File checking method and device based on distributed proxy and electronic equipment
Through distributed proxy technology, unified file integrity inspection in the financial industry, the problem of inconsistent inspection mechanism caused by the diversity of server operating systems is solved, efficient and accurate file integrity inspection is achieved, and the successful passage of PCIDSS certification is ensured.
Patent Information
- Application Number
- CN202510435126.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-07-08
AI Technical Summary
In the payment card industry data security standard (PCIDSS) certification in the financial industry, the traditional file integrity check method causes inconsistent inspection mechanisms due to the diversity of server operating systems, and there is a risk of authentication errors and authentication failures.
A distributed proxy-based file inspection method is adopted. By determining the list of applications to be inspected, a personalized file inspection script is called, and a distributed proxy is used to unify the proxy script on different operating systems, trigger script execution, and finally generate file inspection results to ensure the uniformity and accuracy of the inspection.
It improves the uniformity and accuracy of file integrity checks, reduces the error judgment and authentication failure rate in audit certification processes such as PCIDSS, realizes the automation and standardization of file checks, and enhances the security and compliance of the system.
Smart Images

Figure CN120277726A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of distributed technologies or other related fields. Specifically, it relates to a file inspection method, device, and electronic device based on a distributed agent. Background Art
[0002] In the financial industry, especially in applications related to the Payment Card Industry Data Security Standard (PCIDSS) certification, ensuring the integrity of critical files is an important part of ensuring system security. File integrity inspection is one of the core requirements of PCIDSS certification, used to detect whether files have been modified without authorization, thus preventing data leakage and system security risks. However, with the increase in the number of application servers and the diversification of operating systems and versions, file integrity inspection faces many challenges.
[0003] In related technologies, traditional file integrity inspection methods usually rely on manual operations. Inspectors need to manually log in to each server to execute inspection scripts and record the results, which is not only inefficient but also prone to inconsistent inspection results due to human errors. In addition, due to the large differences in operating systems and versions of different application servers, the writing and deployment of inspection scripts lack a unified standard, further increasing the complexity and difficulty of inspection. This not only consumes a large amount of manpower, material resources, and time but also may lead to PCIDSS certification errors or certification failures, causing business losses to enterprises.
[0004] In response to the above problems, no effective solution has been proposed yet. Summary of the Invention
[0005] The main purpose of this application is to provide a file inspection method, device, and electronic device based on a distributed agent, so as to at least solve the technical problem in related technologies that due to the diversity of server operating systems, the file integrity inspection mechanism is not unified, resulting in risks of certification errors and certification failures during the audit and certification process.
[0006] To achieve the above object, according to one aspect of the present application, a file inspection method based on a distributed agent is provided. The method includes: determining a list of applications to be inspected, where the list of applications to be inspected includes at least one target server and at least one target file; calling a pre-written personalized file inspection script for the target file, and sending the personalized file inspection script to the target server through a distributed agent pre-deployed on the target server, where the distributed agent is used to uniformly proxy the personalized file inspection script on different operating systems used by each server; responding to a file inspection request, triggering the personalized file inspection script on the target server, and obtaining a script execution result; recycling the script execution result through the distributed agent, and generating a file inspection result based on a preset standard threshold and the script execution result.
[0007] Further, the step of determining the list of applications to be inspected includes: requesting an audit list from a third-party audit and certification agency, where the audit list is used to record target applications within the scope of data security audit; obtaining node information of all the target applications from a configuration management system based on the audit list, where the node information at least includes the target files related to the audit in the target applications and the target servers where the target applications are located; generating the list of applications to be inspected based on the node information.
[0008] Further, the step of pre-writing a personalized file inspection script includes: obtaining and analyzing the node information corresponding to the target file to obtain the environment information of the target server and the attribute information of the target file, where the environment information includes: the type information and version information of the operating system used by the target server; generating a basic inspection script available for the target server based on a preset script template according to the environment information; adjusting the parameters of the basic inspection script according to the attribute information to obtain the personalized file inspection script for the target file.
[0009] Further, the step of sending the personalized file inspection script to the target server through a distributed agent pre-deployed on the target server includes: when the distributed agent is in an active state, pushing the personalized file inspection script using a secure communication protocol and a specified file path; receiving the personalized file inspection script through the distributed agent on the target server, and after passing the integrity verification, storing the personalized file inspection script in the execution queue of the target server.
[0010] Further, the step of triggering the personalized file check script on the target server in response to a file check request and obtaining a script execution result includes: parsing the file check request to obtain the check process and time plan preselected by the user on the open interaction platform; generating a task trigger instruction based on the check process, and sending the task trigger instruction to the target server according to the time plan; triggering the personalized file check script by the distributed agent on the target server based on the task trigger instruction to obtain the script execution result.
[0011] Further, the step of triggering the personalized file check script by the distributed agent on the target server based on the task trigger instruction and obtaining the script execution result includes: parsing the task trigger instruction by the distributed agent to identify at least one target file involved in this check and the trigger order; when the trigger moment indicated by the time plan is reached, executing at least one personalized file check script corresponding to the at least one target file according to the trigger order to obtain at least one script execution result; and sending back all the script execution results by the distributed agent according to the time plan.
[0012] Further, generating a file check result based on a preset standard threshold and the script execution result includes: analyzing the script execution result based on a preset key information list to obtain an analysis result, where N key information items are recorded in the preset key information list, and the analysis result contains key information corresponding to the N key information items, and N is a positive integer; comparing each key information in the script execution result with the preset standard threshold corresponding to the key information item to obtain N comparison results, and generating the file check result according to all the comparison results.
[0013] To achieve the above object, according to another aspect of the present application, there is also provided a file check device based on a distributed agent. The device includes: a determination unit for determining a list of applications to be checked, where the list of applications to be checked includes at least one target server and at least one target file; a sending unit for calling a pre-written personalized file check script for the target file and sending the personalized file check script to the target server through a distributed agent pre-deployed on the target server, where the distributed agent is used to uniformly proxy the personalized file check script on different operating systems used by each server; a trigger unit for triggering the personalized file check script on the target server in response to a file check request to obtain a script execution result; and a generation unit for recovering the script execution result through the distributed agent and generating a file check result based on a preset standard threshold and the script execution result.
[0014] Further, the determining unit includes: a request module, configured to request an audit list from a third-party audit and certification agency, where the audit list is used to record target applications within the scope of data security audit; an acquisition module, configured to acquire node information of all the target applications from a configuration management system based on the audit list, where the node information at least includes target files related to the audit in the target applications and the target servers where the target applications are located; a first generation module, configured to generate the list of applications to be inspected based on the node information.
[0015] Further, the file inspection device based on a distributed agent further includes: a first analysis module, configured to acquire and analyze the node information corresponding to the target file to obtain the environment information of the target server and the attribute information of the target file, where the environment information includes: type information and version information of the operating system used by the target server; a second generation module, configured to generate a basic inspection script available for the target server based on a preset script template according to the environment information; an adjustment module, configured to adjust parameters of the basic inspection script according to the attribute information to obtain the personalized file inspection script for the target file.
[0016] Further, the sending unit includes: a push module, configured to push the personalized file inspection script using a secure communication protocol and a specified file path when the distributed agent is in an active state; a storage module, configured to receive the personalized file inspection script through the distributed agent on the target server and store the personalized file inspection script in the execution queue of the target server after passing integrity verification.
