Computer system and maintenance method of computer system

By generating a virtual copy that is synchronized in real time with the target computer system in an isolated environment and performing dynamic behavior monitoring, the technical defects of patch installation security testing in the existing technology are solved, and a safer and more efficient patch installation is achieved, ensuring the stability and performance of the system.

CN120145386APending Publication Date: 2025-06-13SHANGHAI SHENGYONG ENG TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510139682.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-08
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The prior art has technical flaws and drawbacks in the security testing of computer system patch installation. It is impossible to fully capture the potential problems of patches in dynamic operating environments, which may lead to compatibility issues or performance degradation, and real system testing may lead to unforeseen system interruptions or data corruption.

Method used

By generating a virtual copy in a segregated environment that is synchronized in real time with the target computer system, comprehensive dynamic behavior monitoring is carried out to verify patch compatibility and potential behavioral threats, reducing the impact on the actual system.

Benefits of technology

It significantly improves the security and efficiency of patch installation, ensures system stability and performance, avoids compatibility issues and potential threats caused by patches, and reduces the risk of system interruptions and data corruption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145386A_ABST
    Figure CN120145386A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computer system maintenance, and particularly discloses a computer system and a computer system maintenance method, and the method comprises the steps: obtaining the basic information of each to-be-installed patch corresponding to a target computer system, and carrying out the preliminary analysis to obtain the safety evaluation coefficient of each to-be-installed patch; collecting multi-dimensional data of the target computer system, and generating a virtual copy synchronized with the target computer system in real time in the isolation environment; installing each patch to be installed in the original target computer system in the isolation environment, running a core function module of the target computer system in the isolation environment, and further verifying a compatibility evaluation coefficient of each patch to be installed in the isolation environment; synchronously monitoring the dynamic operation behavior of each patch to be installed in real time in the isolation environment, and detecting a potential behavior threat assessment coefficient of each patch to be installed in the isolation environment; not only is the possibility of patch introduction reduced, but also a solid foundation is provided for long-term maintenance and safety management of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of computer system maintenance, and relates to computer systems and maintenance methods for computer systems. Background Art

[0002] In today's digital age, the security and stability of computer systems face unprecedented challenges. With the increasing complexity and frequency of cyberattacks, system vulnerabilities have become the main target of hacker attacks. Whether it is the operating system or application software, various security vulnerabilities and performance issues will emerge over time. To address these threats, software vendors regularly release patches to fix vulnerabilities, enhance functions, and improve system performance. The importance of installing patches lies not only in fixing known problems but also in preventing potential security risks. Patches can block the entry points exploited by attackers, prevent the intrusion of malware and data leakage. In addition, patches can improve the compatibility and stability of software, ensuring that the system remains in the best state in a constantly changing technical environment. Ignoring patch updates may lead to system vulnerability, increase the risk of being attacked, and may result in serious economic and reputational losses.

[0003] There are still some technical defects and drawbacks in the security testing of patch installation in computer systems in the prior art:

[0004] Traditional testing methods often rely on static analysis and limited test cases, and cannot comprehensively capture potential problems of patches in a dynamic running environment. This method may ignore complex interactions and edge cases, resulting in compatibility problems or performance degradation of patches in actual applications. Secondly, the prior art usually conducts tests on real systems, which may lead to unforeseen system interruptions or data corruption. Summary of the Invention

[0005] In view of the above problems existing in the prior art, the present invention provides a computer system and a maintenance method for a computer system. By generating a virtual copy that is synchronized in real time with the target computer system in an isolated environment, the state of the target system can be synchronized in real time, and comprehensive dynamic behavior monitoring can be performed, significantly reducing the impact on the actual system. Compared with traditional patch installation technologies, the virtual copy provides a safer and more efficient alternative solution to solve the above technical problems.

[0006] To achieve the above and other objectives, the technical solution adopted by the present invention is as follows:

[0007] On the one hand, the present invention provides a maintenance method for a computer system, and the method includes the following steps:

[0008] Step S1, obtaining the basic information of each patch to be installed corresponding to the target computer system, and preliminarily analyzing to obtain the security evaluation coefficient of each patch to be installed;

[0009] Step S2: Based on the security evaluation coefficients of each patch to be installed, make a judgment. If the judgment passes, continue to execute the method steps; otherwise, select alternative patches for screening.

[0010] Step S3: By collecting multi-dimensional data of the target computer system, generate a virtual copy in an isolated environment that is synchronized in real time with the target computer system; install each patch to be installed in the original target computer system in the isolated environment, and run the core function modules of the target computer system in the isolated environment, thereby verifying the compatibility evaluation coefficients of each patch to be installed in the isolated environment.

[0011] Step S4: Monitor the dynamic running behaviors of each patch to be installed in real time in the isolated environment, and detect the potential behavior threat evaluation coefficients of each patch to be installed in the isolated environment.

[0012] Step S5: Based on the compatibility evaluation coefficients and potential behavior threat evaluation coefficients of each patch to be installed in the isolated environment, comprehensively judge the available coefficients of each patch to be installed in the actual running environment of the target computer system, and perform corresponding operations on each patch to be installed based on this.

