Safety early warning method of AD domain system and related device

By regularly obtaining and detecting the account data of the AD domain system, the lack of AD domain system security warning in the existing technology is solved, and security detection and alarm of the AD domain system is realized, and its security is improved.

CN120223336APending Publication Date: 2025-06-27NETSUNION CLEARING CORP
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311816891.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-27
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The lack of security early warning methods for AD domain systems in the prior art leads to lower security of AD domain systems.

Method used

The current AD domain account data in the AD domain system is obtained at a specified time, and security detection is performed based on the current data and preset standard data. If the detection result is unsafe, a security alarm will be issued.

Benefits of technology

Timely security detection and alarm of the AD domain system is realized, the security of the AD domain system is improved, and staff are reminded to carry out timely security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223336A_ABST
    Figure CN120223336A_ABST
Patent Text Reader

Abstract

The invention provides a safety early warning method of an AD domain system and a related device. The method comprises the steps of obtaining current AD domain account data in an AD domain system every specified duration; performing security detection on the AD domain system according to the current account data of each AD domain and preset account data of each standard AD domain to obtain a security detection result; and if it is determined that the security detection result is that the AD domain system is unsafe, performing security alarm. Therefore, the security detection can be timely carried out on the system, so that the security of the AD domain system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] Currently, most companies use the AD (Active Directory) domain system as the core account management system of the company, managing all data such as account authentication credentials. Once an attacker breaks through the boundary, they usually regard the AD domain system as the preferred target for lateral penetration attacks. If the AD domain system is further compromised, it means that all systems authenticated based on the AD domain system are completely compromised.

[0003] Due to the importance of the AD domain system, it is necessary to focus on its defense and practice the concept of in-depth defense. However, there is no security warning method for the AD domain system in the existing technology. Therefore, the security of the AD domain system is relatively low. Summary of the Invention

[0004] An exemplary embodiment of the present disclosure provides a security warning method, device, electronic device, and computer storage medium for an AD domain system to improve the security of the AD domain system.

[0005] A first aspect of the present disclosure provides a security warning method for an AD domain system, the method including:

[0006] Obtaining the current AD domain account data in the AD domain system at specified intervals;

[0007] Performing a security detection on the AD domain system according to the current AD domain account data and the preset standard AD domain account data to obtain a security detection result;

[0008] If it is determined that the security detection result is that the AD domain system is insecure, a security warning is issued.

[0009] In this embodiment, by obtaining the current AD domain account data in the AD domain system at specified intervals, then performing a security detection on the AD domain system according to the current AD domain account data and the preset standard AD domain account data to obtain a security detection result, and when it is determined that the security detection result is that the AD domain system is insecure, a security warning is issued. To remind the staff to perform security protection in a timely manner. Thus, the system can be securely detected in a timely manner in the embodiment of the present application, improving the security of the AD domain system.

[0010] In one embodiment, the performing a security detection on the AD domain system according to the current AD domain account data and the preset standard AD domain account data to obtain a security detection result includes:

[0011] Performing a hash calculation on the current AD domain account data by using a hash algorithm to obtain a first hash value corresponding to the current AD domain account data; and,

[0012] Use the hash algorithm to perform hash calculation on the current standard AD domain account data to obtain the second hash value corresponding to the current standard AD domain account data;

[0013] If the first hash value is different from the second hash value, determine that the security detection result is that the AD domain system is insecure;

[0014] If the first hash value is the same as the second hash value, for any standard AD domain account data, based on the standard AD domain account data and the current AD domain account data corresponding to the standard AD domain account data, determine whether the current AD domain account data is a secure account;

[0015] If all the current AD domain account data are secure accounts, determine that the security detection result is that the AD domain system is secure;

[0016] If there is at least one insecure account among the current AD domain account data, determine that the security detection result is that the AD domain system is insecure.

[0017] In this embodiment, by performing security detection on the AD domain system based on the hash values of the current AD domain account data and the preset hash values of the standard AD domain account data, it is possible to accurately detect whether the AD domain account data has changed, etc., so as to further improve the security of the AD domain system detection.

