Asset password changing method, system and device based on bastion host operation and maintenance behavior analysis and medium

By using machine learning in the fortress to analyze operation and maintenance behavior, identify risks and trigger the encryption operation, the lag and compatibility problems of traditional encryption strategies are solved, and a safer and automated encryption process is achieved.

CN120200799APending Publication Date: 2025-06-24CHENGDU DBAPP SECURITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510338245.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-21
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

The traditional fortress machine compaction strategy is based on a fixed cycle and has lag, limitations and compatibility problems. It is impossible to adjust the timing of compaction based on specific operation and maintenance behavior, resulting in the failure to respond to potential attack risks in a timely manner.

Method used

By obtaining the operation and maintenance data of the bastion machine from the audit database, combining the operation and maintenance data of the server, using machine learning methods to extract behavioral characteristics, identify normal and abnormal behaviors, calculate risk coefficients, trigger encryption modification operations, and optimize the encryption modification strategy to improve automation level and security.

Benefits of technology

It realizes intelligent prediction of the timing of encryption changes based on operation and maintenance behavior, reduces unnecessary regular encryption changes, improves the automation and security of the encryption changes process, enhances the security of assets, and ensures password updates before potential threats occur.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200799A_ABST
    Figure CN120200799A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of artificial intelligence, in particular to an asset password changing method, system and device based on bastion host operation and maintenance behavior analysis and a medium. The method comprises the following steps: firstly, acquiring bastion host operation and maintenance data from an audit database, periodically acquiring server operation and maintenance data according to a bastion host, and establishing a comprehensive data set; then, a machine learning method is called to extract behavior characteristics from the fortress machine operation and maintenance data and the server operation and maintenance data, and normal behaviors and abnormal behaviors are obtained through recognition; and finally, calculating a risk coefficient according to the abnormal behavior and the normal behavior, and triggering a corresponding password changing operation. Based on the historical data and the change of the current environment, the potential attack opportunity or security threat is predicted, the optimal opportunity of password changing is determined, a fixed password changing strategy is optimized, and the automation level and security of the password changing process are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology, and in particular to an asset encryption method, system, device and medium based on bastion host operation and maintenance behavior analysis. Background Art

[0002] As the core device of enterprise network security, the bastion host undertakes tasks such as security management of external access, log auditing, and asset password management. Regular password changes during use are essential to maintaining data security.

[0003] Traditional password change strategies are usually based on fixed cycles, such as changing passwords regularly every month or quarter. However, this fixed password change method has the following problems:

[0004] Lag: The timing of changing encryption is not adjusted according to specific operation and maintenance behaviors, and potential attack risks may not be responded to in a timely manner.

[0005] Limitations: Regular password changes may result in a failure to change passwords in a timely manner before they are leaked or before an attack occurs, or a waste of resources on password changes when password security is not threatened.

[0006] Compatibility: Traditional encryption strategies usually use a fixed encryption command set to implement encryption of target assets. The limited command set may not be able to adapt to heterogeneous target assets.

[0007] In addition, the bastion host usually provides the function of exporting the password of the managed assets, such as exporting the password and key of a server. When the password of the bastion host user is leaked, there is a risk that the server password will also be leaked.

[0008] Machine learning is a subfield of artificial intelligence that uses data-driven algorithms to make predictions and decisions. It uses statistical methods and computational algorithms to learn patterns from data and make predictions on new data. In password change strategies, machine learning can be used to analyze historical operation and maintenance data, identify risk trends, and thus determine the best time and strategy for password change.

[0009] Traditional bastion host password change strategies are usually based on fixed cycles, such as monthly or quarterly password changes. This fixed password change strategy has limitations, lags, and compatibility issues.

[0010] In the existing password modification system, information such as the password change cycle, password complexity policy, password expiration policy, and password history policy all rely on the system administrator for manual setting. The system administrator needs to empirically evaluate the usage situation of the system (such as the network environment where the asset machine is located, the number of system users, the login frequency, the asset security rating, etc.) to determine the appropriate password modification policy. After configuring the password modification policy, the password modification system can only manage passwords according to the preset configuration. If it is necessary to modify the policy according to the specific usage situation, it also depends on manual operation.

