Security protection system, method, device, equipment, storage medium and program product

By detecting the host's login behavior information in the server and creating an automatic encryption plan, the problem of poor brute-force attack protection in the existing technology is solved, and more efficient host security protection is achieved.

CN120200767APending Publication Date: 2025-06-24HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311782118.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-21
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In the face of brute-force cracking attacks, the protection effect is poor by blocking the source IP address, especially when the attacker uses a proxy IP.

Method used

By obtaining the host's login behavior information in the server, detecting whether there is a password cracking behavior, and when the cracking behavior is detected, an automatic encryption plan is created through the bastion machine, and the host's password is periodically modified.

Benefits of technology

It effectively reduces the probability of password being cracked, improves the security of the host, and enhances the security protection ability of the server to the host and the management and control capabilities of the bastion machine to the host.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200767A_ABST
    Figure CN120200767A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a security protection system, method, device and equipment, a storage medium and a program product, the system comprises a host, a server and a bastion host, the server is used for acquiring login behavior information of the host, and the login behavior information is used for indicating a behavior of logging in the host through a password; detecting whether a password cracking behavior for the host exists or not according to the login behavior information of the host; if the password cracking behavior is detected, creating an automatic password changing plan of the host through the bastion host; wherein the automatic password changing plan is used for changing the password of the host; and the bastion host is used for modifying the password of the host according to the automatic password modification plan. According to the embodiment of the invention, the password cracking behavior for the host can be detected in time, and the bastion host is called to automatically change the password, so that the probability of cracking the password by an attacker is effectively reduced, and the security of the host is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a security protection system, method, device, equipment, storage medium, and program product. Background Art

[0002] Password is one of the most commonly used authentication methods for hosts. How to prevent passwords from being cracked by malicious attackers using brute force is a key concern in the field of security products.

[0003] In the face of brute force cracking, existing security products will protect by restricting the number of attempts and blocking the source IP (Internet Protocol) address when the number of attempts is excessive. However, when an attacker uses a proxy IP to attack a host, the attack source will change frequently, and the effect of protecting by blocking the source IP is not good.

[0004] Therefore, there is an urgent need for a method to protect the security of a host, improve the protection effect against brute force cracking, and enhance the security of the host. Summary of the Invention

[0005] This application provides a security protection system, method, device, equipment, storage medium, and program product to enhance the security of the host.

[0006] In a first aspect, an embodiment of this application provides a security protection system, including: a host, a server, and a bastion host.

[0007] The server is configured to obtain the login behavior information of the host, where the login behavior information is used to indicate the behavior of logging in to the host through a password; detect whether there is a password cracking behavior against the host according to the login behavior information of the host; if a password cracking behavior is detected, create an automatic password modification plan for the host through the bastion host; where the automatic password modification plan is used to modify the password of the host.

[0008] The bastion host is configured to modify the password of the host according to the automatic password modification plan.

[0009] Optionally, a client is deployed on the host, and the client is configured to collect the network logs of the host and report them to the server, and the network logs include the login behavior information.

[0010] The server is deployed with the server, and the server is configured to detect whether there is a password cracking behavior against the host according to the network logs collected by the client of the host.

[0011] Optionally, communication between the host and the server is implemented through a network-side device.

[0012] The network-side device is used to collect the login behavior information of the host and send it to the server;

[0013] The server is specifically used to detect whether there is a password cracking behavior against the host according to the login behavior information sent by the network-side device.

[0014] Optionally, when the server detects whether there is a password cracking behavior against the host according to the login behavior information of the host, it is specifically used for:

[0015] If it is detected according to the login behavior information that the behavior of logging in to the host appears continuously for a preset number of times within a preset time and all logins fail, it is confirmed that there is a password cracking behavior against the host.

[0016] Optionally, the automatic password modification plan is specifically used to periodically modify the password of the host. When the server creates the automatic password modification plan of the host through the bastion host, it is specifically used for:

[0017] Determine whether the password has been cracked according to the login behavior information; determine the password modification period and / or the security level of the modified password of the automatic password modification plan according to whether the password has been cracked; or,

[0018] Judge whether there is already an automatic password modification plan for the host; if not, create the automatic password modification plan for the host through the bastion host; if so, modify the password modification period and / or the security level of the modified password of the automatic password modification plan.

[0019] Optionally, the automatic password modification plan is specifically used to periodically modify the password of the host, and the server is also used for:

[0020] After creating the automatic password modification plan, if no password cracking behavior is detected within a preset time period, delete the automatic password modification plan through the bastion host.

[0021] In a second aspect, an embodiment of the present application provides a security protection method, which is applied to a server. The method includes:

[0022] Obtain the login behavior information of the host; wherein, the login behavior information is used to indicate the behavior of logging in to the host through a password;

[0023] Detect whether there is a password cracking behavior against the host according to the login behavior information of the host;

[0024] If a password cracking behavior against the host is detected, create an automatic password modification plan for the host through the bastion host, so that the bastion host modifies the password of the host according to the automatic password modification plan;

[0025] Among them, the automatic password change plan is used to modify the password of the host.

[0026] Optionally, a client is deployed on the host, and a server is deployed on the server; obtaining the login behavior information of the host, including:

[0027] Obtaining the network log of the host collected by the client through the server, where the network log includes the login behavior information.

[0028] Optionally, communication between the host and the server is achieved through a network-side device; obtaining the login behavior information of the host, including:

[0029] Obtaining the login behavior information of the host collected by the network-side device.

[0030] Optionally, according to the login behavior information of the host, detecting whether there is a password cracking behavior against the host, including:

[0031] If, according to the login behavior information, it is detected that the behavior of logging in to the host appears continuously a preset number of times within a preset time and all logins fail, it is confirmed that there is a password cracking behavior against the host.

