Management software security maintenance method based on Internet information technology
Through the security maintenance method of blockchain and zero-trust architecture combined with machine learning, the problem of opacity and inefficient vulnerability response in traditional management software is solved, fine-grained access control and dynamic permission management are realized, the system's security and response speed are improved, and the protection ability of new attacks is enhanced.
Patent Information
- Application Number
- CN202510173059.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-17
- Publication Date
- 2025-07-08
AI Technical Summary
The security maintenance of traditional management software relies on traditional security protection mechanisms, and there are problems such as opaque patch management, inefficient vulnerability response, and insufficient protection of unknown threats.
Adopt security maintenance methods based on Internet information technology to ensure the immutability of patch management and vulnerability repair processes through blockchain, combine zero-trust architecture and dynamic behavior analysis to achieve fine-grained access control and permission management, use machine learning and blockchain to automatically detect and repair vulnerability, improve vulnerability response speed, and optimize user experience through multi-factor authentication and behavior analysis.
It improves the transparency of patch management and vulnerability response efficiency, enhances the protection ability of new attacks, reduces the complexity of authentication, improves the flexibility and scalability of the system, and enhances the security of intranet resources.
Smart Images

Figure CN120277672A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of data security, and particularly relates to a method for securely maintaining a management software based on Internet information technology. Background Art
[0002] Currently, the security maintenance of management software mainly relies on traditional security protection mechanisms, including patch management, authentication, access control, and vulnerability response, etc. Most of these mechanisms focus on the protection against known security threats and vulnerabilities, and ensure the security of the software through means such as regular patch updates, vulnerability scanning, authentication, and access control.
[0003] Deficiencies of the prior art:
[0004] Traditional patch management relies on manual operations or automated tools for patch release and update. The patch content is managed through a single storage and distribution method, and there are risks of patch tampering, loss, or unauthenticated use.
[0005] Current authentication methods usually rely on means such as passwords and dynamic passwords, but there is insufficient real-time analysis of user behavior and dynamic adjustment of permissions. Traditional access control models are also easily bypassed, especially in the face of internal threats.
[0006] Vulnerability response is usually based on static vulnerability databases or behavioral log analysis, but these methods often rely on manual input, have risks of missed reports and false reports, and lack the ability to quickly respond to new types of vulnerabilities.
[0007] Many enterprises and organizations still rely on firewalls, virus scans, and simple intrusion detection systems (IDS). These technologies often cannot provide real-time protection when dealing with complex and rapidly changing network attacks (such as zero-day vulnerabilities, internal network attacks, etc.). Summary of the Invention
[0008] The object of the present invention is to provide a method for securely maintaining a management software based on Internet information technology, which solves the technical problems of opaque patch management, low efficiency of vulnerability response, and insufficient protection against unknown threats existing in traditional network security management.
[0009] To achieve the above object, the present invention adopts the following technical solution:
[0010] A method for securely maintaining a management software based on Internet information technology, comprising the following steps:
[0011] Step 1: After the user uploads a patch at the user interaction layer, the patch management layer realizes the release, verification, and deployment of the patch, specifically including: In the patch release phase, digital signatures are applied to the patch content through hashing and encryption algorithms, and both the signature and the patch data are recorded on the blockchain; in the patch verification phase, the signature is verified using the public key at the time of release; the patch that passes the verification will enter the patch deployment phase in Step 3;
[0012] Step 2: Perform authentication and access control based on the zero-trust architecture in the security verification and control layer, specifically including: Judging the normal behavior of the user through multi-factor authentication and behavioral analysis models; evaluating risks through multi-dimensional data, generating a risk score, and judging whether the request meets the access standard. If the risk score exceeds the set threshold, the request is rejected; through fine-grained isolation, the internal network resources are divided into multiple independent areas to ensure that attackers can only operate within one isolation area; multi-dimensional data includes user identity, device status, geographical location, and access time;
[0013] Step 3: Detect, repair, and optimize vulnerabilities in the vulnerability response and repair layer, specifically including: Identifying potential vulnerabilities through static code analysis and behavioral analysis, using machine learning algorithms to analyze behavioral patterns, and outputting potential vulnerabilities and threat levels; Automatically deploying patches through the blockchain and smart contracts, and recording repair events; Analyzing the effect after vulnerability repair through a reinforcement learning model to optimize the strategy process of vulnerability detection and repair;
[0014] Step 4: Real-time optimize security management through machine learning and dynamic behavior analysis in the machine learning and behavior analysis layer, specifically including: Analyzing historical vulnerability data through machine learning algorithms, predicting and identifying new types of vulnerabilities, and generating repair solutions; Analyzing the behavioral patterns of users and devices through machine learning, and adjusting access permissions in real time to ensure that each request is within the scope of credibility.
