Security detection method, device and equipment, readable storage medium and program product

By extracting operation characteristics and calculating the importance and operation specification scores in the hardware management platform, the problems of high management costs and insufficient dynamic adjustment of the authority control solution are solved, flexible security detection and dynamic adjustment are achieved, and the safety and efficiency of user operations are ensured.

CN120372606APending Publication Date: 2025-07-25ZHENGZHOU YUNHAI INFORMATION TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510500000.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The permission control scheme of the existing hardware management platform has problems such as high management costs, lack of dynamic adjustments and abuse of permissions, and it is difficult to flexibly conduct security detection of user operation behavior.

Method used

By obtaining log information of the hardware management platform, extracting operation characteristics, calculating device importance scores and operation normative scores, and comparing the standardized vectors with reference vectors to determine the security of the target operation.

Benefits of technology

It realizes flexible and secure detection of user operation behaviors of hardware management platform, avoids abuse of permissions, reduces management costs, supports dynamic adjustments, and ensures user work efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120372606A_ABST
    Figure CN120372606A_ABST
Patent Text Reader

Abstract

The invention discloses a security detection method, device and equipment, a readable storage medium and a program product, and relates to the technical field of computers. According to the method and the device, the log information of the hardware management platform covers the operation condition of the user, so that the operation characteristics of the target operation can be extracted from the log information. An equipment importance score corresponding to the target operation can be clarified based on the operation equipment in the operation features. A standardized vector may be established for the extracted operational features and compared to a reference vector to determine an operational normative score. And fusing the equipment importance score and the operation normativity score to obtain a total score of the target operation. The security of the target operation may be evaluated based on the total score. According to the method and the device, the normativity of the operation is referred to, the importance of the operated equipment is referred to, the reference vector can be configured and adjusted according to an actual application scene, and the technical effect of flexibly performing safety detection on the user operation behavior of the hardware management platform is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a security detection method, apparatus, device, readable storage medium, and program product. Background Art

[0002] The functions of the hardware management platform include centralized and automated management and monitoring of hardware devices to ensure the efficient and stable operation of the system. The operation of the hardware management platform on devices requires the users of the management platform to perform the operations. Therefore, to ensure the efficient and stable operation of the system, it is necessary to analyze and warn the operation behaviors of the users of the hardware management platform.

[0003] Currently, the control of user behaviors is mainly achieved by controlling user permissions to ensure that user behaviors do not endanger the security of the managed devices. In different monitoring scenarios, different permissions are assigned to different management personnel. For example, ordinary users can only view device information, operation and maintenance administrators can only view and operate some devices, and super administrators can control all devices of the hardware management platform.

[0004] However, this permission control scheme has problems such as high management costs, lack of dynamic adjustment, over-restriction, and permission abuse.

[0005] In summary, how to flexibly perform security detection on the operation behaviors of users of the hardware management platform is a technical problem that needs to be solved by those skilled in the art at present. Summary of the Invention

[0006] This application provides a security detection method, apparatus, device, readable storage medium, and program product, which can flexibly perform security detection on the operation behaviors of users of the hardware management platform.

[0007] This application provides a security detection method, including:

[0008] Obtain the log information of the hardware management platform, and extract the operation features corresponding to the target operation from the log information;

[0009] Use the operation device in the operation features to obtain the device importance score corresponding to the target operation;

[0010] Use the operation features to establish a standardized vector, and compare the standardized vector with a reference vector to determine the operation normality score; the reference vector is the standardized vector corresponding to the standard operation;

[0011] Use the operation normality score and the device importance score to determine the total score, and use the total score to determine the security of the target operation.

[0012] This application also provides a security detection apparatus, including:

[0013] An operation feature acquisition module, configured to acquire log information of a hardware management platform, and extract operation features corresponding to a target operation from the log information;

[0014] A device importance score determination module, configured to use the operation device in the operation features to acquire a device importance score corresponding to the target operation;

[0015] An operation standardization score determination module, configured to establish a standardized vector by using the operation features, and compare the standardized vector with a reference vector to determine an operation standardization score; the reference vector is the standardized vector corresponding to a standard operation;

[0016] A security evaluation module, configured to determine a total score by using the operation standardization score and the device importance score, and determine the security of the target operation by using the total score.

[0017] This application further provides an electronic device, including: a memory, configured to store a computer program; a processor, configured to implement the steps of any one of the above security detection methods when executing the computer program.

[0018] This application further provides a computer-readable storage medium, in which a computer program is stored, and wherein the computer program implements the steps of any one of the above security detection methods when executed by a processor.

[0019] This application further provides a computer program product, including a computer program, and the computer program implements the steps of any one of the above security detection methods when executed by a processor.