[0018] In one embodiment, the method further includes:

[0019] If there is no corresponding current AD domain account data for the standard AD domain account data, determine that the security detection result is that the system is insecure.

[0020] In this embodiment, by determining that the security detection result is that the system is insecure if there is no corresponding current AD domain account data for the standard AD domain account data, it is possible to identify the deleted AD domain account data, further improving the security of the AD domain system.

[0021] In one embodiment, the determining whether the current AD domain account data is a secure account based on the standard AD domain account data and the current AD domain account data corresponding to the standard AD domain account data includes:

[0022] Use the hash algorithm to perform hash calculation on the current AD domain account data to obtain the third hash value; and,

[0023] Perform a hash calculation on the standard AD domain account data using a hash algorithm to obtain a fourth hash value;

[0024] If the third hash value is the same as the fourth hash value, determine that the current AD domain account data is a secure account;

[0025] If the third hash value is different from the fourth hash value, determine that the current AD domain account data is an insecure account.

[0026] In this embodiment, by comparing the hash value of the standard AD domain account data with the hash value of the current AD domain account data corresponding to the standard AD domain account data, it is determined whether the current AD domain account data is a secure account, further improving the security of the system.

[0027] In one embodiment, the current AD domain account data corresponding to the standard AD domain account data is determined by the following method:

[0028] For any standard AD domain account data, use the index of the standard AD domain account data to find the current AD domain account data with the same index as the standard AD domain account data from the current AD domain account data; and,

[0029] Determine the found current AD domain account data as the current AD domain account data corresponding to the standard AD domain account data.

[0030] In this embodiment, the current AD domain account data corresponding to each standard AD domain account data is determined by the index of the standard AD domain account data and the index of the current AD domain account data, ensuring the accuracy of account matching.

[0031] In one embodiment, before obtaining the current AD domain account data in the AD domain system at each specified time interval, the method further includes:

[0032] Respond to a specified time interval setting instruction sent by the user, and set the specified time interval based on the specified time interval setting instruction.

[0033] In the embodiments of the present application, the user can set the corresponding specified time interval, which can be configured according to the user's needs, meeting the user's needs.

[0034] The second aspect of the present disclosure provides a security protection device for an AD domain, and the device includes:

[0035] An acquisition module, configured to acquire the current AD domain account data in the AD domain system at each specified time interval;

[0036] A security detection module, configured to perform a security detection on the AD domain system according to the current AD domain account data and the preset standard AD domain account data, and obtain a security detection result;

[0037] A security warning module, configured to perform a security warning if it is determined that the security detection result indicates that the AD domain system is insecure.

[0038] In one embodiment, the security detection module is specifically configured to:

[0039] Perform a hash calculation on the current AD domain account data by using a hash algorithm to obtain a first hash value corresponding to the current AD domain account data; and,

[0040] Perform a hash calculation on the current standard AD domain account data by using a hash algorithm to obtain a second hash value corresponding to the current standard AD domain account data;

[0041] If the first hash value is different from the second hash value, determine that the security detection result indicates that the AD domain system is insecure;

[0042] If the first hash value is the same as the second hash value, for any one of the standard AD domain account data, determine whether the current AD domain account data is a secure account based on the standard AD domain account data and the corresponding current AD domain account data;

[0043] If all the current AD domain account data are secure accounts, determine that the security detection result indicates that the AD domain system is secure;

[0044] If there is at least one insecure account among the current AD domain account data, determine that the security detection result indicates that the AD domain system is insecure.

[0045] In one embodiment, the device further includes:

[0046] A security detection result determination module, configured to determine that the security detection result indicates that the system is insecure if there is no corresponding current AD domain account data for the standard AD domain account data.