[0017] Further, the triggering unit includes: a parsing module, configured to parse the file inspection request to obtain the inspection process and time plan preselected by a user on an open interaction platform; a sending module, configured to generate a task triggering instruction based on the inspection process and send the task triggering instruction to the target server according to the time plan; a triggering module, configured to trigger the personalized file inspection script based on the task triggering instruction through the distributed agent on the target server to obtain the script execution result.
[0018] Further, the trigger module includes: an identification sub-module, configured to parse the task trigger instruction through the distributed agent and identify at least one target file involved in the current inspection and the trigger order; an execution sub-module, configured to execute at least one personalized file inspection script corresponding to the at least one target file in accordance with the trigger order when the trigger moment indicated by the time plan is reached, so as to obtain at least one script execution result; and a feedback sub-module, configured to feedback all the script execution results in accordance with the time plan through the distributed agent.
[0019] Further, the generating unit includes: a second analysis module, configured to analyze the script execution result based on a preset key information list to obtain an analysis result, wherein N key information items are recorded in the preset key information list, and the analysis result includes key information corresponding to the N key information items, and N is a positive integer; and a comparison module, configured to compare each key information in the script execution result with the preset standard threshold corresponding to the key information item to obtain N comparison results, and generate the file inspection result according to all the comparison results.
[0020] To achieve the above object, according to another aspect of the present application, there is also provided a computer-readable storage medium, where the computer-readable storage medium includes a stored computer program, and when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the distributed agent-based file inspection method described in any one of the above.
[0021] To achieve the above object, according to another aspect of the present application, there is also provided an electronic device, including one or more processors and a memory, where the memory is used to store one or more programs, and when the one or more programs are executed by the one or more processors, the one or more processors are caused to implement the distributed agent-based file inspection method described in any one of the above.
[0022] To achieve the above object, according to another aspect of the present application, there is also provided a computer program product, including computer instructions, and when the computer instructions are executed by a processor, the steps of the distributed agent-based file inspection method described in any one of the above are implemented.
[0023] In the present invention, a file inspection method based on a distributed agent is proposed. First, a list of applications to be inspected is determined, where the list of applications to be inspected includes at least one target server and at least one target file. Then, a pre-written personalized file inspection script is called for the target file, and the personalized file inspection script is sent to the target server through a distributed agent pre-deployed on the target server. The distributed agent is used to uniformly proxy the personalized file inspection script on different operating systems used by each server, and then in response to a file inspection request, trigger the personalized file inspection script on the target server to obtain the script execution result. Finally, the script execution result is recovered through the distributed agent, and a file inspection result is generated based on a preset standard threshold and the script execution result.
[0024] In the present invention, an integrated distributed agent technology framework is adopted. By precisely matching the personalized script deployment and execution strategy of the target server operating system, the standardized purpose of unified file integrity inspection across multiple platforms is achieved. Specifically, first, a list of applications to be inspected is defined to clarify the target server and its key file set. Subsequently, according to the specific operating system and version of each server in the list, a pre-set and specifically optimized file inspection script is called. These scripts are accurately sent to their respective target servers through the intelligent routing of the distributed agent. The agent seamlessly converts the script format in the background to ensure compatibility with the server environment, and then triggers the script execution. After the inspection is completed, the agent is responsible for summarizing the script execution results and performing data analysis based on the preset security threshold, and finally generating an intuitive file integrity status report. Compared with the prior art, the present invention greatly improves the unity and accuracy of the file integrity inspection mechanism under the condition of server operating system diversity, thus significantly reducing the error judgment and authentication failure rate in the audit and certification processes such as PCIDSS, filling the technical gap in the automation and standardization of file inspection in a large-scale and multi-system environment, providing solid compliance and business security support for the financial industry, and thus solving the technical problem in the related technology that due to the diversity of server operating systems, the file integrity inspection mechanism is not unified, resulting in the risk of authentication errors and authentication failures in the audit and certification processes. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] The accompanying drawings, which form a part of this application, are used to provide a further understanding of this application. The illustrative embodiments and descriptions thereof of this application are used to explain this application and do not constitute an improper limitation to this application. In the drawings:
[0026] Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing a file inspection method based on a distributed agent is shown;
[0027] Figure 2It is a flowchart of an optional file checking method based on a distributed agent according to an embodiment of the present invention;
[0028] Figure 3 It is a schematic diagram of an optional file checking device based on a distributed agent according to an embodiment of the present invention;
[0029] Figure 4 It is a structural block diagram of an electronic device for executing a file checking method based on a distributed agent according to an embodiment of the present invention. Detailed implementation manners
[0030] In order to enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0031] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0032] To facilitate the understanding of the present invention by those skilled in the art, the following explains some terms or nouns involved in each embodiment of the present invention:
[0033] Distributed Agent, a distributed agent, is a software component deployed on multiple servers that can accept instructions from a central console and proxy to execute specific tasks, such as file integrity checking in the present invention. In different operating system environments, the agent has cross-platform compatibility and execution capabilities, and can intelligently adjust the script format and execution parameters to ensure the correct operation of the script on the target server.
[0034] File Integrity Check, a security measure used to verify whether a file has been changed without authorization, involves comparing the file's attributes (such as permissions, owner, size) and content (such as by calculating hash values like SHA1) against a pre-recorded "healthy" state to detect potential signs of tampering.
[0035] PCIDSS, Payment Card Industry Data Security Standard, a comprehensive set of security control measures developed by the PCI Security Standards Council, aims to ensure that all companies and organizations involved in credit card processing can maintain a secure environment and protect cardholders' payment data from being leaked or misused. PCIDSS certification is an important compliance requirement in the financial industry, especially in the payment processing field.
[0036] It should be noted that the file checking method and device based on distributed agents in this application can be used in the distributed technology field for automated file integrity checking of multi-application server clusters, and can also be used in any field other than the distributed technology field for automated file integrity checking of multi-application server clusters. The application field of the file checking method and device based on distributed agents in this application is not limited.
[0037] It should be noted that the relevant information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Moreover, the collection, storage, processing, transmission, provision, disclosure, use, and handling of relevant data all comply with the laws, regulations, and standards of the relevant regions, adopt necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for users to choose to authorize or refuse. For example, an interface is set up between this system and relevant users or institutions. Before obtaining relevant information, a request for acquisition needs to be sent to the aforementioned users or institutions through the interface, and relevant information can be obtained after receiving the consent information feedback from the aforementioned users or institutions.
[0038] For the information collection (such as user voice, video, text collection) and analysis operations involved in this application, corresponding operation entrances have been provided for users to choose to agree or refuse the automated decision results when they are executed; if the user chooses to refuse, the expert decision-making process will be entered.
[0039] The following embodiments of the present invention can be applied to various systems / applications / devices that require file integrity checking and multi-platform adaptability management, and can implement a unified file checking mechanism based on distributed agents. The present invention uses distributed agents to perform standardized script deployment and execution control on heterogeneous server environments, and then triggers file integrity checking scripts on target servers, which can better cross the limitations of different operating systems and versions to ensure an accurate assessment of the file security status. Through the intelligent scheduling and result collection of agents, the present invention not only simplifies the preparation work for security audits such as PCI DSS, but also ensures the consistency and reliability of the inspection results, improving the efficiency and accuracy of the overall audit process.
