Host security protection method and system, electronic equipment and program product
By monitoring and automatically modifying the host authentication password in the cloud environment when necessary, the risk of brute-force cracking caused by low host security in the cloud environment is solved, and the security protection capability of the host and the complexity of the authentication password are improved.
Patent Information
- Application Number
- CN202410172586.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-06
- Publication Date
- 2025-08-08
AI Technical Summary
In the cloud environment, the existing technology cannot effectively reduce the risk of brute-force cracking caused by low-security authentication passwords in batch hosts, and cannot effectively reduce the time cost of setting new authentication passwords and modifying batch host passwords.
By monitoring the authentication password on the host, determining its security performance indicators, and when the indicator is below the threshold, the bastion machine in the cloud environment automatically modifys the authentication password to improve its complexity and reliability.
It realizes effective security protection for the host, reduces the risk of brute force cracking, and improves the efficiency and security of authentication password setting.
Smart Images

Figure CN120449145A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing, and in particular to a host security protection method, system, electronic device and program product. Background Art
[0002] Currently, preventing malicious attackers from using brute force methods to break through authentication passwords has been a key focus for host security products. For users in cloud environments, the presence of weak authentication passwords on a large number of hosts poses a significant risk of brute force attacks.
[0003] In the prior art, host security products can monitor existing authentication passwords on hosts during the pre-emptive defense phase against brute force attacks and manually modify each detected authentication password. However, this method fails to effectively reduce the time required to set up new authentication passwords or modify passwords for a batch of hosts, and lacks effective host security protection.
[0004] To address the above-mentioned problems, no effective solutions have been proposed so far. Summary of the Invention
[0005] The embodiments of the present application provide a host security protection method, system, electronic device and program product to at least solve the technical problem of being unable to effectively protect the host.
[0006] According to one aspect of an embodiment of the present application, a host security protection method is provided. This method can be applied to host security products in a cloud environment and may include: monitoring an authentication password set on the host, wherein the authentication password is used to provide security protection for the host; determining a security performance index of the authentication password, wherein the security performance index is used to indicate the strength of the authentication password's security protection for the host; and if the security performance index of the authentication password is below an index threshold, calling a bastion host in the cloud environment to modify the authentication password.
[0007] According to another aspect of an embodiment of the present application, another host security protection method is also provided. The method can be applied to a bastion host in a cloud environment and can include: monitoring a call instruction from a host security product, wherein the call instruction is triggered when a security performance indicator of an authentication password set on the host is lower than an indicator threshold, and includes an authentication password, the authentication password is used to provide security protection for the host, and the security performance indicator is used to indicate the strength of the authentication password's security protection of the host; and in response to the call instruction, modifying the authentication password.
[0008] According to another aspect of an embodiment of the present application, a host security protection system is also provided. This system can be applied in a cloud environment and can include: a host for setting an authentication password, wherein the authentication password is used to provide security protection for the host; a host security product for determining a security performance index of the authentication password, wherein the security performance index is used to indicate the strength of the authentication password's security protection for the host; if the security performance index of the authentication password is lower than an index threshold, triggering a call instruction, wherein the call instruction includes the authentication password; and a bastion host for modifying the authentication password in response to the call instruction.
[0009] According to another aspect of an embodiment of the present application, an electronic device is also provided. The electronic device may include a memory and a processor: the memory is used to store computer-executable instructions, and the processor is used to execute computer-executable instructions. When the above-mentioned computer-executable instructions are executed by the processor, the security protection method of the host described above is implemented.
[0010] According to another aspect of an embodiment of the present application, a processor is further provided, which is used to run a program, wherein any of the above-mentioned host security protection methods is executed when the program is running.
[0011] According to another aspect of an embodiment of the present application, a computer-readable storage medium is also provided, which includes a stored program, wherein when the program is running, the device where the storage medium is located controls the host security protection method to execute any of the above items.
[0012] In an embodiment of the present application, the authentication password set on the host is monitored, wherein the authentication password is used to provide security protection for the host; the security performance index of the authentication password is determined, wherein the security performance index is used to indicate the strength of the security protection provided by the authentication password to the host; if the security performance index of the authentication password is lower than the index threshold, the bastion host in the cloud environment is called to modify the authentication password. That is, in an embodiment of the present application, the weak password monitoring capability of the host security product is combined to monitor the authentication password. If the security performance index of the authentication password is lower than the index threshold, the authentication password can be automatically modified in conjunction with the bastion host to further improve the complexity and reliability of the authentication password, as well as the security protection capability of the host, thereby achieving the technical effect of effective security protection for the host and solving the technical problem of being unable to effectively provide security protection for the application.
[0013] It is easy to notice that the above general description and the following detailed description are merely for the purpose of exemplifying and explaining the present application, and do not constitute a limitation of the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0015] Figure 1 This is a hardware structure block diagram of a computer terminal (or mobile device) for implementing a host security protection method according to an embodiment of the present application;
[0016] Figure 2 is a structural block diagram of a computing environment according to an embodiment of the present application;
[0017] Figure 3 This is a structural block diagram of a service grid according to an embodiment of the present application;
[0018] Figure 4 This is a flow chart of a host security protection method according to an embodiment of the present application;
[0019] Figure 5 is a flow chart of another host security protection method according to an embodiment of the present application;
[0020] Figure 6 is a schematic diagram of a host security protection system according to an embodiment of the present application;
[0021] Figure 7 This is a schematic diagram of combining a bastion host with a host security product to implement host weak password monitoring according to an embodiment of the present application;
[0022] Figure 8 is a schematic diagram of a safety protection device for a host according to an embodiment of the present application;
[0023] Figure 9 is a schematic diagram of another host safety protection device according to an embodiment of the present application;
[0024] Figure 10 is a structural block diagram of a computer terminal according to an embodiment of the present application;
[0025] Figure 11 It is a block diagram of an electronic device according to a host security protection method of an embodiment of the present application. DETAILED DESCRIPTION
[0026] In order to enable those skilled in the art to better understand the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.
[0027] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in a sequence other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0028] First, some nouns or terms that appear in the description of the embodiments of the present application are subject to the following interpretations:
[0029] Brute force cracking is an attack method that attempts to obtain a password or key by trying a large number of possible combinations, guessing the password one by one until the correct password is found. For example, brute force cracking can be performed through brute force attacks such as exhaustive attacks, dictionary attacks, and rainbow table attacks.
[0030] Weak passwords can be easily cracked passwords, which are usually simple number combinations or number combinations with the same account number.
[0031] Bastion host 4A can include centralized authentication, centralized account, centralized authorization, and centralized audit.
[0032] Centralized authentication is a method of managing and verifying user identities through a single authentication center;
[0033] Centralized account, which can be used to identify identity, manage access rights, etc.
[0034] Centralized authorization: Each account can perform different operations in the system, requiring administrators to perform detailed authorization to ensure that each account has appropriate permissions to prevent unauthorized operations.
[0035] Centralized auditing refers to the process in which a bastion host reviews and supervises the authenticity, correctness, and compliance of operations performed by IT operators in the field of IT operations.