[0020] In this application, since the log information of the hardware management platform covers the operation situation of the user, after acquiring the log information, the operation features of the target operation can be extracted therefrom. There is an operation device in the operation features, and based on this operation device, the device importance score corresponding to the target operation can be determined. A standardized vector can be established in advance for the standard operation, and this standardized vector is used as a reference vector when determining the operation standardization of the target operation. That is to say, a standardized vector can be established for the operation features of the target operation, and this standardized vector is compared with the reference vector to determine the operation standardization score of the target operation. By fusing the device importance score and the operation standardization score, the total score of the target operation can be obtained. Based on this total score, the security of the target operation can be effectively evaluated.

[0021] It can be seen that in the process of detecting the security of the target operation in this application, not only the standardization of the target operation itself is referred to, but also the importance of the operation device itself of the target operation is referred to, and the reference vector can be configured and adjusted according to the actual application scenario, achieving the technical effect of flexibly performing security detection on the user operation behavior of the hardware management platform. Description of the Drawings

[0022] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0023] Figure 1 It is a flowchart of an implementation of a security detection method provided by an embodiment of the present application;

[0024] Figure 2 It is a schematic structural diagram of a security detection device provided by an embodiment of the present application;

[0025] Figure 3 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application;

[0026] Figure 4 It is a specific schematic structural diagram of an electronic device provided by an embodiment of the present application. Specific implementation manners

[0027] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.

[0028] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variant thereof are intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.

[0029] To enable those skilled in the art of the present technology to better understand the solution of the present application, the following will further describe the present application in detail with reference to the drawings and specific implementation manners.

[0030] Please refer to Figure 1 , Figure 1 It is a real-time flowchart of a security detection method in an embodiment of the present application. The method includes:

[0031] S101. Obtain the log information of the hardware management platform and extract the operation characteristics corresponding to the target operation from the log information.

[0032] Among them, users can collect the operation status information of various hardware devices in real time through the data collection function of the hardware management platform. After these operation status information are uniformly processed, they are displayed in the form of an intuitive dashboard or report. Users can perform batch management on devices through the batch processing function of the hardware management platform. During the process of users viewing or managing devices through the hardware management platform, the hardware management platform will generate log information. This log information includes service logs and log data recorded in the database, which collect information related to user behavior. These information mainly include: user login information, user platform operation logs, user permission change information, etc. That is to say, the operation characteristics corresponding to each user operation can be obtained from the log information in advance.

[0033] Among them, the target operation can be any operation performed by any user of the hardware management platform on any device managed by the hardware management platform at any time. That is to say, in this embodiment, each operation (i.e., user behavior) of the hardware management platform can be the target operation.

[0034] For example, the target operation can be that user a modifies the function configuration of a certain server at 8 am; or, user b queries the storage device storing key business data at 2 am.

[0035] Among them, the operation characteristics are the key characteristics corresponding to the operation. For example, the operating user, operation time, operation type, operation device, user gateway address, etc. are used as characteristic values. For example, the extracted log shows that an ordinary user queries the basic information of a certain server during working hours.

[0036] S102. Use the operation device in the operation characteristics to obtain the device importance score corresponding to the target operation.

[0037] In this embodiment, corresponding device importance scores can be set in advance for different devices, or the importance scores of devices can be evaluated in real time during the application process.

[0038] Therefore, after determining the operation device of the target operation, the pre-determined device importance score can be obtained by direct reading; or the device importance score can be determined through real-time evaluation.

[0039] When evaluating the device importance score, factors such as the role of the device (such as storing business data, request response processing), health status (such as whether it is faulty), and repair difficulty (such as whether faulty hardware can be directly replaced, or whether maintenance personnel are on duty 24 hours a day, etc.) can be referred to, so as to obtain the importance score of the device. Generally, for devices with high dimensional difficulty and involving core business, their importance scores are higher. For faulty devices, their importance scores are lower.

[0040] In a specific implementation manner of the present application, by using the operating device in the operation characteristics, the device importance score corresponding to the target operation is obtained, including:

[0041] Obtain the device information of the operating device;

[0042] Respectively determine the sub-scores of the information items in the device information;

[0043] Perform weighted summation on the sub-scores to obtain the device importance score.

[0044] For the convenience of description, the above steps will be combined and described below.

[0045] In this embodiment, the operating device information can be first clarified, and the device information includes but is not limited to device type, device service, device health status, and device scalability. Taking the device information including device type, device service, device health status, and device scalability as an example, the sub-scores are determined, that is, according to the corresponding scoring criteria, the sub-scores corresponding to the device type, device service, device health status, and device scalability are respectively determined.