[0040] The present invention also realizes real-time monitoring and anomaly warning of inspection results through preset standard thresholds and dynamic task generation, and immediately takes measures for files that deviate from the standard values to ensure that the system responds to potential security threats in the first time, further enhancing the system's security protection ability.
[0041] The present invention will be described in detail below in conjunction with each embodiment.
[0042] Embodiment 1
[0043] According to an embodiment of the present invention, an embodiment of a file checking method based on distributed agents is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0044] The embodiment of the file checking method based on distributed agents provided by the first embodiment of the present invention can be executed on a mobile terminal, a computer terminal or a similar computing device. Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing a file checking method based on distributed agents is shown. As Figure 1 shown, the computer terminal 10 (or mobile device) may include one or more (shown as 102a, 102b,..., 102n in the figure) processors 102 (the processor 102 may include, but is not limited to, processing devices such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which can be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand, Figure 1The structure shown is only illustrative and does not limit the structure of the above electronic device. For example, computer terminal 10 may also include more or fewer components than those shown in Figure 1 or have a different configuration from that shown in Figure 1 .
[0045] It should be noted that the above one or more processors 102 and / or other data processing circuits can generally be referred to as "data processing circuits" herein. The data processing circuit can be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit can be a single independent processing module, or be incorporated in whole or in part into any one of other elements in computer terminal 10 (or mobile device). As involved in the embodiments of the present application, the data processing circuit is a processor control (such as the selection of a variable resistance terminal path connected to an interface).
[0046] Memory 104 can be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the distributed agent-based file inspection method in the embodiments of the present application. Processor 102 executes various functional applications and data processing by running the software programs and modules stored in memory 104, that is, implements the above distributed agent-based file inspection method. Memory 104 may include high-speed random access memory, and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, memory 104 may further include memories remotely located relative to processor 102, and these remote memories can be connected to computer terminal 10 through a network. Examples of the above network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof.
[0047] Transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by the communication provider of computer terminal 10. In one instance, transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0048] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables a user to interact with the user interface of computer terminal 10 (or mobile device).
[0049] Under the above operating environment, the present invention provides as Figure 2The file inspection method based on distributed agents shown is implemented by the OCAS (Open Compliance and Audit System) system. Combining distributed agent technology, it is used for file integrity inspection scenarios in multi-application environments. In particular, it solves the problem of uniformly performing file integrity inspections in an environment with diverse server operating systems and versions. Through means such as personalized script writing and intelligent agent deployment, it realizes automated and standardized file integrity inspections, ensuring the smooth passage of security certifications such as PCI DSS and enhancing system security and business continuity.
[0050] The embodiments of the present invention will be described in detail below in conjunction with each specific step.
[0051] Figure 2 It is a flowchart of an optional file inspection method based on distributed agents according to an embodiment of the present invention. As Figure 2 shown, the method includes the following steps:
[0052] Step S201, determine the list of applications to be inspected, where the list of applications to be inspected includes at least one target server and at least one target file.
[0053] In the embodiments of the present invention, the list of applications to be inspected refers to the set of all application programs that need to perform file integrity verification within the scope of a specific compliance inspection (such as PCI DSS audit), which is used to define the boundaries and key points of the audit. It not only includes the application names but also all server nodes related to the applications and the list of files that need to be key-monitored in each application. Creating the list can ensure comprehensive audit coverage while focusing on the most sensitive and critical data assets, reducing unnecessary inspections and improving audit efficiency.
[0054] The target server refers to the physical or virtual machine listed in the list that hosts the application to be inspected, running different types of operating systems (such as Linux, Unix variants, Windows Server, etc.) with different versions. Since each operating system and version manages and protects files in different ways, the diversity requires that the inspection mechanism must have high flexibility and wide compatibility to adapt to various complex environments and ensure the effectiveness and consistency of file integrity inspections.
[0055] A target file refers to a file that is considered crucial for the secure and stable operation of the system or compliance in each application to be inspected. It directly or indirectly affects the security state of the system and can be a configuration file, system log, transaction record, or other sensitive documents. Selecting target files based on an understanding of the application's functions and an assessment of potential security threats can ensure that critical areas are not affected by unauthorized changes. In the embodiments of the present invention, clearly indicating the target files in the checklist helps to refine the inspection strategy, concentrate resources and attention, and improve the pertinence of the inspection.
[0056] In addition, the checklist of applications to be inspected can have the ability to be updated dynamically to promptly reflect changes in the application environment, such as events like adding server nodes, removing files, or changing file permissions. The maintenance of the checklist can be automatically synchronized through a configuration management system to ensure the timeliness and accuracy of the checklist.
[0057] Optionally, in the file inspection method based on distributed agents provided by the embodiments of the present invention, the step of determining the checklist of applications to be inspected includes: requesting an audit checklist from a third-party audit and certification agency, where the audit checklist is used to record target applications within the scope of data security audits; obtaining node information of all target applications from the configuration management system based on the audit checklist, where the node information at least includes target files related to the audit in the target application and the target server where the target application is located; generating a checklist of applications to be inspected based on the node information.
[0058] It should be noted that before starting the file integrity inspection process, an audit checklist is obtained from a third-party agency responsible for data security compliance certification. The checklist details all target applications that need to be included in the scope of data security audits, including not only the application names but also information such as the business areas to which the applications belong and key functional modules.
[0059] The configuration management system is a platform for centrally managing the configuration information of all IT resources (including servers, applications, network devices, etc.). Based on the audit checklist, detailed node information of all target applications can be automatically extracted from the configuration management system, at least including a list of target files related to the audit in the target application and information about the target servers where these target files are located, including key attribute information such as server identification, operating system type, version, IP address, file path, etc. The final checklist of applications to be inspected is generated based on the above-mentioned necessary target application node information collected, serving as the basis for subsequent file integrity inspection tasks, clearly listing each application and all related servers and files to ensure no omissions and no duplicates.
[0060] Optionally, the process of generating the checklist can also include: presetting the file integrity inspection method, such as using SHA1 hash values for comparison and designing response strategies for abnormal situations (such as warning levels, notification methods, etc.).
[0061] The above steps avoid errors and delays in manual operations by automatically obtaining the audit checklist and node information, ensuring the accuracy of the inspection scope, and improving the overall efficiency and accuracy of the audit; the integrity verification is closely combined with the audit checklist of the authoritative agency to ensure that the inspection mechanism complies with industry standards and compliance requirements. At the same time, the security of the system is enhanced through meticulous file integrity checks, reducing the risks of data leakage and tampering; the automated generation and management of the checklist simplify the operations of the entire audit process, reduce the dependence on professional IT personnel, and lower the operation and maintenance costs, enabling enterprises to focus more on the innovation and expansion of core businesses.
[0062] By implementing the above steps, the present invention not only solves the technical problem of conducting unified file integrity checks in a large-scale, multi-platform environment, but also additionally realizes the optimization of the audit process, provides an efficient, secure, and compliant file inspection solution for enterprises, and has a significant promoting effect on improving the overall information security management level of enterprises.