[0036] Example 1
[0037] According to an embodiment of the present application, a host security protection method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0038] The method embodiment provided in the first embodiment of the present application can be executed in a mobile terminal, a computer terminal or a similar computing device. Figure 1 This is a hardware structure diagram of a computer terminal (or mobile device) for implementing a host security protection method according to an embodiment of the present application. Figure 1 As shown, the computer terminal 10 (or mobile device) may include one or more (illustrated as 102a, 102b, ..., 102n in the figure) processors 102 (the processor 102 may include but is not limited to a processing device such as a microcontroller unit (MCU) or a programmable logic device (FPGA), a memory 104 for storing data, and a transmission module 106 for communication functions. In addition, it may also include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS), a network interface, a power supply and / or a camera. It will be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above electronic device. Figure 1 More or fewer components than shown, or with Figure 1 Different configurations shown.
[0039] It should be noted that the one or more processors 102 and / or other data processing circuits described above may generally be referred to herein as "data processing circuitry". The data processing circuitry may be embodied in whole or in part as software, hardware, firmware, or any other combination thereof. In addition, the data processing circuitry may be a single independent processing module, or may be incorporated in whole or in part into any of the other components of the computer terminal 10 (or mobile device). As described in the embodiments of the present application, the data processing circuitry serves as a processor control (e.g., selection of a variable resistor terminal path connected to an interface).
[0040] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the host security protection method in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, realizing the above-mentioned host security protection method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories may be connected to the computer terminal 10 via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0041] The transmission device 106 is used to receive or send data via a network. A specific example of the aforementioned network may include a wireless network provided by the communications provider of the computer terminal 10. In one embodiment, the transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0042] The display may be, for example, a touch screen liquid crystal display (LCD), which enables a user to interact with a user interface of the computer terminal 10 (or mobile device).
[0043] Figure 1 The hardware structure block diagram shown can be used not only as an exemplary block diagram of the computer terminal 10 (or mobile device), but also as an exemplary block diagram of the server. In an optional embodiment, Figure 2 The block diagram shows the use of the above Figure 1The computer terminal 10 (or mobile device) is shown as an embodiment of a computing node in the computing environment 201 . Figure 2 is a structural block diagram of a computing environment according to an embodiment of the present application, such as Figure 2 As shown, computing environment 201 includes multiple computing nodes (e.g., servers) (illustrated as 210-1, 210-2, ...) running on a distributed network. Each computing node contains local processing and memory resources, and end user 202 can remotely run applications or store data in computing environment 201. Applications can be provided as multiple services 220-1, 220-2, 220-3, and 220-4 in computing environment 201, representing services "A," "D," "E," and "H," respectively.
[0044] End user 202 can provide and access services through a web browser or other software application on a client. In some embodiments, the provisioning and / or request of end user 202 can be provided to the ingress gateway 230. The ingress gateway 230 may include a corresponding agent to handle the provisioning and / or request for services (one or more services provided in the computing environment 201).
[0045] Services are provided or deployed based on various virtualization technologies supported by the computing environment 201. In some embodiments, services can be provided based on virtual machine (VM)-based virtualization, container-based virtualization, and / or similar methods. Virtual machine-based virtualization can be to simulate a real computer by initializing a virtual machine, and execute programs and applications without directly contacting any actual hardware resources. While the virtual machine virtualizes the machine, according to container-based virtualization, a container can be started to virtualize the entire operating system (Operating System, referred to as OS) so that multiple workloads can run on a single operating system instance.
[0046] In an embodiment based on container virtualization, several containers of a service can be assembled into a Pod (e.g., a Kubernetes Pod). Figure 2 As shown, service 220-2 can be equipped with one or more Pods 240-1, 240-2, ..., 240-N (collectively, Pods). A Pod can include a proxy 245 and one or more containers 242-1, 242-2, ..., 242-M (collectively, containers). One or more containers in a Pod handle requests related to one or more corresponding functions of the service. Proxy 245 typically controls network functions related to the service, such as routing and load balancing. Other services can also be Pods similar to Pods.
[0047] During operation, executing a user request from the end user 202 may require calling one or more services in the computing environment 201, and executing one or more functions of a service may require calling one or more functions of another service. Figure 2 As shown, service “A” 220 - 1 receives a user request from end user 202 from ingress gateway 230 , service “A” 220 - 1 may call service “D” 220 - 2 , and service “D” 220 - 2 may request service “E” 220 - 3 to perform one or more functions.
[0048] This computing environment can be a cloud computing environment, where resource allocation is managed by the cloud service provider, allowing for feature development without having to worry about implementing, adjusting, or scaling servers. This computing environment allows developers to execute code in response to events without building or maintaining complex infrastructure. Services can be partitioned to perform a set of functions that can scale independently and automatically, rather than scaling a single hardware device to handle the potential load.
[0049] In another optional embodiment, Figure 3 The block diagram shows the use of the above Figure 1 The computer terminal 10 (or mobile device) is shown as an embodiment of the service grid. Figure 3 This is a structural diagram of a service grid according to an embodiment of the present application. Figure 3 As shown, the service grid 300 is mainly used to facilitate secure and reliable communication between multiple microservices. Microservices refer to decomposing an application into multiple smaller services or instances and distributing them to run on different clusters / machines.
[0050] like Figure 3 As shown, the microservices may include application service instance A and application service instance B, which form the functional application layer of the service grid 300. In one embodiment, application service instance A runs in the form of container / process 308 on machine / workload container group 314 (Pod), and application service instance B runs in the form of container / process 310 on machine / workload container group 316 (Pod).
[0051] In one implementation, application service instance A may be a product query service, and application service instance B may be a product ordering service.
[0052] like Figure 3As shown, application service instance A and grid proxy (sidecar) 303 coexist in machine workload container group 614, while application service instance B and grid proxy 305 coexist in machine workload container 314. Grid proxy 303 and grid proxy 305 form the data plane of service grid 300. Grid proxy 303 and grid proxy 305 run as container / process 304 and container / process 306, respectively, and can receive requests 312 for product query services. Bidirectional communication is possible between grid proxy 303 and application service instance A, and between grid proxy 305 and application service instance B. Furthermore, bidirectional communication is possible between grid proxy 303 and grid proxy 305.
[0053] In one embodiment, all traffic from application service instance A is routed to the appropriate destination via grid proxy 303, and all network traffic from application service instance B is routed to the appropriate destination via grid proxy 305. It should be noted that network traffic mentioned herein includes, but is not limited to, Hypertext Transfer Protocol (HTTP), Representational State Transfer (REST), the high-performance, general-purpose open source framework (Google Remote Procedure Call, gRPC), and the open source in-memory data structure storage system (Redis).
[0054] In one embodiment, the data plane layer's functionality can be extended by writing custom filters for the proxy (Envoy) in service mesh 300. Service mesh proxy configuration can be designed to enable the service mesh to correctly proxy service traffic, enabling service interoperability and service governance. Mesh proxy 303 and mesh proxy 305 can be configured to perform at least one of the following functions: service discovery, health checking, routing, load balancing, authentication and authorization, and observability.
