only Memory) / RAM (Random Access Memory), a disk, or an optical disk), and includes a number of instructions for a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present application.

[0086] According to another aspect of an embodiment of the present application, a jump server password security management device for implementing the above-mentioned jump server password security management method is also provided. Figure 3 is a structural block diagram of an optional jump server password security management and control device according to an embodiment of the present application, such as Figure 3 As shown, the device may include:

[0087] An identification module 31, used for identifying a jump server in a target network;

[0088] Capturing module 32, used to capture the user password configured by the jump server;

[0089] A weak password detection module 33 is used to perform weak password detection on the user password and determine whether the user password is a weak password;

[0090] The password management and automatic update module 34 is used to generate a strong password corresponding to the jump server when it is determined that the user password is a weak password, and write the strong password into the configuration file of the jump server, wherein the security of the strong password is higher than that of the weak password.

[0091] It should be noted that the identification module 31 in this embodiment can be used to execute the above step S202, the capture module 32 in this embodiment can be used to execute the above step S204, the weak password detection module 33 in this embodiment can be used to execute the above step S206, and the password management and automatic update module 34 in this embodiment can be used to execute the above step S208.

[0092] Through the above module, a method of performing a security assessment on the user password of the jump machine is adopted. Since the strength of the password of the jump machine can be automatically determined, and when the user password is a weak password, a strong password corresponding to the jump machine is generated, the purpose of improving the password security of the jump machine can be achieved, and the technical effect of quickly scanning the jump machines in the target network in batches and performing unified password detection, and automatically modifying weak passwords is achieved, thereby solving the following technical problems existing in the relevant technology: there are limitations in manual management during the use of passwords; only the password management function of a single machine or a single system is provided, and it is impossible to perform unified weak password batch scanning and detection on the jump machines in the entire enterprise network; and the problem that weak passwords can only be modified manually.

[0093] The device in this embodiment, in addition to the above-mentioned modules, may also include a module for executing any method in any of the aforementioned embodiments of the jump server password security management method.

[0094] It should be noted that the examples and application scenarios implemented by the above modules and corresponding steps are the same, but are not limited to the contents disclosed in the above embodiments. It should be noted that the above modules as part of the device can be run in Figure 1 In the hardware environment shown, it can be implemented by software or by hardware, wherein the hardware environment includes a network environment.

[0095] According to another aspect of an embodiment of the present application, an electronic device for implementing the above-mentioned jump server password security management method is also provided. The electronic device may be a server, a terminal, or a combination thereof.

[0096] According to another embodiment of the present application, there is also provided an electronic device, including: Figure 4 As shown, the electronic device may include: a processor 1501 , a communication interface 1502 , a memory 1503 and a communication bus 1504 , wherein the processor 1501 , the communication interface 1502 , and the memory 1503 communicate with each other via the communication bus 1504 .

[0097] Memory 1503, used for storing computer programs;

[0098] The processor 1501 is used to implement the following steps when executing the program stored in the memory 1503:

[0099] Step S202, identifying a jump server in the target network.

[0100] Step S204, capturing the user password configured on the jump server.

[0101] Step S206: Perform weak password detection on the user password and determine whether the user password is a weak password.

[0102] Step S208, when it is determined that the user password is a weak password, a strong password corresponding to the jump server is generated, and the strong password is written into the configuration file of the jump server, wherein the strong password is more secure than the weak password.

[0103] Optionally, in this embodiment, the above-mentioned communication bus can be a PCI (Peripheral Component Interconnect) bus, or an EISA (Extended Industry Standard Architecture) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus. The communication interface is used for communication between the above-mentioned electronic device and other devices.

[0104] The memory may include a random access memory (RAM) or a non-volatile memory (NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.

[0105] As an example, the memory 1503 may include, but is not limited to, the identification module 31, the capture module 32, the weak password detection module 33, and the password management and automatic update module 34 in the jump board password security management device. In addition, it may also include, but is not limited to, other module units in the jump board password security management device, which will not be repeated in this example.

[0106] The above-mentioned processor can be a general-purpose processor, which can include but not be limited to: CPU (Central Processing Unit), NP (Network Processor), etc.; it can also be DSP (Digital Signal Processor), ASIC (Application Specific Integrated Circuit), FPGA (Field-Programmable Gate Array) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.