[0015] Preferably, the user interaction layer provides a front-end user interface, and the specific devices are Web clients and mobile clients. The user performs management authentication, requests access, views patch information, vulnerability repair progress, and uploads patches through the front-end user interface; the interaction between the client and the server is carried out through the RESTful API;
[0016] The security verification and control layer provides authentication services, request verification services, and zero-trust authentication & micro-isolation services:
[0017] The authentication service is used to perform multi-factor authentication and verify the user's identity using a behavioral analysis model;
[0018] The request verification service is used to judge whether to allow the request to pass according to the multi-dimensional risk assessment model;
[0019] Zero Trust Identity Authentication & Microsegmentation Service is used to enforce access control in real time, ensuring that users can only access the resources they are authorized to. Microsegmentation Service isolates internal network resources based on SDN technology;
[0020] The Patch Management Layer provides patch release services, blockchain smart contract services, and patch verification and deployment services:
[0021] The patch release service is used to release patches through blockchain and smart contracts;
[0022] The blockchain smart contract service is responsible for managing patch data, including patch release, verification, and deployment;
[0023] The patch verification and deployment service is used to perform signature verification of patch content and automatically push the verified patches to the Vulnerability Response and Repair Layer, store them in the vulnerability library, and wait for the deployment of patches to be executed;
[0024] The Vulnerability Response and Repair Layer provides vulnerability scanning and detection services, automated repair push services, and vulnerability classification and repair services:
[0025] The vulnerability scanning and detection service is used to detect potential vulnerabilities using static code analysis and behavior analysis tools, and automatically classify and evaluate vulnerability risks in combination with machine learning algorithms;
[0026] The automated repair push service is used to automatically push patches through smart contracts and deploy them to affected terminals;
[0027] The vulnerability classification and repair service is used to classify the discovered vulnerabilities and evaluate risks, and generate repair plans according to the threat level;
[0028] The Data Storage and Blockchain Layer provides a blockchain network, IPFS storage, and a NoSQL database:
[0029] The blockchain network is used to store immutable records of key operations such as patch release, verification, deployment, and vulnerability repair;
[0030] IPFS storage is used to store patch files;
[0031] The NoSQL database is used to store logs, behavior data, and vulnerability scanning results;
[0032] The Machine Learning and Behavior Analysis Layer provides behavior analysis and anomaly detection services, vulnerability classification and prediction services, and dynamic permission adjustment services:
[0033] The behavior analysis and anomaly detection service is used to monitor user behavior and device status in real time and detect abnormal behavior using machine learning algorithms;
[0034] The vulnerability classification and prediction service is used to analyze historical vulnerability data and predict and classify new vulnerabilities using machine learning algorithms;
[0035] The dynamic permission adjustment service is used to adjust the access permissions of users through real-time behavior analysis to ensure that each request is evaluated based on credibility.
[0036] Preferably, when performing step 1, the specific steps are as follows:
[0037] Step 1-1: Patch release. The user or administrator submits the patch content P through the front-end user interface, and the front-end user interface transmits the patch content P to the patch release service;
[0038] The patch release service uses the RSA algorithm to generate the hash value H(P) of the patch:
[0039] H(P) = SHA256(P);
[0040] Then, a digital signature is performed on the hash value H(P) to generate the signature S:
[0041] S = Sign(Prk, H(P));
[0042] where Prk is the private key;
[0043] The signature S and the patch content P are recorded in the blockchain through the smart contract service;
[0044] Step 1-2: Patch verification. The public key PubK is used to verify the signature S and the hash value H(P) of the patch;
[0045] Verification formula: Verify(PubK, S, H(P)) = true; if the verification is valid, it means the patch is legal, and the patch is pushed to the vulnerability response and repair layer.
[0046] Preferably, when performing step 2, the specific steps are as follows:
[0047] Step 2-1: User authentication. Multi-factor authentication of the user identity is performed, including password verification and fingerprint verification; the machine learning KNN algorithm is used to analyze the user behavior, establish a normal behavior pattern, calculate the distance of the behavior pattern, and if abnormal behavior is found, secondary authentication is triggered; both the user verification information and the behavior records are recorded through the blockchain;
[0048] Step 2-2: Request verification and access decision. The user identity, device status, geographical location, and access time of the requester are collected; the risk score is calculated using the comprehensive scoring model R: R = w1×f(U) + w2×f(D) + w3×f(L) + w4×f(T) + w5
[0049] ×f(B);
[0050] Wherein, R is the risk score, w1, w2, w3, w4, w5 are all weight coefficients, f(U) is the risk function of the user identity, f(D) is the risk function of the device status, f(L) is the risk function of the geographical location, f(T) is the risk function of the time window, and f(B) is the risk function of the behavior pattern;
[0051] If the calculation result of the comprehensive scoring model R exceeds the set threshold, the request is rejected, otherwise access is allowed;
[0052] The risk assessment results of all requests are recorded in the blockchain through smart contracts;
[0053] Step 2-3: Micro-segmentation and access control. Divide the internal network resources into multiple isolation areas. Each isolation area only allows access by preset specific users. Manage resource access through SDN, dynamically adjust the access policy, and record the access control information of each resource and the isolation area configuration.
[0054] Preferably, when performing Step 2-1, the specific formula for calculating the distance of the behavior pattern is as follows:
[0055]
[0056] Where x i is the historical behavior, belonging to the historical behavior data set X = [x1, x2,..., x n , and y i is the current behavior, belonging to the current behavior data set Y = [y1, y2,..., y n .
[0057] Preferably, when performing Step 3, the specific steps are as follows:
[0058] Step 3-1: Vulnerability detection and behavior analysis. Use static code analysis tools and behavior analysis tools to identify vulnerabilities, perform behavior analysis using machine learning algorithms, output potential vulnerabilities and risk assessments, and record the vulnerability detection results through the blockchain;
[0059] Step 3-2: Vulnerability repair and automated deployment. Automatically obtain patches from the vulnerability library, push the patches to the terminal devices through smart contracts, and record the repair events;
[0060] Step 3-3: Feedback and optimization. Collect the data after vulnerability repair, and optimize the vulnerability detection and repair process through reinforcement learning. The specific optimization formula is as follows:
[0061] Rnew = α × Rold + β × Feedback(P);
[0062] Among them, Rnew is the new risk score, representing the updated value after adjustment based on the current feedback. α is the weight coefficient, controlling the proportion of the old risk score Rold in the new score Rnew. β is another weight coefficient, which controls the proportion of Feedback(P) in Rnew, and β + α = 1. Feedback(P) is the feedback information, usually representing the evaluation made by the system on the current behavior or state. For example, a certain patch is repaired successfully and effectively.
[0063] Optimize the strategy process of vulnerability detection and repair through feedback data.