[0055] like Figure 3 As shown, the service grid 300 also includes a control plane layer. The control plane layer can be a group of services running in a dedicated namespace, and these services are hosted by a hosting control plane component 301 in a machine / workload container group (machine / Pod) 302. Figure 3 As shown, managed control plane component 301 communicates bidirectionally with mesh proxy 303 and mesh proxy 305. Managed control plane component 301 is configured to perform certain control and management functions. For example, managed control plane component 301 receives telemetry data transmitted by mesh proxy 303 and mesh proxy 305 and can further aggregate this telemetry data. In addition to these services, managed control plane component 301 can also provide a user-oriented application programming interface (API) to facilitate manipulation of network behavior and provide configuration data to mesh proxy 303 and mesh proxy 305.
[0056] Under the above operating environment, this application provides Figure 4 The host security protection method shown can be applied to host security products in cloud environments. Figure 4 This is a flow chart of a host security protection method according to an embodiment of the present application. Figure 4 As shown, the method may include the following steps:
[0057] Step S402: monitoring the authentication password set on the host, wherein the authentication password is used to provide security protection for the host.
[0058] In the technical solution provided in step S402 above, the host security product can monitor the authentication password set on the host. The authentication password can be used to protect the host and can be a cryptographic algorithm used for encryption or decryption or a password used for authentication purposes. It can be composed of numbers, letters, punctuation marks, text, images, and other information. It can be a user-defined password and can include simple, easy-to-guess, and easily cracked weak passwords as well as difficult-to-crack passwords. For example, it can be an account password. It should be noted that this is for illustrative purposes only and does not impose specific restrictions on the type and composition of the authentication password.
[0059] Optionally, the user sets an authentication password on the host, and the host security product can obtain the authentication password set on the host and perform further judgment on the authentication password.
[0060] Step S404: determining a security performance index of the authentication password, wherein the security performance index is used to represent the strength of the security protection provided by the authentication password to the host.
[0061] In the technical solution provided in step S404 of the present application, a security performance index of the authentication password is determined. The security performance index can be used to indicate the strength of the authentication password in providing security protection to the host, and can include the length, complexity, and frequency of historical occurrence of the authentication password. For example, the security performance index can be the number of historical times the authentication password has been set. It should be noted that this is for illustrative purposes only and does not impose any specific limitation on the type of security performance index.
[0062] For example, the security performance indicator may be the length of the authentication password. The longer the length of the authentication password, the stronger the security protection provided by the authentication password to the host. Alternatively, the security performance indicator may be the complexity of the authentication password. The more uppercase and lowercase letters, numbers, and special characters the authentication password contains, the stronger the security protection provided by the authentication password to the host. For example, the authentication password may be "4sP@ssw0rd!". Alternatively, the security performance indicator may be the frequency of changes to the authentication password. The higher the frequency of changes to the authentication password, the stronger the security protection provided by the authentication password to the host. Alternatively, the security performance indicator may be the number of historical uses of the authentication password. The fewer historical uses of the authentication password, the stronger the security protection provided by the authentication password to the host. It should be noted that the above is only an example and does not impose specific restrictions on the types of security performance indicators.
[0063] Step S406: If the security performance index of the authentication password is lower than the index threshold, the bastion host in the cloud environment is called to modify the authentication password.
[0064] In the technical solution provided in the above step S406 of the present application, after determining the security performance index, the security performance index can be judged based on the index threshold to determine whether the security performance index of the authentication password is lower than the index threshold. If the security performance index of the authentication password is lower than the index threshold, it can be determined that the strength of the authentication password in providing security protection to the host is weak, and the bastion host in the cloud environment can be called to modify the authentication password to improve the strength of the authentication password in providing security protection to the host. Among them, the bastion host can be a management and control platform that provides users with operation and maintenance and security audits, which can be used to centrally manage the operation and maintenance permissions of the host. The index threshold can be a pre-set value, which can be the length, historical usage times, complexity, etc. of the authentication password, and can be used to measure the strength of the authentication password in providing security protection to the host. It should be noted that this is only an example, and no specific restrictions are placed on the content of the index threshold.
[0065] For example, we can assume that the indicator threshold is that the length of the authentication password is greater than 8. The security performance indicator of the authentication password set by the user (length is 7) is determined. The security performance indicator is judged based on the indicator threshold. It can be determined that the security performance indicator is lower than the indicator threshold, indicating that the authentication password is not strong enough to protect the host. In this case, we can call the bastion host in the cloud environment to modify the authentication password to improve the security protection provided by the authentication password to the host.
[0066] In this embodiment, the authentication password is monitored through the monitoring capability of the host security product, and the authentication password whose security performance index is lower than the index threshold is modified by the automatic encryption capability of the bastion host, thereby providing a complete closed-loop solution for monitoring and modifying the behavior of weak passwords being attacked by brute force, thereby achieving the technical effect of effective security protection for the host and solving the technical problem of being unable to effectively defend against risks of applications.
[0067] Through the above steps S402 to S408 of the present application, the authentication password set on the host is monitored, wherein the authentication password is used to provide security protection for the host; the security performance index of the authentication password is determined, wherein the security performance index is used to indicate the strength of the security protection provided by the authentication password to the host; if the security performance index of the authentication password is lower than the index threshold, the bastion host in the cloud environment is called to modify the authentication password. That is, in the embodiment of the present application, the weak password monitoring capability of the host security product is combined to monitor the authentication password. If the security performance index of the authentication password is lower than the index threshold, the authentication password can be automatically modified in conjunction with the bastion host to further improve the complexity and reliability of the authentication password, as well as the security protection capability of the host, thereby achieving the technical effect of effective security protection for the host and solving the technical problem of being unable to effectively defend against risks of the application program.
[0068] The above method of this embodiment is further introduced below.
[0069] As an optional implementation, the method may also include: determining the security performance index of the modified authentication password; if the security performance index of the modified authentication password is higher than or equal to the index threshold, calling the bastion host and using the modified authentication password to update the authentication password previously set on the host.
[0070] In this embodiment, the modified authentication password provides a higher level of security protection for the host than the previous authentication password, and it is determined whether the security performance index of the modified authentication password is higher than or equal to the index threshold. If the security performance index of the modified authentication password is higher than or equal to the index threshold, the bastion host can be called to use the modified authentication password to update the authentication password previously set on the host.
[0071] As an optional implementation, the method may also include: calling the bastion host, using the modified authentication password to update the authentication password previously set on the host, and returning to continue the step of monitoring the authentication password until the security performance index of the authentication password is higher than or equal to the index threshold.