[0046] Finally, perform weighted summation on these sub-scores to obtain the device importance score.

[0047] Illustrative example: In practical applications, corresponding weights and scoring rules can be set in different dimensions. After clarifying the device type, device service, device health status, and device scalability of the operating device, by querying a chart similar to Table 1 (of course, in practical applications, different scoring rules can also be set according to the actual application scenario, which is not limited here), the sub-scores and weight values of each dimension can be determined.

[0048] Table 1, Table 1 is the device importance evaluation configuration table

[0049]

[0050] Then, calculate through the weight formula, and the specific formula is as follows: ;

[0051] Among them, is the device importance score, n is the number of current factors, is the ratio of the i-th factor, is the score of the i-th factor. The importance score of a single device calculated through the above formula is between 0 and 10, and the higher the score, the higher the importance of the device.

[0052] That is, in this embodiment, the importance score of a specific device can be evaluated based on aspects such as the device type actually monitored by the hardware management platform, the device health, the business volume borne by the device, the complexity of device operation and maintenance, and the future expandability of the device.

[0053] S103. Establish a standardized vector using operation characteristics, and compare the standardized vector with a reference vector to determine the operation normality score.

[0054] Among them, the reference vector is the standardized vector corresponding to the canonical operation.

[0055] In this embodiment, standardized vectors can be created in advance for corresponding canonical operations. These standardized vectors can be used to clarify whether the target operation is canonical. That is, these standardized vectors are the reference vectors corresponding to the canonical operations.

[0056] Specifically, a standardized vector is established for the operation characteristics corresponding to the canonical operation. Among them, the canonical operation can be a qualified operation configured according to the detection requirements of different scenarios. By extracting the operation characteristics of these qualified operations, a standard vector can be established. In this embodiment, for both the target operation and the canonical operation, the standardized vector is established based on the operation characteristics, and the standardization process is the same. Taking the creation of the standardized vector for the target operation as an example, the creation process of the standardized vector corresponding to the canonical operation can be referred to here and will not be elaborated one by one.

[0057] In this embodiment, different standardization methods can be set for different operation characteristics, and then these standardization methods are respectively executed to convert the characteristics into elements in the standardized vector.

[0058] In a specific implementation manner of this application, establishing a standardized vector using operation characteristics includes:

[0059] Create a feature vector corresponding to the operation characteristics;

[0060] Perform standardization processing on the feature vector to obtain a standardized vector.

[0061] For ease of description, the above steps will be combined and described below.

[0062] The elements in the feature vector are the respective features in the operation characteristics, and the specific sorting of each feature can be randomly combined. However, in the same application scenario, to facilitate comparison of its normality, the order of the features corresponding to each element in the vector needs to be kept the same.

[0063] For example, when extracting logs, a target operation is obtained, indicating that an ordinary user queried the basic information of a certain server during working hours. The operation features can include the ordinary user, working hours, query, and a certain server. Based on these operation features, the feature variable [ordinary user, working hours, query, a certain server] is established.

[0064] Then, to facilitate the comparison of the differences between the target operation and the standard operation, the feature vector can be standardized. That is, each element in the feature vector is standardized. For different elements, different standardization methods can be set. For example, the corresponding operation time can be standardized such that it corresponds to 0.5 for working hours and 1 for non-working hours (of course, other values can also be set, which will not be listed one by one here).

[0065] In a specific implementation manner of the present application, the standardization process of the feature vector includes:

[0066] Determine the permission role of the operator in the operation features;

[0067] Convert the operator in the feature vector to the role weight value of the permission role.

[0068] The standardization rule for the operating user: Different calibration weight values are set according to the role permission function division of the hardware management platform. For example, the weight value of an ordinary user is 0.2, the weight value of the operation and maintenance role is 0.5, and the weight value of the administrator is 1. After clarifying the permission role of the operator through query or other means, the operator can be directly replaced with the corresponding role weight value.

[0069] In a specific implementation manner of the present application, the standardization process of the feature vector includes:

[0070] Determine the time relationship between the operation time and the working time in the operation features;

[0071] Convert the operation time in the feature vector to the time weight value of the time relationship.

[0072] The standardization rule for the operation time: Set the permissions for different times according to the actual situation. For example, the operation weight for working hours is 0.5, and the operation weight for non-working hours is 1.

[0073] After comparing the operation time with the working time, it can be known whether the operation time is the working time. Then, the operation time can be converted to the time weight value corresponding to the time relationship.

[0074] In a specific implementation manner of the present application, the standardization process of the feature vector includes:

[0075] Determine the operation weight value corresponding to the operation type in the operation features;

[0076] Convert the operation types in the feature vector to operation weights.

