Data updating method, electronic equipment and computer readable storage medium
By obtaining the data packets to be updated on the cloud server in the central area and synchronizing them to the cloud server in the unit area, the problems of high time and labor costs and poor timeliness of host security products in multiple regions are solved, and efficient and accurate multi-region updates are achieved.
Patent Information
- Application Number
- CN202410077372.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-18
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, there are problems such as high time cost, high labor cost and poor timeliness for the update of host security vulnerabilities in multiple regions, and there is no effective solution yet.
By obtaining the data packets to be updated, the cloud servers in the central area are updated, and the update instructions and data packets are synchronized to multiple cloud servers in the unit area, so as to achieve synchronous updates of host security products in multiple regions.
It realizes efficient and low-cost multi-region host security product updates, improving the timeliness and accuracy of updates.
Smart Images

Figure CN120335829A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technologies, and in particular, to a data update method, an electronic device, and a computer-readable storage medium. Background Art
[0002] There are usually many security vulnerabilities and weaknesses in a computer host system, leading to potential data security risks such as data leakage in the host system. To protect the security of the host system, host security vulnerability detection is performed on host security products, and the discovered vulnerabilities are patched in a timely manner. However, since security vulnerabilities are constantly changing, it is necessary to frequently update the host security vulnerability rule package in the host security product.
[0003] Currently, the update of the host security vulnerability rule package is usually for the current region (Region). For large customers, such as those with host security products distributed in multiple regions, the update of the host security vulnerability rule package also involves multiple regions. Using the existing update method for the host security vulnerability rule package requires a large amount of time and effort, affecting the timeliness of the update of the host security vulnerability rule package.
[0004] In response to the above problems, no effective solution has been proposed yet. Summary of the Invention
[0005] Embodiments of this application provide a data update method, an electronic device, and a computer-readable storage medium to at least solve the technical problem in the related art that only the host security products in the current region can be updated, resulting in high time and labor costs when updating host security products in multiple regions, and poor timeliness of the update.
[0006] According to one aspect of the embodiments of this application, a data update method is provided, including: obtaining a data packet to be updated, where the data packet to be updated is used to discover and repair system security vulnerabilities on a first server and multiple second servers, the first server is deployed in a first area under a cloud environment, the multiple second servers are respectively deployed in multiple second areas under the cloud environment, and the first area is used to manage the multiple second areas; in response to the received update instruction, updating the security protection application configured on the first server based on the data packet to be updated, and synchronizing the update instruction and the data packet to be updated to the multiple second servers, so that the multiple second servers, in response to the update instruction, synchronously update the security protection application configured on the multiple second servers based on the data packet to be updated.
[0007] According to another aspect of the embodiments of the present application, there is also provided a data update method, including: receiving an update instruction and a data packet to be updated from a first server, where the data packet to be updated is used to discover and repair system security vulnerabilities on multiple second servers, the first server is deployed in a first area of a cloud environment, the multiple second servers are respectively deployed in multiple second areas of the cloud environment, and the first area is used to manage the multiple second areas; in response to the received update instruction, synchronously updating the security protection application programs configured on the multiple second servers based on the data packet to be updated.
[0008] According to another aspect of the embodiments of the present application, there is also provided a data update. By a terminal device, a graphical user interface is provided, and the content displayed by the graphical user interface at least partially includes a system security vulnerability repair scenario, including: in response to a first touch operation on the graphical user interface, selecting an appropriate data packet to be updated for the security protection application program configured on the first server, where the data packet to be updated is used to discover and repair system security vulnerabilities on the first server and multiple second servers, the first server is deployed in a first area of a cloud environment, the multiple second servers are respectively deployed in multiple second areas of the cloud environment, and the first area is used to manage the multiple second areas; in response to a second touch operation on the graphical user interface, initiating an update instruction to control the first server to update the security protection application program based on the data packet to be updated, and synchronizing the update instruction and the data packet to be updated to the multiple second servers, so that the multiple second servers, in response to the update instruction, synchronously update the security protection application programs configured on the multiple second servers based on the data packet to be updated.
[0009] According to another aspect of the embodiments of the present application, there is also provided a computer-readable storage medium. The computer-readable storage medium includes an executable program stored therein. When the executable program runs, it controls the device where the computer-readable storage medium is located to execute any one of the above data update methods.
[0010] According to another aspect of the embodiments of the present application, there is also provided an electronic device, including: a memory storing an executable program; a processor for running the program, where when the program runs, it executes any one of the above data update methods.
[0011] According to another aspect of the embodiments of the present application, there is also provided a computer program product, including a computer program, where when the computer program is executed by a processor, it implements any one of the above data update methods.
[0012] In an embodiment of the present application, by obtaining a data packet to be updated for checking and updating system security vulnerabilities on the cloud servers in the central region and the cloud servers in the unit regions, and then after receiving an update instruction for updating the security protection application, updating the security protection application configured on the cloud servers in the central region based on the data packet to be updated. At the same time, synchronously sending the update instruction and the data packet to be updated to multiple cloud servers in the unit regions, so that the multiple cloud servers in the unit regions respond to the update instruction and synchronously update the security protection application based on the data packet to be updated. Thus, the purpose of timely and accurate updating of the host security products in multiple regions is achieved, thereby realizing the efficient and low-cost updating of the host security products in multiple regions, improving the timeliness and accuracy of the update of the host security products, and further solving the technical problem in the related art that only the host security products in the current region can be updated, resulting in high time cost and labor cost when updating the host security products in multiple regions and poor timeliness of the update.