[0072] In this embodiment, after calling the bastion host to modify the authentication password, the modified authentication password can be used to update the authentication password previously set on the host. The security performance index of the modified authentication password is determined, and the security performance index of the modified authentication password is judged based on the index threshold. If the security performance index of the modified authentication password is lower than the index threshold, the bastion host can be called to further modify the modified authentication password until the security performance index of the modified authentication password is higher than or equal to the index threshold, and the final authentication password is obtained, and the final authentication password is used to perform security protection on the host; or, if the security performance index of the modified authentication password is higher than or equal to the index threshold, the modified authentication password can be directly used to perform security protection on the host. That is, after using the modified authentication password to update the authentication password previously set on the host, this embodiment returns to continue to execute the step of monitoring the authentication password, thereby realizing a complete closed loop of monitoring and modifying the authentication password, and achieving the purpose of effective security protection.
[0073] As an optional implementation, step S406, if the security performance index of the authentication password is lower than the index threshold, the bastion host in the cloud environment is called to modify the authentication password, including: if the security performance index of the authentication password is lower than the index threshold, based on the communication connection between the host security product and the interface of the bastion host, the interface of the bastion host is called to modify the authentication password.
[0074] In this embodiment, a determination is made as to whether a security performance index of the authentication password is below an index threshold. If the security performance index of the authentication password is below the index threshold, it can be determined that the authentication password provides low security protection for the host. Based on the communication connection between the host security product and the interface of the bastion host, an interface of the bastion host can be called to modify the authentication password. The interface can be an application programming interface (API) of the bastion host.
[0075] Optionally, when the host security service (i.e., the host security product) determines that the security performance index of the authentication password set by the user is lower than the index threshold, it can be determined that the authentication password is a weak password that is easy to crack. The host security product can then call the bastion host's application programming interface (API) to call the bastion host's interface to modify the detected weak password. By adjusting the authentication password set by the user, the strength of the security protection of the authentication password is improved, and the attacker's brute force cracking behavior fails.
[0076] As an optional implementation method, if the security performance index of the authentication password is lower than the index threshold, the interface of the bastion host is called to modify the authentication password based on the communication connection between the host security product and the interface of the bastion host, including: if the security performance index of the authentication password is lower than the index threshold, searching for the bastion host in the cloud environment; establishing a communication connection between the host security product and the interface of the found bastion host; and using the communication connection to call the interface of the bastion host to modify the authentication password.
[0077] In this embodiment, if the security performance index of the authentication password is lower than the index threshold, a bastion host is searched in the cloud environment; a communication connection is established between the host security product and the interface of the found bastion host; using the communication connection, the bastion host can be called to modify the authentication password through an encrypted network protocol / remote desktop connection protocol (Secure Shell / Remote Desktop Protocol, abbreviated as SSH / RDP).
[0078] Optionally, in addition to modifying the authentication password by calling the bastion host's interface through the SSH / RDP protocol, the authentication password can also be adjusted through the host agent, the privileged account hosted by the bastion host, the operating system (for example, Windows) Remote Procedure Call service (RCP) or remote management service (Windows RemoteManagement Service, winRm), etc. This is only an example, and there is no specific restriction on the method of adjusting the authentication password.
[0079] As an optional implementation, if the security performance index of the authentication password is lower than the index threshold, then searching for a bastion host in the cloud environment, including: if the security performance index of the authentication password is lower than the index threshold, then searching for a bastion host in the cloud environment that allows the authentication password set on the host to be modified.
[0080] In this embodiment, in a cloud environment, a bastion host can help administrators modify authentication passwords on hosts to meet security performance requirements. If the authentication password's security performance index falls below a threshold, administrators can use the cloud platform or related management tools to find a bastion host that allows modification of authentication passwords set on hosts. Once the bastion host is found, the authentication password on the host can be modified through the bastion host to improve password security.
[0081] For example, suppose the indicator threshold specifies that the complexity of the authentication password must include uppercase and lowercase letters, numbers, and special characters, and its length must be at least 8 characters. If the authentication password on a host contains only numbers and is less than 8 characters long, the authentication password's security performance indicator is below the indicator threshold. If the authentication password's security performance indicator is below the indicator threshold, in a cloud environment, you can use the cloud platform or management tools to find a bastion host that allows modification of the host. You can then use the bastion host to modify the authentication password on the host so that the modified authentication password's security performance indicator is greater than or equal to the indicator threshold. An authentication password with a security performance indicator greater than or equal to the indicator threshold is considered to meet the indicator requirements.
[0082] As an optional implementation, the host security product includes a server, step S406, if the security performance index of the authentication password is lower than the index threshold, then call the bastion host in the cloud environment to modify the authentication password, including: if the server determines that the security performance index of the authentication password is lower than the index threshold, then control the server to call the bastion host in the cloud environment to modify the authentication password.
[0083] In this embodiment, the secure host product may include a server. After the secure host product obtains the authentication password, the server in the secure host product can evaluate the authentication password to determine whether the authentication password's security performance index is below a threshold. If the authentication password's security performance index is below the threshold, the authentication password can be determined to be a weak password that is easily cracked, and the server can be controlled to call a bastion host in the cloud environment to modify the authentication password. The server can be a host security server and can exist in the cloud environment.
[0084] As an optional implementation, the method may further include: controlling the server to search for an authentication password in an authentication password dictionary, wherein the authentication password dictionary includes at least one authentication password, and the security performance index of each authentication password in the at least one authentication password is lower than an index threshold; if the server finds the authentication password in the authentication password dictionary, the control server determines that the security performance index is lower than the index threshold.
[0085] In this embodiment, when the host security product determines the authentication password, it can control the server to search for the authentication password in the authentication password dictionary. Since the authentication passwords in the authentication password dictionary all have security performance indicators below the indicator threshold, if the server finds the user-set authentication password in the authentication password field, it can determine that the security performance indicator of the user-set authentication password is below the indicator threshold. The authentication password field can be a pre-built-in weak password, or it can be a weak password dictionary that can be used to monitor the obtained authentication password, can be pre-stored in the host security product, or can be retrieved by the host security product from elsewhere. The source of the authentication password field is not specifically limited here.
[0086] Optionally, the host security product may be pre-configured with an authentication password dictionary (e.g., a weak password dictionary). When a user-set authentication password is detected, the host security product may monitor the authentication password using the configured authentication password dictionary. The server in the host security product may be controlled to search for the authentication password in the authentication password dictionary. If the server finds the authentication password in the authentication password dictionary, the server may be controlled to determine that the security performance of the authentication password is below an indicator threshold, and that the user-set authentication password is a weak password.
[0087] For example, a host security product can use built-in weak passwords to monitor user-set authentication passwords to determine whether the passwords are weak. If the authentication password set on the host is identical to the authentication password in the authentication password dictionary, or if any of the password's length, composition, or historical usage information is identical to the authentication password in the authentication password dictionary, the server can be controlled to determine that the security performance indicator is below the indicator threshold.
[0088] It should be noted that the method of judging the authentication password through the authentication password dictionary here is only an example. This application is not limited to the content of the above example. As long as the authentication password dictionary is used to judge the strength of the security protection of the authentication password, it should be within the scope of protection of this application.