[0064] Preferably, when performing step 3-1, a classification model is established through historical vulnerability data to classify the vulnerabilities and evaluate their risk levels. The specific classification model is as follows:
[0065] T = w6 × f(vulnerabilityType) + w7 × f(impact) + w8 × f(att
[0066] ackProbability);
[0067] Among them, T represents the threat level, w6, w7, and w8 are all weight coefficients, f(vulnerabil ityType) is the vulnerability type function, f(impact) is the vulnerability impact function, and f(attack Probability) is the attack probability function.
[0068] Preferably, when performing step 4, the specific steps are as follows:
[0069] Step 4-1: Machine learning and dynamic behavior analysis. Use the KNN algorithm to classify and analyze historical vulnerability data, predict new types of vulnerabilities, and evaluate the threat level based on the type, impact, and attack probability of the new vulnerabilities. The classification model is as follows:
[0070] C = argmax(f(vulnerabilityType), f(impact), f(attackProba bility);
[0071] Among them, C represents the classification result, f(vulnerabilityType) is the vulnerability type function, f(impact) is the vulnerability impact function, and f(attackProbability) is the attack probability function;
[0072] The classification results and prediction information will be stored in the blockchain;
[0073] Step 4-2: Dynamic Behavior Analysis and Permission Adjustment. Use machine learning algorithms to analyze the behavior data of users and devices, calculate the trust score based on the behavior analysis results, and dynamically adjust the access permissions. The trust score formula is as follows:
[0074] Tuser = w9 × f(u) + w 10 × f(b) + w 11 × f(d);
[0075] Among them, Tuser represents the trust score of the user, w9, w 10 , w 11 are all weight coefficients, f(u) is the risk function of user behavior, f(b) is the risk function of device status, and f(d) is the risk function of user data;
[0076] The user behavior analysis results and permission adjustment records will be stored in the blockchain.
[0077] A security maintenance method for management software based on Internet information technology according to the present invention solves the technical problems existing in traditional network security management, such as opaque patch management, low efficiency of vulnerability response, and insufficient protection against unknown threats. The present invention ensures the immutability and transparency of the patch management and vulnerability repair processes through the blockchain, effectively preventing patch tampering and malicious software intrusion. Through the zero-trust architecture and dynamic behavior analysis, fine-grained access control and permission management are achieved, ensuring that only requests that have been verified in real time can access the system, improving the security of internal network resources. Combining machine learning with blockchain for automated vulnerability detection, classification, and repair improves the vulnerability response speed, reduces the need for manual intervention, and enhances the system's protection ability against new attacks. Through multi-factor authentication and machine learning-driven behavior analysis, intelligent detection and dynamic adjustment of user behavior are achieved, greatly reducing the complexity in the authentication process and improving the user experience. By using micro-segmentation technology to divide the internal network resources into multiple isolation areas, the scope of potential attacks is reduced, enhancing the flexibility and scalability of the system. Brief Description of the Drawings
[0078] Figure 1 is the main flowchart of the present invention;
[0079] Figure 2 is the system architecture diagram of the present invention;
[0080] Figure 3 is the flowchart of Step 1 of the present invention;
[0081] Figure 4 is the flowchart of Step 2 of the present invention;
[0082] Figure 5 is the flowchart of Step 3 of the present invention;
[0083] Figure 6 It is the flowchart of step 4 of the present invention. Detailed implementation manners
[0084] From Figures 1-6 A security maintenance method for management software based on Internet information technology shown as follows includes the following steps:
[0085] Step 1: After the user uploads a patch at the user interaction layer, the patch management layer realizes the release, verification, and deployment of the patch. Specifically, it includes: in the patch release stage, the patch content is digitally signed through hash and encryption algorithms, and both the signature and the patch data are recorded in the blockchain; in the patch verification stage, the signature is verified using the public key at the time of release; the patch that passes the verification will enter the patch deployment stage in step 3;
[0086] When implementing step 1, the specific steps are as follows:
[0087] Step 1-1: Patch release. The user or administrator submits the patch content P through the front-end user interface, and the front-end user interface transmits the patch content P to the patch release service;
[0088] The patch release service uses the RSA algorithm to generate the hash value H(P) of the patch:
[0089] H(P) = SHA256(P);
[0090] Then, the digital signature is performed on the hash value H(P) to generate the signature S:
[0091] S = Sign(Prk, H(P));
[0092] where Prk is the private key;
[0093] The signature S and the patch content P are recorded in the blockchain through the smart contract service;
[0094] This embodiment realizes the double guarantee of generating a hash value and a digital signature to ensure that the patch content is not tampered with.
[0095] Step 1-2: Patch verification. Use the public key PubK to verify the signature S and the hash value H(P) of the patch;
[0096] Verification formula: Verify(PubK, S, H(P)) = true; if the verification is valid, it means the patch is legal, and the patch is pushed to the vulnerability response and repair layer.
[0097] In this embodiment, the blockchain records are as follows:
[0098] After each patch release and verification, the relevant data will be pushed to the blockchain through a smart contract. Example of part of the smart contract code:
[0099]
[0100]
[0101] During the application process, each patch can create a record in the blockchain, including information such as the patch version, signature, push time, and related devices.
[0102] Step 2: Conduct authentication and access control based on the zero-trust architecture at the security verification and control layer, specifically including: judging the normal behavior of users through multi-factor authentication and behavior analysis models; evaluating risks through multi-dimensional data, generating risk scores, and judging whether the request meets the access criteria. If the risk score exceeds the set threshold, the request will be rejected; dividing the internal network resources into multiple independent areas through fine-grained isolation to ensure that attackers can only operate within one isolation area; multi-dimensional data includes user identity, device status, geographical location, and access time.