[0011] The traditional password modification system cannot adjust the password modification timing according to specific asset operation and maintenance behaviors. The administrator needs to set the password modification cycle based on experience. A longer password modification cycle may lead to insufficiently timely password modification and a longer time window for password leakage. A shorter password modification cycle is likely to trigger multiple password modifications when the password is still in a secure state, resulting in resource waste.

[0012] The traditional password modification system usually sends a preset command set to the target asset by a preset software program to modify the password. By including the judgment logic for the password modification interaction text of the target asset machine in the preset program (usually including interactions such as logging in to the target asset, sending the password modification command, confirming whether to modify the password, repeating the input of the password, and confirming the password strength), the password modification command is triggered in a certain order to complete the automated password modification. When there is a system version update or asset configuration change in the target asset, the interaction behavior may change, and the original judgment logic cannot be adapted, resulting in the inability to complete the password modification.

[0013] For example, in RHEL 6, the interaction process of the passwd command is relatively simple. The user only needs to input the current password and the new password. In RHEL 8, the password complexity check is strengthened, and the pam_pwquality module is enabled by default, requiring the password to contain uppercase and lowercase letters, numbers, and special characters. If the password does not meet the requirements, the system will give more detailed prompts. Summary of the Invention

[0014] In view of the limitations, lag, and compatibility problems of the existing bastion host password modification policy based on a fixed cycle, the present invention proposes an asset password modification method, system, device, and medium based on bastion host operation and maintenance behavior analysis. The method first obtains the bastion host operation and maintenance data from the audit database, and periodically obtains the server operation and maintenance data according to the bastion host to establish a comprehensive data set. Then, it calls the machine learning method to extract behavior features from the bastion host operation and maintenance data and server operation and maintenance data, and identifies normal behaviors and abnormal behaviors. Finally, according to the abnormal behaviors and normal behaviors, it calculates the risk coefficient and triggers the corresponding password modification operation. Based on historical data and changes in the current environment, it predicts potential attack times or security threats, determines the best timing for password modification, optimizes the fixed password modification policy, and improves the automation level and security of the password modification process.

[0015] The specific implementation content of the present invention is as follows:

[0016] An asset password-changing method based on bastion host operation and maintenance behavior analysis specifically includes the following steps:

[0017] Step S1: Obtain bastion host operation and maintenance data from the audit database, and periodically obtain server operation and maintenance data according to the bastion host;

[0018] Step S2: Invoke machine learning methods to extract behavior features from the bastion host operation and maintenance data and server operation and maintenance data, and identify normal behaviors and abnormal behaviors;

[0019] Step S3: Calculate the risk coefficient according to the abnormal behaviors and normal behaviors, and trigger the corresponding password-changing operation.

[0020] To better implement the present invention, further, the specific steps of step S1 include the following steps:

[0021] Step S11: Read the operation and maintenance data accessed through the bastion host from the audit database to obtain the bastion host operation and maintenance data;

[0022] Step S12: Log in to the target asset according to the privileged account, obtain the server operation and maintenance data, and encrypt and save it to the configuration file of the proxy program;

[0023] Step S13: Preprocess the bastion host operation and maintenance data and server operation and maintenance data, and store them in the database.

[0024] To better implement the present invention, further, the specific steps of step S2 include the following steps:

[0025] Step S21: Extract behavior data from the bastion host operation and maintenance data and server operation and maintenance data to obtain behavior features;

[0026] Step S22: Train a machine learning model according to the preprocessed bastion host operation and maintenance data and server operation and maintenance data to obtain normal behaviors and abnormal behaviors.

[0027] To better implement the present invention, further, the specific steps of step S3 include the following steps:

[0028] Step S31: According to the set recognition rules, judge the degree of influence of the behavior evaluation risk, and calculate the risk coefficient according to the behavior features;

[0029] Step S32: Trigger the password-changing operation according to the set trigger threshold.

[0030] To better implement the present invention, further, the specific operation of step S31 is as follows: Calculate the risk coefficient according to the behavior feature weight, the number of occurrences of the behavior feature in the current period, the historical average value of the behavior feature, the standard deviation of the behavior feature, the abnormal behavior weight, the number of occurrences within the abnormal behavior period, and the adjustment coefficient.

[0031] To better implement the present invention, further, the asset password-changing method based on bastion host operation and maintenance behavior analysis further includes:

[0032] Step S4: Analyze historical password-changing data, call natural language recognition technology to analyze the interactive text of password-changing, and optimize the password-changing command.