[0032] Optionally, the automatic password change plan is specifically used to periodically modify the password of the host. Creating the automatic password change plan of the host through a bastion host includes:

[0033] Determining whether the password has been cracked according to the login behavior information; determining the password change period and / or the security level of the modified password of the automatic password change plan according to whether the password has been cracked; or,

[0034] Judging whether there is already an automatic password change plan for the host; if not, creating the automatic password change plan of the host through the bastion host; if so, modifying the password change period and / or the security level of the modified password of the automatic password change plan.

[0035] Optionally, the automatic password change plan is specifically used to periodically modify the password of the host, and the method further includes:

[0036] After creating the automatic password change plan, if no password cracking behavior is detected within a preset time period, deleting the automatic password change plan through the bastion host.

[0037] In a third aspect, an embodiment of the present application provides a security protection device, including:

[0038] An obtaining module, configured to obtain the login behavior information of the host; among them, the login behavior information is used to indicate the behavior of logging in to the host through a password;

[0039] A detection module, configured to detect whether there is a password cracking behavior against the host according to the login behavior information of the host;

[0040] A creation module, configured to create an automatic password change plan for the host through a bastion host when detecting a password cracking behavior against the host, so that the bastion host modifies the password of the host according to the automatic password change plan;

[0041] Wherein, the automatic password change plan is used to modify the password of the host.

[0042] In a fourth aspect, an embodiment of the present application provides an electronic device, including:

[0043] At least one processor; and

[0044] A memory communicatively connected to the at least one processor;

[0045] Wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the electronic device to execute the method described in the second aspect.

[0046] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the processor executes the computer-executable instructions, the method described in the second aspect is implemented.

[0047] In a sixth aspect, an embodiment of the present application provides a computer program product, including a computer program, and when the computer program is executed by a processor, the method described in the second aspect is implemented.

[0048] The security protection system, method, device, equipment, storage medium and program product provided by the embodiments of the present application include: a host, a server and a bastion host. The server is configured to obtain the login behavior information of the host, wherein the login behavior information is used to indicate the behavior of logging in to the host through a password; detect whether there is a password cracking behavior against the host according to the login behavior information of the host; if a password cracking behavior is detected, create an automatic password change plan for the host through the bastion host; wherein, the automatic password change plan is used to modify the password of the host; the bastion host is configured to modify the password of the host according to the automatic password change plan. The embodiments of the present application can timely detect the password cracking behavior against the host, and call the bastion host to perform automatic password change, effectively reducing the probability of the password being cracked and improving the security of the host. Moreover, the embodiments of the present application realize the security protection of the host through the risk identification function of the server and the management and control function of the bastion host, and also improve the security protection ability of the server for the host and the management and control ability of the bastion host for the host, improve the overall resource management performance of the system, provide a higher level of protection ability for users, and improve the asset security of users. Brief Description of the Drawings

[0049] The drawings herein are incorporated into and form a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.

[0050] Figure 1 A schematic diagram of an application scenario provided for an embodiment of the present application;

[0051] Figure 2 A schematic diagram of a security protection system provided for an embodiment of the present application;

[0052] Figure 3 Another schematic diagram of a security protection system provided for an embodiment of the present application;

[0053] Figure 4 A schematic diagram of a client interaction interface provided for an embodiment of the present application;

[0054] Figure 5 A schematic flowchart of a security protection method provided for an embodiment of the present application;

[0055] Figure 6 A schematic structural diagram of a security protection device provided for an embodiment of the present application;

[0056] Figure 7 A schematic structural diagram of an electronic device provided for an embodiment of the present application.

[0057] Through the above drawings, specific embodiments of the present application have been shown, and there will be more detailed descriptions hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present application in any way, but to illustrate the concept of the present application to those skilled in the art by referring to specific embodiments. Detailed Description of Specific Embodiments

[0058] Exemplary embodiments will be described in detail herein, and examples thereof are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0059] It should be noted that the user information (including but not limited to user device information, user attribute information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with relevant laws, regulations, and standards, and corresponding operation entrances are provided for users to choose to authorize or reject.

[0060] First, the nouns involved in this application are explained as follows:

[0061] Brute-force cracking: Brute-force cracking is an attack method that attempts to obtain a password or key. By trying a large number of possible combinations and guessing the password one by one until the correct password is found, hackers generally use brute-force cracking means such as exhaustive attacks, dictionary attacks, and rainbow table attacks.

[0062] Automatic regular password change: Automatically and periodically modify and back up the host account password to reduce or eliminate weak passwords, meeting the requirements of hierarchical protection.

[0063] Jump server: A kind of operation and maintenance and security audit management platform that can collect and monitor the status of each host in the cluster in real time for centralized alarm, timely processing, and audit responsibility determination. In the embodiments of this application, the password change service provided by the jump server can be used to improve the security of the host.

[0064] This application can be applied to any scenario that requires improving the host protection effect. For example, it can be applied to protect a single host or the hosts in a cluster.

[0065] Figure 1 This is a schematic diagram of an application scenario provided by the embodiments of this application. As Figure 1 shown, a cluster can be deployed in the user's local computer room. The cluster includes multiple hosts, and the hosts are used to process tasks in the user's industry. A jump server and a server can be deployed in the cloud. The server can be used to communicate with the hosts to prevent and control the security of the hosts, and the jump server can be used to implement operations such as management and audit of host tasks.

[0066] Specifically, the server can be deployed with a host security service, which can provide basic security protection capabilities for the hosts, such as risk identification, vulnerability protection, sensitive data protection, cloud firewall, etc.