[0089] As an optional implementation, the host security product includes a client deployed on the host, and determines the security performance index of the authentication password, including: controlling the server to obtain the authentication password from the client; and controlling the server to determine the security performance index of the obtained authentication password.
[0090] In this embodiment, the host security product includes a client deployed on the host in addition to the server, which can control the server to obtain the authentication password from the client and control the server to determine the security performance index of the obtained authentication password. The client can be a host protection client.
[0091] Alternatively, users can unconsciously set authentication passwords on the host. The host protection client deployed on the host can obtain the authentication passwords set by the user and transmit the obtained passwords to the host security product for further monitoring.
[0092] For example, a host protection client can obtain a user-set authentication password and transmit it to a host security product. The host security product can then control a server to obtain the authentication password from the client and determine the security performance indicators of the obtained authentication password.
[0093] As an optional implementation manner, monitoring the authentication password set on the host includes: controlling the client to monitor the authentication password set on the host.
[0094] In this embodiment, the client deployed on the host can be controlled to monitor the authentication password set on the host.
[0095] Optionally, the host security product may control the client to monitor the host corresponding to the user protected by the host security product to obtain the authentication password set on the host.
[0096] As an optional implementation, the method may further include: if the security performance index of the authentication password is lower than the index threshold, generating an authentication password setting policy based on the authentication password, wherein the authentication password setting policy is used to represent the rules that the authentication password set on the host needs to meet so that the security performance index of the set authentication password is higher than or equal to the index threshold; and sending the authentication password setting policy to the host.
[0097] In this embodiment, if the security performance index of the authentication password is lower than the index threshold, an authentication password setting policy can be generated based on the authentication password. Based on the set authentication password setting policy, the rules that the authentication password set on the host must meet can be determined. The authentication password setting policy is then sent to the host. The authentication password setting policy can be a password policy suggestion that can be used to indicate the rules that the authentication password set on the host must meet and can be used to prompt the user to ensure that the security performance index of the set authentication password is higher than or equal to the index threshold.
[0098] Optionally, this embodiment records historical weak passwords and can provide a reasonable authentication password setting strategy when the user sets a new password, so as to improve the security performance of the authentication password set by the user.
[0099] For example, authentication password policies can be determined based on historically weak passwords. This can help prevent users from using common weak passwords. For example, users can be reminded that weak passwords like "123456," "password," and "qwerty" are easily guessed or cracked using dictionary attacks, so they should be set with caution. Alternatively, users can be prompted to choose complex passwords to increase the difficulty of cracking. Passwords can include uppercase and lowercase letters, numbers, and special characters, and be long to increase the difficulty. For example, a password like "p@ssW0rd!" can be used. Alternatively, authentication password policies can be used to remind users to avoid personal information and common words or phrases when setting passwords, such as birthdays, names, and phone numbers. Furthermore, authentication password policies can be used to remind users to regularly change their passwords. Regular password changes can reduce the risk of password cracking. For example, users can be advised to change their passwords every three months, or they can be reminded to do so every three months.
[0100] In this embodiment, a password management tool can be used to generate and save complex passwords, and ensure that each online user has a different password. In this way, even if the password set by one user is leaked, the security of other accounts will not be affected.
[0101] In this embodiment, in addition to authentication passwords, multi-factor authentication can also be provided for user identity verification. By enabling multi-factor authentication, account security is enhanced. Multi-factor authentication can include verification via mobile phone verification codes, fingerprint recognition, and other methods. This is for illustrative purposes only and does not limit the types of multi-factor authentication.
[0102] As an optional implementation, the modified authentication password may be a modified high-strength password. Therefore, the security performance index of the modified authentication password is higher than the security performance index of the authentication password before the modification.
[0103] In this embodiment, the weak password monitoring capability of the host security product is combined to monitor the authentication password. If the security performance index of the authentication password is lower than the index threshold, the authentication password can be automatically modified in conjunction with the bastion host to further improve the complexity and reliability of the authentication password, as well as the security protection capability of the host, thereby achieving the technical effect of effective security protection for the host and solving the technical problem of being unable to effectively defend against risks of the application.
[0104] The embodiment of the present application also provides another host security protection method, which can be applied to a bastion host in a cloud environment. Figure 5 FIG. 1 is a flow chart of another host security protection method according to an embodiment of the present application. Figure 5As shown, the method may include the following steps:
[0105] Step S502, monitor the call instructions from the host security product, wherein the call instructions are triggered when the security performance index of the authentication password set on the host is lower than the index threshold, and include the authentication password, the authentication password is used to provide security protection for the host, and the security performance index is used to indicate the strength of the authentication password's security protection for the host.
[0106] In the technical solution provided in the above step S502 of the present application, when it is determined that the security performance index of the authentication password set on the host is lower than the index threshold, it can be determined that the authentication password provides weak security protection for the host, then the host security product can trigger a call instruction and send the call instruction to the bastion host.
[0107] Step S504: Modify the authentication password in response to the calling instruction.
[0108] In the technical solution provided in the above step S504 of the present application, the bastion host can modify the authentication password in response to the monitored call instruction.
[0109] As an optional implementation, the method may further include: if the security performance index of the modified authentication password is higher than or equal to the index threshold, using the modified authentication password to update the authentication password previously set on the host.
[0110] In this embodiment, the bastion host can send the modified authentication password to the host to update the authentication password previously set by the host. After the authentication password is updated, the host security product can further judge the updated authentication password. If the security performance index of the authentication password is higher than or equal to the index threshold, the updated authentication password can be used to protect the host. If the security performance of the authentication password is lower than the index threshold, the bastion host can be called to further modify the updated authentication password and further judge the security performance index of the modified authentication password. Through repeated monitoring, the security performance index of the authentication password is higher than or equal to the index threshold.
[0111] As an optional implementation, step S504, in response to a call instruction, the authentication password is modified, including: the interface of the control bastion host responds to the call instruction to modify the authentication password.
[0112] In this embodiment, the bastion host responds to the call instruction, and the interface of the bastion host can be controlled to respond to the call instruction to modify the authentication password. For example, the number of authentication passwords can be adjusted, the content of the authentication password can be adjusted, etc. This is only an example and does not impose specific restrictions on the method of modifying the authentication password.
[0113] As an optional implementation, the host security product includes a server, and step S502, monitoring the call instructions from the host security product, includes: monitoring the call instructions from the server.
[0114] In this embodiment, when the server in the host security product determines that the security performance index of the authentication password is lower than the index threshold, a call instruction may be issued. The bastion host may monitor the call instructions from the server in the host security product.
[0115] As an optional implementation, the host security product includes a client deployed on the host, and the method may further include: sending the modified authentication password to the client for monitoring as the authentication password set on the host.
[0116] In this embodiment, the bastion host can send the modified authentication password to the client as the authentication password on the host. The host product security can further monitor the modified authentication password to determine whether the security performance index of the modified authentication password is greater than or equal to the index threshold.