[0013] Exemplarily, the security evaluation coefficients of each patch to be installed are obtained, and the specific analysis process is as follows:

[0014] Based on the basic information of each patch to be installed corresponding to the target computer system, analyze it to obtain the applicable range score, dependency score, and security source score of each patch to be installed, and mark them as P1 j 、P2 j 、P3 j , where j is the number of each patch to be installed;

[0015] Thus, comprehensively calculate the security evaluation coefficient of each patch to be installed e is the natural constant.

[0016] Exemplarily, the applicable score, dependency score, and security source score of each patch to be installed are obtained, and the specific acquisition process is as follows:

[0017] Based on the basic information of each patch to be installed corresponding to the target computer system, obtain the applicable component ratio, user environment matching degree, and historical applicability score of each patch to be installed, and then calculate the applicable range score of each patch to be installed α1 j 、α2 j 、α3 j respectively represent the applicable component ratio, user environment matching degree, and historical applicability score of the j-th patch to be installed;

[0018] Based on the basic information of each patch to be installed corresponding to the target computer system, obtain the proportion of satisfied dependencies, the dependency complexity index, and the historical dependency resolution success rate corresponding to each patch to be installed, and denote them as α4 j 、α5 j 、α6 j , and then calculate the dependency score of each patch to be installed

[0019]

[0020] Based on the basic information of each patch to be installed corresponding to the target computer system, extract the verification credibility, source credibility, and historical security record corresponding to each patch to be installed, and denote them as α7 j 、α8 j 、α9 j , and then calculate the security source score of each patch to be installed

[0021]

[0022] Exemplarily, verify the compatibility evaluation coefficient of each patch to be installed in the isolation environment. The specific verification logic is as follows:

[0023] In the virtual environment, perform installation tests on each patch to be installed in turn. The specific installation test steps are as follows:

[0024] Step 1: Install each patch to be installed one by one in the virtual copy, and strictly monitor the core function modules of the system during the installation process, and collect the performance index parameters of each patch to be installed on each core function module;

[0025] Step 2: After collecting all the index parameters of the current patch to be installed, the virtual copy uses the transaction rollback strategy. Through the transaction rollback strategy, clear all the installation traces left by the current patch in the virtual environment to ensure that the system returns to the initial state;

[0026] Step 3: After the rollback is completed and it is confirmed that the system state has been restored, the virtual copy continues to install and test the next patch to be installed;

[0027] Select any patch to be installed from the above installation test steps as the target patch;

[0028] Obtain the number M of the core function modules of the target computer system, and sequentially number each core function module in the target computer system as 1, 2,... m,... M;

[0029] Obtain the performance index evaluation coefficient of the target patch on the m-th core function module in the isolation environment and the performance index evaluation coefficient of the m-th core function module in the actual operating environment

[0030] And analyze to obtain the function integrity evaluation factor F of each core function module of the target patch in the isolation environment m , and thus comprehensively analyze to obtain the compatibility evaluation coefficient of the target patch in the isolation environment

[0031]

[0032] According to the calculation method of the compatibility evaluation coefficient of the target patch in the isolation environment, similarly calculate the compatibility evaluation coefficient C of each patch to be installed in the isolation environment j .

[0033] Exemplarily, analyze to obtain the function integrity evaluation factor F of each core function module of the target patch in the isolation environment m , and the specific analysis process is as follows:

[0034] Based on the function modules included in the virtual copy, further detect the successful execution rate β1 of the target patch corresponding to each core function module in the isolation environment m , the resource utilization stability rate β2 m and the dependency integrity β3 m ;

[0035] Furthermore, define the function integrity evaluation factor F of each core function module of the target patch in the isolation environment m as:

[0036]

[0037] Exemplarily, detect the potential behavior threat evaluation coefficient of each patch to be installed in the isolation environment, and the specific detection process is as follows:

[0038] Run each patch to be installed in the isolation environment, record all its dynamic behaviors, and take each independent dynamic behavior corresponding to each patch to be installed as a node in the behavior graph corresponding to each patch to be installed. If one behavior occurs immediately after another behavior, create a directed edge between these two nodes to represent the behavior transition relationship; combine all the nodes and edges in the behavior graph corresponding to each patch to be installed, and merge the repeated behaviors and edges to form a behavior directed graph, representing the behavior sequence of each patch to be installed in the isolation environment;

[0039] Obtain the total number of nodes N of the behavior directed graph corresponding to each patch to be installed, and form a set of other nodes pointing to each node in the behavior directed graph corresponding to each patch to be installed, and record it as the node set of each node in the behavior directed graph corresponding to each patch to be installed n is the number of each node in the behavior directed graph, n = 1, 2,... N;

[0040] Calculate the PageRank value of each node in the behavior directed graph corresponding to each patch to be installed accordingly. where d is the damping factor, usually set to 0.85. represents the c-th other node that has a connection relationship with the n-th node in the behavior directed graph, and c is the index number of each other node; represents the PageRank value of the c-th other node that has a connection relationship with the n-th node in the behavior directed graph corresponding to the j-th patch to be installed; represents the out-degree of the c-th other node that has a connection relationship with the n-th node in the behavior directed graph corresponding to the j-th patch to be installed;

[0041] Furthermore, calculate the information entropy of the behavior directed graph corresponding to the j-th patch to be installed where is the probability of the n-th node in the behavior directed graph corresponding to the j-th patch to be installed;