[0013] It is easy to notice that the above general description and the following detailed description are only for exemplifying and explaining the present application and do not constitute a limitation to the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The schematic embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:
[0015] Figure 1 is a hardware structure block diagram of a computer terminal (or mobile device) for implementing a data update method according to Embodiment 1 of the present application;
[0016] Figure 2 is a flowchart of a data update method according to Embodiment 1 of the present application;
[0017] Figure 3 is another flowchart of a data update method according to Embodiment 1 of the present application;
[0018] Figure 4 is a flowchart of a data update method according to Embodiment 2 of the present application;
[0019] Figure 5 is a flowchart of a data update method according to Embodiment 3 of the present application;
[0020] Figure 6 is a schematic structural diagram of a data update device according to Embodiment 4 of the present application;
[0021] Figure 7It is a schematic structural diagram of another data update device according to Embodiment 4 of the present application;
[0022] Figure 8 It is a schematic structural diagram of yet another data update device according to Embodiment 4 of the present application;
[0023] Figure 9 It is a block diagram of the structure of a computer terminal according to an embodiment of the present application. Detailed implementation manners
[0024] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0026] First, some nouns or terms that appear in the process of describing the embodiments of the present application are applicable to the following explanations:
[0027] Multi-region (Region) architecture: It refers to a business architecture that can be deployed and used in multiple geographical regions or data centers in a private cloud environment. The multi-Region architecture can provide higher availability and disaster tolerance capabilities, and at the same time can also reduce network latency and improve system performance.
[0028] Private cloud: It is a cloud environment built for a specific organization or enterprise. The private cloud provides higher customizability, security, and control, and has exclusivity, that is, only a specific organization or enterprise has the right to access and manage it.
[0029] Host security vulnerability rule package: A set of predefined rules and policies for discovering and fixing security vulnerabilities on hosts. These rules include detecting known vulnerabilities, weaknesses, and configuration errors in the host system, as well as detecting unknown vulnerabilities and new attack techniques.
[0030] Data Transmission Service (DTS): A data transmission solution that helps users easily implement operations such as data migration, data synchronization, and data subscription between different data sources. DTS supports data transmission between multiple data sources, including relational databases, NoSQL databases, message queues, data warehouses, etc. DTS has characteristics and advantages such as real-time data synchronization, high reliability, flexibility, and data security, effectively simplifying the complexity of data management and improving the efficiency and reliability of data transmission.
[0031] There are the following defects in updating only the host security vulnerability rule package for the current single region in the related art.
[0032] Defect 1: For the update of the host security vulnerability rule package in multiple regions, there are defects such as high time cost, high labor cost, and poor timeliness of updating the host security vulnerability rule package.
[0033] In response to the above defects, no effective solution has been proposed before this application.
[0034] Embodiment 1
[0035] According to an embodiment of the present application, a data update method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0036] The method embodiment provided by the first embodiment of the present application can be executed on a mobile terminal, a computer terminal, or a similar computing device. Figure 1 It is a hardware structure block diagram of a computer terminal (or mobile device) for implementing the data update method according to Embodiment 1 of the present application. As Figure 1As shown, the computer terminal 10 (or mobile device) may include one or more processors 102 (illustrated as 102a, 102b, ……, 102n in the figure) (the processor 102 may include, but is not limited to, processing devices such as a microprocessor MCU or a field-programmable gate array FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only illustrative and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown therein, or have a different configuration from Figure 1 that shown.
[0037] It should be noted that the above one or more processors 102 and / or other data processing circuits are generally referred to as "data processing circuits" herein. The data processing circuit may be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit may be a single independent processing module, or be incorporated in whole or in part into any one of the other elements in the computer terminal 10 (or mobile device). As involved in the embodiments of the present application, the data processing circuit is used for processor control (such as the selection of a variable resistor terminal path connected to an interface).
[0038] The memory 104 may be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the data update method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned data update method. The memory 104 may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, a flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories may be connected to the computer terminal 10 through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0039] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0040] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables the user to interact with the user interface of the computer terminal 10 (or mobile device).
[0041] Under the above operating environment, the present application provides a data update method as Figure 2 shown. Figure 2 It is a flowchart of a data update method according to Embodiment 1 of the present application. As Figure 2 shown, the method may include the following steps:
[0042] Step S21, obtain a data packet to be updated, where the data packet to be updated is used to discover and repair system security vulnerabilities on a first server and multiple second servers. The first server is deployed in a first area of the cloud environment, and the multiple second servers are respectively deployed in multiple second areas of the cloud environment. The first area is used to manage the multiple second areas;
[0043] Step S22, in response to the received update instruction, update the security protection application configured on the first server based on the data packet to be updated, and synchronize the update instruction and the data packet to be updated to the multiple second servers, so that the multiple second servers, in response to the update instruction, synchronously update the security protection applications configured on the multiple second servers based on the data packet to be updated.
[0044] Embodiments of the present application may include, but are not limited to, being applied to scenarios such as a proprietary cloud multi-Region architecture scenario, a multi-Region architecture scenario, etc. It can be understood that in a multi-Region architecture scenario, application programs or systems are deployed in data centers or cloud service providers in multiple geographical locations. Exemplarily, the execution subject of Embodiment 1 can be a cloud server in the central area of a multi-Region architecture scenario.
[0045] Among multiple geographical locations, there are a central area and unit areas. The central area can be understood as a main data center or region, which has main resources and services. The central area is usually the core of the entire architecture, responsible for handling most of the workloads and data storage. The unit areas refer to auxiliary data centers or regions, which are usually used for backup, disaster recovery, load balancing, or service requirements in specific regions. The unit areas usually achieve high availability and fault tolerance through replication and synchronization with the central area. It can be understood that the central area is used to manage multiple unit areas.
[0046] In the embodiments of the present application, the first server and the second server can be understood as servers or cloud servers deployed under a multi-Region architecture. The first region is the central area under the multi-Region architecture, and the second region is the unit area under the multi-Region architecture.
[0047] Optionally, the first server can be a cloud server deployed in the central area of the cloud environment, and the second server can be a cloud server deployed in the unit area of the cloud environment.
[0048] The data packet to be updated can be understood as a data packet used to update an application. Exemplarily, the data packet to be updated can be a host security vulnerability rule packet, which is used to update the host security product, that is, to discover and repair the host system security vulnerabilities on the first server and multiple second servers. There is no limitation here.
[0049] The update instruction can be an upgrade instruction, an instruction used to upgrade an application, that is, an instruction used to update the security protection application. Exemplarily, the update instruction can be an update instruction issued by customer security operations. For example, when a web page or application shows a white screen due to reasons such as program errors, network problems, or data loading failures, customer security operations can issue an update instruction to the cloud server in the central area to repair the vulnerabilities of the host security product configured on the cloud server in the central area. The security protection application can be a host security product.