[0117] In this embodiment, a call instruction from a host security product is monitored, wherein the call instruction is triggered when a security performance index of an authentication password set on the host is lower than an index threshold, and includes an authentication password, the authentication password is used to provide security protection for the host, and the security performance index is used to indicate the strength of the security protection provided by the authentication password to the host; in response to the call instruction, the authentication password is modified; the modified authentication password is sent to the host to update the authentication password previously set by the host, and the step of monitoring the call instruction from the host security product is returned until the security performance index of the authentication password is higher than or equal to the index threshold, thereby achieving a technical effect of providing effective security protection for the host and solving the technical problem of being unable to effectively defend against risks of the application program.
[0118] Example 2
[0119] According to an embodiment of the present application, an embodiment of a host security protection system is also provided. Figure 6 is a schematic diagram of a host security protection system according to an embodiment of the present application, such as Figure 6 As shown, the host security protection system 600 may include: a host 602, a host security product 604 and a bastion host 606.
[0120] The host 602 is used to set an authentication password, wherein the authentication password is used to provide security protection for the host.
[0121] In this embodiment, the user can set an authentication password on the host and use the authentication password to protect the host.
[0122] The host security product 604 is used to determine the security performance index of the authentication password, wherein the security performance index is used to represent the strength of the authentication password's security protection for the host; if the security performance index of the authentication password is lower than the index threshold, a call instruction is triggered, wherein the call instruction includes the authentication password.
[0123] In this embodiment, the host security product 604 can be used to detect the host 602, and can include a client and a server. In actual deployment, the client can be deployed on the host, and the server can be deployed on the cloud.
[0124] Optionally, the host security product 604 needs to communicate with the host 602. However, the host security product 604 may be deployed in the host 602 or not. There may be a functional association between the two, but not necessarily a physical location relationship.
[0125] In this embodiment, the host security product deploys a client in the host, and the client can be used to monitor the authentication password set by the user. After the authentication password is monitored, the server in the host security product can be controlled to further judge the authentication password to determine whether the security performance index of the authentication password is lower than the index threshold. If the security performance index of the authentication password is lower than the index threshold, a call instruction can be triggered.
[0126] Optionally, the calling instruction may include an authentication password. The calling instruction may send the authentication password to be authenticated to the bastion host, and the bastion host may be called to modify the authentication password.
[0127] The bastion host 606 is used to modify the authentication password in response to the call instruction.
[0128] In this embodiment, the bastion host modifies the authentication password in response to the call instruction and can send the modified authentication password to the host. This password is then used to update the host's previously set authentication password. This triggers the host security product to further determine the security performance index of the modified authentication password until the security performance index of the authentication password is greater than or equal to the index threshold.
[0129] For example, a user may unconsciously set an authentication password on host 602. Host security product 604 can monitor the detected authentication password for weak passwords. If the client in host security product 604 detects a weak password or a weak password, the server can call the bastion host to automatically modify the authentication password. Bastion host 606 can modify the authentication password set on the host through the SSH / RDP protocol, thereby increasing the strength of the authentication password's security protection for the host and preventing attackers from attempting brute force attacks.
[0130] In this embodiment, an authentication password is set through the host 602, wherein the authentication password is used to provide security protection for the host; a security performance index of the authentication password is determined through the host security product 604, wherein the security performance index is used to indicate the strength of the security protection provided by the authentication password to the host; if the security performance index of the authentication password is lower than the index threshold, a call instruction is triggered, wherein the call instruction includes the authentication password; the authentication password is modified through the bastion host in response to the call instruction; the modified authentication password is sent to the host to update the authentication password previously set by the host, triggering the host security product to determine the security performance index of the authentication password, until the security performance index of the authentication password is higher than or equal to the index threshold, thereby achieving the technical effect of effective security protection for the host and solving the technical problem of being unable to effectively defend against risks of applications.
[0131] Example 3
[0132] Passwords are a common authentication method for hosts. Preventing malicious attackers from using brute force cracking and other methods to break through password protection has always been a key focus for security products. For server users in cloud environments, weak passwords on a large number of hosts pose a significant risk of brute force cracking. Conventional host security products can only detect weak passwords but cannot modify them in batches. While bastion host products in cloud environments can modify weak passwords for host users in batches through various authentication methods, such as passwords, certificates, and keys, they cannot detect weak passwords on hosts.
[0133] In the face of brute force attacks, host security products can monitor weak password configurations on hosts during the pre-emptive defense phase and manually modify detected weak passwords one by one. However, this method cannot effectively reduce the time cost of setting up new weak passwords or modifying passwords for batches of hosts. Especially in industry cloud scenarios, security product operators and actual host users need to communicate and collaborate across multiple departments to complete the rectification of weak passwords, resulting in a technical problem of being unable to effectively protect host security.
[0134] To solve the above problems, this embodiment proposes a method for combining a bastion host with a host security product to realize host weak password monitoring and password modification. This method combines the weak password monitoring capability of the host security product and the automatic periodic password modification protection capability of the bastion host, optimizes the overall process of password modification, and effectively reduces the probability of the host being attacked by brute force, thereby achieving the technical effect of effective security protection for the host and solving the technical problem of being unable to effectively protect the host.
[0135] In this embodiment, weak passwords can be discovered by combining the weak password monitoring capabilities of host security products. The bastion host can then automatically modify and manage weak passwords for existing users, thereby improving the complexity and reliability of user passwords. At the same time, historical weak passwords can be recorded and reasonable password policy recommendations can be given when users set new passwords. This solution greatly improves the reliability of the bastion host's centralized authentication and achieves a complete closed-loop system for monitoring and modifying weak passwords for existing and incremental hosts.
[0136] The following is a further introduction to the method of combining the bastion host with host security products to implement weak host password monitoring and password modification.
[0137] In this embodiment, the network log collection capability and brute force cracking monitoring capability of the host security are combined with the automatic password modification capability of the bastion host, and an automatic password modification response strategy is automatically customized for the attacked high-risk host. By modifying the high-strength password, the probability of the host being hacked is reduced, and the host's security protection capability is improved.
[0138] Figure 7 This is a schematic diagram of combining a bastion host with a host security product to implement host weak password monitoring according to an embodiment of the present application, such as Figure 7 As shown, the host security product 72 has a client 721 (also called a host protection client) deployed in the host 71. The host security product 72 has a built-in weak password for judging the obtained authentication password.
[0139] Step S701: The user sets an authentication password.
[0140] In this embodiment, the user may unconsciously set an authentication password on the host. The host protection client deployed on the host can obtain the authentication password set by the user and transmit the obtained password to the host security product for further monitoring. The authentication password can be a custom password set by the user.
[0141] In step S702, the host security product monitors the authentication password.
[0142] In this embodiment, the host security product can control the client to monitor the host corresponding to the user protected by the host security product to obtain the authentication password set on the host.
[0143] Optionally, the host security product may have a pre-configured authentication password dictionary (e.g., a weak password dictionary). When a user-set authentication password is detected, the host security product may monitor the authentication password using the configured authentication password dictionary. The server in the host security product may be controlled to search for the authentication password in the authentication password dictionary. If the server finds the authentication password in the authentication password dictionary, the server may be controlled to determine that the security performance of the authentication password is below an indicator threshold, and that the user-set authentication password is a weak password.