[0033] To better implement the present invention, further, step S4 specifically includes the following steps:

[0034] Step S41: Train a natural language model according to the bastion host historical password-changing data and the command set script;

[0035] Step S42: Classify the interactive text into different prompt types according to the trained natural language model;

[0036] Step S43: Identify the key information in the interactive text and generate a response according to the prompt type.

[0037] Based on the above-mentioned asset password-changing method based on bastion host operation and maintenance behavior analysis, to better implement the present invention, further, an asset password-changing system based on bastion host operation and maintenance behavior analysis is proposed, including a data collection module, a data analysis module, and a password-changing implementation module;

[0038] The data collection module is used to obtain bastion host operation and maintenance data from the audit database and obtain server operation and maintenance data according to the bastion host periodically;

[0039] The data analysis module is used to call machine learning methods to extract behavior features from the bastion host operation and maintenance data and the server operation and maintenance data, and identify normal behaviors and abnormal behaviors;

[0040] The password-changing implementation module is used to calculate the risk coefficient according to the abnormal behavior and the normal behavior, and trigger the corresponding password-changing operation.

[0041] Based on the above-mentioned asset password-changing method based on bastion host operation and maintenance behavior analysis, to better implement the present invention, further, an electronic device is proposed, including a memory and a processor; a computer program is stored on the memory; when the computer program is executed on the processor, the above-mentioned asset password-changing method based on bastion host operation and maintenance behavior analysis is implemented.

[0042] Based on the above-mentioned asset password modification method based on bastion host operation and maintenance behavior analysis, in order to better implement the present invention, further, a computer-readable storage medium is proposed. Computer instructions are stored on the computer-readable storage medium; when the computer instructions are executed on the above-mentioned electronic device, the above-mentioned asset password modification method based on bastion host operation and maintenance behavior analysis is implemented.

[0043] The present invention has the following beneficial effects:

[0044] (1) By analyzing the operation and maintenance behavior of the assets managed by the bastion host, the historical password modification records of the bastion host, and the user operations of the bastion host, the present invention identifies abnormal operation and maintenance behaviors, improves the security of the assets, and to a greater extent ensures that password updates are carried out before potential threats occur. It realizes the intelligent prediction of the password modification time and reduces unnecessary regular password modifications.

[0045] (2) By analyzing the historical password modification behaviors, the present invention automatically adjusts the password modification command set, making the password modification process more flexible and compatible. It reduces human intervention and improves the automation level of password modification.

[0046] (3) By analyzing the user behaviors after the user logs in to the bastion host, the present invention evaluates the session security level. When the plaintext password is exported in a session in a high-risk state, the asset password modification can be automatically triggered. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 It is a schematic block diagram of the process of the asset password modification method based on bastion host operation and maintenance behavior analysis provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0048] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. It should be understood that the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments, and therefore should not be regarded as a limitation on the protection scope. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.

[0049] In the description of the present invention, it should be noted that unless otherwise clearly defined and limited, the terms "set", "connected", and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can also be directly connected, or indirectly connected through an intermediate medium, and it can be the internal communication of two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.

[0050] The technical terms and English abbreviations involved in the embodiments of the present invention are as follows:

[0051] Bastion Host: A comprehensive operation and maintenance management system integrating operation and maintenance, auditing, and asset hosting. It can control and record the operations of operation and maintenance personnel on resources such as servers, security devices, and databases, and implement functions such as asset management, access control, and behavior traceability.

[0052] Password Rotation Strategy: Refers to a series of regulations and methods, usually including password change cycle, password complexity policy, password expiration policy, password history policy, etc., used to update the passwords of systems or accounts regularly or under specific conditions. To enhance security and reduce potential security risks

[0053] Automatic password change: Automatic password change is a technology that automates the password update process by sending password change instructions to the server. This process usually involves several command interactions with the server.

[0054] Machine Learning Model: A machine learning model is a mathematical representation of objects and their relationships, which finds patterns or makes predictions by sorting through massive amounts of data. Commonly used models include decision trees, random forests, support vector machines, etc.

[0055] Embodiment 1:

[0056] This embodiment proposes an asset password change method based on the operation and maintenance behavior analysis of the bastion host, which specifically includes the following steps:

[0057] Step S1: Obtain the operation and maintenance data of the bastion host from the audit database, and obtain the operation and maintenance data of the server according to the periodic acquisition of the bastion host.