[0063] In step S202, a pre-written personalized file inspection script is called for the target file, and the personalized file inspection script is sent to the target server through a distributed agent pre-deployed on the target server, where the distributed agent is used to uniformly proxy the personalized file inspection script on different operating systems used by each server.
[0064] It should be noted that the personalized file inspection script refers to an automated script pre-written for specific operating systems and versions and the attributes of specific target files for performing file integrity checks. The "personalization" fully considers the differences between different operating systems, such as the expression of file permissions, the structure of the file system, the availability of command-line tools, etc. This script can perform a series of operations on the target file, including but not limited to: confirming the existence of the file; verifying whether the permissions and owners of the file meet the preset security standards; checking whether the size and modification time of the file have changed; calculating and comparing the hash value of the file (such as SHA1) to detect whether the content has been tampered with. The script is written in accordance with security programming principles to ensure that its execution on the target server will not bring new security risks or affect system performance. In addition, the script can also have a logging function to be able to record in detail various states and results during its execution process.
[0065] The distributed agent is a small software component deployed on each target server, acting as a bridge between the central console and the target server. The main functions of the agent include: receiving and parsing the file inspection tasks sent from the OCAS system to ensure the correct execution of the tasks and the accurate feedback of the results; adapting to the operating system of the target server and executing the corresponding personalized file inspection scripts; collecting the results of the script execution, including the integrity status of the files, the detailed information of abnormal situations, etc., sorting out and feeding back this data to the OCAS system; intelligently converting the script format between different operating systems and versions, optimizing the execution commands to ensure the consistency and compatibility of the scripts in various environments.
[0066] Deploying the intelligent agent not only simplifies the execution of the file inspection tasks, but also ensures the accuracy and timeliness of the inspection results through its powerful adaptation ability and data processing ability, improving the efficiency and reliability of the overall file inspection.
[0067] In some embodiments, to ensure the effective operation of the agent on different operating systems, the following can be considered in the underlying design: building in script conversion rules for automatically identifying the type and version of the operating system of the target server and converting the script format as needed to ensure the correct execution of the script; creating a secure execution environment before executing the personalized script to isolate the direct interaction between the script and the system core resources and prevent potential malicious code from damaging the system by using the inspection script; preliminarily verifying the results of the script execution and then feeding back the results to the OCAS system through a secure communication protocol to achieve centralized management and analysis of the inspection results while ensuring the integrity and accuracy of the results.
[0068] Optionally, in the file inspection method based on a distributed agent provided in the embodiments of the present invention, the step of pre-writing a personalized file inspection script includes: obtaining and analyzing the node information corresponding to the target file to obtain the environment information of the target server and the attribute information of the target file, where the environment information includes: the type information and version information of the operating system used by the target server; generating a basic inspection script available for the target server based on a preset script template according to the environment information; adjusting the parameters of the basic inspection script according to the attribute information to obtain a personalized file inspection script for the target file.
[0069] During the preparation process of writing the personalized script, obtain the detailed node information related to the target file from the configuration management system, which at least includes the basic information of the target server: the type of operating system, version, IP address, and can also deeply mine the attribute information of the target file: file path, file name, expected permission settings, owner information, and the hash value of the file, etc. By comprehensively analyzing the above information, the environmental characteristics of the target server and the security requirements of the target file can be deeply understood, providing a basis for script customization.
[0070] Accurately obtaining environmental information is a prerequisite for generating applicable scripts. Appropriate basic inspection script templates can be selected from a preset script library based on the type and version of the operating system used by the target server. It should be noted that there are significant differences in file management, permission control, the use of command-line tools, etc. among different operating systems and versions. Therefore, selecting a script template that matches the environment is the key to ensuring that the file inspection script can be correctly executed on the target server. In addition, environmental information is also used to guide the adjustment of specific commands or parameters in the script to adapt to the syntax and behavior of a specific operating system.
[0071] After obtaining the attribute information of the target file, further refine the selected basic inspection script. Ensure that the inspection script accurately performs an integrity check on the target file by introducing or modifying parameters in the script, including but not limited to: verifying whether the file exists, confirming whether the permission settings of the file meet expectations, checking whether the hash value of the file has changed, etc. The above process emphasizes the personalization of the script, enabling the inspection script to accurately reflect the security requirements of the target file and effectively avoiding false positives or false negatives that may occur due to the general script's lack of understanding of file details.
[0072] Through the above steps, a highly customized file inspection script is generated to ensure that the script can accurately reflect the unique security requirements of each file when executed. The mechanism of combining the preset script template with environmental information can flexibly adapt to different operating systems and versions, overcoming the problems of script execution failure or result deviation caused by platform differences in traditional inspection methods and achieving wide compatibility for file integrity inspection.
[0073] Optionally, in the file inspection method based on distributed agents provided in the embodiments of the present invention, the step of sending the personalized file inspection script to the target server through the distributed agents pre-deployed on the target server includes: when the distributed agents are in an active state, push the personalized file inspection script using a secure communication protocol and a specified file path; receive the personalized file inspection script through the distributed agents on the target server, and after passing the integrity verification, store the personalized file inspection script in the execution queue of the target server.
[0074] It should be noted that the successful deployment and active state of the distributed agents on the target server mean that the agents are ready to receive instructions and scripts from the OCAS system. Using a secure communication protocol (such as HTTPS, SSH, etc.), the encrypted personalized file inspection script can be pushed to the specified file path on the target server. This ensures the security of script transmission and prevents interception or tampering during transmission.
[0075] After receiving the script, the distributed agent on the target server first performs integrity verification, including: checking the digital signature of the script to confirm the legitimacy of the source; comparing the hash value of the script (such as MD5, SHA-256, etc.) to ensure that the script has not been damaged or tampered with during transmission. Only after passing the complete verification process will the personalized file inspection script be safely stored in the execution queue of the target server waiting for further scheduling and execution. Setting up an execution queue can ensure that multiple inspection tasks can be carried out in an orderly manner, avoiding resource conflicts and confusing results that may be caused by concurrent execution.
[0076] By adopting secure communication protocols and a complete script verification process in the above steps, network security attacks that may occur during the transmission process, such as man-in-the-middle attacks and data tampering, are effectively resisted, the purity and authority of the execution script are guaranteed, and the security level of the entire file inspection system is improved; by allocating a dedicated execution queue, the priority and execution order of tasks can be reasonably arranged, and even in the face of a large number of concurrent tasks, each personalized file inspection script can be executed according to the predetermined schedule and sequence, improving the efficiency and reliability of multi-application file integrity checks; in addition, since the script is downloaded and verified on the target server through a distributed agent, it allows new servers to be added or existing inspection tasks to be modified at any time without making major changes to the OCAS system itself. This distributed design model greatly enhances the scalability and flexibility of the system and can adapt to the ever-changing IT environment and audit needs.
[0077] Step S203, responding to the file check request, triggering the personalized file check script on the target server, and obtaining the script execution result.
[0078] Specifically, this step involves obtaining feedback on the response to the file check request and the script execution result. The file check request is an instruction issued by the OCAS system to the distributed agent on the target server through a secure communication channel according to the predefined inspection cycle and strategy. It contains detailed information of the target file to be checked, the ID of the inspection script, and parameter settings related to the inspection, such as detailed standards for file integrity inspection, thresholds for abnormal reporting, etc. The embodiment of the present invention designs a request response mechanism to ensure that each inspection request can be accurately received and processed by the agent in a timely manner. When the agent receives the request, it immediately calls the corresponding personalized file inspection script from the execution queue, triggers the execution process of the script, and starts to check the integrity of the target file.