[0047] In one embodiment, when the security detection module executes the determination of whether the current AD domain account data is a secure account based on the standard AD domain account data and the corresponding current AD domain account data, it is specifically configured to:

[0048] Perform a hash calculation on the current AD domain account data by using a hash algorithm to obtain a third hash value; and,

[0049] Perform a hashing calculation on the standard AD domain account data using a hashing algorithm to obtain a fourth hash value;

[0050] If the third hash value is the same as the fourth hash value, determine that the current AD domain account data is a secure account;

[0051] If the third hash value is different from the fourth hash value, determine that the current AD domain account data is an insecure account.

[0052] In one embodiment, the apparatus further includes:

[0053] A matching module, configured to determine the current AD domain account data corresponding to the standard AD domain account data in the following manner:

[0054] For any standard AD domain account data, use the index of the standard AD domain account data to find the current AD domain account data in the current AD domain account data whose index is the same as the index of the standard AD domain account data; and,

[0055] Determine the found current AD domain account data as the current AD domain account data corresponding to the standard AD domain account data.

[0056] In one embodiment, the apparatus further includes:

[0057] A duration setting module, configured to, before obtaining the current AD domain account data in the AD domain system every specified duration, in response to a specified duration setting instruction sent by a user, set the specified duration based on the specified duration setting instruction.

[0058] According to a third aspect of the embodiments of the present disclosure, there is provided an electronic device, including:

[0059] At least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor; the instructions are executed by the at least one processor so that the at least one processor can execute the method as described in the first aspect.

[0060] According to a fourth aspect provided by the embodiments of the present disclosure, there is provided a computer storage medium, the computer storage medium stores a computer program, and the computer program is used to execute the method as described in the first aspect. Description of the Drawings

[0061] To more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.

[0062] Figure 1 It is a schematic diagram of an applicable scenario according to an embodiment of the present disclosure;

[0063] Figure 2 It is one of the schematic flowcharts of the security warning method for the AD domain system according to an embodiment of the present disclosure;

[0064] Figure 3 It is the second of the schematic flowcharts of the method for determining the security detection result according to an embodiment of the present disclosure;

[0065] Figure 4 It is the third of the schematic flowcharts of the security warning method for the AD domain system according to an embodiment of the present disclosure;

[0066] Figure 5 It is a security warning device for the AD domain system according to an embodiment of the present disclosure;

[0067] Figure 6 It is a schematic structural diagram of an electronic device according to an embodiment of the present disclosure. Specific embodiments

[0068] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present disclosure in conjunction with the accompanying drawings in the embodiments of the present disclosure. Obviously, the described embodiments are some, but not all, of the embodiments of the present disclosure. Based on the embodiments of the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present disclosure.

[0069] The term "and / or" in the embodiments of the present disclosure describes the association relationship of associated objects and indicates that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.

[0070] The application scenarios described in the embodiments of the present disclosure are for more clearly illustrating the technical solutions of the embodiments of the present disclosure, and do not constitute a limitation on the technical solutions provided by the embodiments of the present disclosure. Those of ordinary skill in the art can know that with the emergence of new application scenarios, the technical solutions provided by the embodiments of the present disclosure are equally applicable to similar technical problems. Among them, in the description of the present disclosure, unless otherwise specified, the meaning of "a plurality of" is two or more.

[0071] In the prior art, there is no security warning method for the AD domain system. Therefore, the security of the AD domain system is relatively low.

[0072] Therefore, the present disclosure provides a security warning method for an AD domain system. By obtaining the current AD domain account data in the AD domain system at regular intervals, and then performing security detection on the AD domain system according to the current AD domain account data and the preset standard AD domain account data to obtain a security detection result. When it is determined that the security detection result indicates that the AD domain system is insecure, a security warning is issued to remind the staff to perform security protection in a timely manner. Thus, in the embodiments of the present application, the system can be timely subjected to security detection, improving the security of the AD domain system. Next, the solution of the present disclosure will be introduced in detail with reference to the accompanying drawings.

[0073] As Figure 1 shown, an application scenario of a security warning method for an AD domain system includes a terminal device 110 and a server 120.