[0058] The specific steps of step S1 are as follows:

[0059] Step S11: Read the operation and maintenance data accessed by the bastion host from the audit database to obtain the operation and maintenance data of the bastion host;

[0060] Step S12: Log in to the target asset according to the privileged account, obtain the operation and maintenance data of the server, and encrypt and save it to the configuration file of the proxy program;

[0061] Step S13: Preprocess the operation and maintenance data of the bastion host and the operation and maintenance data of the server, and store them in the database.

[0062] Step S2: Call the machine learning method to extract behavior features from the operation and maintenance data of the bastion host and the operation and maintenance data of the server, and identify normal behaviors and abnormal behaviors.

[0063] Step S2 specifically includes the following steps:

[0064] Step S21: Extract behavioral data from the bastion host operation and maintenance data and server operation and maintenance data to obtain behavioral characteristics;

[0065] Step S22: Train a machine learning model based on the preprocessed bastion host operation and maintenance data and server operation and maintenance data to obtain normal behaviors and abnormal behaviors.

[0066] Step S3: Calculate the risk coefficient based on the abnormal behaviors and normal behaviors, and trigger the corresponding password change operation.

[0067] Step S3 specifically includes the following steps:

[0068] Step S31: Judge the degree of influence of the behavior evaluation risk according to the set recognition rules, and calculate the risk coefficient according to the behavioral characteristics;

[0069] The specific operation of Step S31 is: Calculate the risk coefficient according to the behavioral characteristic weight, the number of occurrences of the behavioral characteristic in the current cycle, the historical average value of the behavioral characteristic, the standard deviation of the behavioral characteristic, the abnormal behavior weight, the number of occurrences within the abnormal behavior cycle, and the adjustment coefficient.

[0070] Step S32: Trigger the password change operation according to the set trigger threshold.

[0071] Step S4: Analyze the historical password change data, call the natural language recognition technology to analyze the interactive text of the password change, and optimize the password change command.

[0072] Step S4 specifically includes the following steps:

[0073] Step S41: Train a natural language model based on the bastion host historical password change data and command set script;

[0074] Step S42: Classify the interactive text into different prompt types according to the trained natural language model;

[0075] Step S43: Identify the key information in the interactive text and generate a response according to the prompt type.

[0076] Working principle: In this embodiment, by continuously monitoring the operation and maintenance behaviors of the target assets, collecting data such as its operation logs, access frequencies, device performances, and network traffic, a comprehensive data set is established. Key features related to security are extracted from the above data set through machine learning. Based on the historical data and the changes in the current environment, potential attack times or security threats are predicted, the best time for password change is determined, and the fixed password change strategy is optimized, improving the automation level and security of the password change process.

[0077] Embodiment 2:

[0078] Based on the above-mentioned Embodiment 1, as Figure 1 shown, a specific embodiment will be described in detail, which specifically includes the following steps.

[0079] Step S1: Collect historical data for asset security assessment.

[0080] Operation and maintenance session data stored in the bastion host audit service: Modern bastion hosts usually have the function of auditing operation and maintenance operations, and can directly read data such as operation and maintenance session records and command records accessed through the bastion host from the audit database.

[0081] The bastion host periodically obtains server data: When the bastion host hosts the privileged account of the target asset, the bastion host regularly logs in to the target asset through the privileged account to obtain the log information of the target asset, such as system logs, kernel logs, authentication logs, firewall logs, etc., the command line execution records (bash_history) of each user, and obtains the current status information of the target asset such as network traffic and resource occupancy.

[0082] The bastion host provides the function of a proxy program for the one-click deployment proxy service of the target asset. After the user clicks to generate a deployment command on the bastion host, it is copied and pasted into the target server for execution. The proxy program runs permanently in the target server, monitors the changes of various log files and log directories, tracks the creation, modification and deletion of log files, and regularly pushes the information such as system logs, kernel logs, authentication logs, firewall logs, etc., and the data of the command line execution records (bash_history) of each user to the bastion host through the HTTP method or the RPC method. The ak (AccessKey) and sk (SecretKey) are used for authentication during the pushing process to ensure data security. The ak and sk are automatically generated when the deployment command is generated and encrypted and saved in the configuration file of the proxy program (preferably: encryption can use a cloud cipher machine to improve security). Each pushed message contains metadata, data content and the hash information of the content.