[0042] Finally, calculate the potential behavior threat assessment coefficient for each patch to be installed in the isolation environment

[0043]

[0044] Exemplarily, the specific operation logic in step S5 is as follows:

[0045] Based on the compatibility assessment coefficient and the potential behavior threat assessment coefficient of each patch to be installed in the isolation environment, further comprehensively judge the available coefficient U of each patch to be installed in the actual running environment of the target computer system j = ω1 × C j + ω2 × (1 - H j ), where ω1 and ω2 respectively represent the weight factors corresponding to the compatibility assessment coefficient and the potential behavior threat assessment coefficient, and satisfy ω1 > ω2 and ω1 + ω2 = 1;

[0046] Compare the available coefficient of each patch to be installed in the actual running environment of the target computer system with the set patch comprehensive operation threshold coefficient. If the available coefficient of a certain patch to be installed in the actual running environment of the target computer system is less than the set patch comprehensive operation threshold coefficient, it is determined that there is a compatibility risk for this patch to be installed, and another alternative patch is selected.

[0047] On the other hand, the present invention provides a computer system, including a patch security assessment module, a security assessment judgment module, a virtual copy assessment module, a patch real-time analysis module, and a patch processing analysis module. The above-mentioned modules are connected by wired and / or wireless connection methods to realize data transmission between the modules;

[0048] Patch Security Assessment Module: Obtain the basic information of each patch to be installed corresponding to the target computer system, and preliminarily analyze to obtain the security assessment coefficients of each patch to be installed;

[0049] Security Assessment Judgment Module: Connect to the Patch Security Assessment Module, make judgments based on the security assessment coefficients of each patch to be installed. If the judgment passes, continue to execute the method steps; otherwise, screen for alternative patches;

[0050] Virtual Replica Assessment Module: By collecting multi-dimensional data of the target computer system, generate a virtual replica in an isolated environment that is synchronized with the target computer system in real time; install each patch to be installed in the original target computer system in the isolated environment, and run the core function modules of the target computer system in the isolated environment, and then verify the compatibility assessment coefficients of each patch to be installed in the isolated environment;

[0051] Patch Real-time Analysis Module: In the isolated environment, monitor the dynamic running behaviors of each patch to be installed in real time, and detect the potential behavior threat assessment coefficients of each patch to be installed in the isolated environment;

[0052] Patch Processing Analysis Module: Based on the compatibility assessment coefficients and potential behavior threat assessment coefficients of each patch to be installed in the isolated environment, comprehensively judge the available coefficients of each patch to be installed in the actual running environment of the target computer system, and perform corresponding operations on each patch to be installed based on this;

[0053] As described above, the computer system and the maintenance method of the computer system provided by the present invention have at least the following beneficial effects:

[0054] (1) The computer system and the maintenance method of the computer system provided by the present invention can accurately simulate the running state of the real system in the isolated environment by creating a virtual replica that is synchronized with the target computer system in real time. This virtualization technology can not only save resources, but also ensure a high degree of consistency between the test environment and the production environment, avoiding inaccurate test results caused by environmental differences. This method allows for comprehensive testing of patches without affecting the actual system operation, thus ensuring that the patches will not have a negative impact on the system stability and performance.

[0055] (2) In the embodiments of the present invention, the core function modules are run and patches are installed in the isolated environment, which can verify the compatibility of the patches. In this way, compatibility problems between patches and the system or other software can be discovered and solved in advance, preventing the patches from causing system crashes or function failures in the production environment. This preventive measure is crucial for maintaining the normal operation of the system, especially in critical business systems, where any downtime or failure may cause serious economic losses.

[0056] (3) By monitoring the dynamic running behavior of patches in real time, the embodiments of the present invention can detect potential behavioral threats in a timely manner. This real-time monitoring not only improves the transparency of patch behavior but also enables a rapid response when malicious behavior is introduced by the patch, protecting the system from attacks.

[0057] (4) By testing and evaluating the security, compatibility, and potential threats of patches in an isolated environment, the embodiments of the present invention can significantly enhance the security and stability of the system. This method not only reduces the likelihood of problems introduced by patches but also provides a solid foundation for the long-term maintenance and security management of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0059] Figure 1 Schematic diagram of the connection of each step of the method of the present invention.

[0060] Figure 2 Schematic diagram of the connection of each module of the system of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0061] The above content is only an example and explanation of the concept of the present invention. Those skilled in the art of the present technology can make various modifications or supplements to the described specific embodiments or use similar methods for substitution, as long as they do not deviate from the concept of the invention or exceed the scope defined by the claims of the present invention, they should all fall within the protection scope of the present invention.

[0062] Embodiment 1

[0063] Please refer to Figure 1 shown. A maintenance method for a computer system, the method comprising the following steps:

[0064] Step S1: Obtain the basic information of each patch to be installed corresponding to the target computer system, and preliminarily analyze to obtain the security evaluation coefficient of each patch to be installed;

[0065] According to a preferred embodiment, the security evaluation coefficient of each patch to be installed is analyzed, and the specific analysis process is as follows:

[0066] Based on the basic information of each patch to be installed corresponding to the target computer system, further analyze it to obtain the applicable range score, dependency score, and security source score of each patch to be installed, and mark them as P1 j , P2 j, P3 j , where j is the number of each patch to be installed;

[0067] Thus, comprehensively calculate the security assessment coefficient of each patch to be installed e is the natural constant.