[0050] In the embodiments of the present application, by obtaining an update data packet for checking and updating system security vulnerabilities on the cloud servers in the central region and the cloud servers in the unit regions, and then after receiving an update instruction for updating the security protection application, updating the security protection application configured on the cloud servers in the central region based on the update data packet. At the same time, synchronously sending the update instruction and the update data packet to multiple cloud servers in the unit regions, so that the multiple cloud servers in the unit regions respond to the update instruction and synchronously update the security protection application based on the update data packet. Thus, the purpose of timely and accurate updating of the host security products in multiple regions can be achieved, realizing the efficient and low-cost updating of the host security products in multiple regions, and improving the timeliness and accuracy of the updating of the host security products.
[0051] The above data update method provided by the embodiments of the present application can be, but is not limited to, applied to application scenarios involving the update of host security products in fields such as e-commerce services, education services, legal services, medical services, conference services, social network services, financial product services, logistics services, and navigation services. For example: the update of the host security product in e-commerce services, the update of the host security product in education services, the update of the host security product in legal services, etc., which are not limited here.
[0052] By adopting the embodiments of the present application, by obtaining an update data packet for checking and updating system security vulnerabilities on the cloud servers in the central region and the cloud servers in the unit regions, and then after receiving an update instruction for updating the security protection application, updating the security protection application configured on the cloud servers in the central region based on the update data packet. At the same time, synchronously sending the update instruction and the update data packet to multiple cloud servers in the unit regions, so that the multiple cloud servers in the unit regions respond to the update instruction and synchronously update the security protection application based on the update data packet. Thus, the purpose of timely and accurate updating of the host security products in multiple regions is achieved, thereby realizing the efficient and low-cost updating of the host security products in multiple regions, and improving the timeliness and accuracy of the updating of the host security products. Furthermore, the technical problem in the related art that only the host security products in the current region can be updated, resulting in high time cost and labor cost when updating the host security products in multiple regions and poor timeliness of the update, is solved.
[0053] In an alternative embodiment, the first region and the multiple second regions are different geographical regions that are isolated from each other.
[0054] In the embodiments of the present application, the central region and multiple unit regions in the multi-Region architecture can be different geographically isolated regions, that is, the central region and multiple unit regions are physically separated from each other and are located in different geographical regions. Thus, the central region and multiple unit regions are independent of each other, which can improve the stability and fault tolerance of the system, and at the same time, can also reduce the influence and risk between different regions.
[0055] In an alternative embodiment, the first region and multiple second regions are different data centers isolated from each other.
[0056] In the embodiments of the present application, the central region and multiple unit regions in the multi-Region architecture can be different data centers (Data Center) isolated from each other, that is, the central region and multiple unit regions can be located in different data centers under the same geographical region.
[0057] The isolation between data centers can be understood as that multiple data centers are physically independent of each other and there is no direct network connection between them, or only a strictly controlled and restricted network connection. In the embodiments of the present application, the central region and multiple unit regions are located in different data centers isolated from each other. When a data center fails or becomes unavailable, other data centers can continue to provide services to ensure business continuity, thereby ensuring data security and availability. In an alternative embodiment, in step S22, synchronizing the update instruction and the data packet to be updated to multiple second servers includes the following method steps:
[0058] Step S221, using a data transmission service to synchronize the update instruction and the data packet to be updated to multiple second servers.
[0059] In the embodiments of the present application, when synchronizing the update instruction and the data packet to be updated to multiple second servers, a data transmission service (Data Transmission Service, DTS) can be used to synchronize the received update instruction and the data packet to be updated to multiple second servers. Exemplarily, the cloud server in the central region can synchronize through the dedicated cloud DTS to synchronize the upgrade instruction and the host security vulnerability rule package to multiple cloud servers in the unit region, so as to achieve real-time data synchronization between multiple data sources and improve the efficiency and reliability of data transmission.
[0060] In an alternative embodiment, the data update method further includes the following method steps:
[0061] Step S23: Receive the update results reported by multiple second servers. The update results are used to represent one of the following: all of the multiple second servers have completed the update of the security protection application; a first part of the multiple second servers have completed the update of the security protection application, and a second part of the multiple second servers have not completed the update of the security protection application, where the second part of the servers are the remaining servers among the multiple second servers other than the first part of the servers.
[0062] In an embodiment of the present application, after multiple cloud servers in a unit area receive the upgrade instructions and host security vulnerability rule packages sent by the cloud server in the central area and update the host security products configured on the multiple cloud servers, they can also perform an upgrade callback and send the update results to the cloud server in the central area.
[0063] Therefore, the first server in the central area can also receive the update results reported by multiple second servers. The update results are used to represent at least one of the following: all of the multiple second servers in the unit area have completed the update of the security protection application; a first part of the multiple second servers in the unit area have completed the update of the security protection application; and a second part of the multiple second servers in the unit area have not completed the update of the security protection application. The second part of the servers are the remaining servers among the multiple second servers other than the first part of the servers, that is, the update results are used to reflect which servers in the multiple second servers in the unit area have successfully completed the update and which have not.
[0064] In an alternative embodiment, the data update method further includes the following method steps:
[0065] Step S231: In response to the update result indicating that the second part of the servers have not completed the update of the security protection application, resynchronize the update instructions and the data packets to be updated to the second part of the servers until the second part of the servers complete the update of the security protection application.
[0066] In an embodiment of the present application, after the central area receives the update results, if the update results indicate that some of the multiple cloud servers in the unit area (i.e., the second part of the servers) have not completed the update of the security protection application, the update instructions and the data packets to be updated can be resent to the second part of the servers until the second part of the servers complete the update of the security protection application, so as to ensure that the host security products in the cloud servers in each area under the multi-Region architecture can be updated in a timely and accurate manner.