[0083] Preprocess the data. Usually, the collected data contains various forms of log records and command records, and there may be problems such as data redundancy and inconsistent formats. Therefore, data cleaning and sorting are required. Remove invalid, duplicate or irrelevant log entries (such as system heartbeats, no-op operations, etc.). Format unification: Convert log data in different formats (such as text logs, session videos) into a data structure convenient for analysis, such as Json.

[0084] Data storage: The above-mentioned user behavior and server operation and maintenance data collected can be stored in time series databases such as InfluxDB and TimescaleDB. According to specific usage scenarios, data scale, and query requirements, databases with efficient big data search and indexing capabilities such as Elasticsearch can also be used to optimize read and write performance and data retrieval efficiency.

[0085] Step S2: Data analysis.

[0086] Analyze and extract the data related to behavior characteristics collected above, including but not limited to: basic user information; session duration; command operation sequence, time, frequency; network traffic, connection status; privilege escalation commands, high-risk commands.

[0087] Select a suitable machine learning model for training. Commonly used models include decision trees, random forests, support vector machines, etc., and selection is based on the actual data and the complexity of specific scenarios. Model training uses the historical data of the bastion host and the server historical data. In a supervised learning environment, mark the normal and abnormal behavior patterns of server operation and maintenance operations, and evaluate the risk impact degree for each behavior. Furthermore, according to different application scenarios, some recognition rules for abnormal behaviors can be predefined to improve the accuracy of risk assessment: execute sensitive commands that are not executed or rarely executed in normal historical operation and maintenance, such as privilege escalation, user switching, password modification; execute high-risk commands defined by the bastion host audit rules; the command execution sequence, time, frequency are quite different from the historical operation and maintenance data; there are operations to attempt to delete or modify system log files.

[0088] Calculate the risk coefficient. Use the following method to calculate the risk coefficient R:

[0089]

[0090] Among them, w i represents the weight of behavior characteristic i, N i is the occurrence times of behavior characteristic i in the current period, μ i represents the historical average value of behavior characteristic i, σ i represents the standard deviation of behavior characteristic i, ∈ is an extremely small constant used to exclude the division-by-zero error when the standard deviation is 0, w j is the weight of abnormal behavior j, m j is the occurrence times of abnormal behavior within the period, and α and β are adjustment coefficients used to adjust the influence of the two parts.

[0091] The higher the risk coefficient R, the greater the risk of server password leakage. High, medium, and low risk thresholds can be set according to the security level of the asset, and the system can automatically compare the risk coefficient with the risk threshold to trigger corresponding actions. When the risk coefficient is greater than the high risk threshold, it indicates that the risk of password leakage of the target server is extremely high, and password modification should be immediately triggered. When the risk coefficient is greater than the medium risk threshold, it indicates that there is a relatively high risk of password leakage of the target server, and the preset execution cycle of the password modification plan should be reduced (increase the password modification frequency). When the risk coefficient is less than the low risk threshold, it indicates that the risk of password leakage of the target server is small, and the preset execution cycle of the password modification plan can be extended (reduce the password modification frequency).

[0092] Regularly submit the behavior feature analysis and risk assessment results to the administrator for result confirmation. The accuracy of the model identification is evaluated through cross-validation, and the model parameters are adjusted or a new model is selected according to the evaluation results to continuously optimize the identification accuracy.

[0093] Step S3: Password modification.

[0094] Use the historical password modification data and command set scripts in the bastion host to train natural language models, such as BERT model, GPT model, including:

[0095] Text classification: Use a machine learning model to classify interactive text into different prompt types. For example, "Y / N confirmation prompt", "input prompt", "error prompt", etc.

[0096] Entity recognition: Identify the key information in the interactive text, such as the fields to be input or the information to be confirmed.

[0097] Generate response: Use a natural language model to generate an appropriate response.

[0098] The password modification module is built-in with pre-trained natural language models, such as BERT model, GPT model, which are used to recognize and understand the semantics of interactive text when there is a response other than the preset instructions in the program, so as to achieve automatic processing. For confirmation prompts and input prompts, the natural language model automatically generates appropriate responses. For error prompts, try to automatically process them. For example, if the password strength does not meet the requirements, the original password complexity policy can be automatically adjusted and a new password can be generated. Improve the automation level of the password modification process.