[0079] After the distributed agent triggers the personalized file inspection script, the script will perform a series of preset security checks on the target file, including but not limited to: the existence of the file, the permission settings of the file, the comparison of the file hash value (such as SHA1) with the historical record, etc. Each link in the script execution process will generate detailed execution results, including: the timestamp of the inspection, the status of the target file, whether an anomaly is found, the specific description of the anomaly, etc., which are recorded in real time and organized into a structured data format by the distributed agent after the script execution is completed, and fed back to the OCAS system through a secure communication channel.
[0080] Optionally, in the file inspection method based on a distributed agent provided in the embodiment of the present invention, the step of triggering the personalized file inspection script on the target server in response to the file inspection request and obtaining the script execution result includes: parsing the file inspection request to obtain the inspection process and time plan preselected by the user on the open interaction platform; generating a task trigger instruction based on the inspection process and sending the task trigger instruction to the target server according to the time plan; triggering the personalized file inspection script based on the task trigger instruction by the distributed agent on the target server to obtain the script execution result.
[0081] In some embodiments, after the user preselects the inspection process to be executed and sets the time plan on the open interaction platform, the OCAS system will parse these requests, extract key parameters such as the specific inspection object, inspection method, and execution time from them, automatically generate a corresponding task trigger instruction based on the parsed information, and the instruction at least includes the identifier of the target server, the reference to the personalized file inspection script, the specific inspection parameters, and the execution time. The OCAS system will strictly follow the set time plan and send the task trigger instruction to the distributed agent on the target server on time.
[0082] After receiving the task trigger instruction, the distributed agent on the target server immediately loads and triggers the personalized file inspection script in the local execution environment. During the script execution process, the agent will monitor the running status of the script. Once the script is completed, it will immediately obtain the script execution result, including the status of each index of the file integrity inspection, the description of the abnormal situation, and the recommended response measures, etc., and package these results into a standardized feedback message and send it back to the OCAS system through a secure communication channel. This script trigger method based on task instructions ensures the consistency of the inspection process and the traceability of the results, providing detailed data records for subsequent abnormal situation analysis and problem location.
[0083] By parsing the inspection request, generating a task trigger instruction, and automatically issuing an inspection task through the above steps, the embodiments of the present invention have successfully realized the automation and standardization of the file inspection process, reduced manual intervention, improved the efficiency and accuracy of inspection. The set time plan and punctual task trigger mechanism ensure that the file integrity inspection task can be executed according to the preset schedule, avoiding waste of resources caused by overly frequent inspections. The immediate acquisition and feedback of the script execution results and detailed execution records not only facilitate the timely discovery of abnormal situations but also ensure the transparency and traceability of the inspection process, providing solid data support for subsequent fault troubleshooting and responsibility determination.
[0084] Further, in the file inspection method based on a distributed agent provided by the embodiments of the present invention, the step of triggering a personalized file inspection script by the distributed agent on the target server based on the task trigger instruction to obtain the script execution result includes: parsing the task trigger instruction by the distributed agent to identify at least one target file involved in this inspection and the trigger order; in the case of reaching the trigger moment indicated by the time plan, executing at least one personalized file inspection script corresponding to at least one target file according to the trigger order to obtain at least one script execution result; and transmitting all the script execution results back by the distributed agent according to the time plan.
[0085] It should be noted that after receiving the task trigger instruction issued from the OCAS system, the distributed agent first parses the parameters in the instruction, including but not limited to the inspection task ID, the target file list, the trigger order, the specific inspection method (such as file existence inspection, permission inspection, hash value inspection, etc.), and the execution time. The agent can quickly understand the meaning of the instruction through the built-in parsing engine, identify at least one target file involved in this inspection and its priority, and prepare for the subsequent script execution.
[0086] Once reaching the trigger moment indicated by the time plan, the agent sequentially executes the personalized file inspection scripts corresponding to the target files according to the preset trigger order in the task trigger instruction. This order can be based on the importance of the files, the complexity of the inspection, or the system resource allocation strategy to ensure the efficient and orderly progress of the inspection work. When executing each script, the agent will strictly monitor the running state of the script, record information such as the execution time, script ID, target file, inspection result, etc., to ensure that every detail of the script execution is accurately recorded, providing a basis for the analysis of the results and the tracing of problems.
[0087] After all personalized file check scripts are executed, the agent collates all the script execution results and, according to the feedback time indicated by the time plan, transmits the results back to the OCAS system through a secure communication channel. To avoid data loss or corruption during transmission, the agent adopts data integrity verification and redundant transmission mechanisms to ensure the accuracy of the results. The transmitted data undergoes further processing in the OCAS system, including result parsing, comparison with preset standards, marking of abnormal situations, etc., and finally appears on the system front end for users to view and analyze.
[0088] Through the parsing and recognition of task trigger instructions by the distributed agent in the above steps, it can be ensured that each personalized file check script can be executed at the correct time and in the correct order, avoiding inaccurate checks caused by incorrect execution order or time deviation. The preset trigger order and time plan enable the agent to reasonably arrange system resources, avoiding waste and conflicts of resources. At the same time, by optimizing the script execution strategy, the execution efficiency of file integrity checks can be improved, shortening the audit cycle. In the embodiment of the present invention, the distributed agent also ensures that the script execution results can be safely and completely transmitted back to the OCAS system through data integrity verification and a secure communication protocol, avoiding security risks during transmission and ensuring the authenticity and credibility of audit data.
[0089] Step S204, the distributed agent retrieves the script execution results and generates file check results based on preset standard thresholds and the script execution results.
[0090] Specifically, the preset standard threshold refers to a benchmark value of a series of indicators established to judge whether the file status is normal in file integrity checks, including but not limited to the expected hash value of the file, authorized file permission configuration, expected file size and modification time, etc. It is formulated based on security policies, compliance requirements, and historical data statistical analysis to measure whether the file has been modified without authorization, providing a basis for ensuring the objectivity and consistency of check results and for automated anomaly detection and response.
[0091] It should be noted that when the distributed agent receives the script execution results, it will immediately compare these results with the preset standard thresholds, usually involving multiple levels of checks. For example, for hash value checks, the agent will precisely match the current hash value obtained from the script execution with the expected hash value in the threshold; for permission checks, the agent will verify whether the current permission settings of the file match the authorized permissions specified in the threshold; for file size and modification time checks, it is completed by comparing the current values with the threshold ranges.
[0092] The agent will generate a detailed file inspection result based on these comparison results, including the inspection status (such as normal, warning, abnormal) of each target file, the inspection time, the detailed information of the executed script, and the specific description of the abnormal situation.
[0093] Furthermore, the generated file inspection result will be further processed and analyzed through the OCAS system. Files in the normal state will be marked as "inspection passed" according to the nature of the result, while files in the abnormal state will be marked as "abnormal", and the specific reasons for the abnormality and the recommended response measures will be attached. The results can be organized into a report form for users to view intuitively at the front end of the system. At the same time, for files marked as "abnormal", an alarm mechanism will be automatically triggered, and the application responsible person will be notified immediately through system notifications, emails, text messages, etc., so as to quickly take remedial measures to prevent the spread of threats.