[0067] Figure 3 It is another flowchart of the data update method according to Embodiment 1 of the present application, as Figure 3As shown, if a blank screen occurs on a web page or application due to program errors, network problems, data loading failures, etc., security operations can issue an upgrade rule package under the blank screen, that is, issue a host security vulnerability rule package to the host security products in the central region. After receiving the host security vulnerability rule package and the upgrade instruction, the host security products in the central region can upgrade and repair the host security products based on the host security vulnerability rule package, and at the same time synchronize the upgrade instruction and the host security vulnerability rule package to the host security products in multiple unit regions through the DTS dedicated line data. After receiving the upgrade instruction and the host security vulnerability rule package, the host security products in the unit regions upgrade and repair the host security products based on the host security vulnerability rule package, and callback the update result of the upgrade and repair to the host security products in the central region, so that the host security products in the central region can reissue the upgrade instruction and the host security vulnerability rule package based on the update result, ensuring that the host security products in the cloud servers in each region under the multi-Region architecture can be updated in a timely and accurate manner.
[0068] It can be seen that based on the host security vulnerability detection ability and the multi-Region architecture in the cloud environment, this application effectively optimizes the update process of the host security vulnerability rule package for large customers, improves the timeliness and accuracy of the update of the host security vulnerability rule package, and at the same time effectively improves the host security defense ability of customers.
[0069] It is easy to understand that the beneficial effects of the data update method provided by this application include the following points.
[0070] Beneficial effect (1): It can update the host security vulnerability rule package in multiple regions at low cost and high efficiency, with low time cost and low labor cost, and can update the host security vulnerability rule package in a timely and accurate manner.
[0071] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or refuse.
[0072] In addition, it should also be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be carried out in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0073] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc), and includes several instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in various embodiments of the present application.
[0074] Embodiment 2
[0075] Under the operating environment as in Embodiment 1, the present application provides a data update method as Figure 4 shown. Figure 4 FIG. is a flowchart of a data update method according to Embodiment 2 of the present application. As Figure 4 shown, the method includes:
[0076] Step S41: Receive an update instruction and a data packet to be updated from a first server. The data packet to be updated is used to discover and repair system security vulnerabilities on multiple second servers. The first server is deployed in a first area in a cloud environment, and the multiple second servers are respectively deployed in multiple second areas in the cloud environment. The first area is used to manage the multiple second areas;
[0077] Step S42: In response to the received update instruction, synchronously update the security protection application programs configured on the multiple second servers based on the data packet to be updated.
[0078] Embodiments of the present application may include, but are not limited to, being applied to scenarios such as a proprietary cloud multi-Region architecture scenario, a multi-Region architecture scenario, etc. It can be understood that in a multi-Region architecture scenario, application programs or systems are deployed in data centers or cloud service providers in multiple geographical locations. Exemplarily, the execution subject of Embodiment 2 may be a cloud server in a unit area in a multi-Region architecture scenario.
[0079] The multiple geographical locations include a central area and unit areas. Among them, the central area can be understood as a main data center or area, which has main resources and services. The central area is usually the core of the entire architecture and is responsible for processing most of the workload and data storage. The unit area refers to an auxiliary data center or area. The unit area is usually used for backup, disaster recovery, load balancing, or service requirements in a specific region. The unit area usually achieves high availability and fault tolerance through replication and synchronization with the central area. It can be understood that the central area is used to manage the multiple unit areas.
[0080] In the embodiments of the present application, the first server and the second server can be understood as servers or cloud servers deployed in a multi-Region architecture. The first region is the central region in the multi-Region architecture, and the second region is the unit region in the multi-Region architecture.
[0081] Optionally, the first server can be a cloud server deployed in the central region of the cloud environment, and the second server can be a cloud server deployed in the unit region of the cloud environment.
[0082] The data packet to be updated can be understood as a data packet used to update an application. Exemplarily, the data packet to be updated can be a host security vulnerability rule packet, which is used to update the host security product, that is, to discover and repair the system security vulnerabilities of the host systems on the first server and multiple second servers. There is no limitation here.
[0083] The update instruction can be an upgrade instruction, an instruction used to upgrade an application, that is, an instruction used to update the security protection application. Exemplarily, the update instruction can be an update instruction issued by the customer security operation. For example, when a white screen situation occurs on a web page or an application due to reasons such as program errors, network problems, or data loading failures, the customer security operation can issue an update instruction to the cloud server in the central region to repair the vulnerabilities of the host security product configured on the cloud server in the central region. The security protection application can be the host security product.
[0084] In the embodiments of the present application, by receiving the update instruction sent from the cloud server in the central region and the data packet to be updated used to check and update the system security vulnerabilities of the multiple cloud servers in the unit region, and then based on the received update instruction and the data packet to be updated, synchronously update the security protection applications configured on the multiple cloud servers in the unit region. Thus, the purpose of timely and accurate updating of the host security products in multiple regions can be achieved, the technical effect of efficiently and low-cost updating the host security products in multiple regions and improving the timeliness and accuracy of updating the host security products is realized.
[0085] The above data update method provided by the embodiments of the present application can be but is not limited to being applied to application scenarios involving the update of host security products in fields such as e-commerce services, education services, legal services, medical services, conference services, social network services, financial product services, logistics services, and navigation services. For example: the update of the host security product in e-commerce services, the update of the host security product in education services, the update of the host security product in legal services, etc. There is no limitation here.
[0086] By adopting the embodiment of the present application, an update instruction sent by a cloud server in the central region and an update data packet for checking and updating system security vulnerabilities on multiple cloud servers in the unit region are received. Then, based on the received update instruction and update data packet, the security protection application programs configured on the multiple cloud servers in the unit region are synchronously updated, thereby achieving the purpose of timely and accurate update of host security products in multiple regions, thus realizing the efficient and low-cost update of host security products in multiple regions, improving the timeliness and accuracy of the update of host security products, and further solving the technical problem in the related art that only the host security products in the current region can be updated, resulting in high time cost and labor cost when updating host security products in multiple regions, and poor timeliness of the update.
[0087] In an alternative embodiment, in step S41, receiving the update instruction and the update data packet from the first server includes the following method steps:
[0088] Step S411, receiving the update instruction and the update data packet from the first server through the data transmission service.
[0089] In the embodiment of the present application, when receiving the update instruction and the update data packet from the first server, the update instruction and the update data packet sent by the cloud server in the central region can be received through the Data Transmission Service (DTS), so as to realize the real-time synchronization of data between multiple data sources and improve the efficiency and reliability of data transmission.