[0099] The bastion host usually provides a function to export the passwords of the managed assets, such as exporting the passwords and keys of a certain server, downloading the password modification history in the password modification plan, etc. Preferably, the analysis of the user behavior after logging in to the bastion host can also be introduced to avoid the problem of server password leakage caused by the leakage of the bastion host user password.

[0100] Analyze data such as the time when the user logs in to the bastion host, the source IP, the network environment, improper login behaviors such as suspicious password brute force, the operation sequence, operation frequency, operation type, and operation risk level on the bastion host after logging in. Evaluate the security status of the current user session through a machine learning model. When the session is in a high-risk state and the operation of exporting the server password is performed on the bastion host side, it can be considered that there is a risk of server password leakage, and corresponding security measures can be automatically triggered, such as immediately changing the server password and notifying the system administrator.

[0101] Working principle: In this embodiment, the historical operation and maintenance data and recent operation and maintenance data of the assets in the bastion host are first collected, including the operation and maintenance data recorded in the bastion host, as well as the log data, operation logs, access frequencies, device performances, and network traffic data pushed by the Agent proxy service to the bastion host.

[0102] After that, pattern recognition is performed on the collected behavior data through machine learning, and behavior characteristics such as operation frequency, access time difference, and operation sequence are extracted and analyzed to automatically distinguish normal behaviors and abnormal behaviors.

[0103] When there are abnormal behaviors, it represents the existence of a potential password leakage risk, and the password change program is automatically triggered. For assets with no abnormal behaviors after multiple analyses, it can be considered that there is no password leakage risk, and the fixed password change duration can be automatically adjusted to reduce the password change overhead when there is no password leakage risk.

[0104] Secondly, this embodiment analyzes the historical password change data of the bastion host, analyzes the interactive text of the password change through natural language recognition technology, optimizes the selection of password change commands by the password change program, improves the compatibility of the password change program for various heterogeneous asset machines, and improves the automation level of the program.

[0105] Other parts of this embodiment are the same as those of the above Embodiment 1, so they will not be elaborated here.

[0106] Embodiment 3:

[0107] Based on any one of the above Embodiment 1 - Embodiment 2, this embodiment proposes an asset password change system based on bastion host operation and maintenance behavior analysis, including a data collection module, a data analysis module, and a password change implementation module;

[0108] The data collection module is used to obtain the bastion host operation and maintenance data from the audit database and obtain the server operation and maintenance data according to the bastion host's periodic acquisition;

[0109] The data analysis module is used to call machine learning methods to extract behavior characteristics from the bastion host operation and maintenance data and server operation and maintenance data, and identify normal behaviors and abnormal behaviors;

[0110] The password change implementation module is used to calculate the risk coefficient based on abnormal behaviors and normal behaviors and trigger corresponding password change operations.

[0111] Data collection module: An Agent proxy service deployment program is built into the bastion host and supports one-click deployment to the target asset machine. This program automatically monitors changes in specific log files, tracks file creation, modification, and deletion, and regularly pushes log data to the bastion host, including operation and maintenance operations not performed through the bastion host into the scope of the next data analysis.

[0112] Data analysis module: Use artificial intelligence technology to train a machine learning model with historical operation and maintenance data to identify potential password leakage risks of asset machines, thereby optimizing the password change timing, improving asset security, and reducing ineffective password changes.

[0113] Password change module: Use a pre-trained natural language processing model, such as the BERT model or GPT model, to identify key entities in the password change interaction, improve the compatibility of the password change program with heterogeneous asset machines, and improve the automation level of the password change program.

[0114] This embodiment also provides an electronic device, including a memory and a processor; a computer program is stored on the memory; when the computer program is executed on the processor, the above-mentioned asset password change method based on bastion host operation and maintenance behavior analysis is implemented.

[0115] This embodiment also provides a computer-readable storage medium, on which computer instructions are stored; when the computer instructions are executed on the above-mentioned electronic device, the above-mentioned asset password change method based on bastion host operation and maintenance behavior analysis is implemented.

[0116] Other parts of this embodiment are the same as any one of the above-mentioned Embodiment 1 - Embodiment 2, so they will not be elaborated here.