[0067] The bastion host can serve as an intermediate medium for users to control hosts. After a user logs in to the bastion host, the user can manage host assets through the bastion host. For example, add or delete hosts, set access permissions for hosts, etc. Different users can have different access permissions to host resources. Through the bastion host, operations executed on the host can also be audited and analyzed, building a perfect resource control system for users, reducing the maintenance work of users, and improving the resource management effect.

[0068] In practical applications, attackers will launch attacks on hosts through brute-force cracking. If the host password is cracked, it will cause immeasurable losses to users.

[0069] To effectively protect the security of users' host resources, the embodiments of the present application provide a security protection system, which can monitor the login behavior of hosts through a server, detect whether there is a brute-force cracking behavior according to the login behavior, and if so, create an automatic password-changing plan for the host through the bastion host. Among them, the automatic password-changing plan can be used for automatic regular password changing, that is, modify the password every preset period.

[0070] Through the security protection system provided by the embodiments of the present application, password cracking behaviors against hosts can be detected in a timely and accurate manner, and the bastion host can be called to perform automatic regular password changing, effectively reducing the probability of attackers cracking passwords and improving host security. Moreover, the embodiments of the present application achieve the security protection of hosts through the risk identification function of the server and the control function of the bastion host, and also improve the security protection ability of the server for hosts and the management and control ability of the bastion host for hosts, improving the overall resource management performance of the system, providing a higher level of protection ability for users, and improving the asset security of users.

[0071] The following will describe in detail some embodiments of the present application with reference to the accompanying drawings. Without conflict between the embodiments, the embodiments and the features in the embodiments can be combined with each other. In addition, the step timings in the following method embodiments are only examples, not strictly limited.

[0072] Figure 2 A schematic diagram of a security protection system provided by an embodiment of the present application is as Figure 2 shown. The system may include: a host, a server, and a bastion host; the server is used to obtain the login behavior information of the host, where the login behavior information is used to indicate the behavior of logging in to the host through a password; detect whether there is a password cracking behavior against the host according to the login behavior information of the host; if a password cracking behavior is detected, create an automatic password-changing plan for the host through the bastion host; where the automatic password-changing plan is used to modify the password of the host.

[0073] Among them, the host can be any host in the cluster or a separately deployed host. Users can log in to the host through a password. Without the password, an attacker may try to log in to the host by brute force.

[0074] The server is used to obtain the login behavior information of the host. The login information can be used to indicate the behavior of a user or an attacker logging in to the host through a password. In this embodiment, the manner in which the server obtains the host login behavior is not limited. It can be that the server obtains the host login behavior information at preset intervals, or the host sends the login behavior information to the server at preset intervals.

[0075] After the server obtains the host login behavior information, it can detect whether there is a password cracking behavior by an attacker against the host based on the host login behavior information. If a password cracking behavior is detected, an automatic password change plan for the host is created through the bastion host. The automatic password change plan is used to modify the password of the host.

[0076] Optionally, the automatic password change plan can be used to modify the password of the host once or multiple times. For example, the automatic password change plan can be specifically used to periodically modify the password of the host, that is, modify the password at preset intervals, further enhancing the security of the host.

[0077] After the password is modified, the modified password can be sent to the user so that the user can log in to the host using the modified password. Optionally, the user can also be allowed to configure one or more devices for accessing the host. After the password is modified, the modified password can also be synchronized to the devices allowed to access the host.

[0078] Optionally, the bastion host can provide an API (Application Programming Interface) for creating an automatic password change plan; when the server creates the automatic password change plan for the host through the bastion host, it can specifically be used to: create the automatic password change plan for the host by calling the API of the bastion host.

[0079] Specifically, the bastion host can modify the password of the host according to the automatic password change plan created by the server. For example, modify the password of the host once a day or once every week, improving the password protection level of the host.

[0080] Optionally, when the automatic password change plan is used to periodically modify the host password, after the automatic password change plan is created, it can be continuously executed or stopped after a period of time. For example, after creating the automatic password change plan, if no password cracking behavior is detected within the preset time period, it is confirmed that the password cracking behavior has stopped, and the automatic password change plan can be deleted through the bastion host. Alternatively, the automatic password change plan can be synchronized to the user, and after the password cracking behavior stops, the user can decide whether to terminate the automatic password change plan and the specific termination time.

[0081] In this way, when the server detects an attack behavior against the host, it indicates that the risk coefficient of the exposed host is very high. An automatic password change plan is created through the bastion host to regularly update the host password, reducing the probability of the password being brute-forced and improving security.

[0082] In an alternative implementation, host security services can be provided for the user's host. The host security services can provide functions for real-time detection, analysis, and identification of security threats, helping users achieve automatic security operation of the host. The host security services can include a client and a server, and brute-force cracking detection is achieved through the network log collection ability of the host security services.

[0083] Specifically, the host is deployed with a client, and the client is used to collect the network logs of the host and report them to the server. The network logs include the login behavior information; the server is deployed with the server, and the server is used to detect whether there is a password cracking behavior against the host according to the network logs collected by the client of the host.

[0084] Among them, the client can collect the network logs of the host, and the network logs contain login behavior information, which can be used to indicate the login time, whether the login is successful, etc. The client can send the network logs to the server in real time or at preset intervals, and this embodiment does not limit this.

[0085] The server can receive the network logs collected by the client on the host and detect whether there is a password cracking behavior against the host according to the received network logs.

[0086] Figure 3 Another schematic diagram of the security protection system provided by the embodiments of the present application. As Figure 3 shown, the system includes a host, a server, and a bastion host. The host and the server can be respectively deployed with a client and a server. The working process of this system can be reflected through the following steps a to e:

[0087] Step a, the attacker brute-forces the host password by means such as brute-force attack, dictionary attack, rainbow table attack, etc.

[0088] Step b: The client installed on the host collects network logs.

[0089] Step c: The client reports the collected network logs to the server-side located on the server.