[0090] In an alternative embodiment, the data update method further includes the following method steps:
[0091] Step S43, reporting the update result to the first server, where the update result is used to indicate that the update of the security protection application program has been completed currently.
[0092] In the embodiment of the present application, after the multiple cloud servers in the unit region receive the upgrade instruction and the host security vulnerability rule package sent by the cloud server in the central region and update the host security products configured on the multiple cloud servers, they can also perform an upgrade callback and report the update result indicating that the update of the security protection application program has been completed currently to the first server, that is, send the update result to the cloud server in the central region.
[0093] It should be noted that the preferred implementation manner of this embodiment can refer to the relevant description in Embodiment 1, and will not be elaborated here.
[0094] Embodiment 3
[0095] Under the operating environment as in Embodiment 1, the present application provides a data update method as follows Figure 5 as shown below. Figure 5 FIG. is a flowchart of a data update method according to Embodiment 3 of the present application. As Figure 5 shown, a graphical user interface is provided by a terminal device, and the content displayed on the graphical user interface at least partially includes a system security vulnerability repair scenario. The method includes:
[0096] Step S51, in response to a first touch operation on the graphical user interface, select an adapted data packet to be updated for the security protection application configured on the first server, where the data packet to be updated is used to discover and repair system security vulnerabilities on the first server and multiple second servers. The first server is deployed in a first area of the cloud environment, and the multiple second servers are respectively deployed in multiple second areas of the cloud environment. The first area is used to manage the multiple second areas;
[0097] Step S52, in response to a second touch operation on the graphical user interface, initiate an update instruction, control the first server to update the security protection application based on the data packet to be updated, and synchronize the update instruction and the data packet to be updated to the multiple second servers, so that the multiple second servers respond to the update instruction and synchronously update the security protection applications configured on the multiple second servers based on the data packet to be updated.
[0098] In the graphical user interface in the embodiment of the present application, at least a system security vulnerability repair scenario is displayed, that is, a host system security vulnerability repair scenario. The user can freely select an adapted data packet to be updated from a variety of data packets to be updated displayed in the system security vulnerability repair scenario, that is, select a host security vulnerability rule packet adapted to the host security product, and can initiate an update instruction through a touch operation to update the security protection application deployed on the server, etc.
[0099] The above-mentioned graphical user interface further includes a first control (or a first touch area). When a first touch operation on the first control (or the first touch area) is detected, an adapted data packet to be updated can be selected for the security protection application configured on the first server. The above-mentioned first touch operation can be an operation such as point selection, box selection, check box selection, conditional filtering, etc., which is not limited here.
[0100] The above-mentioned graphical user interface further includes a second control (or a second touch area). When a second touch operation on the second control (or the second touch area) is detected, an update instruction can be initiated to control the first server to update the security protection application program based on the data packet to be updated, and synchronize the update instruction and the data packet to be updated to multiple second servers, so that the multiple second servers respond to the update instruction and synchronously update the security protection application programs configured on the multiple second servers based on the data packet to be updated. The above-mentioned second touch operation can be operations such as clicking, selecting, ticking, conditional filtering, etc., which are not limited here.
[0101] Among them, the first server and the second server can be understood as servers or cloud servers deployed in a multi-Region architecture. The first region is the central area in the multi-Region architecture, and the second region is the unit area in the multi-Region architecture. It can be understood that the central area is used to manage multiple unit areas.
[0102] Optionally, the first server can be a cloud server deployed in the central area of the cloud environment, and the second server can be a cloud server deployed in the unit area of the cloud environment.
[0103] The data packet to be updated can be understood as a data packet used to update the application program. Exemplarily, the data packet to be updated can be a host security vulnerability rule packet, which is used to update the host security product, that is, to discover and repair the host system security vulnerabilities on the first server and multiple second servers, which is not limited here.
[0104] The update instruction can be an upgrade instruction, an instruction used to upgrade the application program, that is, an instruction used to update the security protection application program. Exemplarily, the update instruction can be an update instruction issued by the customer security operation. For example, when a white screen situation occurs on a web page or an application program due to reasons such as program errors, network problems, or data loading failures, the customer security operation can issue an update instruction to the cloud server in the central area to repair the vulnerabilities of the host security product configured on the cloud server in the central area. The security protection application program can be a host security product.
[0105] It should be noted that both the above-mentioned first touch operation and the second touch operation can be operations where the user touches the display screen of the above-mentioned terminal device with a finger and touches the terminal device. This touch operation can include single-touch and multi-touch. Among them, the touch operation of each touch point can include clicking, long-pressing, hard-pressing, swiping, etc. The above-mentioned first touch operation and the second touch operation can also be touch operations implemented through input devices such as a mouse and a keyboard, which are not limited here.
[0106] The above data update method provided by the embodiments of the present application can be but is not limited to being applied to application scenarios involving the update of host security products in fields such as e-commerce services, education services, legal services, medical services, conference services, social network services, financial product services, logistics services, and navigation services. For example: the update of host security products for e-commerce services, the update of host security products for education services, the update of host security products for legal services, etc. There is no limitation here.
[0107] By adopting the embodiments of the present application, by responding to the first touch operation acting on the graphical user interface, an adapted data packet to be updated is selected for the security protection application program configured on the first server. The data packet to be updated is used to discover and repair system security vulnerabilities on the first server and multiple second servers. The first server is deployed in the first area of the cloud environment, and the multiple second servers are respectively deployed in multiple second areas of the cloud environment. The first area is used to manage the multiple second areas. By responding to the second touch operation acting on the graphical user interface, an update instruction is initiated to control the first server to update the security protection application program based on the data packet to be updated, and the update instruction and the data packet to be updated are synchronized to the multiple second servers, so that the multiple second servers respond to the update instruction and synchronously update the security protection application programs configured on the multiple second servers based on the data packet to be updated. Thus, the purpose of timely and accurate updating of host security products in multiple regions is achieved, thereby realizing efficient and low-cost updating of host security products in multiple regions, improving the timeliness and accuracy of updating host security products, and further solving the technical problem in the related art that only the host security products in the current region can be updated, resulting in high time cost and labor cost when updating host security products in multiple regions, and poor timeliness of updating.