[0074] In a possible application scenario, the server 120 obtains the current AD domain account data in the AD domain system at regular intervals; then the server 120 performs security detection on the AD domain system according to the current AD domain account data and the preset standard AD domain account data to obtain a security detection result; if the server 120 determines that the security detection result indicates that the AD domain system is insecure, a security warning is issued through the terminal device 110.

[0075] Among them, Figure 1 information interaction can be carried out between the terminal device 110 and the server 120 through a communication network. Among them, the communication method adopted by the communication network can be divided into a wireless communication method or a wired communication method.

[0076] Exemplarily, the server 120 can access the network through cellular mobile communication technology and communicate with the terminal device 110. Among them, the cellular mobile communication technology, for example, includes the fifth generation mobile communication (5th Generation Mobile Networks, 5G) technology.

[0077] Optionally, the server 120 can access the network through short-range wireless communication to communicate with the terminal device 110. Among them, the short-range wireless communication method, for example, includes Wireless Fidelity (Wi-Fi) technology.

[0078] Among them, in the description of this application, only a single server 120 and a single terminal device 110 are described in detail. However, those skilled in the art should understand that the shown server 120 and terminal device 110 are intended to represent the operations of the server 120 and terminal device 110 involved in the technical solution of this application. Instead of implying any limitations on the number, type, or location of the server 120 and terminal device 110. It should be noted that if additional modules are added to or individual modules are removed from the illustrated environment, the underlying concept of the exemplary embodiments of this application will not be changed.

[0079] It should be noted that the security warning method of the AD domain system proposed in this application is not only applicable to Figure 1 the application scenario shown, but also applicable to any security warning device with an AD domain system.

[0080] Next, in combination with the above-described application scenario, refer to the accompanying drawings to describe the security warning method of the AD domain system in the exemplary embodiments of this application. It should be noted that the above application scenario is only shown for the convenience of understanding the method and principle of this application, and the embodiments of this application are not limited in this regard.

[0081] As Figure 2 shown, it is a schematic flowchart of the security warning method of the AD domain system of the present disclosure, which may include the following steps:

[0082] Step 201: Every specified duration, obtain the current AD domain account data in the AD domain system;

[0083] In one embodiment, before executing step 201, in response to a specified duration setting instruction sent by the user, set the specified duration based on the specified duration setting instruction.

[0084] The specified duration setting instruction in the embodiment of this application includes the specified duration, so the specified duration can be set based on the value of the specified duration in the specified duration setting instruction. The specified duration can be 0.1 second, 1 second, 10 seconds, etc. The specific value of the specified duration is not limited in the embodiments of this application.

[0085] Step 202: Perform a security detection on the AD domain system according to the current AD domain account data and the preset standard AD domain account data, and obtain a security detection result;

[0086] Next, the method for determining the security detection result in the embodiments of the present application will be introduced. As Figure 3 shown, it is a schematic flowchart for determining the security detection result, which may include the following steps:

[0087] Step 301: Use a hash algorithm to perform hash calculation on the current AD domain account data to obtain the first hash value corresponding to the current AD domain account data;

[0088] In one embodiment, step 301 may be specifically implemented as: input the current AD domain account data into the hash algorithm to obtain the first hash value.

[0089] Step 302: Use a hash algorithm to perform hash calculation on the current standard AD domain account data to obtain the second hash value corresponding to the current standard AD domain account data;

[0090] It should be noted that: the execution sequence of step 301 and step 302 in the embodiments of the present application is not limited herein. Step 301 may be executed first, and then step 302. Or step 302 may be executed first, and then step 301. Or step 301 and step 302 may be executed simultaneously.