[0077] Standardized rules for specific operations: different weights are set for different operations. For example, the weight for querying the device is 0.3, the weight for collecting device information is 0.4, the weight for configuring the device with BMC (a dedicated microcontroller embedded on the server motherboard for remote management and monitoring of hardware status) is 0.6, the weight for configuring the device with RAID (Redundant Array of Independent Disks, which combines multiple disks to improve data redundancy and performance) is 0.7, the weight for configuring the device with BIOS (firmware solidified on the computer motherboard, responsible for hardware initialization and system settings at startup, and providing a hardware abstraction layer for the operating system) is 0.7, and the weight for restarting the device is 1.

[0078] When the operation type is clear, the corresponding operation weight can be directly determined by looking up a table, etc. The operation type is replaced with the operation weight to complete the standardization of the operation type.

[0079] In a specific implementation of the present application, the feature vector is normalized, including:

[0080] Determine the device weight corresponding to the operation device in the operation characteristic;

[0081] Convert the operation devices in the feature vector to device weights.

[0082] Different devices can be set with different device weights. Considering that there are many devices in actual applications, setting device weights one by one does not make use of actual operations. Therefore, different weights can be determined based on device types. That is, determining the device weight corresponding to the operating device includes:

[0083] Determine the type of equipment that operates the device;

[0084] The standardized code corresponding to the device type is determined as the device weight.

[0085] In order to effectively calculate the similarity between vectors, the process of determining standardized encoding includes:

[0086] Get the type samples corresponding to the operable devices;

[0087] Calculate the ratio of the characteristic value of the operating device to the number of type samples; wherein the characteristic value is the serial number of the operating device in the operable devices;

[0088] The ratios were determined as normalized codes.

[0089] For ease of description, the above steps are combined for explanation below.

[0090] Standardization rules for specific device types: The types of devices can be encoded, and different weights can be assigned to different device types. For example, the weight value of a server is set to 0.8, and the weight value of a storage device is set to 0.2.

[0091] Specifically, the types of operable devices, that is, the number of type samples, or also known as the number of samples.

[0092] The eigenvalue can be the serial number corresponding to the device in these type samples (or the normalized representation). By calculating the ratio of the eigenvalue of the operable device to the number of type samples, the eigenvalue of the device can be standardized.

[0093] Illustrative example: The standardization rules for specific device types are as follows: Use methods such as calculating differences to standardize the eigenvalue for similarity calculation. The specific formula is as follows:

[0094] ;

[0095] Among them, x represents the original eigenvalue, and respectively represent the minimum and maximum values of this feature in all samples. For example, if the maximum and minimum numbers of input parameters with the largest device weight involved in all user operations are 6 and 1 respectively, and the operation device weight of this feature variable of the device is 4, then the standardized value is .

[0096] Through the above standardization process, for the feature variable [ordinary user, working hours, query, a certain server], the standardized vector of the target operation can be obtained as [0.2, 0.5, 0.3, 0.8].

[0097] Among them, step S102 and step S103 can be executed in reverse order or in parallel, that is, this embodiment does not strictly require the sequence of steps S102 and S103.

[0098] After completing the standardization of the feature vector, the standardized vector of the target operation and the reference vector can be directly compared, and based on the difference or similarity situation (such as the similarity distance), the operation compliance score of the target operation can be determined, that is, the more similar they are, the higher the corresponding operation compliance score.

[0099] In a specific implementation manner of this application, it further includes:

[0100] Store the reference vector in the list of standard operations;

[0101] Manage the reference vector based on this list of standard operations;

[0102] Among them, managing the reference vector based on this list of standard operations includes:

[0103] Receive the configuration information of the specification operation;

[0104] Use the configuration information to determine the specification operation and determine the operation characteristics corresponding to the specification operation;

[0105] Create a standardized vector corresponding to the operation characteristics, use this standardized vector as a reference vector, and update the reference vector list.

[0106] In practical applications, manage the reference vectors based on the specification operation list, including viewing, adding, updating, modifying, and deleting the reference vectors therein. When viewing, the reference vectors can be read out first and converted into feature expressions, that is, perform reverse operations on the standardized elements to make them represent their original meanings. For example, for the element position of "device", if the corresponding value is 0.8, it is converted into the corresponding device type, such as server, for the user to view.

[0107] By managing the specification operation list, flexible configuration and adjustment of the specification operation can be achieved, thereby realizing dynamic configuration of various security detection standards to adapt to dynamically changing detection requirements.

[0108] In a specific implementation manner of the present application, compare the standardized vector with the reference vector to determine the operation compliance score, including:

[0109] Calculate the similarity between the standardized vector and the reference vector;

[0110] Use the similarity to determine the operation compliance score.