[0090] Step d: The server-side processes the network logs. After detecting password cracking behavior, it calls the bastion host API to create an automatic password change plan.

[0091] Step e: The bastion host modifies the password of the host according to the automatic password change plan through SSH (Secure Shell Protocol) / RDP (Remote Desktop Protocol). The network logs detail the login behavior for the host. The server determines whether there is password cracking behavior for the host based on the received network logs, which can improve the accuracy of the judgment.

[0092] In an alternative implementation, when the server detects whether there is password cracking behavior for the host according to the login behavior information of the host, it can specifically be used for:

[0093] If, according to the login behavior information, it is detected that there are consecutive preset times of host login behaviors within a preset time and all login attempts fail, it is confirmed that there is password cracking behavior for the host.

[0094] Exemplarily, the preset time is 5 minutes and the preset number of times is 10 times. The server detects, based on the obtained login behavior information, that within 5 minutes, there are 10 consecutive host login behaviors and the result of each login is a failure, then it is confirmed that there is password cracking behavior for the host.

[0095] In this way, by judging whether there is a behavior of consecutive preset times of failed host logins within a preset time to determine whether there is password cracking behavior, the accuracy of the judgment result can be improved and the probability of misjudgment can be reduced.

[0096] In another alternative implementation, when the server detects whether there is password cracking behavior for the host according to the login behavior information of the host, it can specifically be used for:

[0097] If, according to the login behavior information, it is detected that there are consecutive preset times of host login behaviors within a preset time, it is confirmed that there is password cracking behavior for the host.

[0098] Specifically, as long as the behavior of logging in to the host continuously occurs a preset number of times within a preset time, regardless of whether the login is successful or not, it is considered that there is a password cracking behavior against the host. In this way, the security of the host can be further improved. Since users usually do not have a large number of frequent login behaviors in a short period of time, this method can also ensure a certain degree of accuracy.

[0099] Among them, the specific values of the preset time and the preset number of times can be the same as those in the foregoing embodiments, or different. They can be set by the user or default values can be adopted.

[0100] In addition to Figure 3 the method shown above, the embodiments of the present application also provide a solution, which can assist in detecting password cracking behavior through a network-side device.

[0101] Optionally, communication between the host and the server is implemented through a network-side device; the network-side device is used to collect login behavior information of the host and send it to the server; the server is specifically used to detect whether there is a password cracking behavior against the host according to the login behavior information sent by the network-side device.

[0102] Specifically, communication between the host and the server is implemented through a network-side device. The network-side device can be, for example, a switch. The network-side device can obtain the five-tuple data of the host. Among them, the five-tuple data includes: communication protocol, source IP, source port, destination IP, and destination port. The network-side device can identify the login behavior information of the host from the five-tuple data and send the login behavior information of the host to the server. Among them, the login behavior information can be used to indicate the login time, etc.

[0103] The server can detect whether there is a password cracking behavior against the host according to the login behavior information sent by the network-side device. For example, if the behavior of logging in to the host continuously occurs a preset number of times within a preset time, it is confirmed that there is a password cracking behavior against the host.

[0104] Since the login behavior information identified by the network-side device from the five-tuple data generally cannot indicate whether the login is successful, when the server detects that the behavior of logging in to the host continuously occurs a preset number of times within a preset time according to the login behavior information sent by the network-side device, it is confirmed that there is a password cracking behavior against the host. Compared with the method of the server determining whether there is a password cracking behavior according to the network log, when detecting according to the login behavior information sent by the network-side device, the preset number of times set can be less, reducing the duration of the host being successfully brute-forced and in an exposed environment, and improving the security of the host.

[0105] In other alternative implementations, the network-side device may also send the five-tuple data as login behavior information to the server, and the server determines whether there is a password cracking behavior based on the five-tuple data.

[0106] In this way, by collecting the login behavior information of the host by the network-side device and sending it to the server, so that the server determines whether there is a password cracking behavior based on the login behavior information of the host, the burden on the host can be effectively reduced.

[0107] In practical applications, using network logs for detection and using the information sent by the network-side device for detection can be used alternatively or simultaneously. For example, the server can obtain the network logs collected by the host client and the login behavior information collected by the network-side device, and respectively detect the obtained network logs and the login behavior information collected by the network-side device to detect whether there is a password cracking behavior for the host. When the detection result of one of them is that there is a password cracking behavior, the bastion host API is called to create an automatic password modification plan for the host, which can further improve the security of the host.

[0108] Optionally, the server is further configured to: obtain a password modification policy configured by a user, where the password modification policy includes at least one of the following: the preset time, the preset number of times, and the password modification period in the automatic password modification plan.

[0109] Specifically, the user can input the password modification policy through the terminal device. The terminal device can communicate with the server directly or indirectly and send the password modification policy to the server. The password modification policy may include the preset time, the preset number of times, and the password modification period in the automatic password modification plan. Among them, the preset time and the preset number of times are used by the server to detect whether there is a password cracking behavior based on the login behavior information, and the password modification period is the period for periodically modifying the host password.

[0110] The embodiment of the present application also supports configuring different password modification policies for different hosts and modifying the password modification policies. Figure 4 For an interactive interface schematic diagram provided by the embodiment of the present application, as Figure 4 shown, the value corresponding to the parameter item "current preset time" in the password modification policy is 5 minutes, the value corresponding to the parameter item "preset number of times" is 10 times, and the value corresponding to the parameter item "password modification period" is 3 days. The user can input the corresponding values in the input boxes corresponding to the parameter items "modified preset time", "modified preset number of times", and "modified password modification period" according to actual needs. After the input is completed, click the confirmation button, and the terminal device sends the modified password modification policy input by the user to the server.