[0103] When implementing Step 2, the specific steps are as follows:
[0104] Step 2-1: User authentication, conduct multi-factor verification of user identity, including password verification and fingerprint verification; use the machine learning KNN algorithm to analyze user behavior, establish a normal behavior pattern, calculate the distance of the behavior pattern, and trigger secondary authentication if abnormal behavior is found; both user verification information and behavior records are recorded through the blockchain.
[0105] When implementing Step 2-1, the specific formula for calculating the distance of the behavior pattern is as follows:
[0106]
[0107] where x i is the historical behavior, belonging to the historical behavior data set X = [x1, x2,..., x n , and y i is the current behavior, belonging to the current behavior data set Y = [y1, y2,..., y n .
[0108] In this embodiment, abnormal behavior is detected through the result of Distance. x and y are various activities of the user in the system, such as logging in, accessing resources, performing certain operations, etc. By comparing the user's current behavior with their historical behavior, the system can identify whether there is abnormal behavior, for example:
[0109] Login operation:
[0110] Historical behavior data set X:
[0111] x1: User A logged in from the company IP address at 08:30 on January 1, 2024;
[0112] x2: User A logged in from the company IP address at 08:40 on January 2, 2024;
[0113] x3: User A logged in from the company IP address at 08:45 on January 3, 2024;
[0114] x4: User A logged in from the company IP address at 08:50 on January 4, 2024;
[0115] These data represent the login behavior of User A in the past few days. The X set contains multiple x elements, and each element represents a past login behavior.
[0116] Current behavior data set Y (behavior record of User D on the current day):
[0117] y1: User A logged in from the company network at 08:35 on January 5, 2024;
[0118] y2: User A logged in from outside the company at 09:30 on January 5, 2024.
[0119] This is the current login behavior of User A. It is compared with the historical behavior data in X to check for anomalies (such as logging in from an abnormal IP address):
[0120] y1: It is a normal login behavior because it occurred on the same network (company network) and at a similar time (around 8:30 in the morning).
[0121] y2: It may be an abnormal behavior because it occurred at a different IP address (outside the company), which means the user attempted to log in from an unauthorized location.
[0122] Step 2-2: Request verification and access decision. Collect the user identity, device status, geographical location, and access time of the requester; use the comprehensive scoring model R to calculate the risk score: R = w1×f(U) + w2×f(D) + w3×f(L) + w4×f(T) + w5
[0123] ×f(B);
[0124] Where R is the risk score, w1, w2, w3, w4, w5 are all weight coefficients, f(U) is the risk function of user identity, f(D) is the risk function of device status, f(L) is the risk function of geographical location, f(T) is the risk function of time window, and f(B) is the risk function of behavior pattern;
[0125] In this embodiment, f(U), f(D), f(L), f(T), and f(B) are all preset scoring functions. These programs are used to obtain corresponding risk scores by looking up tables based on different input parameters. Similar functions also include f(vulnerabilityType), f(impact), f(attackProbability), f(u), f(b), and f(d).
[0126] f(U) is used to evaluate the identity risk of the request initiator, which is usually determined by analyzing factors such as the user's role, permissions, and historical behavior:
[0127] Identity authentication method: According to the strength of the user's identity authentication (such as single-factor authentication, two-factor authentication, password strength, etc.), the higher the user's identity, the lower the risk;
[0128] User role and permissions: Based on the user's role and access permissions. If the user has high permissions or a special role (such as an administrator), additional security verification is required;
[0129] Historical behavior: If the user's past behavior shows anomalies or suspicious behavior (such as frequent access failures, historical violation records, etc.), the risk will increase.
[0130] f(D) is used to evaluate the security of the request-initiated device, mainly evaluated based on factors such as the device's health status, patch update status, and the presence of malware:
[0131] Operating system and software patches: The update status of the device's operating system and applications. If the device does not install the latest patches or has known vulnerabilities, the risk increases.
[0132] Security tools: Whether the device has security tools such as antivirus software and endpoint detection and response (EDR). The lack of these tools will increase the risk.
[0133] Device credibility: Determine whether the device is credible based on the device ID, device type, and the device's historical behavior.
[0134] f(L) is used to evaluate the geographical location risk of the request initiator, usually by judging whether the request comes from a geographical location outside the normal activity range to evaluate the risk:
[0135] Normal location: If the request comes from the user's usual geographical location, the risk is lower.
[0136] Abnormal location: If the request comes from a new and uncommon geographical location, especially from a high-risk country or region, the risk increases.
[0137] IP Geolocation and VPN: If a user uses anonymous services such as VPN, proxy, or TOR, it may be a sign of malicious activity, increasing the risk.
[0138] f(T) is used to evaluate whether there is a risk in the time when the request is initiated. For example, some unusual time windows (such as nights, holidays, etc.) may have potential security risks:
[0139] Normal working hours: Users usually initiate requests during working hours (such as 9:00 - 18:00), and the risk is relatively low.
[0140] Abnormal time: If a request is initiated outside of working hours (such as late at night or on holidays), especially when the user does not usually operate at these times, the risk will increase.
[0141] Historical time pattern: If this user is historically accustomed to initiating requests during a specific time period, requests outside of this time period will be regarded as abnormal.
[0142] f(B) is used to evaluate whether the behavior of the request initiator conforms to the normal pattern. By analyzing the differences between the user's historical behavior and current behavior, it is judged whether there are potential security risks:
[0143] Behavior consistency: If the user's current behavior is consistent with their historical behavior pattern (such as the pages visited, operation frequency, request type, etc.), the risk is relatively low.
[0144] Abnormal behavior: If the user's behavior deviates from their normal behavior pattern (such as frequently operating at different time periods, accessing sensitive resources, etc.), the risk increases.
[0145] Machine learning and pattern recognition: Through historical data, machine learning models (such as KNN, clustering analysis, etc.) are used to identify abnormal behavior patterns.