[0094] Optionally, in the file inspection method based on a distributed agent provided in the embodiment of the present invention, a file inspection result is generated based on a preset standard threshold and the script execution result, including: analyzing the script execution result based on a preset key information list to obtain an analysis result, where N key information items are recorded in the preset key information list, and the analysis result contains the key information corresponding to the N key information items, and N is a positive integer; comparing each key information in the script execution result with the preset standard threshold corresponding to the key information item to obtain N comparison results, and generating a file inspection result according to all the comparison results.
[0095] It should be noted that the preset key information list is an information template that records multiple key information items, and each information item represents a core index in the file integrity inspection, such as the hash value of the file, permission configuration, modification time, file size, etc. After receiving the script execution result recycled by the distributed agent, the OCAS system deeply analyzes the result based on the preset key information list, extracts the index values corresponding to each key information item, and forms an analysis result containing all the key information.
[0096] Compare all the extracted key information one by one with the preset standard threshold corresponding to the key information item. For example, if one of the key information items is the SHA1 hash value of the file, then check whether the actual hash value of the file in the script execution result matches the preset hash value. Similarly, similar comparisons are also made for information such as file permissions and modification time. Through this process, it is possible to clearly identify which files' status deviates from the preset normal range and an abnormal situation occurs.
[0097] The OCAS system generates the final file inspection result based on the comparison result, which not only includes the comparison conclusion of the current status of each key information with the preset standard, but also includes specific anomaly descriptions, anomaly levels (such as low risk, medium risk, high risk), and recommended countermeasures, and presents them in the form of a report at the front end of the system, facilitating users to clearly understand the file status on all application servers at a glance. In addition, the embodiments of the present invention also support real-time alarming of abnormal situations, and notify the application responsible person through various methods such as system messages, emails or text messages to ensure that the anomaly can be discovered and processed in the first time.
[0098] The above steps accurately capture the subtle changes in the file status through a detailed preset key information list and a strict comparison process, avoiding misjudgment or missed judgment caused by vague inspection rules, improving the accuracy of file integrity inspection. The generated file inspection result not only details the specific inspection situation, but also includes the classification of anomaly levels and recommended countermeasures, providing users with clear operation guidelines and improving the efficiency and actual effect of security auditing; by continuously collecting and analyzing file inspection results, the enterprise security status can be deeply understood, potential security risks and system vulnerabilities can be discovered, providing empirical basis for adjusting preset standard thresholds and optimizing security policies, and promoting the continuous iteration and improvement of the enterprise security system.
[0099] Through the above steps S201 to S204, the list of applications to be inspected can be determined first, where the list of applications to be inspected includes at least one target server and at least one target file. Then, a pre-written personalized file inspection script is called for the target file, and the personalized file inspection script is sent to the target server through a distributed agent pre-deployed on the target server. The distributed agent is used to uniformly proxy the personalized file inspection script on different operating systems used by each server, then responds to the file inspection request, triggers the personalized file inspection script on the target server to obtain the script execution result, and finally recovers the script execution result through the distributed agent and generates a file inspection result based on the preset standard threshold and the script execution result.
[0100] In the embodiments of the present invention, an integrated distributed proxy technology framework is adopted. By precisely matching the personalized script deployment and execution strategies of the target server operating system, the standardized purpose of unified file integrity checking across multiple platforms is achieved. Specifically, first, a list of applications to be checked is defined to clarify the target servers and their key file sets. Subsequently, according to the specific operating systems and versions of each server in the list, pre-set and specifically optimized file checking scripts are called. These scripts are accurately sent to their respective target servers via the intelligent routing of the distributed proxy. The proxy seamlessly converts the script format in the background to ensure compatibility with the server environment, and then triggers the execution of the scripts. After the check is completed, the proxy is responsible for summarizing the execution results of the scripts and performing data analysis based on the pre-set security thresholds, and finally generating an intuitive file integrity status report. Compared with the prior art, the present invention greatly improves the unity and accuracy of the file integrity checking mechanism under the condition of server operating system diversity, thus significantly reducing the error judgment and authentication failure rate in the audit and certification processes such as PCIDSS, filling the technical gap in the automation and standardization of file checking in large-scale and multi-system environments, providing solid compliance and business security support for the financial industry, and further solving the technical problem that the file integrity checking mechanism is not unified due to server operating system diversity in the related technologies, resulting in the risks of authentication errors and authentication failures in the audit and certification processes.
[0101] The following describes the present invention in conjunction with another optional embodiment.
[0102] Embodiment 2
[0103] The embodiments of the present invention further provide a file checking device based on a distributed proxy. It should be noted that the file checking device based on a distributed proxy in the embodiments of the present invention includes multiple implementation units, and can be used to execute the file checking method based on a distributed proxy provided in the first embodiment above. Each implementation unit corresponds to each implementation step in the first embodiment above.
[0104] Figure 3 is a schematic diagram of an optional file checking device based on a distributed proxy according to an embodiment of the present invention, as Figure 3 shown. The device may include: a determination unit 31, a distribution unit 32, a trigger unit 33, and a generation unit 34.
[0105] Among them, the determination unit 31 is used to determine a list of applications to be checked, where the list of applications to be checked includes at least one target server and at least one target file.
[0106] A distribution unit 32, configured to call a pre-written personalized file check script for a target file, and distribute the personalized file check script to a target server through a distributed agent pre-deployed on the target server, where the distributed agent is used to uniformly proxy the personalized file check script on different operating systems used by each server.
[0107] A trigger unit 33, configured to respond to a file check request, trigger the personalized file check script on the target server, and obtain a script execution result.
[0108] A generation unit 34, configured to recycle the script execution result through the distributed agent, and generate a file check result based on a preset standard threshold and the script execution result.
[0109] The above file check device based on a distributed agent may first determine a list of applications to be checked through a determination unit 31, where the list of applications to be checked includes at least one target server and at least one target file, and then call a pre-written personalized file check script for the target file through the distribution unit 32, and distribute the personalized file check script to the target server through a distributed agent pre-deployed on the target server, where the distributed agent is used to uniformly proxy the personalized file check script on different operating systems used by each server, then respond to a file check request through the trigger unit 33, trigger the personalized file check script on the target server, and obtain a script execution result, and finally recycle the script execution result through the distributed agent through the generation unit 34, and generate a file check result based on a preset standard threshold and the script execution result.
[0110] In an embodiment of the present invention, an integrated distributed proxy technology framework is adopted. By precisely matching the personalized script deployment and execution strategy of the target server operating system, the standardized purpose of unified file integrity check across multiple platforms is achieved. Specifically, first, a list of applications to be checked is defined to clarify the target server and its key file sets. Subsequently, according to the specific operating system and version of each server in the list, pre-set and specifically optimized file check scripts are called. These scripts are accurately sent to their respective target servers via the intelligent routing of the distributed proxy. The proxy seamlessly converts the script format in the background to ensure compatibility with the server environment, and then triggers the script execution. After the check is completed, the proxy is responsible for summarizing the script execution results and performing data analysis based on the pre-set security thresholds, and finally generating an intuitive file integrity status report. Compared with the prior art, the present invention greatly improves the unity and accuracy of the file integrity check mechanism under the condition of server operating system diversity, thus significantly reducing the error judgment and authentication failure rate in the audit and certification processes such as PCIDSS, filling the technical gap in file check automation and standardization in a large-scale and multi-system environment, providing solid compliance and business security support for the financial industry, and further solving the technical problem in the related art that the file integrity check mechanism is not unified due to server operating system diversity, resulting in the risk of authentication errors and authentication failures in the audit and certification processes.