[0111] In this way, the user can modify the existing password change policy according to requirements. When important data is stored in the host or the host has just been attacked, the preset time can be reduced, the preset number of times can be reduced, or the password change cycle can be shortened to improve the security and flexibility of the host. Optionally, the automatic password change plan is specifically used to periodically modify the password of the host. When the server creates the automatic password change plan for the host through the bastion host, it specifically:

[0112] When determining whether the password has been cracked according to the login behavior information; determining the password change cycle of the automatic password change plan and / or the security level of the modified password according to whether the password has been cracked; or,

[0113] Judging whether there is already an automatic password change plan for the host; if not, creating the automatic password change plan for the host through the bastion host; if so, modifying the password change cycle of the automatic password change plan and / or the security level of the modified password.

[0114] Specifically, the server can first judge whether the attacker has logged in successfully according to the obtained login behavior information, that is, whether it has been continuously logged in failure or the last login is successful. If the login is successful, it is considered that the password has been cracked, and the password change cycle of the automatic password change plan and / or the security level of the modified password can be determined according to whether the login is successful.

[0115] Exemplarily, compared with the attacker continuously logging in failure, the cycle corresponding to the automatic password change plan created by the server when the attacker finally logs in successfully is shorter, and the security level of the modified password is higher. Among them, the security level of the password can be reflected by the complexity of the password. The more complex the password, the higher the corresponding security level.

[0116] The server can also first judge whether there is already an automatic password change plan for the host. If not, it can create an automatic password change plan through the bastion host. If it already exists, it can modify the password change cycle of the automatic password change plan and / or the security level of the modified password.

[0117] Exemplarily, if the server determines that there is already an automatic password change plan for the host, it means that there has been a password cracking behavior of the attacker before. Therefore, after detecting the password cracking behavior again, the security of the host can be further improved, such as shortening the password change cycle of the existing password change plan and increasing the security level of the modified password.

[0118] In this way, according to whether the attacker has logged in successfully or whether there is already an automatic password change plan, the risk level of the current host is determined, and the password change cycle and the security level of the modified password are determined according to the risk level of the host, which can make the level of the modified password or the password change cycle match the current situation better and improve the security factor.

[0119] In one or more embodiments of the present application, optionally, when the server detects whether there is a password cracking behavior against the host according to the login behavior information of the host, in addition to the above-mentioned method (detecting whether there is a behavior of logging in to the host continuously for a preset number of times within a preset time), it can also be implemented by other methods. For example, a trained cracking recognition model can be used for detection, and the specific process is as follows:

[0120] The server inputs the login behavior information of the host into the trained cracking recognition model, and the output information of the trained cracking recognition model is used to indicate whether there is a password cracking behavior against the host.

[0121] Optionally, the specific training process of the cracking recognition model is as follows: Collect normal login behavior information and risky login behavior information. Among them, the risky login behavior information can be the login behavior information (such as network logs) collected when artificially simulating a brute-force cracking of the host, and the normal login behavior information can be the login behavior information collected when the host is not under attack. According to the normal login behavior information and the risky login behavior information, training samples can be constructed respectively. When the training sample is normal login behavior information, the corresponding label is used to indicate that there is no password cracking behavior against the host. When the training sample is risky login behavior information, the corresponding label is used to indicate that there is a password cracking behavior against the host.

[0122] According to the constructed training samples, a neural network model or other deep learning models can be trained to obtain a cracking recognition model.

[0123] Optionally, when constructing the training samples, the risk level of the password cracking behavior can also be added to the label, and the risk level can be determined by indicators such as the cracking method, the probability of the password being cracked, and the time when the password is cracked. Optionally, an attacker can be imitated to initiate a brute-force cracking of the host. Different cracking methods may have different cracking success probabilities and the time spent cracking the password, so different risk levels can be corresponding.

[0124] After training the model with the training samples, the model can also output the corresponding risk level. The server can call the bastion host API to create different automatic password modification plans according to the risk level. The higher the risk level, the shorter the password modification period in the automatic password modification plan, and the higher the complexity of the modified password.

[0125] Optionally, in actual applications, when the risk level output by the cracking recognition model is greater than the preset risk value, the server can also send a high-risk warning for the host to the terminal device, so that after the user receives the high-risk warning for the host through the terminal device, the password modification policy can be reconfigured to improve the security of the host, or important data in the host can be transferred.

[0126] Optionally, in addition to obtaining the password change policy configured by the user, the server can also set a default password change policy. The default password change policy can include an enhanced password change policy and a weakened password change policy. The default password change policy can modify the password change period in the automatic password change plan. For the automatic password change plan modified using the enhanced password change policy, the corresponding password change period is shorter; for the automatic password change plan modified using the weakened password change policy, the corresponding password change period is longer.

[0127] After detecting a password cracking behavior and creating an automatic password change plan, if the host is subsequently detected to meet the preset conditions, the server can use the default password change policy to modify the automatic password change plan.

[0128] In an optional implementation, which default password change policy to adopt can be determined by the situation of the host being attacked. For example, the server can count the number of times the host is attacked within multiple preset time periods. Within each preset time period, if there are preset numbers of login behaviors within the preset time period, it is considered that a password cracking behavior is detected, and detection continues in the next preset time period. Each time a password cracking behavior is detected, the number of times the host is attacked increases by one. After counting multiple preset time periods, if the number of times the host is attacked exceeds the first preset number, the default enhanced password change policy is used to modify the automatic password change plan; if the number of times the host is attacked is less than the second preset number, the default weakened password change policy is used to modify the automatic password change plan.