[0091] Step 303: Determine whether the first hash value is the same as the second hash value. If they are the same, execute step 304. If they are different, execute step 307;

[0092] Step 304: For any standard AD domain account data, based on the standard AD domain account data and the current AD domain account data corresponding to the standard AD domain account data, determine whether the current AD domain account data is a secure account;

[0093] In one embodiment, step 304 may be specifically implemented as: use a hash algorithm to perform hash calculation on the current AD domain account data to obtain a third hash value; and use a hash algorithm to perform hash calculation on the standard AD domain account data to obtain a fourth hash value. If the third hash value is the same as the fourth hash value, determine that the current AD domain account data is a secure account; if the third hash value is different from the fourth hash value, determine that the current AD domain account data is an insecure account.

[0094] Step 305: Determine whether all the current AD domain account data are secure accounts. If so, execute step 306. If not, execute step 307;

[0095] Step 306: Determine that the security detection result is that the AD domain system is secure;

[0096] Step 307: Determine that the security detection result is that the AD domain system is insecure.

[0097] In one embodiment, the current AD domain account data corresponding to the standard AD domain account data is determined in the following manner:

[0098] For any standard AD domain account data, use the index of the standard AD domain account data to find the current AD domain account data in the current AD domain account data whose index is the same as that of the standard AD domain account data; and, determine the found current AD domain account data as the current AD domain account data corresponding to the standard AD domain account data.

[0099] Step 203: If it is determined that the security detection result is that the AD domain system is insecure, then perform a security warning.

[0100] In the embodiment of the present application, the security warning method may be to send the insecure accounts to the terminal device for display to prompt the staff to determine the reason for the account change to discover potential attack behaviors.

[0101] To further understand the technical solution of the present disclosure, the following is combined with Figure 4 for a detailed description, which may include the following steps:

[0102] Step 401: In response to a specified duration setting instruction sent by the user, set the specified duration based on the specified duration setting instruction;

[0103] Step 402: Every specified duration, obtain the current AD domain account data in the AD domain system;

[0104] Step 403: Use the hash algorithm to perform a hash calculation on the current AD domain account data to obtain the first hash value corresponding to the current AD domain account data;

[0105] Step 404: Use the hash algorithm to perform a hash calculation on the current standard AD domain account data to obtain the second hash value corresponding to the current standard AD domain account data;

[0106] Step 405: Determine that the first hash value is different from the second hash value. If so, execute step 406. If not, execute step 413;

[0107] Step 406: For any standard AD domain account data, use the hash algorithm to perform a hash calculation on the standard AD domain account data to obtain the fourth hash value;

[0108] Step 407: Calculate the hash value of the current AD domain account data corresponding to the standard AD domain account data by using the hash algorithm to obtain a third hash value;

[0109] Step 408: Determine whether the third hash value is the same as the fourth hash value. If so, execute Step 409; if not, execute Step 410;

[0110] Step 409: Determine that the current AD domain account data is a secure account;

[0111] Step 410: Determine that the current AD domain account data is an insecure account;

[0112] Step 411: Determine whether all the current AD domain account data are secure accounts. If so, execute Step 412; if not, execute Step 413;

[0113] Step 412: Determine that the security detection result is that the AD domain system is secure;

[0114] Step 413: Determine that the security detection result is that the AD domain system is insecure and issue a security warning.

[0115] Based on the same inventive concept, the above-described security warning method for an AD domain system according to the present disclosure can also be implemented by a security warning device for an AD domain system. The effects of the security warning device for an AD domain system are similar to those of the foregoing method and will not be elaborated herein.

[0116] Figure 5 It is a schematic structural diagram of a security warning device for an AD domain system according to an embodiment of the present disclosure.

[0117] As Figure 5 shown, the security warning device 500 for an AD domain system according to the present disclosure may include an acquisition module 510, a security detection module 520, and a security warning module 530.

[0118] The acquisition module 510 is configured to acquire the current AD domain account data in the AD domain system at intervals of a specified duration;

[0119] The security detection module 520 is configured to perform a security detection on the AD domain system according to the current AD domain account data and the preset standard AD domain account data to obtain a security detection result;

[0120] The security warning module 530 is configured to issue a security warning if it is determined that the security detection result is that the AD domain system is insecure.