[0068] When calculating the security assessment coefficient of a patch, using a non - linear formula can more comprehensively reflect the comprehensive impact of the multi - dimensional characteristics of the patch on security.

[0069] The above calculation formula combines the three scores using the cube root and exponential function, which can better capture the complex interaction relationships between various factors. The non - linear combination makes the extreme value of a certain score not overly affect the overall score, providing a more balanced assessment. Compared with the traditional weighted summation method, the calculation method of traditional weighted summation may ignore the non - linear relationships between factors, resulting in a high - scoring factor overly affecting the total score. The non - linear formula can more precisely reflect the true impact of each factor.

[0070] According to a preferred implementation, obtain the applicability score, dependency score, and security source score of each patch to be installed. The specific acquisition process is as follows:

[0071] Based on the basic information of each patch to be installed corresponding to the target computer system, obtain the applicable component ratio, user environment matching degree, and historical applicability score of each patch to be installed, and then calculate the applicability scope score of each patch to be installed α1 j , α2 j , α3 j respectively represent the applicable component ratio, user environment matching degree, and historical applicability score of the j - th patch to be installed;

[0072] Among them, the ratio of applicable components refers to the ratio of the number of components applicable to a patch in the target computer system to the total number of components. Specifically, it measures the proportion of components in the system to which the patch can be effectively applied. This ratio can help evaluate the wide applicability of the patch;

[0073] For example:

[0074] If a patch is applicable to all components in the target computer system, the ratio of applicable components is 1;

[0075] If it is only applicable to half of the components, the ratio is 0.5.

[0076] A high proportion means that the patch has wide applicability in the system. Wide applicability means that the patch can operate effectively in more system environments, reducing the risk of incompatibility. By measuring the proportion of applicable components, the coverage of the patch can be quantified to ensure that it does not cause compatibility issues in the target system.

[0077] The user environment matching degree is used to measure the degree of match between the patch and the user's specific environment. It takes into account the user's operating system version, configuration, and usage habits. Different user environments may vary, and the patch needs to adapt to these differences to function effectively. A patch with a high matching degree can reduce the need for adjustments during implementation. By evaluating the user environment matching degree, it can be ensured that the patch runs well in the user's specific environment, thereby reducing installation failures or functional abnormalities caused by environmental differences.

[0078] The historical applicability evaluation is based on historical data to assess the success rate of the patch application in similar systems. Historical data provides information on the reliability and stability of the patch in actual applications. The historical applicability evaluation can obtain data from previous patch deployments to understand its performance in different environments. By analyzing historical data, the performance of the patch in the current system can be predicted, helping decision-makers judge its applicability and potential risks.

[0079] The first term of the above formula is used to calculate the combined effect of the applicable component proportion and the user environment matching degree, smoothing the influence of extreme values and ensuring the stability of the score. The second term is used to handle the historical applicability evaluation, emphasizing the gain of a higher historical applicability to the score while avoiding overly linear growth of the score; by combining multiple dimensions, the formula can provide a comprehensive assessment of the patch's applicability scope. This multi-dimensional analysis helps identify potential problems and ensure the effectiveness and security of the patch.

[0080] Based on the basic information of each patch to be installed corresponding to the target computer system, obtain the proportion of satisfied dependencies, the dependency complexity index, and the historical dependency resolution success rate corresponding to each patch to be installed, and denote them as α4 j 、α5 j 、α6 j ,and then calculate the dependency score of each patch to be installed

[0081]

[0082] The proportion of satisfied dependencies refers to the proportion of satisfied dependency relationships in the total dependency relationships before installing the patch. By analyzing the dependency list of the patch, using a package management tool to check the components or software packages installed in the system and match them with the dependency list, calculate the ratio of the number of satisfied dependencies to the total number of dependencies, and use the calculation result as the proportion of satisfied dependencies corresponding to each patch to be installed;

[0083] The dependency complexity index represents the complexity of the dependency relationships of patches. The higher the complexity, the more and deeper the dependency relationships are. Use a dependency parsing tool to generate a dependency graph, calculate the depth (the longest path) and breadth (the maximum number of branches) of the graph, and then calculate the dependency complexity index of each patch to be installed through the complexity formula: log({depth} * {breadth});

[0084] The historical dependency resolution success rate refers to the proportion of successfully resolved dependency relationships during past patch installations. Historical installation records can be extracted from system logs or patch management tools, and the ratio of the number of successfully installed patches to the number of patches attempted to be installed is statistically calculated, and the calculation result is used as the historical dependency resolution success rate of each patch to be installed.

[0085] Based on the basic information of each patch to be installed corresponding to the target computer system, extract the verification credibility, source credibility, and historical security records corresponding to each patch to be installed, and record them as α7 j 、α8 j 、α9 j and then calculate the security source score of each patch to be installed

[0086]

[0087] α7 j This parameter measures the strictness of the verification process that the patch has undergone. High credibility means that the patch has gone through a strict testing and certification process, reducing the risk of malware or backdoor programs. The reason for choosing this parameter is that the verification process is a key step in ensuring patch security. In reality, many security vulnerabilities are introduced due to lack of sufficient verification.