[0108] It should be noted that the preferred implementation manner of this embodiment can refer to the relevant description in Embodiment 1, and will not be elaborated here.
[0109] Embodiment 4
[0110] According to the embodiments of the present application, there is also provided an apparatus embodiment for implementing the above data update. Figure 6 It is a structural schematic diagram of a data update apparatus according to Embodiment 4 of the present application, as Figure 6 shown. The apparatus includes:
[0111] An acquisition module 601, configured to acquire a data packet to be updated, where the data packet to be updated is used to discover and repair system security vulnerabilities on the first server and multiple second servers. The first server is deployed in the first area of the cloud environment, and the multiple second servers are respectively deployed in multiple second areas of the cloud environment. The first area is used to manage the multiple second areas;
[0112] An update module 602, configured to update a security protection application configured on a first server based on an update data packet in response to a received update instruction, and synchronize the update instruction and the update data packet to a plurality of second servers, so that the plurality of second servers update the security protection applications configured on the plurality of second servers based on the update data packet in response to the update instruction.
[0113] Optionally, it further includes: a receiving module, configured to: receive update results reported by a plurality of second servers, where the update results are used to represent one of the following: all of the plurality of second servers have completed the update of the security protection application; a first part of the plurality of second servers have completed the update of the security protection application, and a second part of the plurality of second servers have not completed the update of the security protection application, and the second part of the servers are the remaining servers among the plurality of second servers except the first part of the servers.
[0114] Optionally, it further includes: a sub-update module, configured to: in response to the update result indicating that the second part of the servers have not completed the update of the security protection application, re-synchronize the update instruction and the update data packet to the second part of the servers until the second part of the servers complete the update of the security protection application.
[0115] Optionally, the first region and the plurality of second regions are different geographical regions isolated from each other, or the first region and the plurality of second regions are different data centers isolated from each other.
[0116] By adopting the embodiment of the present application, by obtaining an update data packet for checking and updating system security vulnerabilities on cloud servers in the central region and cloud servers in the unit region, and then, after receiving an update instruction to update the security protection application, updating the security protection application configured on the cloud server in the central region based on the update data packet, and at the same time, synchronously sending the update instruction and the update data packet to a plurality of cloud servers in the unit region, so that the plurality of cloud servers in the unit region update the security protection application based on the update data packet in response to the update instruction, thereby achieving the purpose of timely and accurate updating of host security products in multiple regions, thus realizing the technical effect of efficiently and low-cost updating host security products in multiple regions, improving the timeliness and accuracy of updating host security products, and further solving the technical problem in the related art that only the host security products in the current region can be updated, resulting in high time cost and labor cost when updating host security products in multiple regions, and poor timeliness of updating.
[0117] It should be noted here that the above-mentioned acquisition module 601 and processing module 602 correspond to step S21 and step S22 in Embodiment 1. The instances and application scenarios realized by the two modules and the corresponding steps are the same, but are not limited to the content disclosed in the above-mentioned Embodiment 1. It should be noted that the above-mentioned module or unit can be a hardware component or software component stored in a memory (for example, memory 104) and processed by one or more processors (for example, processors 102a, 102b,..., 102n). The above-mentioned module can also be part of a device and can run in the computer terminal 10 provided in Embodiment 1.
[0118] According to an embodiment of the present application, there is also provided another device embodiment for implementing the above data update. Figure 7 It is a schematic structural diagram of another data update device according to Embodiment 4 of the present application. As Figure 7 shown, the device includes:
[0119] A receiving module 701, configured to receive an update instruction and a data packet to be updated from a first server. The data packet to be updated is used to discover and repair system security vulnerabilities on multiple second servers. The first server is deployed in a first area under a cloud environment, and the multiple second servers are respectively deployed in multiple second areas under the cloud environment. The first area is used to manage the multiple second areas;
[0120] An update module 702, configured to synchronously update the security protection application programs configured on the multiple second servers based on the data packet to be updated in response to the received update instruction.
[0121] Optionally, it further includes: a sub-update module, configured to report an update result to the first server, where the update result is used to indicate that the update of the security protection application program has been completed.
[0122] By adopting the embodiment of the present application, an update instruction and a data packet to be updated for checking and updating system security vulnerabilities on multiple cloud servers in a unit area are received from a cloud server in a central area, and then, based on the received update instruction and the data packet to be updated, the security protection application programs configured on the multiple cloud servers in the unit area are synchronously updated, thereby achieving the purpose of timely and accurate update of host security products in multiple regions, and thus realizing the technical effect of efficiently and low-cost updating host security products in multiple regions, improving the timeliness and accuracy of updating host security products, and further solving the technical problem in the related art that only the host security products in the current region can be updated, resulting in high time cost and labor cost when updating host security products in multiple regions, and poor timeliness of updating.
[0123] It should be noted here that the above receiving module 701 and updating module 702 correspond to steps S41 and S42 in Embodiment 2. The instances and application scenarios implemented by the two modules and the corresponding steps are the same, but are not limited to the content disclosed in the above Embodiment 1. It should be noted that the above modules or units may be hardware components or software components stored in a memory (for example, memory 104) and processed by one or more processors (for example, processors 102a, 102b,..., 102n). The above modules may also be part of a device and may run in the computer terminal 10 provided in Embodiment 1.
[0124] According to an embodiment of the present application, there is also provided another device embodiment for implementing the above data update. Figure 8 It is a schematic structural diagram of another data update device according to Embodiment 4 of the present application. As Figure 8 shown, a graphical user interface is provided through a terminal device. The content displayed on the graphical user interface at least partially includes a system security vulnerability repair scenario. The device includes:
[0125] A selection module 801, configured to select an adapted data packet to be updated for a security protection application program configured on a first server in response to a first touch operation on the graphical user interface. The data packet to be updated is used to discover and repair system security vulnerabilities on the first server and multiple second servers. The first server is deployed in a first area in a cloud environment, and the multiple second servers are respectively deployed in multiple second areas in the cloud environment. The first area is used to manage the multiple second areas;
[0126] An update module 802, configured to initiate an update instruction in response to a second touch operation on the graphical user interface, control the first server to update the security protection application program based on the data packet to be updated, and synchronize the update instruction and the data packet to be updated to the multiple second servers, so that the multiple second servers respond to the update instruction and synchronously update the security protection application programs configured on the multiple second servers based on the data packet to be updated.