[0121] In one embodiment, the security detection module 520 is specifically configured to:

[0122] Performing a hash calculation on the current AD domain account data using a hash algorithm to obtain a first hash value corresponding to the current AD domain account data; and,

[0123] Performing a hash calculation on the current standard AD domain account data using a hash algorithm to obtain a second hash value corresponding to the current standard AD domain account data;

[0124] If the first hash value is different from the second hash value, determining that the security detection result is that the AD domain system is insecure;

[0125] If the first hash value is the same as the second hash value, then for any standard AD domain account data, based on the standard AD domain account data and the corresponding current AD domain account data, determining whether the current AD domain account data is a secure account;

[0126] If all the current AD domain account data are secure accounts, determining that the security detection result is that the AD domain system is secure;

[0127] If there is at least one insecure account among the current AD domain account data, determining that the security detection result is that the AD domain system is insecure.

[0128] In one embodiment, the device further includes:

[0129] A security detection result determination module 540, configured to determine that the security detection result is that the system is insecure if there is no corresponding current AD domain account data for the standard AD domain account data.

[0130] In one embodiment, when the security detection module 520 performs the determination of whether the current AD domain account data is a secure account based on the standard AD domain account data and the corresponding current AD domain account data, it is specifically configured to:

[0131] Performing a hash calculation on the current AD domain account data using a hash algorithm to obtain a third hash value; and,

[0132] Performing a hash calculation on the standard AD domain account data using a hash algorithm to obtain a fourth hash value;

[0133] If the third hash value is the same as the fourth hash value, determining that the current AD domain account data is a secure account;

[0134] If the third hash value is different from the fourth hash value, determining that the current AD domain account data is an insecure account.

[0135] In one embodiment, the device further includes:

[0136] A matching module 550, configured to determine current AD domain account data corresponding to the standard AD domain account data in the following manner:

[0137] For any standard AD domain account data, using the index of the standard AD domain account data, search for current AD domain account data with the same index as the standard AD domain account data from the current AD domain account data; and,

[0138] Determine the found current AD domain account data as the current AD domain account data corresponding to the standard AD domain account data.

[0139] In one embodiment, the device further includes:

[0140] A duration setting module 560, configured to, every specified duration, before obtaining the current AD domain account data in the AD domain system, in response to a specified duration setting instruction sent by the user, set the specified duration based on the specified duration setting instruction.

[0141] After introducing a security warning method and device for an AD domain system according to an exemplary embodiment of the present disclosure, next, an electronic device according to another exemplary embodiment of the present disclosure will be introduced.

[0142] Those skilled in the art can understand that various aspects of the present disclosure can be implemented as a system, a method, or a program product. Therefore, various aspects of the present disclosure can be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to as "circuitry", "module", or "system" here.

[0143] In some possible implementation manners, an electronic device according to the present disclosure may at least include at least one processor and at least one computer storage medium. Among them, the computer storage medium stores program code, and when the program code is executed by the processor, the processor executes the steps in the security warning method for an AD domain system according to various exemplary embodiments of the present disclosure described above in this specification. For example, the processor may execute steps 201 - 203 as shown in Figure 2 shown in.

[0144] Next, refer to Figure 6 to describe the electronic device 600 according to this embodiment of the present disclosure. Figure 6 The shown electronic device 600 is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.

[0145] As shown Figure 6 As shown in Figure 6 , the electronic device 600 is presented in the form of a general electronic device. The components of the electronic device 600 may include, but are not limited to: the at least one processor 601 described above, the at least one computer storage medium 602 described above, and a bus 603 that connects different system components (including the computer storage medium 602 and the processor 601).

[0146] The bus 603 represents one or more of several types of bus structures, including a computer storage medium bus or a computer storage medium controller, a peripheral bus, a processor, or a local bus using any of the various bus structures.

[0147] The computer storage medium 602 may include a readable medium in the form of a volatile computer storage medium, such as a random access computer storage medium (RAM) 621 and / or a cache storage medium 622, and may further include a read-only computer storage medium (ROM) 623.