[0146] If the calculation result of the comprehensive scoring model R exceeds the set threshold, the request is rejected; otherwise, access is allowed.
[0147] The risk assessment results of all requests are recorded in the blockchain through smart contracts;
[0148] Step 2 - 3: Micro - isolation and access control. The internal network resources are divided into multiple isolation areas, and each isolation area only allows preset specific users to access. The resource access is managed through SDN (Software - Defined Network), the access policy is dynamically adjusted, and the access control information and isolation area configuration of each resource are recorded.
[0149] SDN (Software - Defined Network) is a design method for a network architecture. It decouples the centralized control plane from the data plane, making the control and management of the network more flexible and programmable. It is an existing technology, so it will not be described in detail.
[0150] Step 3: Detect, repair, and optimize vulnerabilities in the vulnerability response and repair layer, specifically including: identifying potential vulnerabilities through static code analysis and behavior analysis, using machine learning algorithms for behavior pattern analysis, and outputting potential vulnerabilities and threat levels; automatically deploying patches through blockchain and smart contracts and recording repair events; analyzing the effect after vulnerability repair through a reinforcement learning model and optimizing the strategy process of vulnerability detection and repair;
[0151] When performing Step 3, the specific steps are as follows:
[0152] Step 3-1: Vulnerability detection and behavior analysis, using static code analysis tools and behavior analysis tools to identify vulnerabilities, using machine learning algorithms for behavior analysis, outputting potential vulnerabilities and risk assessments, and recording the vulnerability detection results through blockchain;
[0153] Step 3-2: Vulnerability repair and automatic deployment, automatically obtaining patches from the vulnerability library, pushing patches to terminal devices through smart contracts, and recording repair events;
[0154] Step 3-3: Feedback and optimization, collecting data after vulnerability repair, and optimizing the vulnerability detection and repair process through reinforcement learning. The specific optimization formula is as follows:
[0155] Rnew = α × Rold + β × Feedback(P);
[0156] Where Rnew is the new risk score, representing the updated value after adjustment based on the current feedback. α is the weight coefficient, controlling the proportion of the old risk score Rold in the new score Rnew. β is another weight coefficient, which controls the proportion of Feedback(P) in Rnew, and β + α = 1. Feedback(P) is the feedback information, usually representing the evaluation made by the system on the current behavior or state. For example, a certain patch repair is successful and effective.
[0157] Optimize the strategy process of vulnerability detection and repair through feedback data.
[0158] Preferably, when performing Step 3-1, establish a classification model to classify vulnerabilities through historical vulnerability data and evaluate their risk levels. The specific classification model is as follows:
[0159] T = w6 × f(vulnerabilityType) + w7 × f(impact) + w8 × f(att
[0160] ackProbability);
[0161] Among them, T represents the threat level, w6, w7, and w8 are all weight coefficients, f(vulnerabilityType) is the vulnerability type function, f(impact) is the vulnerability impact function, and f(attackProbability) is the attack probability function.
[0162] In this embodiment, f(vulnerabilityType) is used to evaluate the risk of vulnerabilities according to the types of vulnerabilities (for example, buffer overflow, SQL injection, cross-site scripting, etc.). Different types of vulnerabilities will have different degrees of impact. Therefore, this function can be set to give a numerical value according to the type of vulnerability, usually a standardized score based on the vulnerability type (such as a score from 1 to 10).
[0163] f(impact) is used to measure the potential damage to the system, data, or business once a vulnerability is exploited by an attacker. For example, a certain vulnerability may cause data leakage, system crash, or resource leakage, etc. The impact score corresponding to the damage is preset in this function, and the impact score reflects the severity of these potential consequences.
[0164] f(attackProbability) is used to measure the likelihood of a vulnerability being exploited by an attacker. For example, the attack probability is usually determined by multiple factors, including the publicity of the vulnerability, the history of the vulnerability being widely exploited, the ease of exploitation of the vulnerability, etc. Vulnerabilities with a high probability usually have a higher threat level because they are more likely to be exploited by attackers.
[0165] Step 4: Optimize security management in real time through machine learning and behavioral analysis in the machine learning and behavioral analysis layer, specifically including: analyzing historical vulnerability data through machine learning algorithms, predicting and identifying new types of vulnerabilities, and generating repair solutions; analyzing the behavioral patterns of users and devices through machine learning, and adjusting access permissions in real time to ensure that each request is within the scope of credibility.
[0166] When performing Step 4, the specific steps are as follows:
[0167] Step 4-1: Machine learning and dynamic behavior analysis, using the KNN algorithm to classify and analyze historical vulnerability data, predict new types of vulnerabilities, and evaluate the threat level according to the type, impact, and attack probability of the new types of vulnerabilities. The classification model is as follows:
[0168] C = argmax(f(vulnerabilityType), f(impact), f(attackProbability));
[0169] Among them, C represents the classification result, f(vulnerabilityType) is the vulnerability type function, f(impact) is the vulnerability impact function, and f(attackProbability) is the attack probability function;
[0170] The classification result and prediction information will be stored in the blockchain;
[0171] In this embodiment, the KNN algorithm is first used to analyze the historical vulnerability data. The historical vulnerability data contains a large amount of vulnerability information, such as characteristic data like vulnerability type, vulnerability description, attack method, and impact scope. The KNN algorithm will classify the vulnerabilities according to the characteristics of the historical data. The core idea of the KNN algorithm is that for a new vulnerability, its category is determined by the categories of the K nearest neighbors to it.
[0172] Extract key features from the historical vulnerability data, such as the type of vulnerability (e.g., SQL injection, buffer overflow, etc.), the impact of the vulnerability, the attack probability, the repair difficulty, etc.
[0173] Convert these features into numerical forms and provide them as input data to the KNN model.