[0111] For ease of description, the above steps will be combined and described below.

[0112] According to the hardware management software / platform, the scoring criteria shown in Table 2 can be summarized for the device operation situation.

[0113] Table 2, Scoring Criteria for Operation Compliance Score

[0114]

[0115] That is, after obtaining the standardized vector of the target operation, the algorithm of the distance between vectors can be used to calculate the similarity between the target operation and the behaviors in the operation scoring criteria of the above management software device. The formula for similarity calculation is as follows:

[0116] ;

[0117] Among them, n is the length of the standardized feature vector, is the th bit of the user behavior A vector (the standardized vector of the target operation), For the th bit of the B vector (reference vector) after the operation scoring standard of the hardware management platform is standardized, when is smaller, it indicates that the user behavior has a higher similarity with the behavior in the above management software device operation scoring standard.

[0118] A threshold can be set: According to specific requirements and actual situations, set the threshold of similarity. For example, the default similarity threshold is set to 0.8, that is, when x_similarity > 0.8, it is considered that the currently collected user behavior matches the device operation situation of the hardware management software, and thus the pre-set score is used as the operation standard score (i.e., the behavior risk score).

[0119] S104. Determine the total score using the operation standard score and the device importance score, and determine the security of the target operation using the total score.

[0120] The operation standard score and the device importance score can be directly multiplied, added, or other fusion methods can be used for fusion processing to determine the total score. For example, the final scoring formula for user operation behavior is as follows:

[0121] Total score = operation standard score × device importance score.

[0122] Through the above scoring formula, the total score corresponding to the target operation with the standardized vector [0.2, 0.5, 0.3, 0.8] is calculated to be 4.

[0123] Then, through the security delineation standard corresponding to different total scores, based on this total score, the security of the current target operation can be clarified. Thus, based on the security judgment situation, the user behavior can be managed or controlled.

[0124] In a specific implementation manner of this application, using the total score to determine the security of the target operation includes:

[0125] Compare the total score with the score interval corresponding to the warning level to determine the target warning level corresponding to the total score;

[0126] Execute the warning operation corresponding to the target warning level.

[0127] For the convenience of operation, the above steps will be combined and described below.

[0128] In this embodiment, different warning levels can be set, and different warning levels correspond to different score intervals. After obtaining the total score, compare it with the score interval equal to the warning level to determine the target warning level. Then, directly execute the warning operation corresponding to the target warning level.

[0129] For example, by comparing the total score with the corresponding threshold, when it is determined that the user operation behavior score exceeds the specified threshold, the warning details are pushed via email / sms, and the execution is automatically terminated and the account is locked.

[0130] The threshold settings based on the actual usage of the management software include but are not limited to the following examples:

[0131] High-risk warning: weight ≥ 60;

[0132] Medium-risk warning: 60 ≥ weight ≥ 45.

[0133] That is, when it is collected that an ordinary user queries the basic information of a certain server during working hours, no alarm will be triggered.

[0134] In this application, since the log information of the hardware management platform covers the user's operation situation, after obtaining the log information, the operation characteristics of the target operation can be extracted from it. There is an operation device in the operation characteristics, and based on this operation device, the device importance score corresponding to the target operation can be determined. A standardized vector can be established in advance for the standard operation, and this standardized vector is used as a reference vector when determining the operation standardization of the target operation. That is to say, a standardized vector can be established for the operation characteristics of the target operation, and this standardized vector is compared with the reference vector to determine the operation standardization score of the target operation. By fusing the device importance score and the operation standardization score, the total score of the target operation can be obtained. Based on this total score, the security of the target operation can be effectively evaluated.

[0135] It can be seen that in the process of detecting the security of the target operation in this application, not only the standardization of the target operation itself is referred to, but also the importance of the operation device of the target operation is referred to, and the reference vector can be configured and adjusted according to the actual application scenario, achieving the technical effect of flexibly detecting the user operation behavior of the hardware management platform.

[0136] That is to say, the security detection method provided by this application can effectively avoid the abuse of permissions. That is, when a user with legitimate permissions abuses the permissions and performs malicious operations (such as data leakage, tampering, or deletion), their abnormal behavior can be discovered, and internal threats can be effectively prevented; it can reduce the high management cost. Even as the number of users and the complexity of the system increase, the administrator only needs to assign appropriate roles to users or user groups, without the need for frequent review and update of permission settings; it can achieve dynamic adjustment. Since the reference vector corresponding to the standard operation can be managed, that is, operations such as update, modification, and deletion can be performed, the detection situation can be dynamically adjusted according to the actual behavior or context environment of the user; there will be no excessive restriction on the user to avoid that the user cannot complete the necessary work due to overly strict permission division, and the work efficiency of the user can be effectively guaranteed.