[0088] α8 j This parameter evaluates the reliability of the patch source. A trusted source usually refers to the official release channel or a certified third party. This parameter is chosen because the source of the patch directly affects its security. In reality, many attackers use untrusted channels to spread malicious patches, so source credibility is an important security indicator.

[0089] α9 j This parameter reflects the past security performance of the source. The historical record is chosen as a parameter because history is often one of the best predictors of future performance. A source with a good past security record usually means it will maintain stable security in the future.

[0090] The above calculation formula adopts a non - linear combination method to capture the complex relationships between various factors. By using the cube - root function and exponential function, the formula can adapt to the variation ranges of different factors and avoid biases that may be caused by simple linear weighting;

[0091] In the above calculation formula, the denominator of the fraction is used to represent the impact of smoothing the historical security record, preventing the extreme impact of too low or too high historical scores on the final score;

[0092] The introduction of the second term in the above calculation formula increases the sensitivity to the verification credibility. Especially when the verification is close to the extreme values (0 or 1), it can more significantly reflect its impact on security.

[0093] Among them, from α1 j to α9 j The value ranges of these nine parameters are all between 0 and 1.

[0094] Step S2: Make a judgment based on the security evaluation coefficients of each patch to be installed. If the judgment passes, continue to execute the method steps; otherwise, screen for alternative patches.

[0095] Compare the security evaluation coefficients of each patch to be installed with the set patch security threshold coefficient. If the security evaluation coefficient of a certain patch to be installed is less than the set patch security threshold coefficient, it is determined that there is a security risk for this patch to be installed, and screen for alternative patches. The specific screening process is as follows:

[0096] The target computer system will retrieve other patch versions similar or identical in function to the patch to be installed from the patch database. These alternative patches need to undergo the same security evaluation to ensure that their security evaluation coefficients are higher than the set threshold. Then, the system will sort the screened alternative patches according to factors such as the release time of the patch, the developer's reputation, user feedback, and compatibility with the existing system. Priority is given to those patch versions that are relatively new and have a high user evaluation. In addition, the system will also consider the applicability and stability of the patch to ensure that the alternative patch will not have a negative impact on the normal operation of the system after installation. After this series of screening and evaluation, an optimal alternative patch is finally determined for installation to replace the original patch with security risks, thereby ensuring the overall security and stability of the system.

[0097] Step S3: By collecting multi-dimensional data of the target computer system, generate a virtual copy that is synchronized in real time with the target computer system in an isolated environment; install each patch to be installed in the original target computer system in the isolated environment, and run the core functional modules of the target computer system in the isolated environment, and then verify the compatibility evaluation coefficients of each patch to be installed in the isolated environment;

[0098] According to a preferred implementation, verify the compatibility evaluation coefficients of each patch to be installed in the isolated environment. The specific verification logic is as follows:

[0099] In the virtual environment, perform installation tests on each patch to be installed in turn. The specific installation test steps are as follows:

[0100] Step 1: Install each patch to be installed one by one in the virtual copy, and strictly monitor the core function modules of the system during the installation process to collect the performance index parameters of each patch to be installed on each core function module;

[0101] Step 2: After completing the collection of all index parameters of the current patch to be installed, the virtual copy will adopt a transaction rollback strategy. The core of this strategy is to ensure that each test is carried out in a clean system state to avoid the interference of the previous patch on subsequent tests. Through the rollback strategy, all installation traces left by the current patch in the virtual environment are cleared to ensure that the system returns to the initial state; this is a crucial step because it ensures that the test results of each patch are independent and not affected by other patches;

[0102] Step 3: After the rollback is completed and it is confirmed that the system state has been restored, the virtual copy continues to install and test the next patch to be installed;

[0103] Such a test process not only improves the accuracy and reliability of patch testing but also provides detailed data support for subsequent patch compatibility analysis. Through this systematic testing and rollback mechanism, we can comprehensively evaluate the impact of each patch on the core function modules of the system, thereby ensuring that the stability and security of the system will not be threatened by any potential risks during actual deployment. Such a methodology provides us with a scientific patch management strategy to ensure that the stability and security of the system are always guaranteed throughout the patch management life cycle;

[0104] Select any patch to be installed from the above installation test steps as the target patch;

[0105] Obtain the number M of the core function modules of the target computer system, and sequentially number each core function module in the target computer system as 1, 2,... m,... M;

[0106] Obtain the performance index evaluation coefficient of the target patch on the m-th core function module in the isolation environment and the performance index evaluation coefficient of the m-th core function module in the actual operating environment

[0107] Collect the performance index parameters of the target patch on each corresponding core function module in the isolation environment, where the performance index parameters include the response time XY m , resource utilization rate ZY m and load handling capacity FY m ; further calculate the performance index evaluation coefficient of the target patch on the m-th core function module in the isolation environment

[0108]

[0109] And analyze to obtain the function integrity evaluation factor F of each core function module of the target patch in the isolation environment m , and thus comprehensively analyze to obtain the compatibility evaluation coefficient of the target patch in the isolation environment

[0110]

[0111] Similarly calculate the compatibility evaluation coefficient C of each patch to be installed in the isolation environment according to the calculation method of the compatibility evaluation coefficient of the target patch in the isolation environment j .