[0174] When the system receives a newly reported vulnerability, although the vulnerability itself is already known, it may not have been classified or discovered in some environments yet. The purpose of prediction is to help the system predict potential unreported or not fully understood vulnerabilities based on historical data and the characteristics of known vulnerabilities, especially new attack methods or possible attack vectors.
[0175] Many times, hackers will use a new type of attack method, which may not be fully reflected in the historical vulnerability data. The machine learning model can make a "pre-judgment" based on the existing vulnerability data. If the characteristics of a certain attack method are similar to known vulnerabilities, the system can predict the possibility of similar attacks and take preventive measures in a timely manner.
[0176] The KNN algorithm predicts by calculating the distance between the features of the new vulnerability and the historical vulnerabilities (usually using metrics such as Euclidean distance or Manhattan distance), and based on the categories of the K historical vulnerabilities with the closest distance.
[0177] Once the system receives a newly reported vulnerability, it will first identify and classify it to confirm whether it belongs to a known vulnerability.
[0178] If it is a new type of vulnerability (i.e., not yet classified or analyzed), the system will compare the characteristics of this vulnerability with the historical vulnerability data, and use the machine learning algorithm KNN to determine whether it is similar to some potential unreported vulnerabilities, so as to achieve pre-judgment and enable the pre-prepared patches.
[0179] Step 4-2: Dynamic Behavior Analysis and Permission Adjustment. Use machine learning algorithms to analyze the behavior data of users and devices, calculate the trust score based on the behavior analysis results, and dynamically adjust the access permissions. The trust score formula is as follows:
[0180] Tuser = w9×f(u)+w 10 ×f(b)+w 11 ×f(d);
[0181] Where, Tuser represents the trust score of the user, w9, w 10 , w 11 are all weight coefficients, f(u) is the risk function of user behavior, f(b) is the risk function of device status, and f(d) is the risk function of user data.
[0182] In this embodiment, f(u) is used to quantify and evaluate the impact of user behavior on the trust score. User behavior may include the user's login time, accessed resources, request frequency, etc. For example, if a user frequently tries to access sensitive resources or logs in at unusual times, it may have a negative impact on the trust score. On the contrary, normal access behavior may increase the user's trust.
[0183] f(b) is used to quantify and evaluate the impact of device status on the trust score. Device status usually includes the security of the device (such as whether the latest security patches are installed), the health of the device, whether the device is in a trusted network, etc. For example, if a user is using an unupdated device or the device is infected with a virus, then the risk of the device is high, which will reduce the user's trust score; if the device is in a secure state, the trust score will increase accordingly.
[0184] f(d) is used to quantify and evaluate the impact of user data on the trust score, which may include the user's identity information, behavior records, geographical location, device identification information, etc. For example, if the user's data seems inconsistent (for example, the login location does not match the user's normal activity area, or the identity information is tampered with), this may reduce the user's trust score; while if the data verification passes and is consistent with the expectation, the trust score may increase.
[0185] The user behavior analysis results and permission adjustment records will be stored in the blockchain.
[0186] In this embodiment, the user interaction layer provides a front-end user interface. The specific devices are Web clients and mobile clients. Users perform management authentication, request access, view patch information, vulnerability repair progress, and upload patches through the front-end user interface; the clients and the server interact through RESTful APIs;
[0187] The security verification and control layer provides authentication services, request verification services, and zero-trust identity authentication & micro-segmentation services:
[0188] The authentication service is used to perform multi-factor authentication and verify the user identity using a behavior analysis model;
[0189] The request verification service is used to determine whether to allow a request to pass based on a multi-dimensional risk assessment model;
[0190] The zero-trust identity authentication & micro-segmentation service is used to perform real-time access control to ensure that users can only access their authorized resources. The micro-segmentation service is based on SDN technology to implement internal network resource isolation;
[0191] The patch management layer provides patch release services, blockchain smart contract services, and patch verification and deployment services:
[0192] The patch release service is used to release patches through blockchain and smart contracts;
[0193] The blockchain smart contract service is responsible for managing patch data, including patch release, verification, and deployment;
[0194] The patch verification and deployment service is used to perform signature verification of patch content and automatically push the verified patches to the vulnerability response and repair layer, store them in the vulnerability library, and wait for the deployment of patches to be executed;
[0195] The vulnerability response and repair layer provides vulnerability scanning and detection services, automated repair push services, and vulnerability classification and repair services:
[0196] The vulnerability scanning and detection service is used to detect potential vulnerabilities using static code analysis and behavior analysis tools, and automatically classify and evaluate vulnerability risks in combination with machine learning algorithms;
[0197] The automated repair push service is used to automatically push patches through smart contracts and deploy them to affected terminals;
[0198] The vulnerability classification and repair service is used to classify the discovered vulnerabilities and evaluate risks, and generate repair plans according to the threat level;
[0199] The data storage and blockchain layer provides a blockchain network, IPFS storage, and a NoSQL database:
[0200] The blockchain network is used to store immutable records of key operations such as patch release, verification, deployment, and vulnerability repair;
[0201] IPFS storage is used to store patch files;
[0202] The NoSQL database is used to store logs, behavior data, and vulnerability scanning results;
[0203] The machine learning and behavior analysis layer provides behavior analysis and anomaly detection services, vulnerability classification and prediction services, and dynamic permission adjustment services:
[0204] The behavior analysis and anomaly detection service is used to monitor user behavior and device status in real time, and detect abnormal behavior using machine learning algorithms;
[0205] The vulnerability classification and prediction service is used to analyze historical vulnerability data and predict and classify new vulnerabilities using machine learning algorithms;
[0206] The dynamic permission adjustment service is used to adjust the access permissions of users through real-time behavior analysis to ensure that each request is evaluated based on credibility.