[0148] The computer storage medium 602 may also include a program / utilities 625 having a set (at least one) of program modules 624. Such program modules 624 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include an implementation of a network environment.

[0149] The electronic device 600 may also communicate with one or more external devices 604 (such as a keyboard, a pointing device, etc.), may also communicate with one or more devices that enable a user to interact with the electronic device 600, and / or may communicate with any device that enables the electronic device 600 to communicate with one or more other electronic devices (such as a router, a modem, etc.). Such communication may be carried out through an input / output (I / O) interface 605. Moreover, the electronic device 600 may also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter 606. As shown in the figure, the network adapter 606 communicates with other modules for the electronic device 600 through the bus 603. It should be understood that although not shown in the figure, other hardware and / or software modules may be used in conjunction with the electronic device 600, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0150] In some possible embodiments, various aspects of a security warning method for an AD domain system provided by the present disclosure can also be implemented in the form of a program product, which includes program code. When the program product runs on a computer device, the program code is used to cause the computer device to execute the steps in the security warning method for the AD domain system according to various exemplary embodiments of the present disclosure described above in this specification.

[0151] The program product can adopt any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access computer storage medium (RAM), a read-only computer storage medium (ROM), an erasable programmable read-only computer storage medium (EPROM or flash memory), an optical fiber, a portable compact disk read-only computer storage medium (CD-ROM), an optical computer storage medium, a magnetic computer storage medium, or any suitable combination of the above.

[0152] The program product of the security warning of the AD domain system according to the embodiments of the present disclosure can adopt a portable compact disk read-only computer storage medium (CD-ROM) and include program code, and can run on an electronic device. However, the program product of the present disclosure is not limited to this. In this document, the readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0153] The readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal can take various forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. The readable signal medium can also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0154] The program code contained on the readable medium can be transmitted by any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination of the above.

[0155] The program code for performing the operations of the present disclosure can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's electronic device, partially on the user's device, executed as a stand-alone software package, partially on the user's electronic device and partially on a remote electronic device, or entirely on a remote electronic device or server. In cases involving a remote electronic device, the remote electronic device can be connected to the user's electronic device through any type of network including a local area network (LAN) or a wide area network (WAN), or, alternatively, can be connected to an external electronic device (e.g., by connecting through the Internet using an Internet service provider).

[0156] It should be noted that although several modules of the device are mentioned in the above detailed description, this division is merely exemplary and not mandatory. In fact, according to the embodiments of the present disclosure, the features and functions of two or more of the above-described modules can be embodied in one module. Conversely, the features and functions of one module described above can be further divided and embodied by multiple modules.

[0157] In addition, although the operations of the method of the present disclosure are described in a specific order in the drawings, this does not require or imply that the operations must be performed in that specific order, or that all of the shown operations must be performed to achieve the desired result. Additionally or alternatively, certain steps can be omitted, multiple steps can be combined into one step for execution, and / or one step can be decomposed into multiple steps for execution.

[0158] Those skilled in the art should understand that the embodiments of the present disclosure can be provided as a method, a system, or a computer program product. Therefore, the present disclosure can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic computer storage media, CD-ROM, optical computer storage media, etc.) containing computer-usable program code.

[0159] The present disclosure is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the present disclosure. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to generate a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices generate means for implementing the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0160] These computer program instructions can also be stored in a computer-readable computer storage medium that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable computer storage medium generate a manufactured article including instruction means that implement the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0161] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in the Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.

[0162] Obviously, those skilled in the art can make various changes and modifications to the present disclosure without departing from the spirit and scope of the present disclosure. Thus, if these modifications and variations of the present disclosure fall within the scope of the claims of the present disclosure and their equivalent technologies, the present disclosure is also intended to include these changes and modifications.