[0112] According to a preferred implementation, analyze to obtain the function integrity evaluation factor F of each core function module of the target patch in the isolation environment m , and the specific analysis process is as follows:

[0113] Based on the function modules included in the virtual copy, further detect the successful execution rate β1 of the target patch corresponding to each core function module in the isolation environment m , resource utilization stability rate β2 m and dependency integrity β3 m ;

[0114] Run the functions of each core function module through the automated test suite, calculate the ratio of the number of passed test cases to the total number of test cases, and thus obtain the successful execution rate of each core function module;

[0115] Detect the resource usage situation in the isolation environment through the monitoring module, and then calculate the ratio of the standard deviation to the average value of the resource usage to obtain the resource utilization stability of each core function module;

[0116] Check whether the calls of other modules or external services by the check module in the isolation environment are successful, and then calculate the ratio of the number of successful calls to the total number of calls to obtain the dependency integrity of each core function module;

[0117] Furthermore, define the function integrity evaluation factor F of each core function module of the target patch in the isolation environment m as:

[0118]

[0119] Use β1 in the above calculation formula m ×log(1 + β2 m ) to emphasize the mutual relationship between the successful execution rate and resource stability; use Smoothing processing depends on integrity to reduce the impact of extreme values; the denominator of the above calculation formula is used to adjust the difference between the successful execution rate and integrity, ensuring the balance of the overall evaluation.

[0120] Step S4: Monitor the dynamic running behaviors of each patch to be installed in an isolated environment in real time, and detect the potential behavior threat assessment coefficient for each patch to be installed in the isolated environment;

[0121] According to a preferred implementation, detecting the potential behavior threat assessment coefficient for each patch to be installed in the isolated environment, the specific detection process is as follows:

[0122] Run each patch to be installed in the isolated environment, record all its dynamic behaviors, such as file reading and writing, network requests, registry modifications, etc.; regard each independent dynamic behavior corresponding to each patch to be installed as a node in the behavior graph corresponding to each patch to be installed. If one behavior occurs immediately after another behavior, create a directed edge between these two nodes to represent the transfer relationship of the behaviors; combine all the nodes and edges in the behavior graph corresponding to each patch to be installed, and merge the duplicate behaviors and edges to form a directed behavior graph, representing the behavior sequence of each patch to be installed in the isolated environment;

[0123] Obtain the total number of nodes N of the directed behavior graph corresponding to each patch to be installed, and form a set of other nodes pointing to each node in the directed behavior graph corresponding to each patch to be installed, and denote it as the node set of each node in the directed behavior graph corresponding to each patch to be installed n is the number of each node in the directed behavior graph, n = 1, 2,... N;

[0124] Thus, calculate the PageRank value of each node in the directed behavior graph corresponding to each patch to be installed, where d is the damping factor, usually set to 0.85, represents the c-th other node that has a connection relationship with the n-th node in the directed behavior graph, and c is the index number of each other node; represents the PageRank value of the c-th other node that has a connection relationship with the n-th node in the directed behavior graph corresponding to the j-th patch to be installed, represents the out-degree of the c-th other node that has a connection relationship with the n-th node in the directed behavior graph corresponding to the j-th patch to be installed;

[0125] Furthermore, calculate the information entropy of the directed behavior graph corresponding to the j-th patch to be installed where is the probability of the n-th node in the directed behavior graph corresponding to the j-th patch to be installed;

[0126] Finally, calculate the potential behavior threat assessment coefficient for each patch to be installed in the isolated environment

[0127]

[0128] Step S5: Based on the compatibility evaluation coefficients and potential behavior threat evaluation coefficients of each patch to be installed in the isolated environment, comprehensively judge the available coefficients of each patch to be installed in the actual operating environment of the target computer system, and perform corresponding operations on each patch to be installed based on this.

[0129] According to a preferred embodiment, the specific operation logic in Step S5 is as follows:

[0130] Based on the compatibility evaluation coefficients and potential behavior threat evaluation coefficients of each patch to be installed in the isolated environment, and then comprehensively judge the available coefficient U of each patch to be installed in the actual operating environment of the target computer system j = ω1×C j + ω2×(1 - H j ), where ω1 and ω2 respectively represent the weight factors corresponding to the compatibility evaluation coefficient and the potential behavior threat evaluation coefficient, and satisfy ω1 > ω2 and ω1 + ω2 = 1;

[0131] Compare the available coefficient of each patch to be installed in the actual operating environment of the target computer system with the set comprehensive operation threshold coefficient of the patch. If the available coefficient of a certain patch to be installed in the actual operating environment of the target computer system is less than the set comprehensive operation threshold coefficient of the patch, it is determined that there is a compatibility risk for this patch to be installed, and another alternative patch is screened; if the available coefficient of a certain patch to be installed in the actual operating environment of the target computer system is greater than or equal to the set comprehensive operation threshold coefficient of the patch, it is determined that there is no compatibility risk for this patch to be installed, and it is applied to the target computer system.