[0207] In this embodiment, the security verification and control layer, the patch management layer, the vulnerability response and repair layer, the data storage and blockchain layer, and the machine learning and behavior analysis layer are all established in a server cluster.
[0208] A security maintenance method for management software based on Internet information technology according to the present invention solves the technical problems existing in traditional network security management, such as opaque patch management, low efficiency of vulnerability response, and insufficient protection against unknown threats. The present invention ensures the immutability and transparency of the patch management and vulnerability repair processes through blockchain, effectively preventing patch tampering and malware intrusion. Through the zero-trust architecture and dynamic behavior analysis, fine-grained access control and permission management are achieved, ensuring that only requests that have been verified in real time can access the system, improving the security of internal network resources. Combining the automated vulnerability detection, classification, and repair of machine learning and blockchain improves the vulnerability response speed, reduces the need for manual intervention, and enhances the system's protection against new attacks. Through multi-factor authentication and machine learning-driven behavior analysis, intelligent detection and dynamic adjustment of user behavior are achieved, greatly reducing the complexity in the authentication process and improving the user experience. By using micro-segmentation technology to divide internal network resources into multiple isolation areas, the scope of potential attacks is reduced, enhancing the flexibility and scalability of the system.
Claims
1. A method for security maintenance of management software based on Internet information technology, characterized in that: It includes the following steps: Step 1: After the user uploads a patch at the user interaction layer, the patch management layer implements the release, verification, and deployment of the patch, specifically including: In the patch release stage, the patch content is digitally signed through hash and encryption algorithms, and both the signature and the patch data are recorded in the blockchain; in the patch verification stage, the signature is verified using the public key at the time of release; the patch that passes the verification will enter the patch deployment stage in Step 3; Step 2: Perform authentication and access control based on the zero-trust architecture at the security verification and control layer, specifically including: Judging the normal behavior of the user through multi-factor authentication and behavior analysis models; Evaluating risks through multi-dimensional data, generating a risk score, and judging whether the request meets the access standard. If the risk score exceeds the set threshold, the request is rejected; Through fine-grained isolation, the internal network resources are divided into multiple independent areas to ensure that the attacker can only act within one isolation area; The multi-dimensional data includes user identity, device status, geographical location, and access time; Step 3: Detect, repair, and optimize vulnerabilities at the vulnerability response and repair layer, specifically including: Identifying potential vulnerabilities through static code analysis and behavior analysis, using machine learning algorithms for behavior pattern analysis, and outputting potential vulnerabilities and threat levels; Automatically deploying patches through the blockchain and smart contracts, and recording repair events; Analyzing the effect after vulnerability repair through a reinforcement learning model, and optimizing the strategy process of vulnerability detection and repair; Step 4: Real-time optimize security management through machine learning and dynamic behavior analysis at the machine learning and behavior analysis layer, specifically including: Analyzing historical vulnerability data through machine learning algorithms, predicting and identifying new types of vulnerabilities, and generating repair solutions; Analyzing the behavior patterns of users and devices through machine learning, and adjusting access permissions in real time to ensure that each request is within the credibility range.
2. A security maintenance method for a management software based on Internet information technology according to claim 1, characterized in that: The user interaction layer provides a front-end user interface, and the specific devices are Web clients and mobile clients. The user performs management authentication, requests access, views patch information, vulnerability repair progress, and uploads patches through the front-end user interface; The client and the server interact through RESTful APIs; The security verification and control layer provides authentication services, request verification services, and zero-trust authentication & micro-segmentation services: The authentication service is used to perform multi-factor authentication and verify the user identity using a behavior analysis model; The request verification service is used to judge whether to allow the request to pass according to the multi-dimensional risk assessment model; The zero-trust authentication & micro-segmentation service is used to perform access control in real time to ensure that the user can only access the resources authorized to it. The micro-segmentation service implements the isolation of internal network resources based on SDN technology; The patch management layer provides patch release services, blockchain smart contract services, and patch verification and deployment services: The patch release service is used to release patches through the blockchain and smart contracts; The blockchain smart contract service is used to manage the data of the patch, including the release, verification, and deployment of the patch; The patch verification and deployment service is used to perform signature verification of patch content and automatically push the verified patch to the vulnerability response and repair layer, store it in the vulnerability database, and wait for the deployment of the patch to be executed; The vulnerability response and repair layer provides vulnerability scanning and detection services, automated repair push services, and vulnerability classification and repair services: The vulnerability scanning and detection service is used to detect potential vulnerabilities using static code analysis and behavior analysis tools, and automatically classify and evaluate vulnerability risks in combination with machine learning algorithms; The automated repair push service is used to automatically push patches through smart contracts and deploy them to affected terminals; The vulnerability classification and repair service is used to classify the discovered vulnerabilities and evaluate the risks, and generate repair plans according to the threat level; The data storage and blockchain layer provides a blockchain network, IPFS storage, and a NoSQL database: The blockchain network is used to store immutable records of key operations such as patch release, verification, deployment, and vulnerability repair; IPFS storage is used to store patch files; The NoSQL database is used to store logs, behavior data, and vulnerability scanning results; The machine learning and behavior analysis layer provides behavior analysis and anomaly detection services, vulnerability classification and prediction services, and dynamic permission adjustment services: The behavior analysis and anomaly detection service is used to monitor user behavior and device status in real time, and detect abnormal behavior using machine learning algorithms; The vulnerability classification and prediction service is used to analyze historical vulnerability data and use machine learning algorithms to predict and classify new vulnerabilities; The dynamic permission adjustment service is used to adjust the access permissions of users through real-time behavior analysis to ensure that each request is evaluated based on credibility.