[0129] In another optional implementation, which default password change policy to adopt can also be jointly determined by the security level of the host and the situation of the host being attacked. The security level of the host can be set by the user. The user can determine the security level of the host according to the functions carried by the host or the importance of the stored data. The security level of the host can be divided into level 1, level 2, and level 3, where level 1 is the weakest and level 3 is the strongest. The user can adjust the security level of the host in real time through the terminal device. After the adjustment is completed, click the confirmation button, and the terminal device sends the security level of the host to the server. The server determines the default password change policy based on the current situation of the host being attacked and the security level of the host.

[0130] Specifically, the enhanced password change policy may include a level 1 enhanced password change policy, a level 2 enhanced password change policy, and a level 3 enhanced password change policy. Among them, the security level of the level 1 enhanced password change policy is relatively the lowest, and the security level of the level 3 enhanced password change policy is relatively the highest. The weakened password change policy may include a level 1 weakened password change policy, a level 2 weakened password change policy, and a level 3 weakened password change policy. Among them, the security level of the level 1 weakened password change policy is relatively the highest, and the security level of the level 3 weakened password change policy is relatively the lowest. Table 1 is a mapping relationship table between the security level of the host and the default password change policy provided by the embodiments of the present application.

[0131] Table 1

[0132]

[0133] The server can count the number of times the host is attacked within multiple preset time periods. If the number of times the host is attacked exceeds the first preset number, the security level of the host can be further determined. If the security level of the host is level 3, it means that the security level of the host is very high. Referring to Table 1, it can be seen that the level 3 enhanced password change policy is adopted. If the security level of the host is level 1, it means that the security level of the host is not high. Referring to Table 1, it can be seen that the level 1 enhanced password change policy is adopted; if the number of times the host is attacked is lower than the second preset number, the security level of the host is further determined. If the security level of the host is level 3, referring to Table 1, it can be seen that the level 1 weakened password change policy is adopted to make the host protection level weakened to a lower level. If the security level of the host is level 1, referring to Table 1, it can be seen that the level 3 weakened password change policy is adopted to make the host protection level weakened to a higher level.

[0134] In another alternative implementation, the default password change policy can also be jointly determined by the industry and the attack situation of the host. The default password change policy can be divided according to the industry. For industries with relatively high security requirements, the security level of the default password change policy is set higher. For industries with relatively low security requirements, the security level of the default password change policy is set lower.

[0135] In this way, by automatically determining the password change policy according to the attack situation, the security level of the host, and the industry, a password change policy with a higher adaptability to the host can be obtained, further improving the security of the host.

[0136] In one or more embodiments of the present application, optionally, the security level of the host may also be adjusted according to the situation of the host being attacked, and data transfer or task reallocation may be performed according to the adjusted security level to improve the overall security of the system. The specific implementation method is as follows: The server counts the number of times the host is attacked within multiple preset time periods, and adjusts the security level of the host according to the number of times the host is attacked. For example, if the number of times the host is attacked is greater than a preset threshold, the security level of the host is adjusted downward. After the adjustment is completed, the server sends the adjusted security level to the terminal device so that the user can perform task reallocation and / or data transfer according to the security levels of different hosts.

[0137] Exemplarily, the security levels of the host are divided into level 1, level 2, and level 3, with level 3 being the highest. The higher the security level of the host, the higher the importance of the data that can be stored, and the higher the level of the tasks that can be assigned. The importance of the data stored in the host and / or the level of the tasks assigned match the current security level of the host. When the security level of the host decreases, the data stored in the host whose importance exceeds the current security level of the host can be transferred to other matching hosts, and / or, the tasks assigned to the host whose security level exceeds the current security level of the host can be assigned to other matching hosts.

[0138] Figure 5 It is a schematic flowchart of a security protection method provided by an embodiment of the present application. The method in this embodiment can be applied to a server. As Figure 5 shown, the method may include:

[0139] Step 501, obtain the login behavior information of the host; wherein, the login behavior information is used to indicate the behavior of logging in to the host through a password.

[0140] Specifically, the server may actively obtain the login behavior of the host, or the host sends the login behavior information to the server. The login behavior information may indicate the behavior of a user or an attacker logging in to the host through a password.

[0141] Optionally, a client is deployed on the host and a server is deployed on the server side. Obtaining the login behavior information of the host includes:

[0142] Obtain the network log of the host collected by the client through the server side, and the network log includes the login behavior information.

[0143] Specifically, a client of the host security service is deployed on the host, and a server side of the host security service is deployed on the server. The client can collect the network log of the host and send it to the server side in the server, and the server side receives the login behavior of the host sent by the client.

[0144] Optionally, communication between the host and the server is achieved through a network-side device, and the login behavior information of the host is obtained, including:

[0145] Obtain the login behavior information of the host collected by the network-side device.

[0146] Specifically, communication between the host and the server is achieved through a network-side device. The network-side device can collect the login behavior information of the host and send it to the server, and the server receives the login behavior information of the host sent by the network-side device.

[0147] Step 502: Detect whether there is a password cracking behavior against the host according to the login behavior information of the host.

[0148] Optionally, detecting whether there is a password cracking behavior by an attacker against the host according to the login behavior information of the host includes:

[0149] If, according to the login behavior information, it is detected that the behavior of logging in to the host appears continuously a preset number of times within a preset time and all logins fail, it is confirmed that there is a password cracking behavior against the host.

[0150] Step 503: If a password cracking behavior against the host is detected, create an automatic password change plan for the host through the bastion host, so that the bastion host modifies the password of the host according to the automatic password change plan.

[0151] Among them, the automatic password change plan is used to modify the password of the host.

[0152] Specifically, if the server detects a password cracking behavior against the host, it creates an automatic password change plan for the host by calling the API of the bastion host. After creating the automatic password change plan, the bastion host can modify the password of the host according to the automatic password change plan.