[0132] Embodiment 2

[0133] Please refer to Figure 2 as shown. A computer system, which includes a patch security evaluation module, a security evaluation judgment module, a virtual copy evaluation module, a patch real-time analysis module, and a patch processing analysis module. The above-mentioned modules are connected by wired and / or wireless connection methods to achieve data transmission between each module;

[0134] Patch security evaluation module: Obtain the basic information of each patch to be installed corresponding to the target computer system, and preliminarily analyze to obtain the security evaluation coefficients of each patch to be installed;

[0135] Security evaluation judgment module: Connected to the patch security evaluation module, judge based on the security evaluation coefficients of each patch to be installed. If the judgment passes, continue to execute the method steps; otherwise, screen another alternative patch;

[0136] Virtual copy evaluation module: By collecting multi-dimensional data of the target computer system, generate a virtual copy in an isolated environment that is synchronized in real time with the target computer system; install each patch to be installed in the original target computer system in the isolated environment, and run the core function modules of the target computer system in the isolated environment, and then verify the compatibility evaluation coefficient of each patch to be installed in the isolated environment.

[0137] Patch real-time analysis module: Monitor the dynamic running behavior of each patch to be installed in real time in the isolated environment, and detect the potential behavior threat evaluation coefficient of each patch to be installed in the isolated environment.

[0138] Patch processing and analysis module: Based on the compatibility evaluation coefficient and potential behavior threat evaluation coefficient of each patch to be installed in the isolated environment, comprehensively judge the available coefficient of each patch to be installed in the actual running environment of the target computer system, and perform corresponding operations on each patch to be installed based on this.

[0139] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0140] As described above, this is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claimed rights.

[0141] Finally: The above description is only the preferred embodiment of the present invention and is not used to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A computer system maintenance method, characterized in that: The steps include: Step S1, obtaining basic information of each patch to be installed corresponding to the target computer system, and performing preliminary analysis to obtain a security assessment coefficient of each patch to be installed; Step S2: make a judgment based on the security assessment coefficient of each patch to be installed. If the judgment is passed, continue to execute the method steps. Otherwise, select another alternative patch. Step S3, by collecting multi-dimensional data of the target computer system, generating a virtual copy synchronized with the target computer system in real time in the isolated environment; and installing each patch to be installed in the original target computer system in the isolated environment, and running the core functional modules of the target computer system in the isolated environment, thereby verifying the compatibility evaluation coefficient of each patch to be installed in the isolated environment; Step S4: real-time monitoring of the dynamic operation behavior of each patch to be installed in the isolated environment, and detecting the potential behavior threat assessment coefficient of each patch to be installed in the isolated environment; Step S5: Based on the compatibility assessment coefficient and potential behavior threat assessment coefficient of each patch to be installed in the isolated environment, comprehensively determine the availability coefficient of each patch to be installed in the actual operating environment of the target computer system, and perform corresponding operations on each patch to be installed based on the availability coefficient.

2. The computer system maintenance method according to claim 1, characterized in that: The security assessment coefficient of each patch to be installed is obtained through analysis. The specific analysis process is as follows: Based on the basic information of each patch to be installed corresponding to the target computer system, the applicability score, dependency score and security source score of each patch to be installed are analyzed and marked as P1 respectively. j 、P2 j 、P3 j , j is the number of each patch to be installed; The security assessment coefficient of each patch to be installed is calculated comprehensively e is a natural constant.

3. The computer system maintenance method according to claim 2, characterized in that: Get the applicability score, dependency score, and security source score of each patch to be installed. The specific acquisition process is as follows: Based on the basic information of each patch to be installed corresponding to the target computer system, obtain the applicable component ratio, user environment matching degree and historical applicability score of each patch to be installed, and then calculate the applicability score of each patch to be installed α1 j , α2 j , α3 j They are respectively represented as the applicable component ratio, user environment matching degree and historical applicability score of the jth patch to be installed; Based on the basic information of each patch to be installed corresponding to the target computer system, the proportion of satisfied dependencies, dependency complexity index and historical dependency resolution success rate of each patch to be installed are obtained, which are recorded as α4 j , α5 j , α6 j , and then calculate the dependency score of each patch to be installed Based on the basic information of each patch to be installed corresponding to the target computer system, the verification credibility, source credibility and historical security record of each patch to be installed are extracted and recorded as α7 j 、α8 j 、α9 j , and then calculate the security source score of each patch to be installed 4. The computer system maintenance method according to claim 1, characterized in that: Verify the compatibility assessment coefficient of each patch to be installed in the isolated environment. The specific verification logic is as follows: In the virtual environment, perform installation tests on each patch to be installed in turn. The specific installation test steps are as follows: Step 1: Install each patch to be installed one by one in the virtual copy, and strictly monitor the core functional modules of the system during the installation process, and collect performance indicator parameters of each patch to be installed on each core functional module; Step 2: After collecting all the indicator parameters of the patch to be installed, the virtual copy uses the transaction rollback strategy to clear all installation traces left by the current patch in the virtual environment, ensuring that the system is restored to its initial state. Step 3: After the rollback is completed and the system status is confirmed to have been restored, the virtual copy continues to install and test the next patch to be installed; Randomly select a patch to be installed from the above installation test steps as a target patch; Obtain the number M of core function modules of the target computer system, and number the core function modules in the target computer system in sequence as 1, 2, ...m, ...M; Get the performance index evaluation coefficient of the mth core functional module of the target patch in the isolated environment And the performance index evaluation coefficient of the mth core functional module in the actual operating environment And analyze and obtain the functional integrity evaluation factor F of each core functional module of the target patch in the isolated environment m , and the compatibility evaluation coefficient of the target patch in the isolated environment is obtained through comprehensive analysis According to the calculation method of the compatibility evaluation coefficient of the target patch in the isolated environment, the compatibility evaluation coefficient C of each patch to be installed in the isolated environment is calculated in the same way. j .