3. A security maintenance method for a management software based on Internet information technology according to claim 2, characterized in that: When performing step 1, the specific steps are as follows: Step 1-1: Patch release. The user or administrator submits patch content P through the front-end user interface, and the front-end user interface transmits the patch content P to the patch release service; The patch release service uses the RSA algorithm to generate the hash value H(P) of the patch: H(P) = SHA256(P); Then, a digital signature is performed on the hash value H(P) to generate the signature S: S = Sign(Prk, H(P)); where Prk is the private key; The signature S and the patch content P are recorded in the blockchain through the smart contract service; Step 1-2: Patch verification. The public key PubK is used to verify the signature S and the hash value H(P) of the patch; Verification formula: Verify(PubK, S, H(P)) = true; if the verification is valid, it means the patch is legal, and the patch is pushed to the vulnerability response and repair layer.
4. A method for security maintenance of a management software based on Internet information technology according to claim 2, characterized in that: When performing step 2, the specific steps are as follows: Step 2-1: User authentication. Multifactor authentication of the user identity is performed, including password verification and fingerprint verification; the machine learning KNN algorithm is used to analyze the user behavior, establish a normal behavior pattern, calculate the distance of the behavior pattern, and if abnormal behavior is found, secondary authentication is triggered; The user verification information and behavior records are both recorded through the blockchain; Step 2-2: Request verification and access decision. The user identity, device status, geographical location, and access time of the requester are collected; the risk score is calculated using the comprehensive scoring model R: R = w1×f(U) + w2×f(D) + w3×f(L) + w4×f(T) + w5×f(B); Wherein, R is the risk score, w1, w2, w3, w4, and w5 are all weight coefficients, f(U) is the risk function of the user identity, f(D) is the risk function of the device status, f(L) is the risk function of the geographical location, f(T) is the risk function of the time window, and f(B) is the risk function of the behavior pattern; If the calculation result of the comprehensive scoring model R exceeds the set threshold, the request is rejected, otherwise access is allowed; The risk assessment results of all requests are recorded in the blockchain through a smart contract; Step 2-3: Micro-segmentation and access control. Divide the internal network resources into multiple isolation areas. Each isolation area only allows access by preset specific users. Manage resource access through SDN, dynamically adjust the access policy, and record the access control information and isolation area configuration of each resource.
5. A method for security maintenance of management software based on Internet information technology as claimed in claim 4, wherein: When performing step 2-1, the specific formula for calculating the distance of the behavior pattern is as follows: where x i is a historical behavior and belongs to the historical behavior data set X = [x1, x2,... x n , y i is the current behavior and belongs to the current behavior data set Y = [y1, y2,..., y n .
6. The security maintenance method of a management software based on Internet information technology according to claim 2, characterized in that: When performing step 3, the specific steps are as follows: Step 3-1: Vulnerability detection and behavior analysis. Use static code analysis tools and behavior analysis tools to identify vulnerabilities, perform behavior analysis using machine learning algorithms, output potential vulnerabilities and risk assessments, and record the vulnerability detection results through the blockchain; Step 3-2: Vulnerability repair and automated deployment. Automatically obtain patches from the vulnerability database, push the patches to the terminal devices through a smart contract, and record the repair events; Step 3-3: Feedback and optimization. Collect the data after vulnerability repair, and optimize the vulnerability detection and repair process through reinforcement learning. The specific optimization formula is as follows: Rnew = α×Rold + β×Feedback(P); Wherein, Rnew is the new risk score, representing the updated value after adjustment based on the current feedback. α is the weight coefficient, which controls the proportion of the old risk score Rold in the new score Rnew. β is another weight coefficient, which controls the proportion of Feedback(P) in Rnew, and β + α = 1. Feedback(P) is the feedback information, usually representing the evaluation made by the system on the current behavior or state. For example, a certain patch is repaired successfully and effectively; Optimize the policy process of vulnerability detection and repair through the feedback data.
7. A security maintenance method for management software based on Internet information technology according to claim 6, characterized in that: When performing step 3-1, establish a classification model to classify the vulnerabilities through historical vulnerability data, and evaluate their risk levels. The specific classification model is as follows: T = w6×f(vulnerabilityType) + w7×f(impact) + w8×f(att ackProbability); Wherein, T represents the threat level, w6, w7, and w8 are all weight coefficients, f(vulnerabilityT ype) is the vulnerability type function, f(impact) is the vulnerability impact function, and f(attackProb ability) is the attack probability function.
8. The security maintenance method of a management software based on Internet information technology according to claim 2, characterized in that: When performing step 4, the specific steps are as follows: Step 4-1: Machine learning and dynamic behavior analysis. Use the KNN algorithm to classify and analyze historical vulnerability data, predict new types of vulnerabilities, and evaluate the threat level based on the type, impact, and attack probability of the new vulnerabilities. The classification model is as follows: C = argmax(f(vulnerabilityType), f(impact), f(attackProbability)); Where C represents the classification result, f(vulnerabilityType) is the vulnerability type function, f(impact) is the vulnerability impact function, and f(attackProbability) is the attack probability function; The classification result and prediction information will be stored in the blockchain; Step 4-2: Dynamic behavior analysis and permission adjustment. Use machine learning algorithms to analyze the behavior data of users and devices, calculate the trust score based on the behavior analysis results, and dynamically adjust the access permissions. The trust score formula is as follows: Tuser = w9 × f(u) + w 10 × f(b) + w 11 × f(d); Among them, Tuser represents the user's trust score, w9, w 10 , w 11 are all weight coefficients, f(u) is the risk function of user behavior, f(b) is the risk function of device status, and f(d) is the risk function of user data; The user behavior analysis results and permission adjustment records will be stored in the blockchain.
Citation Information
Cited By
Internet of vehicles vulnerability management method, system and device based on block chain, and medium
CN121037074A
Blockchain-based methods, systems, devices, and media for managing vulnerabilities in the Internet of Vehicles (IoV).
CN121037074B