[0111] Optionally, the determination unit includes: a request module, configured to request an audit list from a third-party audit and certification institution, where the audit list is used to record target applications within the scope of data security audit; an acquisition module, configured to acquire node information of all target applications from a configuration management system based on the audit list, where the node information at least includes target files related to the audit in the target applications and the target servers where the target applications are located; a first generation module, configured to generate a list of applications to be checked based on the node information.
[0112] Optionally, the file check device based on a distributed proxy further includes: a first analysis module, configured to acquire and analyze the node information corresponding to a target file to obtain the environment information of the target server and the attribute information of the target file, where the environment information includes: type information and version information of the operating system used by the target server; a second generation module, configured to generate a basic check script available for the target server based on the environment information and a pre-set script template; an adjustment module, configured to adjust the parameters of the basic check script according to the attribute information to obtain a personalized file check script for the target file.
[0113] Optionally, the sending unit includes: a pushing module, configured to push the personalized file checking script using a secure communication protocol and a specified file path when the distributed agent is in an active state; a storage module, configured to receive the personalized file checking script through the distributed agent on the target server, and store the personalized file checking script in the execution queue of the target server after passing the integrity verification.
[0114] Optionally, the triggering unit includes: a parsing module, configured to parse the file checking request to obtain the checking process and time plan preselected by the user on the open interaction platform; a sending module, configured to generate a task triggering instruction based on the checking process and send the task triggering instruction to the target server according to the time plan; a triggering module, configured to trigger the personalized file checking script based on the task triggering instruction through the distributed agent on the target server to obtain a script execution result.
[0115] Optionally, the triggering module includes: an identifying sub-module, configured to parse the task triggering instruction through the distributed agent to identify at least one target file involved in this check and the triggering order; an executing sub-module, configured to execute at least one personalized file checking script corresponding to at least one target file according to the triggering order when the triggering moment indicated by the time plan arrives, to obtain at least one script execution result; a feedback sub-module, configured to feedback all the script execution results according to the time plan through the distributed agent.
[0116] Optionally, the generating unit includes: a second analysis module, configured to analyze the script execution result based on a preset key information list to obtain an analysis result, where the preset key information list records N key information items, and the analysis result includes the key information corresponding to the N key information items, and N is a positive integer; a comparison module, configured to compare each key information in the script execution result with a preset standard threshold corresponding to the key information item to obtain N comparison results, and generate a file checking result according to all the comparison results.
[0117] It should be noted here that the above-mentioned determining unit 31, sending unit 32, triggering unit 33, and generating unit 34 correspond to steps S201 to S204 in Embodiment 1. The examples and application scenarios implemented by the above units and the corresponding steps are the same, but are not limited to the content disclosed in Embodiment 1 above. It should be noted that the above modules or units may be hardware components or software components stored in a memory (for example, memory 104) and processed by one or more processors (for example, processors 102a, 102b,..., 102n), and the above modules or units may also be part of a device and can run in the computer terminal 10 provided in Embodiment 1.
[0118] The present invention will be described below in conjunction with another optional embodiment.
[0119] Embodiment III
[0120] An embodiment of the present invention may further provide an electronic device, Figure 4 which is a structural block diagram of an electronic device for executing a file checking method based on a distributed agent according to an embodiment of the present invention, as Figure 4 shown. The electronic device may include: one or more ( Figure 4 only one is shown in the figure) processors 402, a memory 404, a storage controller, and a peripheral interface, where the peripheral interface is connected to a radio frequency module, an audio module, and a display.
[0121] The memory may be used to store software programs and modules, such as program instructions / modules corresponding to the file checking method and device based on a distributed agent in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implements the above-mentioned file checking method based on a distributed agent. The memory may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, a flash memory, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely disposed relative to the processor, and these remote memories may be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0122] The processor may call the information and application programs stored in the memory through a transmission device to execute the following steps: determining a list of applications to be checked, where the list of applications to be checked includes at least one target server and at least one target file; calling a pre-written personalized file checking script for the target file, and sending the personalized file checking script to the target server through a distributed agent pre-deployed on the target server, where the distributed agent is used to uniformly proxy the personalized file checking script on different operating systems used by each server; responding to a file checking request, triggering the personalized file checking script on the target server, and obtaining a script execution result; recycling the script execution result through the distributed agent, and generating a file checking result based on a preset standard threshold and the script execution result.
[0123] The processor may also call the information and application programs stored in the memory through a transmission device to execute the following steps: requesting an audit list from a third-party audit and certification agency, where the audit list is used to record target applications within the scope of data security audit; obtaining node information of all target applications from a configuration management system based on the audit list, where the node information at least includes target files related to audit in the target applications and the target servers where the target applications are located; generating a list of applications to be checked based on the node information.
[0124] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: obtain and analyze the node information corresponding to the target file to obtain the environment information of the target server and the attribute information of the target file, where the environment information includes: the type information and version information of the operating system used by the target server; based on the environment information, generate a basic inspection script available for the target server based on a preset script template; adjust the parameters of the basic inspection script according to the attribute information to obtain a personalized file inspection script for the target file.
[0125] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: when the distributed agent is in an active state, push the personalized file inspection script using a secure communication protocol and a specified file path; receive the personalized file inspection script through the distributed agent on the target server, and after passing the integrity verification, store the personalized file inspection script in the execution queue of the target server.
[0126] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: parse the file inspection request to obtain the inspection process and time plan preselected by the user on the open interaction platform; generate a task trigger instruction based on the inspection process and issue the task trigger instruction to the target server according to the time plan; trigger the personalized file inspection script based on the task trigger instruction through the distributed agent on the target server to obtain a script execution result.
[0127] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: parse the task trigger instruction through the distributed agent to identify at least one target file involved in this inspection and the trigger order; when the trigger moment indicated by the time plan is reached, execute at least one personalized file inspection script corresponding to at least one target file according to the trigger order to obtain at least one script execution result; transmit all the script execution results back according to the time plan through the distributed agent.
[0128] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: analyze the script execution result based on a preset key information list to obtain an analysis result, where N key information items are recorded in the preset key information list, and the analysis result includes the key information corresponding to the N key information items, and N is a positive integer; compare each key information in the script execution result with the preset standard threshold corresponding to the key information item to obtain N comparison results, and generate a file inspection result according to all the comparison results.