[0144] Step S703: Determine whether the monitored authentication password is a weak password.
[0145] In this embodiment, when the host security service determines that the security performance index of the authentication password set by the user is lower than the index threshold, it can be determined that the authentication password is a weak password that is easy to crack. The host security product can then call the bastion host 73 to modify the monitored weak password by calling the application programming interface of the bastion host.
[0146] Step S704: The host security product calls the bastion host to modify the password.
[0147] In this embodiment, the bastion host 73 can adjust the custom password set by the user.
[0148] If the security performance index of the authentication password is lower than the index threshold, a bastion host is searched in the cloud environment; a communication connection is established between the host security product and the interface of the found bastion host; using the communication connection, the bastion host can be called to modify the authentication password through an encrypted network protocol / remote desktop connection protocol.
[0149] Optionally, in addition to modifying the authentication password by calling the bastion host's interface through the SSH / RDP protocol, the authentication password can also be adjusted through a host agent, a privileged account hosted by the bastion host, the operating system's remote procedure call service, or a remote management service. This is only an example, and there is no specific restriction on how to adjust the authentication password.
[0150] Optionally, adjust the user-defined password through the bastion host to prevent the attacker's brute force cracking attempts from failing.
[0151] As an optional implementation method, historical weak passwords can be recorded in a book, and when the user sets a new password, reasonable password policy suggestions can be made to the user based on the historical weak passwords.
[0152] In this embodiment, the authentication password is monitored through the monitoring capability of the host security product, and the authentication password whose security performance index is lower than the index threshold is modified by the automatic encryption capability of the bastion host, thereby providing a complete closed-loop solution for monitoring and modifying the behavior of weak passwords being attacked by brute force, thereby achieving the technical effect of effective security protection for the host and solving the technical problem of being unable to effectively defend against risks of applications.
[0153] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0154] It should be noted that for the aforementioned method embodiments, for the sake of simplicity, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.
[0155] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods of each embodiment of the present application.
[0156] Example 4
[0157] According to an embodiment of the present application, there is also provided a method for implementing the above Figure 4 The host security protection method and host security protection device shown can be applied to host security products in a cloud environment.
[0158] Figure 8 Schematic diagram of a host safety protection device according to an embodiment of the present application. Figure 8As shown, the host security protection device 800 may include: a first monitoring unit 802 , a determination unit 804 and a first modification unit 806 .
[0159] The first monitoring unit 802 is used to monitor the authentication password set on the host, wherein the authentication password is used to provide security protection for the host.
[0160] The determining unit 804 is configured to determine a security performance index of the authentication password, wherein the security performance index is used to indicate the strength of the security protection provided by the authentication password to the host.
[0161] The first modification unit 806 is configured to call a bastion host in a cloud environment to modify the authentication password if the security performance index of the authentication password is lower than an index threshold.
[0162] Here, the first monitoring unit 802, the determination unit 804, and the first modification unit 806 correspond to steps S402 to S406 in Example 1. The examples and application scenarios implemented by the three units and the corresponding steps are the same, but are not limited to the contents disclosed in Example 1. It should be noted that the above-mentioned units can be hardware components or software components stored in a memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b..., 102n). The above-mentioned units can also be part of the device and can be run in the computer terminal 10 provided in Example 1.
[0163] According to an embodiment of the present application, there is also provided a method for implementing the above Figure 5 The host security protection method shown is a host security protection device, which can be applied to a bastion host in a cloud environment.
[0164] Figure 9 Schematic diagram of another host safety protection device according to an embodiment of the present application. Figure 9 As shown, the host security protection device 900 may include: a second monitoring unit 902 , a second modifying unit 904 and a sending unit 906 .
[0165] The second monitoring unit 902 is used to monitor the call instructions from the host security product, wherein the call instruction is triggered when the security performance index of the authentication password set on the host is lower than the index threshold, and includes the authentication password, the authentication password is used to provide security protection for the host, and the security performance index is used to indicate the strength of the authentication password's security protection for the host.
[0166] The second modifying unit 904 is configured to modify the authentication password in response to the calling instruction.
[0167] The sending unit 906 is configured to send the modified authentication password to the host to update the authentication password previously set by the host.
[0168] It should be noted that the second monitoring unit 902, the second modifying unit 904, and the sending unit 906 correspond to steps S502 to S506 in Example 1. The examples and application scenarios implemented by the three units and the corresponding steps are the same, but are not limited to the contents disclosed in Example 1. It should be noted that the above-mentioned units can be hardware components or software components stored in a memory (e.g., memory 104) and processed by one or more processors (e.g., processors 102a, 102b..., 102n). The above-mentioned units can also be part of the device and can be run in the computer terminal 10 provided in Example 3.
[0169] In the security protection device of the host, the weak password monitoring capability of the host security product is combined to monitor the authentication password. If the security performance index of the authentication password is lower than the index threshold, the authentication password can be automatically modified in combination with the bastion host to further improve the complexity and reliability of the authentication password, as well as the security protection capability of the host, thereby achieving the technical effect of effective security protection for the host and solving the technical problem of being unable to effectively defend against risks of applications.
[0170] Example 5
[0171] The embodiment of the present application can provide a computer terminal, which can be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the computer terminal can also be replaced by a terminal device such as a mobile terminal.
[0172] Optionally, in this embodiment, the computer terminal may be located in at least one network device among a plurality of network devices of a computer network.
[0173] In this embodiment, the above-mentioned computer terminal can execute the program code of the following steps in the host security protection method: monitoring the authentication password set on the host, wherein the authentication password is used to perform security protection on the host; determining the security performance index of the authentication password, wherein the security performance index is used to indicate the strength of the security protection provided by the authentication password to the host; if the security performance index of the authentication password is lower than the index threshold, calling the bastion host in the cloud environment to modify the authentication password; using the modified authentication password to update the authentication password previously set on the host, and returning to continue to execute the step of monitoring the authentication password until the security performance index of the authentication password is higher than or equal to the index threshold.
[0174] Optionally, Figure 10 is a structural block diagram of a computer terminal according to an embodiment of the present application, such as Figure 10As shown, the computer terminal A may include: one or more (only one is shown in the figure) processors 1002 , a memory 1004 and a transmission device 1006 .
[0175] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the host security protection method and device in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, realizing the above-mentioned host security protection method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory may further include a memory remotely located relative to the processor, and these remote memories can be connected to the computer terminal A via a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0176] The processor can call the information and application programs stored in the memory through the transmission device to perform the following steps: monitor the authentication password set on the host, wherein the authentication password is used to provide security protection for the host; determine the security performance index of the authentication password, wherein the security performance index is used to indicate the strength of the security protection provided by the authentication password to the host; if the security performance index of the authentication password is lower than the index threshold, call the bastion host in the cloud environment to modify the authentication password; use the modified authentication password to update the authentication password previously set on the host, and return to continue to perform the step of monitoring the authentication password until the security performance index of the authentication password is higher than or equal to the index threshold.