[0153] Optionally, the automatic password change plan is specifically used to periodically modify the password of the host. Creating the automatic password change plan for the host through the bastion host includes:

[0154] Determine whether the password has been cracked according to the login behavior information; determine the password change period and / or the security level of the modified password of the automatic password change plan according to whether the password has been cracked; or,

[0155] Judge whether there is already an automatic password change plan for the host; if not, create the automatic password change plan for the host through the bastion host; if it exists, modify the password change period and / or the security level of the modified password of the automatic password change plan.

[0156] Optionally, the method may further include:

[0157] After creating an automatic password change plan, if no password cracking behavior is detected within the preset time period, the automatic password change plan is deleted through the bastion host.

[0158] Optionally, the security protection method provided in this application may further include: obtaining a password change policy configured by a user, where the password change policy includes at least one of the following:

[0159] The preset time, the preset number of times, and the password change cycle in the automatic password change plan.

[0160] Specifically, the user can input the password change policy on the host, where the password change policy may include at least one of the preset time, the preset number of times, and the password change cycle in the automatic password change plan. After the user finishes inputting, the user clicks the confirmation button, and the host sends the password change policy input by the user to the server.

[0161] For the security protection method provided in the embodiments of this application, the specific implementation principle and beneficial effects can be referred to the foregoing embodiments, and will not be elaborated here.

[0162] Corresponding to the above security protection method, the embodiments of this application also provide a security protection device. Figure 6 It is a schematic structural diagram of a security protection device provided in the embodiments of this application. The device is applied to a server, as Figure 6 shown, the device includes:

[0163] An obtaining module 601, configured to obtain the login behavior information of the host; where the login behavior information is used to indicate the behavior of logging in to the host through a password;

[0164] A detection module 602, configured to detect whether there is a password cracking behavior against the host according to the login behavior information of the host;

[0165] A creation module 603, configured to create an automatic password change plan for the host through the bastion host when a password cracking behavior against the host is detected, so that the bastion host modifies the password of the host according to the automatic password change plan;

[0166] Wherein, the automatic password change plan is used to modify the password of the host.

[0167] Optionally, a client is deployed on the host, and the client is configured to collect network logs of the host and report them to the server, and the network logs include the login behavior information;

[0168] The server is deployed with the server, and the server includes the obtaining module 601, the detection module 602, and the creation module 603. The detection module 602 is specifically configured to detect whether there is a password cracking behavior against the host according to the network logs collected by the client of the host.

[0169] Optionally, communication between the host and the server is implemented through a network-side device;

[0170] The network-side device is used to collect the login behavior information of the host and send it to the acquisition module 601;

[0171] The detection module 602 is specifically configured to detect whether there is a password cracking behavior against the host according to the login behavior information sent by the network-side device.

[0172] Optionally, the detection module 602 is specifically configured to:

[0173] If, according to the login behavior information, it is detected that the behavior of logging in to the host appears continuously for a preset number of times within a preset time and all logins fail, it is confirmed that there is a password cracking behavior against the host.

[0174] Optionally, the automatic password change plan is specifically used to periodically modify the password of the host. When the creation module 603 creates the automatic password change plan of the host through the bastion host, it is specifically used to:

[0175] Determine whether the password has been cracked according to the login behavior information; determine the password change period and / or the security level of the modified password of the automatic password change plan according to whether the password has been cracked; or,

[0176] Judge whether there is already an automatic password change plan for the host; if not, create the automatic password change plan of the host through the bastion host; if so, modify the password change period and / or the security level of the modified password of the automatic password change plan.

[0177] Optionally, the creation module 603 is further used to:

[0178] After creating the automatic password change plan, if no password cracking behavior is detected within a preset time period, delete the automatic password change plan through the bastion host.

[0179] Optionally, the creation module 603 is further used to:

[0180] Obtain the password change policy configured by the user, and the password change policy includes at least one of the following:

[0181] The preset time, the preset number of times, and the password change period in the automatic password change plan.

[0182] Each device provided in the embodiments of the present application is used to execute the corresponding method embodiments described above. The specific implementation principles and beneficial effects can be seen in the foregoing embodiments and will not be elaborated here.

[0183] Figure 7The structural schematic diagram of an electronic device provided by an embodiment of the present application. As Figure 7 shown, the electronic device of this embodiment may include:

[0184] At least one processor 701; and

[0185] A memory 702 communicatively connected to the at least one processor;

[0186] Wherein, the memory 702 stores instructions executable by the at least one processor 701, and the instructions are executed by the at least one processor 701 to cause the electronic device to execute the method described in any of the foregoing embodiments.

[0187] Optionally, the memory 702 can be either independent or integrated with the processor 701.

[0188] The implementation principle and technical effects of the electronic device provided by this embodiment can be referred to the foregoing embodiments, and will not be elaborated here.

[0189] An embodiment of the present application also provides a computer-readable storage medium, in which computer-executable instructions are stored. When the processor executes the computer-executable instructions, the method described in any of the foregoing embodiments is implemented.

[0190] An embodiment of the present application also provides a computer program product, including a computer program, which implements the method described in any of the foregoing embodiments when executed by a processor.

[0191] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation. For example, multiple modules can be combined or integrated into another system, or some features can be ignored or not executed.

[0192] The integrated modules implemented in the form of software function modules as described above can be stored in a computer-readable storage medium. The above software function modules are stored in a storage medium, including several instructions to cause a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute some steps of the methods described in various embodiments of the present application.

[0193] It should be understood that the above-mentioned processor can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), etc. The general-purpose processor can be a microprocessor or any conventional processor, etc. The steps of the method disclosed in combination with the application can be directly implemented by the execution of the hardware processor, or by the combination of hardware and software modules in the processor. The memory may include high-speed random access memory (RAM), and may also include non-volatile memory (NVM), such as at least one disk memory, and can also be a USB flash drive, a mobile hard disk, a read-only memory, a magnetic disk or an optical disc, etc.