[0107] An embodiment of the present application further provides a computer-readable storage medium, the storage medium including a stored program, wherein the method steps of the above method embodiment are executed when the program is run.

[0108] Optionally, in this embodiment, the storage medium may include, but is not limited to, various media that can store program codes, such as a USB flash drive, a ROM, a RAM, a mobile hard disk, a magnetic disk, or an optical disk.

[0109] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0110] If the integrated units in the above embodiments are implemented in the form of software functional units and sold or used as independent products, they can be stored in the above computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling one or more computer devices (which may be personal computers, servers, or network devices, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application.

[0111] In the above embodiments of the present application, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.

[0112] In the several embodiments provided in the present application, it should be understood that the disclosed client can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.

[0113] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution provided in this embodiment.

[0114] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.

[0115] The above is only a preferred implementation of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A method for controlling password security of a jump server, characterized in that: include: Identify jump servers in the target network; Capture the user password configured on the jump server; Performing weak password detection on the user password and determining whether the user password is a weak password; When it is determined that the user password is a weak password, a strong password corresponding to the jump server is generated, and the strong password is written into a configuration file of the jump server, wherein the strong password has higher security than the weak password.

2. The method according to claim 1, characterized in that The step of identifying a jump server in a target network includes: The target network is scanned by a preset scanning method, and all jump servers in the target network are identified, wherein the preset scanning method supports at least one of the following protocols: SSH, RDP, and Telnet.

3. The method according to claim 1, characterized in that The captured user password configured on the jump server includes: Log in to the jump server; The user password configured by the jump server is obtained by at least one of the following methods: identifying a file for storing passwords in the target network, identifying a path where the password file is stored in the target network, and obtaining the configuration of a target business system, wherein the target business system is a system used by the jump server to access, and the configuration of the target business system includes a configuration file of the jump server.

4. The method according to claim 1, characterized in that The performing weak password detection on the user password and determining whether the user password is a weak password includes: When it is determined through the weak password detection that the user password satisfies at least one of the following weak password conditions, the user password is determined to be a weak password: the character types of the user password are less than or equal to the preset number of types, the number of characters of the user password is less than or equal to the preset number of characters, the character relationship between the characters in the user password satisfies the preset weak password character relationship, and the user password is one of the preset weak passwords.

5. The method according to claim 1, characterized in that Writing the strong password into the configuration file of the jump server includes: Obtaining a review result of the strong password; When the audit result indicates that the strong password can be applied, the strong password is written into the configuration file of the jump server.

6. The method according to claim 1, characterized in that The method further comprises: Recording at least one of the following password management information: a user password configured by the jump server, a password detection result for determining whether the user password is a weak password, and a strong password generated corresponding to the jump server; Generate reports and display charts based on the password management information.

7. The method according to claim 6, characterized in that The method further comprises at least one of the following: Encrypting the strong password and storing it in a target encryption area, wherein a user who meets a preset identity requirement has access rights to the target encryption area; Synchronizing the report and / or the display chart to a security management platform, so that the security management platform responds when determining that the report and / or the display chart does not meet preset security requirements; A security detection result of a security detection system is obtained, and when the security of the user password does not meet the security detection result, the user password is updated according to the security detection result.

8. A jump board password security control device, characterized in that: include: Identification module, used to identify the jump server in the target network; A capture module, used to capture the user password configured on the jump server; A weak password detection module, used to perform weak password detection on the user password and determine whether the user password is a weak password; The password management and automatic update module is used to generate a strong password corresponding to the jump server when it is determined that the user password is a weak password, and write the strong password into the configuration file of the jump server, wherein the strong password is more secure than the weak password.

9. An electronic device comprising a processor, a communication interface, a memory and a communication bus, wherein: The processor, the communication interface and the memory communicate with each other via the communication bus, wherein: The memory is used to store computer programs; The processor is configured to execute the method according to any one of claims 1 to 7 by running the computer program stored in the memory.

10. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, wherein the computer program is configured to execute the method according to any one of claims 1 to 7 when executed.