[0137] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method.

[0138] The embodiments of the present application also provide a security detection device. For the description of the features corresponding to the embodiments of this security detection device, reference can be made to the relevant descriptions of the corresponding embodiments of the security detection method.

[0139] Please refer to Figure 2 , this device includes:

[0140] An operation feature acquisition module 101, configured to acquire log information of a hardware management platform, and extract operation features corresponding to a target operation from the log information;

[0141] A device importance score determination module 102, configured to use the operation device in the operation features to acquire a device importance score corresponding to the target operation;

[0142] An operation standardization score determination module 103, configured to establish a standardized vector using the operation features, and compare the standardized vector with a reference vector to determine an operation standardization score; the reference vector is the standardized vector corresponding to a standard operation;

[0143] A security evaluation module 104, configured to use the operation standardization score and the device importance score to determine a total score, and use the total score to determine the security of the target operation.

[0144] When applying the device provided by the embodiments of the present application, in the present application, since the log information of the hardware management platform covers the operation situation of the user, after obtaining the log information, the operation features of the target operation can be extracted from it. There is an operation device in the operation features, and based on this operation device, the device importance score corresponding to the target operation can be determined. A standardized vector can be established in advance for standard operations, and this standardized vector is used as a reference vector when determining the operation standardization of the target operation. That is to say, a standardized vector can be established for the operation features of the target operation, and this standardized vector is compared with the reference vector to determine the operation standardization score of the target operation. By fusing the device importance score and the operation standardization score, the total score of the target operation can be obtained. Based on this total score, the security of the target operation can be effectively evaluated.

[0145] It can be seen that in the process of detecting the security of the target operation, the present application not only refers to the standardization of the operation itself of the target operation, but also refers to the importance of the operation device itself of the target operation, and the reference vector can be configured and adjusted according to the actual application scenario, achieving the technical effect of flexibly detecting the user operation behavior of the hardware management platform.

[0146] In a specific embodiment of the present application, the operation standardization score determination module is specifically configured to create a feature vector corresponding to the operation feature; perform normalization processing on the feature vector to obtain a normalized vector.

[0147] In a specific embodiment of the present application, the operation standardization score determination module is specifically configured to determine the permission role of the operator in the operation feature;

[0148] Convert the operator in the feature vector into the role weight value of the permission role.

[0149] In a specific embodiment of the present application, the operation standardization score determination module is specifically configured to determine the time relationship between the operation time and the working time in the operation feature;

[0150] Convert the operation time in the feature vector into the time weight value of the time relationship.

[0151] In a specific embodiment of the present application, the operation standardization score determination module is specifically configured to determine the operation weight value corresponding to the operation type in the operation feature;

[0152] Convert the operation type in the feature vector into the operation weight value.

[0153] In a specific embodiment of the present application, the operation standardization score determination module is specifically configured to determine the device weight value corresponding to the operation device in the operation feature;

[0154] Convert the operation device in the feature vector into the device weight value.

[0155] In a specific embodiment of the present application, the operation standardization score determination module is specifically configured to determine the device type of the operation device;

[0156] Determine the standardized code corresponding to the device type as the device weight value.

[0157] In a specific embodiment of the present application, the operation standardization score determination module is specifically configured to obtain the number of type samples corresponding to the operable device;

[0158] Calculate the ratio of the eigenvalue of the operation device to the number of type samples; wherein, the eigenvalue is the serial number of the operation device in the operable devices;

[0159] Determine the ratio as a standardized code.

[0160] In a specific embodiment of the present application, the operation standardization score determination module is specifically configured to calculate the similarity between the standardized vector and the reference vector;

[0161] Determine the operation standardization score using the similarity.

[0162] In a specific embodiment of the present application, the device importance score determination module is specifically configured to obtain the device information of the operating device;

[0163] Respectively determine the sub-scores corresponding to the information items in the device information;

[0164] Perform a weighted sum of the sub-scores to obtain the device importance score.

[0165] In a specific embodiment of the present application, the security assessment module is specifically configured to compare the total score with the score range corresponding to the warning level to determine the target warning level corresponding to the total score;

[0166] Execute the warning operation corresponding to the target warning level.

[0167] The embodiments of the present application also provide an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any of the above-mentioned security detection method embodiments.

[0168] See Figure 3 As shown, the electronic device includes:

[0169] A memory 332 for storing a computer program;

[0170] A processor 322 for implementing the steps of the security detection method in the above method embodiment when executing the computer program.