[0194] The above storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disc. The storage medium can be any available medium that can be accessed by a general or special-purpose computer.

[0195] An exemplary storage medium is coupled to the processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and the storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the storage medium can also exist as discrete components in an electronic device or a master control device.

[0196] It should be noted that in this text, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising such element.

[0197] The serial numbers of the embodiments of the present application above are only for description and do not represent the superiority or inferiority of the embodiments.

[0198] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of the present application.

[0199] The above are only the preferred embodiments of the present application and do not limit the patent scope of the present application. Any equivalent structural or equivalent process transformation made by using the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, shall be equally included in the patent protection scope of the present application.

Claims

1. A security protection system, characterized in that, Including: A host, a server, and a bastion host The server is used to obtain the login behavior information of the host, where the login behavior information is used to indicate the behavior of logging in to the host by password; according to the login behavior information of the host, detect whether there is a password cracking behavior against the host; if a password cracking behavior is detected, create an automatic password change plan for the host through the bastion host; where the automatic password change plan is used to modify the password of the host; The bastion host is used to modify the password of the host according to the automatic password change plan.

2. The system according to claim 1, characterized in that, A client is deployed on the host, and the client is used to collect the network logs of the host and report them to the server side, and the network logs include the login behavior information; The server side is deployed on the server, and the server side is used to detect whether there is a password cracking behavior against the host according to the network logs collected by the client of the host.

3. The system according to claim 1, wherein Communication between the host and the server is realized through a network-side device; The network-side device is used to collect the login behavior information of the host and send it to the server; The server is specifically used to detect whether there is a password cracking behavior against the host according to the login behavior information sent by the network-side device.

4. The system according to any one of claims 1-3, characterized in that, When the server detects whether there is a password cracking behavior against the host according to the login behavior information of the host, it is specifically used to: If, according to the login behavior information, it is detected that the behavior of logging in to the host appears continuously for a preset number of times within a preset time and all logins fail, it is confirmed that there is a password cracking behavior against the host.

5. The system according to any one of claims 1-3, characterized in that, The automatic password change plan is specifically used to periodically modify the password of the host; when the server creates the automatic password change plan for the host through the bastion host, it is specifically used to: Determine whether the password has been cracked according to the login behavior information; determine the password change period and / or the security level of the modified password of the automatic password change plan according to whether the password has been cracked; Or Judge whether there is already an automatic password change plan for the host; if not, create an automatic password change plan for the host through the bastion host; if so, modify the password change period and / or the security level of the modified password of the automatic password change plan.

6. The system according to claim 1, wherein The automatic password change plan is specifically used to periodically modify the password of the host; the server is also used to: After creating the automatic password change plan, if no password cracking behavior is detected within a preset period, delete the automatic password change plan through the bastion host.

7. A security protection method, characterized in that, Applied to a server, the method includes: Obtain the login behavior information of the host; where the login behavior information is used to indicate the behavior of logging in to the host by password; According to the login behavior information of the host, detect whether there is a password cracking behavior against the host; If a password cracking behavior against the host is detected, create an automatic password change plan for the host through the bastion host, so that the bastion host modifies the password of the host according to the automatic password change plan; Where the automatic password change plan is used to modify the password of the host.

8. The method according to claim 7, wherein A client is deployed on the host, and a server side is deployed on the server; obtaining the login behavior information of the host includes: Obtain the network logs of the host collected by the client through the server, where the network logs include the login behavior information.

9. The method according to claim 7, wherein Communication between the host and the server is achieved through a network-side device; Obtain the login behavior information of the host, including: Obtain the login behavior information of the host collected by the network-side device.

10. The method according to any one of claims 7-9, characterized in that, According to the login behavior information of the host, detect whether there is a password cracking behavior against the host, including: If, according to the login behavior information, it is detected that the behavior of logging in to the host occurs continuously for a preset number of times within a preset time and all logins fail, then confirm that there is a password cracking behavior against the host.

11. The method according to any one of claims 7-9, characterized in that, The automatic password modification plan is specifically used to periodically modify the password of the host. Create the automatic password modification plan for the host through the bastion host, including: Determine whether the password has been cracked according to the login behavior information; determine the password modification cycle and / or the security level of the modified password of the automatic password modification plan according to whether the password has been cracked; or, Judge whether there is already an automatic password modification plan for the host; if not, create the automatic password modification plan for the host through the bastion host; if so, modify the password modification cycle and / or the security level of the modified password of the automatic password modification plan.

12. The method according to claim 7, wherein The automatic password modification plan is specifically used to periodically modify the password of the host, and the method further includes: After creating the automatic password modification plan, if no password cracking behavior is detected within a preset period, delete the automatic password modification plan through the bastion host.

13. A safety protection device, characterized in that, Including: An acquisition module, configured to acquire the login behavior information of the host; wherein, the login behavior information is used to indicate the behavior of logging in to the host through a password; A detection module, configured to detect whether there is a password cracking behavior against the host according to the login behavior information of the host; A creation module, configured to create an automatic password modification plan for the host through the bastion host when a password cracking behavior against the host is detected, so that the bastion host modifies the password of the host according to the automatic password modification plan; Wherein, the automatic password modification plan is used to modify the password of the host.

14. An electronic device, characterized in that, Including: At least one processor; And A memory communicatively connected to the at least one processor; Wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, so that the electronic device executes the method according to any one of claims 7-12.

15. A computer-readable storage medium, characterized in that, Computer-executable instructions are stored in the computer-readable storage medium, and when the processor executes the computer-executable instructions, the method according to any one of claims 7-12 is implemented.

16. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, the method according to any one of claims 7-12 is implemented.