[0127] By adopting the embodiment of the present application, in response to a first touch operation on a graphical user interface, an adapted data packet to be updated is selected for a security protection application configured on a first server, where the data packet to be updated is used to discover and repair system security vulnerabilities on the first server and multiple second servers. The first server is deployed in a first area of a cloud environment, and the multiple second servers are respectively deployed in multiple second areas of the cloud environment. The first area is used to manage the multiple second areas. In response to a second touch operation on the graphical user interface, an update instruction is initiated to control the first server to update the security protection application based on the data packet to be updated, and the update instruction and the data packet to be updated are synchronized to the multiple second servers, so that the multiple second servers respond to the update instruction and synchronously update the security protection applications configured on the multiple second servers based on the data packet to be updated. Thus, the purpose of timely and accurate update of host security products in multiple regions is achieved, thereby realizing efficient and low-cost update of host security products in multiple regions, improving the timeliness and accuracy of the update of host security products, and further solving the technical problem in the related art that only the host security products in the current region can be updated, resulting in high time cost and labor cost when updating host security products in multiple regions and poor timeliness of the update.
[0128] It should be noted here that the above selection module 801 and update module 802 correspond to step S51 and step S52 in Embodiment 3. The instances and application scenarios implemented by the two modules and the corresponding steps are the same, but are not limited to the content disclosed in the above Embodiment 1. It should be noted that the above modules or units can be hardware components or software components stored in a memory (for example, memory 104) and processed by one or more processors (for example, processors 102a, 102b,..., 102n), and the above modules can also be part of a device and can run in the computer terminal 10 provided in Embodiment 1.
[0129] It should be noted that the preferred implementation schemes involved in the above embodiments of the present application are the same as the schemes, application scenarios, and implementation processes provided in Embodiment 1, but are not limited to the schemes provided in Embodiment 1.
[0130] Embodiment 5
[0131] An embodiment of the present application can provide a computer terminal, and the computer terminal can be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the above computer terminal can also be replaced with a terminal device such as a mobile terminal.
[0132] Optionally, in this embodiment, the above computer terminal can be at least one network device among multiple network devices in a computer network.
[0133] In this embodiment, the above computer terminal may execute the program code of the following steps in the data update method: obtaining a data packet to be updated, where the data packet to be updated is used to discover and repair system security vulnerabilities on a first server and a plurality of second servers. The first server is deployed in a first area of the cloud environment, and the plurality of second servers are respectively deployed in a plurality of second areas of the cloud environment. The first area is used to manage the plurality of second areas; in response to the received update instruction, updating the security protection application program configured on the first server based on the data packet to be updated, and synchronizing the update instruction and the data packet to be updated to the plurality of second servers, so that the plurality of second servers, in response to the update instruction, synchronously update the security protection application programs configured on the plurality of second servers based on the data packet to be updated.
[0134] Optionally, Figure 9 is a structural block diagram of a computer terminal according to an embodiment of the present application. As Figure 9 shown, the computer terminal 9 may include: one or more (only one is shown in the figure) processors 902, a memory 904, a storage controller, and a peripheral interface, where the peripheral interface is connected to a radio frequency module, an audio module, and a display.
[0135] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the data update method and device in the embodiment of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored therein, that is, implements the above data update method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely provided with respect to the processor, and these remote memories may be connected to the computer terminal 9 through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0136] The processor may call the information and application programs stored in the memory through a transmission device to execute the following steps: obtaining a data packet to be updated, where the data packet to be updated is used to discover and repair system security vulnerabilities on a first server and a plurality of second servers. The first server is deployed in a first area of the cloud environment, and the plurality of second servers are respectively deployed in a plurality of second areas of the cloud environment. The first area is used to manage the plurality of second areas; in response to the received update instruction, updating the security protection application program configured on the first server based on the data packet to be updated, and synchronizing the update instruction and the data packet to be updated to the plurality of second servers, so that the plurality of second servers, in response to the update instruction, synchronously update the security protection application programs configured on the plurality of second servers based on the data packet to be updated.
[0137] Optionally, the above-mentioned processor may also execute program code for the following steps: receiving update results reported by multiple second servers, where the update results are used to represent one of the following: all of the multiple second servers have completed the update of the security protection application; a first part of the multiple second servers have completed the update of the security protection application, and a second part of the multiple second servers have not completed the update of the security protection application, and the second part of the servers are the remaining servers among the multiple second servers other than the first part of the servers.
[0138] Optionally, the above-mentioned processor may also execute program code for the following steps: in response to the update result indicating that the second part of the servers have not completed the update of the security protection application, resynchronize the update instruction and the data packet to be updated to the second part of the servers until the second part of the servers complete the update of the security protection application.
[0139] Optionally, the first region and the multiple second regions are different geographical regions isolated from each other, or the first region and the multiple second regions are different data centers isolated from each other.
[0140] By adopting the embodiment of the present application, by obtaining a data packet to be updated for checking and updating system security vulnerabilities on the cloud servers in the central region and the cloud servers in the unit region, and then after receiving an update instruction for updating the security protection application, updating the security protection application configured on the cloud servers in the central region based on the data packet to be updated. At the same time, synchronously sending the update instruction and the data packet to be updated to multiple cloud servers in the unit region, so that the multiple cloud servers in the unit region respond to the update instruction and synchronously update the security protection application based on the data packet to be updated, thereby achieving the purpose of timely and accurate updating of the host security products in multiple regions, thus realizing the technical effect of efficiently and low-cost updating the host security products in multiple regions, improving the timeliness and accuracy of the update of the host security products, and further solving the technical problem in the related art that only the host security products in the current region can be updated, resulting in high time cost and labor cost when updating the host security products in multiple regions, and poor timeliness of the update.