[0117] As mentioned above, the above are only preferred embodiments of the present invention, and do not impose any form of limitation on the present invention. Any simple modification or equivalent change made to the above embodiments based on the technical essence of the present invention shall fall within the protection scope of the present invention.

Claims

1. A method for changing the encryption of assets based on the analysis of the operation and maintenance behavior of the bastion host, characterized in that: The specific steps include: Step S1: Obtain bastion host operation and maintenance data from the audit database, and periodically obtain server operation and maintenance data based on the bastion host; Step S2: Calling a machine learning method to extract behavior features from the bastion host operation and maintenance data and the server operation and maintenance data, and identifying normal behavior and abnormal behavior; Step S3: Calculate the risk factor based on abnormal behavior and normal behavior, and trigger the corresponding encryption operation.

2. According to claim 1, a method for changing the encryption of assets based on the analysis of the operation and maintenance behavior of the bastion host is characterized in that: The step S1 specifically includes the following steps: Step S11: read the operation and maintenance data accessed by the bastion host from the audit database to obtain the operation and maintenance data of the bastion host; Step S12: Log in to the target asset using the privileged account, obtain the server operation and maintenance data, and encrypt and save it in the configuration file of the agent program; Step S13: Preprocess the bastion host operation and maintenance data and the server operation and maintenance data, and store them in the database.

3. According to claim 1, a method for changing the encryption of assets based on the analysis of the operation and maintenance behavior of the bastion host is characterized in that: The step S2 specifically includes the following steps: Step S21: extracting behavior data from the bastion host operation and maintenance data and the server operation and maintenance data to obtain behavior features; Step S22: Train the machine learning model based on the preprocessed bastion host operation and maintenance data and server operation and maintenance data to obtain normal behavior and abnormal behavior.

4. According to claim 2, a method for changing the encryption of assets based on the analysis of the operation and maintenance behavior of the bastion host is characterized in that: The step S3 specifically comprises the following steps: Step S31: judging the risk impact of the behavior assessment according to the set identification rules, and calculating the risk coefficient according to the behavior characteristics; Step S32: triggering the encryption operation according to the set trigger threshold.

5. According to claim 3, the asset encryption method based on bastion host operation and maintenance behavior analysis is characterized in that: The specific operation of step S31 is: calculating the risk coefficient according to the behavior feature weight, the number of occurrences of the behavior feature in the current cycle, the historical average of the behavior feature, the standard deviation of the behavior feature, the abnormal behavior weight, the number of occurrences in the abnormal behavior cycle, and the adjustment coefficient.

6. According to claim 1, a method for changing the encryption of assets based on the analysis of the operation and maintenance behavior of the bastion host is characterized in that: The asset encryption method based on bastion host operation and maintenance behavior analysis also includes: Step S4: Analyze historical decryption data, use natural language recognition technology to analyze decryption interactive text, and optimize decryption commands.

7. According to claim 6, a method for changing the encryption of assets based on the analysis of the operation and maintenance behavior of the bastion host is characterized in that: The step S4 specifically comprises the following steps: Step S41: training a natural language model based on the historical encryption data and command set scripts of the bastion host; Step S42: classifying the interactive text into different prompt types according to the trained natural language model; Step S43: Identify key information in the interactive text and generate a response according to the prompt type.

8. An asset encryption system based on bastion host operation and maintenance behavior analysis, used to execute the asset encryption method based on bastion host operation and maintenance behavior analysis as claimed in claim 1; characterized in that: It includes data collection module, data analysis module and encryption implementation module; The data collection module is used to obtain the bastion host operation and maintenance data from the audit database, and periodically obtain the server operation and maintenance data according to the bastion host; The data analysis module is used to call a machine learning method to extract behavior features from the bastion host operation and maintenance data and the server operation and maintenance data, and identify normal behavior and abnormal behavior; The encryption implementation module is used to calculate the risk coefficient according to abnormal behavior and normal behavior, and trigger the corresponding encryption operation.

9. An electronic device, characterized in that: It includes a memory and a processor; a computer program is stored on the memory; when the computer program is executed on the processor, the asset encryption method based on bastion host operation and maintenance behavior analysis as described in any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions; when the computer instructions are executed on the electronic device as described in claim 9, the asset encryption method based on bastion host operation and maintenance behavior analysis as described in any one of claims 1-7 is implemented.