[0129] Embodiments of the present invention provide a file inspection solution based on a distributed agent. By adopting an integrated distributed agent technology framework and precisely matching the personalized script deployment and execution strategies of the target server operating system, the standardization goal of unified file integrity inspection across multiple platforms is achieved. Specifically, first, a list of applications to be inspected is defined to clarify the target server and its key file sets. Subsequently, according to the specific operating system and version of each server in the list, pre-set and specifically optimized file inspection scripts are called. These scripts are accurately sent to their respective target servers via the intelligent routing of the distributed agent. The agent seamlessly converts the script format in the background to ensure compatibility with the server environment, and then triggers the script execution. After the inspection is completed, the agent is responsible for summarizing the script execution results and performing data analysis based on the pre-set security thresholds, and finally generating an intuitive file integrity status report. Compared with the prior art, the present invention greatly improves the unity and accuracy of the file integrity inspection mechanism under the condition of server operating system diversity, thereby significantly reducing the error judgment and authentication failure rate in the audit and certification processes such as PCIDSS, filling the technical gap in the automation and standardization of file inspection in large-scale and multi-system environments, providing solid compliance and business security support for the financial industry, and thus solving the technical problem that the file integrity inspection mechanism is not unified due to the diversity of server operating systems in the related art, resulting in the risks of authentication errors and authentication failures in the audit and certification processes.
[0130] Those of ordinary skill in the art can understand that Figure 4 the structure shown is only schematic, and the electronic device can also be a terminal device such as a smart phone, a tablet computer, a palm computer, and a Mobile Internet Device (MID), a PAD, etc. Figure 4 It does not limit the structure of the above-mentioned electronic device. For example, the electronic device may further include more or fewer components (such as a network interface, a display device, etc.) than those shown Figure 4 in the figure, or have a different configuration from that shown Figure 4 in the figure.
[0131] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the relevant hardware of the terminal device through a program, and the program can be stored in a computer-readable storage medium. The storage medium may include: a flash drive, a Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk or an optical disc, etc.
[0132] The present invention will be described below in conjunction with another optional embodiment.
[0133] Embodiment 4
[0134] An embodiment of the present invention also provides a computer-readable storage medium. Optionally, in the embodiment of the present invention, the above computer-readable storage medium can be used to store the program code executed by the file checking method based on distributed agents provided in the first embodiment above.
[0135] Optionally, in the embodiment of the present invention, the above storage medium can be located in any one of the computer terminals in a computer terminal group in a computer network, or in any one of the mobile terminals in a mobile terminal group.
[0136] An embodiment of the present invention also provides a computer program product. When executed on a data processing device, it is adapted to execute a program for the steps of the file checking method based on distributed agents: determining a list of applications to be checked, where the list of applications to be checked includes at least one target server and at least one target file; calling a pre-written personalized file checking script for the target file, and sending the personalized file checking script to the target server through a distributed agent pre-deployed on the target server, where the distributed agent is used to uniformly proxy the personalized file checking script on different operating systems used by each server; responding to a file checking request, triggering the personalized file checking script on the target server to obtain a script execution result; recycling the script execution result through the distributed agent, and generating a file checking result based on a preset standard threshold and the script execution result.
[0137] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages or disadvantages of the embodiments.
[0138] In the above embodiments of the present application, the descriptions of the respective embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0139] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.
[0140] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0141] In addition, in each embodiment of the present application, each functional unit can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0142] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: USB flash drive, read-only memory (ROM), random access memory (RAM), mobile hard disk, magnetic disk or optical disc and other various media that can store program codes.
[0143] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A file checking method based on distributed agents, characterized in that Including: Determine a list of applications to be inspected, where the list of applications to be inspected includes at least one target server and at least one target file; Invoke a pre-written personalized file inspection script for the target file, and send the personalized file inspection script to the target server through a distributed agent pre-deployed on the target server, where the distributed agent is used to uniformly proxy the personalized file inspection script on different operating systems used by each server; In response to a file inspection request, trigger the personalized file inspection script on the target server to obtain a script execution result; Recover the script execution result through the distributed agent, and generate a file inspection result based on a preset standard threshold and the script execution result.
2. The document checking method according to claim 1, wherein, The step of determining the list of applications to be inspected includes: Request an audit list from a third-party audit and certification agency, where the audit list is used to record target applications within the scope of data security audit; Obtain node information of all the target applications from a configuration management system based on the audit list, where the node information at least includes the target file related to the audit in the target application and the target server where the target application is located; Generate the list of applications to be inspected based on the node information.
3. The document checking method according to claim 1, wherein The step of pre-writing a personalized file inspection script includes: Obtain and analyze the node information corresponding to the target file to obtain the environment information of the target server and the attribute information of the target file, where the environment information includes: type information and version information of the operating system used by the target server; Based on the environment information, generate a basic inspection script available for the target server based on a preset script template; Adjust the parameters of the basic inspection script according to the attribute information to obtain the personalized file inspection script for the target file.
4. The document checking method according to claim 1, characterized in that, The step of sending the personalized file inspection script to the target server through a distributed agent pre-deployed on the target server includes: When the distributed agent is in an active state, push the personalized file inspection script using a secure communication protocol and a specified file path; Receive the personalized file inspection script through the distributed agent on the target server, and after passing the integrity verification, store the personalized file inspection script in the execution queue of the target server.
5. The document checking method according to claim 1, wherein The step of triggering the personalized file inspection script on the target server in response to a file inspection request to obtain a script execution result includes: Parse the file inspection request to obtain the inspection process and time plan pre-selected by the user on an open interaction platform; Generate a task trigger instruction based on the inspection process, and send the task trigger instruction to the target server according to the time plan; Trigger the personalized file inspection script through the distributed agent on the target server based on the task trigger instruction to obtain the script execution result.
6. The document checking method according to claim 5, characterized in that The step of triggering the personalized file check script by the distributed agent on the target server based on the task trigger instruction to obtain the script execution result includes: The distributed agent parses the task trigger instruction to identify at least one target file involved in this check and the trigger order; When the trigger moment indicated by the time plan is reached, execute at least one of the personalized file check scripts corresponding to the at least one target file in accordance with the trigger order to obtain at least one script execution result; The distributed agent uploads all the script execution results according to the time plan.
7. The document checking method according to claim 1, characterized in that Generating a file check result based on a preset standard threshold and the script execution result includes: Analyze the script execution result based on a preset key information list to obtain an analysis result, wherein N key information items are recorded in the preset key information list, and the analysis result contains key information corresponding to the N key information items, and N is a positive integer; Compare each key information in the script execution result with the preset standard threshold corresponding to the key information item to obtain N comparison results, and generate the file check result according to all the comparison results.
8. A file checking device based on distributed agents, characterized in that Including: A determination unit for determining a list of applications to be checked, where the list of applications to be checked includes at least one target server and at least one target file; A distribution unit for calling a pre-written personalized file check script for the target file and distributing the personalized file check script to the target server through a distributed agent pre-deployed on the target server, where the distributed agent is used to uniformly proxy the personalized file check script on different operating systems used by each server; A trigger unit for triggering the personalized file check script on the target server in response to a file check request to obtain a script execution result; A generation unit for retrieving the script execution result through the distributed agent and generating a file check result based on a preset standard threshold and the script execution result.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored computer program, wherein when the computer program runs, it controls the device where the computer-readable storage medium is located to execute the distributed-agent-based file check method according to any one of claims 1 to 7.
10. An electronic device, characterized in that, Including one or more processors and a memory, the memory is used to store one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the distributed-agent-based file check method according to any one of claims 1 to 7.