5. The computer system maintenance method according to claim 4, characterized in that: The functional integrity evaluation factor F of each core functional module of the target patch in the isolated environment is obtained by analysis. m , the specific analysis process is as follows: According to the functional modules included in the virtual copy, the successful execution rate of the target patch corresponding to each core functional module in the isolated environment is detected β1 m , Resource utilization stability rate β2 m and dependency integrity β3 m ; Then define the functional integrity evaluation factor F of each core functional module of the target patch in the isolated environment m for:

6. The computer system maintenance method according to claim 1, characterized in that: Detect the potential behavior threat assessment coefficient of each patch to be installed in an isolated environment. The specific detection process is as follows: Run each patch to be installed in an isolated environment, record all its dynamic behaviors, and use each independent dynamic behavior corresponding to each patch to be installed as a node in the behavior graph corresponding to each patch to be installed. If one behavior occurs immediately after another behavior, create a directed edge between the two nodes to indicate the transfer relationship of the behaviors. Combine all nodes and edges in the behavior graph corresponding to each patch to be installed, and merge repeated behaviors and edges to form a behavior directed graph, which represents the behavior sequence of each patch to be installed in the isolated environment; Obtain the total number of nodes N of the directed graph corresponding to each patch to be installed, and form a set of other nodes pointing to each node in the directed graph corresponding to each patch to be installed, and record it as the node set of each node in the directed graph corresponding to each patch to be installed n is the number of each node in the behavior directed graph, n = 1, 2, ... N; The PageRank value of each node in the directed graph corresponding to each patch to be installed is calculated. Where d is the damping coefficient, usually set to 0.85, Indicates the cth other node that is connected to the nth node in the behavior directed graph, where c is the index number of each other node; Indicates the PageRank value of the cth node in the directed graph corresponding to the jth patch to be installed that is connected to the nth node. Indicates the out-degree of the cth other node in the directed graph corresponding to the behavior of the jth patch to be installed that is connected to the nth node; Then calculate the information entropy of the directed graph of the behavior corresponding to the jth patch to be installed in is the probability of the nth node in the directed graph of behaviors corresponding to the jth patch to be installed; Finally, calculate the potential behavior threat assessment coefficient of each patch to be installed in the isolated environment 7. The computer system maintenance method according to claim 1, characterized in that: The specific operation logic in step S5 is as follows: Based on the compatibility evaluation coefficient and potential behavior threat evaluation coefficient of each patch to be installed in the isolated environment, the availability coefficient U of each patch to be installed in the actual operating environment of the target computer system is comprehensively judged. j =ω1×C j +ω2×(1-H j ), ω1 and ω2 represent the weight factors corresponding to the compatibility assessment coefficient and the potential behavior threat assessment coefficient, respectively, where ω1>ω2 and ω1+ω2=1; The availability coefficient of each patch to be installed in the actual operating environment of the target computer system is compared with the set patch comprehensive operation threshold coefficient. If the availability coefficient of a patch to be installed in the actual operating environment of the target computer system is less than the set patch comprehensive operation threshold coefficient, it is determined that the patch to be installed has a compatibility risk, and an alternative patch is screened.

8. A computer system, characterized in that: The computer system maintenance method according to any one of claims 1 to 7 is implemented and includes the following modules: Patch security assessment module: obtains the basic information of each patch to be installed corresponding to the target computer system, and obtains the security assessment coefficient of each patch to be installed through preliminary analysis; Security assessment judgment module: connected to the patch security assessment module, based on the security assessment coefficient of each patch to be installed, the method steps are continued if the judgment is passed, otherwise, alternative patches are selected; Virtual copy evaluation module: by collecting multi-dimensional data of the target computer system, a virtual copy that is synchronized with the target computer system in real time is generated in an isolated environment; and each patch to be installed in the original target computer system is installed in the isolated environment, and the core functional modules of the target computer system are run in the isolated environment, thereby verifying the compatibility evaluation coefficient of each patch to be installed in the isolated environment; Patch real-time analysis module: monitors the dynamic operation behavior of each patch to be installed in real time in an isolated environment, and detects the potential behavior threat assessment coefficient of each patch to be installed in the isolated environment; Patch processing analysis module: Based on the compatibility assessment coefficient and potential behavior threat assessment coefficient of each patch to be installed in the isolated environment, the availability coefficient of each patch to be installed in the actual operating environment of the target computer system is comprehensively judged, and corresponding operations are performed on each patch to be installed based on it.

Citation Information

Cited By

  • Software patch security execution method and system based on container isolation

    CN120654229A

  • A software patch security execution method and system based on container isolation

    CN120654229B