[0171] Specifically, please refer to Figure 4 , Figure 4FIG. 0 is a schematic structural diagram of an electronic device provided in this embodiment. The electronic device may vary greatly due to different configurations or performances, and may include one or more processors (central processing units, CPUs) (for example, one or more processors) and a memory 332. The memory 332 stores one or more computer programs 342 or data 344. Among them, the memory 332 may be short-term storage or persistent storage. The program stored in the memory 332 may include one or more modules (not shown in the figure), and each module may include a series of instruction operations on the data processing device. Further, the processor 322 may be set to communicate with the memory 332 and execute a series of instruction operations in the memory 332 on the electronic device 301.

[0172] The electronic device 301 may further include one or more power supplies 326, one or more wired or wireless network interfaces 350, one or more input / output interfaces 358, and / or one or more operating systems 341.

[0173] The steps in the security detection method described above may be implemented by the structure of the electronic device.

[0174] That is, in this electronic device, the executable steps include: obtaining the log information of the hardware management platform and extracting the operation characteristics corresponding to the target operation from the log information; using the operation device in the operation characteristics to obtain the device importance score corresponding to the target operation; using the operation characteristics to establish a standardized vector, and comparing the standardized vector with the reference vector to determine the operation compliance score; the reference vector is the standardized vector corresponding to the standard operation; using the operation compliance score and the device importance score to determine the total score, and using the total score to determine the security of the target operation.

[0175] In a specific implementation manner of this application, establishing a standardized vector using the operation characteristics includes:

[0176] Creating a feature vector corresponding to the operation characteristics; performing standardization processing on the feature vector to obtain a standardized vector.

[0177] In a specific implementation manner of this application, performing standardization processing on the feature vector includes:

[0178] Determining the permission role of the operator in the operation characteristics; converting the operator in the feature vector into the role weight of the permission role.

[0179] In a specific implementation manner of this application, performing standardization processing on the feature vector includes: determining the time relationship between the operation time and the working time in the operation characteristics; converting the operation time in the feature vector into the time weight of the time relationship.

[0180] In a specific embodiment of the present application, the normalization process of the feature vector includes: determining the operation weight corresponding to the operation type in the operation feature; converting the operation type in the feature vector into an operation weight.

[0181] In a specific embodiment of the present application, the normalization process of the feature vector includes: determining the device weight corresponding to the operation device in the operation feature; converting the operation device in the feature vector into a device weight.

[0182] In a specific embodiment of the present application, determining the device weight corresponding to the operation device includes: determining the device type of the operation device; determining the standardized code corresponding to the device type as the device weight.

[0183] In a specific embodiment of the present application, the process of determining the standardized code includes: obtaining the number of type samples corresponding to the operable device; calculating the ratio of the eigenvalue of the operation device to the number of type samples; where the eigenvalue is the serial number of the operation device in the operable device; determining the ratio as the standardized code.

[0184] In a specific embodiment of the present application, comparing the standardized vector with the reference vector to determine the operation compliance score includes: calculating the similarity between the standardized vector and the reference vector; using the similarity to determine the operation compliance score.

[0185] In a specific embodiment of the present application, using the operation device in the operation feature to obtain the device importance score corresponding to the target operation includes: obtaining the device information of the operation device; respectively determining the sub-scores corresponding to the information items in the device information; performing weighted summation on the sub-scores to obtain the device importance score.

[0186] In a specific embodiment of the present application, using the total score to determine the safety of the target operation includes: comparing the total score with the score interval corresponding to the warning level to determine the target warning level corresponding to the total score; performing the warning operation corresponding to the target warning level.

[0187] That is to say, the electronic device provided by the present application can execute the security detection method provided by the embodiments of the present application. During the process of detecting the safety of the target operation, the electronic device not only refers to the compliance of the target operation itself, but also refers to the importance of the operation device itself of the target operation, and the reference vector can be configured and adjusted according to the actual application scenario, achieving the technical effect of flexibly performing security detection on the user operation behavior of the hardware management platform.

[0188] Embodiments of the present application also provide a computer-readable storage medium storing a computer program, where the computer program is configured to execute the steps in any of the above-described embodiments of the security detection method when running.

[0189] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media such as USB flash drives, read-only memories (ROM for short), random access memories (RAM for short), external hard drives, magnetic disks, or optical discs that can store computer programs.

[0190] That is to say, the computer-readable storage medium provided by the present application can store the computer program corresponding to the security detection method provided by the embodiments of the present application. When executing this computer program, in the process of detecting the security of the target operation, not only the normativity of the target operation itself is referred to, but also the importance of the operation device of the target operation itself is referred to, and the reference vector can be configured and adjusted according to the actual application scenario, achieving the technical effect of being able to flexibly perform security detection on the user operation behavior of the hardware management platform.