[0141] Those of ordinary skill in the art can understand that Figure 9 the structure shown is only schematic, and the computer terminal 9 may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a handheld computer, and a mobile Internet device (Mobile Internet Devices, MID), a PAD and other terminal devices. Figure 9 It does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 9 may further include more Figure 9more or fewer components (such as network interfaces, display devices, etc.) shown therein, or having a configuration different from that Figure 9 shown.
[0142] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium. The storage medium can include: flash drives, read-only memories (ROMs), random access memories (RAMs), magnetic disks, optical discs, etc.
[0143] Embodiment 6
[0144] An embodiment of the present application further provides a computer-readable storage medium. Optionally, in this embodiment, the above computer-readable storage medium can be used to store the program code executed by the data update method provided in the first embodiment above.
[0145] Optionally, in this embodiment, the above computer-readable storage medium can be located in any one of the computer terminals in the computer terminal group in the computer network, or in any one of the mobile terminals in the mobile terminal group.
[0146] Optionally, in this embodiment, the computer-readable storage medium is set to store program code for performing the following steps: obtaining a data packet to be updated, where the data packet to be updated is used to discover and repair system security vulnerabilities on a first server and multiple second servers. The first server is deployed in a first area under the cloud environment, and the multiple second servers are respectively deployed in multiple second areas under the cloud environment. The first area is used to manage the multiple second areas; in response to the received update instruction, updating the security protection application program configured on the first server based on the data packet to be updated, and synchronizing the update instruction and the data packet to be updated to the multiple second servers, so that the multiple second servers, in response to the update instruction, synchronously update the security protection application programs configured on the multiple second servers based on the data packet to be updated.
[0147] Optionally, in this embodiment, the computer-readable storage medium is set to store program code for performing the following steps: receiving update results reported by multiple second servers, where the update results are used to represent one of the following: all of the multiple second servers have completed the update of the security protection application program; a first part of the multiple second servers have completed the update of the security protection application program, and a second part of the multiple second servers have not completed the update of the security protection application program, and the second part of the servers are the remaining servers among the multiple second servers other than the first part of the servers.
[0148] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: in response to the update result indicating that the second part of the servers has not completed the update of the security protection application, resynchronize the update instruction and the data packet to be updated to the second part of the servers until the second part of the servers completes the update of the security protection application.
[0149] Optionally, the first region and the multiple second regions are different geographical regions isolated from each other, or the first region and the multiple second regions are different data centers isolated from each other.
[0150] An embodiment of the present application also provides a computer program product, including a computer program which, when executed by a processor, implements the data update method provided by the embodiment of the present application.
[0151] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages or disadvantages of the embodiments.
[0152] In the above embodiments of the present application, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0153] In the several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the units or modules can be in electrical or other forms.
[0154] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0155] In addition, the functional units in the various embodiments of the present application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0156] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs.
[0157] The above are only the preferred embodiments of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of this application.
Claims
1. A data update method, characterized in that, Including: Obtain a data packet to be updated, where the data packet to be updated is used to discover and repair system security vulnerabilities on a first server and multiple second servers. The first server is deployed in a first area of a cloud environment, and the multiple second servers are respectively deployed in multiple second areas of the cloud environment. The first area is used to manage the multiple second areas; In response to the received update instruction, update the security protection application configured on the first server based on the data packet to be updated, and synchronize the update instruction and the data packet to be updated to the multiple second servers, so that the multiple second servers, in response to the update instruction, synchronously update the security protection application configured on the multiple second servers based on the data packet to be updated.
2. The data update method according to claim 1, wherein The data update method further includes: Receive update results reported by the multiple second servers, where the update results are used to represent one of the following: All of the multiple second servers have completed the update of the security protection application; A first part of the multiple second servers have completed the update of the security protection application, and a second part of the multiple second servers have not completed the update of the security protection application. The second part of the servers are the remaining servers among the multiple second servers other than the first part of the servers.
3. The data update method according to claim 2, wherein The data update method further includes: In response to the update result indicating that the second part of the servers have not completed the update of the security protection application, re-synchronize the update instruction and the data packet to be updated to the second part of the servers until the second part of the servers complete the update of the security protection application.
4. The data update method according to claim 1, wherein The first area and the multiple second areas are different geographical areas isolated from each other, or the first area and the multiple second areas are different data centers isolated from each other.
5. A data update method, characterized in that, Including: Receive an update instruction and a data packet to be updated from a first server, where the data packet to be updated is used to discover and repair system security vulnerabilities on multiple second servers. The first server is deployed in a first area of a cloud environment, and the multiple second servers are respectively deployed in multiple second areas of the cloud environment. The first area is used to manage the multiple second areas; In response to the received update instruction, synchronously update the security protection application configured on the multiple second servers based on the data packet to be updated.
6. The data update method according to claim 5, wherein The data update method further includes: Report an update result to the first server, where the update result is used to indicate that the update of the security protection application has been completed currently.
7. A data update method, characterized in that, Provide a graphical user interface through a terminal device. At least part of the content displayed on the graphical user interface includes a system security vulnerability repair scenario. The data update method includes: In response to a first touch operation on the graphical user interface, select an appropriate data packet to be updated for a security protection application configured on a first server, where the data packet to be updated is used to detect and repair system security vulnerabilities on the first server and multiple second servers. The first server is deployed in a first area of a cloud environment, and the multiple second servers are respectively deployed in multiple second areas of the cloud environment. The first area is used to manage the multiple second areas; In response to a second touch operation on the graphical user interface, initiate an update instruction to control the first server to update the security protection application based on the data packet to be updated, and synchronize the update instruction and the data packet to be updated to the multiple second servers, so that the multiple second servers, in response to the update instruction, synchronously update the security protection application configured on the multiple second servers based on the data packet to be updated.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes a stored executable program, where, when the executable program runs, it controls the device where the computer-readable storage medium is located to execute the data update method according to any one of claims 1 to 7.
9. An electronic device, characterized in that, Comprising: A memory storing an executable program; A processor for running the program, where, when the program runs, it executes the data update method according to any one of claims 1 to 7.
10. A computer program product, characterized in that, Comprising a computer program, which, when executed by a processor, implements the data update method according to any one of claims 1 to 7.