Claims

1. A security warning method for an AD domain system, characterized in that, The method includes: Obtaining the current AD domain account data in the AD domain system at every specified time interval; Performing a security detection on the AD domain system according to the current AD domain account data and the preset standard AD domain account data to obtain a security detection result; If it is determined that the security detection result is that the AD domain system is insecure, a security warning is issued.

2. The method according to claim 1, characterized in that, The performing a security detection on the AD domain system according to the current AD domain account data and the preset standard AD domain account data to obtain a security detection result includes: Performing a hash calculation on the current AD domain account data by using a hash algorithm to obtain a first hash value corresponding to the current AD domain account data; and, Performing a hash calculation on the current standard AD domain account data by using a hash algorithm to obtain a second hash value corresponding to the current standard AD domain account data; If the first hash value is different from the second hash value, it is determined that the security detection result is that the AD domain system is insecure; If the first hash value is the same as the second hash value, for any standard AD domain account data, based on the standard AD domain account data and the corresponding current AD domain account data, determining whether the current AD domain account data is a secure account; If all the current AD domain account data are secure accounts, it is determined that the security detection result is that the AD domain system is secure; If there is at least one insecure account in the current AD domain account data, it is determined that the security detection result is that the AD domain system is insecure.

3. The method according to claim 2, characterized in that, The method further includes: If there is no corresponding current AD domain account data for the standard AD domain account data, it is determined that the security detection result is that the system is insecure.

4. The method according to claim 2, wherein The determining whether the current AD domain account data is a secure account based on the standard AD domain account data and the corresponding current AD domain account data includes: Performing a hash calculation on the current AD domain account data by using a hash algorithm to obtain a third hash value; and, Performing a hash calculation on the standard AD domain account data by using a hash algorithm to obtain a fourth hash value; If the third hash value is the same as the fourth hash value, it is determined that the current AD domain account data is a secure account; If the third hash value is different from the fourth hash value, it is determined that the current AD domain account data is an insecure account.

5. The method according to any one of claims 2 to 4, characterized in that, The current AD domain account data corresponding to the standard AD domain account data is determined by the following method: For any standard AD domain account data, using the index of the standard AD domain account data to find the current AD domain account data in the current AD domain account data whose index is the same as the index of the standard AD domain account data; And, Determining the found current AD domain account data as the current AD domain account data corresponding to the standard AD domain account data.

6. The method according to claim 1, characterized in that, Before the obtaining the current AD domain account data in the AD domain system at every specified time interval, the method further includes: In response to a specified duration setting instruction sent by a user, set the specified duration based on the specified duration setting instruction.

7. A security protection device for an AD domain, characterized in that, The device includes: An acquisition module, configured to acquire current AD domain account data in the AD domain system every specified duration; A security detection module, configured to perform a security detection on the AD domain system according to the current AD domain account data and preset standard AD domain account data, and obtain a security detection result; A security warning module, configured to perform a security warning if it is determined that the security detection result is that the AD domain system is insecure.

8. The device according to claim 7, characterized in that, The security detection module is specifically configured to: Perform a hash calculation on the current AD domain account data by using a hash algorithm to obtain a first hash value corresponding to the current AD domain account data; And, Perform a hash calculation on the current standard AD domain account data by using a hash algorithm to obtain a second hash value corresponding to the current standard AD domain account data; If the first hash value is different from the second hash value, determine that the security detection result is that the AD domain system is insecure; If the first hash value is the same as the second hash value, for any standard AD domain account data, determine whether the current AD domain account data is a secure account based on the standard AD domain account data and the current AD domain account data corresponding to the standard AD domain account data; If all the current AD domain account data are secure accounts, determine that the security detection result is that the AD domain system is secure; If there is at least one insecure account in the current AD domain account data, determine that the security detection result is that the AD domain system is insecure.

9. An electronic device, characterized in that, Comprising at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executed by the at least one processor; the instructions are executed by the at least one processor so that the at least one processor can execute the method according to any one of claims 1-6.

10. A computer storage medium, characterized in that, The computer storage medium stores a computer program, and the computer program is used to execute the method according to any one of claims 1-6.