[0191] Embodiments of the present application also provide a computer program product. The above computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-described embodiments of the security detection method.

[0192] When the computer program is executed, not only the normativity of the target operation itself is referred to, but also the importance of the operation device of the target operation itself is referred to, and the reference vector can be configured and adjusted according to the actual application scenario, achieving the technical effect of being able to flexibly perform security detection on the user operation behavior of the hardware management platform.

[0193] Embodiments of the present application also provide another computer program product, including a non-volatile computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-described embodiments of the security detection method.

[0194] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0195] The above has introduced in detail a security detection method, device, equipment, and readable storage medium provided by this application. Specific examples have been used herein to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the protection scope of this application.

Claims

1. A security detection method, characterized in that, Including: Obtain the log information of the hardware management platform, and extract the operation characteristics corresponding to the target operation from the log information; Utilize the operating device in the operation characteristics to obtain the device importance score corresponding to the target operation; Establish a standardized vector using the operation characteristics, and compare the standardized vector with a reference vector to determine the operation compliance score; The reference vector is the standardized vector corresponding to the standard operation; Determine the total score using the operation compliance score and the device importance score, and determine the security of the target operation using the total score.

2. The method according to claim 1, characterized in that, Establishing a standardized vector using the operation characteristics includes: Create a feature vector corresponding to the operation characteristics; Perform standardization processing on the feature vector to obtain the standardized vector.

3. The method according to claim 2, characterized in that, Performing standardization processing on the feature vector includes: Determine the permission role of the operator in the operation characteristics; Convert the operator in the feature vector into the role weight value of the permission role.

4. The method according to claim 2, wherein Performing standardization processing on the feature vector includes: Determine the time relationship between the operation time and the working time in the operation characteristics; Convert the operation time in the feature vector into the time weight value of the time relationship.

5. The method according to claim 2, characterized in that, Performing standardization processing on the feature vector includes: Determine the operation weight value corresponding to the operation type in the operation characteristics; Convert the operation type in the feature vector into the operation weight value.

6. The method according to claim 2, wherein Performing standardization processing on the feature vector includes: Determine the device weight value corresponding to the operating device; Convert the operating device in the feature vector into the device weight value.

7. The method according to claim 6, wherein Determining the device weight value corresponding to the operating device includes: Determine the device type of the operating device; Determine the standardized code corresponding to the device type as the device weight value.

8. The method according to claim 7, wherein The process of determining the standardized code includes: Obtain the number of type samples corresponding to the operable devices; Calculate the ratio of the eigenvalue of the operating device to the number of type samples; where the eigenvalue is the serial number of the operating device among the operable devices; Determine the ratio as the standardized code.

9. The method according to claim 1, characterized in that, Comparing the standardized vector with the reference vector to determine the operation compliance score includes: Calculate the similarity between the standardized vector and the reference vector; Determine the operation compliance score using the similarity.

10. The method according to claim 1, wherein Utilizing the operating device in the operation characteristics to obtain the device importance score corresponding to the target operation includes: Obtain the device information of the operating device; Respectively determine the sub-scores corresponding to the information items in the device information; Perform weighted summation on the sub-scores to obtain the device importance score.

11. The method according to any one of claims 1 to 10, characterized in that, Determining the security of the target operation using the total score includes: Compare the total score with the score interval corresponding to the warning level to determine the target warning level corresponding to the total score; Execute the warning operation corresponding to the target warning level.

12. A security detection device, characterized in that, Including: An operation characteristic acquisition module, configured to obtain the log information of the hardware management platform, and extract the operation characteristics corresponding to the target operation from the log information; A device importance score determination module, configured to utilize the operating device in the operation characteristics to obtain the device importance score corresponding to the target operation; An operation standardization score determination module, configured to establish a standardized vector by using the operation features, and compare the standardized vector with a reference vector to determine an operation standardization score; The reference vector is the standardized vector corresponding to the standard operation; A safety assessment module, configured to determine a total score by using the operation standardization score and the device importance score, and determine the safety of the target operation by using the total score.

13. An electronic device, characterized in that, Comprising: A memory, configured to store a computer program; A processor, configured to implement the steps of the safety detection method according to any one of claims 1 to 11 when executing the computer program.

14. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, wherein the computer program implements the steps of the safety detection method according to any one of claims 1 to 11 when executed by a processor.

15. A computer program product, comprising a computer program, characterized in that, The computer program implements the steps of the safety detection method according to any one of claims 1 to 11 when executed by a processor.

Citation Information

Cited By

  • BMC security assessment method and device, equipment, storage medium and program product

    CN120744940A