[0177] Optionally, the processor may also execute the following program code: if the security performance index of the authentication password is lower than the index threshold, based on the communication connection between the host security product and the interface of the bastion host, call the interface of the bastion host to modify the authentication password.
[0178] Optionally, the above-mentioned processor can also execute the program code of the following steps: if the security performance index of the authentication password is lower than the index threshold, search for a bastion host in the cloud environment; establish a communication connection between the host security product and the interface of the found bastion host; use the communication connection to call the interface of the bastion host to modify the authentication password.
[0179] Optionally, the processor may further execute program code of the following steps: if the security performance index of the authentication password is lower than the index threshold, searching for a bastion host in the cloud environment that allows modification of the authentication password set on the host.
[0180] Optionally, the processor may further execute the program code of the following steps: if the server determines that the security performance index of the authentication password is lower than the index threshold, the control server calls the bastion host in the cloud environment to modify the authentication password.
[0181] Optionally, the processor may also execute the program code of the following steps: the control server searches for the authentication password in the authentication password dictionary, wherein the authentication password dictionary includes at least one authentication password, and the security performance index of each authentication password in the at least one authentication password is lower than the index threshold; if the server finds the authentication password in the authentication password dictionary, the control server determines that the security performance index is lower than the index threshold.
[0182] Optionally, the processor may further execute program codes of the following steps: controlling the server to obtain an authentication password from the client; and controlling the server to determine a security performance indicator of the obtained authentication password.
[0183] Optionally, the processor may further execute program code of the following steps: controlling the client to monitor an authentication password set on the host.
[0184] Optionally, the processor may also execute the program code of the following steps: if the security performance index of the authentication password is lower than the index threshold, generate an authentication password setting policy based on the authentication password, wherein the authentication password setting policy is used to represent the rules that the authentication password set on the host needs to meet so that the security performance index of the set authentication password is higher than or equal to the index threshold; and send the authentication password setting policy to the host.
[0185] The processor can call the information and application stored in the memory through the transmission device to perform the following steps: monitoring the call instruction from the host security product, wherein the call instruction is triggered when the security performance index of the authentication password set on the host is lower than the index threshold, and includes the authentication password, the authentication password is used to provide security protection for the host, and the security performance index is used to indicate the strength of the security protection provided by the authentication password to the host; in response to the call instruction, modifying the authentication password; sending the modified authentication password to the host to update the authentication password previously set by the host, and returning to the step of monitoring the call instruction from the host security product until the security performance index of the authentication password is higher than or equal to the index threshold.
[0186] Optionally, the processor may further execute the program code of the following steps: controlling the interface of the bastion host to modify the authentication password in response to a call instruction.
[0187] Optionally, the processor may further execute program code of the following steps: monitoring a call instruction from a server.
[0188] Optionally, the processor may further execute the program code of the following steps: sending the modified authentication password to the client to be monitored as the authentication password set on the host.
[0189] By using the embodiment of the present application, the running data of the application is verified using the corresponding correction strategy in the correction strategy set, and the application is defensively processed based on the risk level determined based on the verification result, thereby improving the operation and maintenance efficiency and preventing unknown stability and security risks of the application, thereby achieving the technical effect of effectively defending against risks of the application and solving the technical problem of being unable to effectively defend against risks of the application.
[0190] It can be understood by those skilled in the art that Figure 10 The structure shown is for illustration only. The computer terminal A may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a PDA, a mobile Internet device (MID for short), a PAD, or other terminal devices. Figure 10 It does not limit the structure of the above-mentioned computer terminal A. For example, the computer terminal A may also include Figure 10 More or fewer components (such as network interfaces, display devices, etc.) shown in, or with Figure 10 Different configurations shown.
[0191] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the hardware related to the terminal device through a program, and the program can be stored in a computer-readable storage medium, which may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0192] Example 6
[0193] The embodiment of the present application further provides a computer-readable storage medium. Optionally, in this embodiment, the computer-readable storage medium can be used to store the program code executed by the host security protection method provided in the first embodiment.
[0194] Optionally, in this embodiment, the computer-readable storage medium may be located in any computer terminal in a computer terminal group in a computer network, or in any mobile terminal in a mobile terminal group.
[0195] Optionally, in this embodiment, the computer-readable storage medium is configured to store program code for performing the following steps: monitoring the authentication password set on the host, wherein the authentication password is used to provide security protection for the host; determining a security performance index of the authentication password, wherein the security performance index is used to indicate the strength of the security protection provided by the authentication password to the host; if the security performance index of the authentication password is lower than the index threshold, calling the bastion host in the cloud environment to modify the authentication password; using the modified authentication password to update the authentication password previously set on the host, and returning to continue the step of monitoring the authentication password until the security performance index of the authentication password is higher than or equal to the index threshold.
[0196] Optionally, the computer-readable storage medium may also execute program codes such as the steps executed in the processor.
[0197] In an embodiment of the present application, the weak password monitoring capability of the host security product is combined to monitor the authentication password. If the security performance index of the authentication password is lower than the index threshold, the authentication password can be automatically modified in conjunction with the bastion host to further improve the complexity and reliability of the authentication password, as well as the security protection capability of the host, thereby achieving the technical effect of effective security protection for the host and solving the technical problem of being unable to effectively defend against risks of the application.
[0198] Example 7
[0199] An embodiment of the present application may provide an electronic device, which may include a memory and a processor.
[0200] Figure 11 1 is a block diagram of an electronic device for a host security protection method according to an embodiment of the present application. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described and / or claimed herein.
[0201] like Figure 11As shown, the device 1100 includes a computing unit 1101, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 1102 or a computer program loaded from a storage unit 1108 into a random access memory (RAM) 1103. Various programs and data required for the operation of the device 1100 can also be stored in the RAM 1103. The computing unit 1101, the ROM 1102, and the RAM 1103 are connected to each other via a bus 1104. An input / output (I / O) interface 1105 is also connected to the bus 1104.
[0202] Various components in device 1100 are connected to I / O interface 1105, including: an input unit 1106, such as a keyboard, mouse, etc.; an output unit 1104, such as various types of displays, speakers, etc.; a storage unit 1108, such as a magnetic disk, optical disk, etc.; and a communication unit 1109, such as a network card, modem, wireless communication transceiver, etc. The communication unit 1109 allows device 1100 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0203] The computing unit 1101 can be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 1101 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 1101 performs the various methods and processes described above, such as the data verification method. For example, in some embodiments, the data verification method can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 1108. In some embodiments, part or all of the computer program can be loaded and / or installed on the device 1100 via the ROM 1102 and / or the communication unit 1109. When the computer program is loaded into the RAM 1103 and executed by the computing unit 1101, one or more steps of the data verification method described above can be performed. Alternatively, in other embodiments, the computing unit 1101 may be configured to execute the data verification method in any other appropriate manner (for example, by means of firmware).
[0204] According to an embodiment of the present application, a host security protection method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0205] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.
[0206] The program code for implementing the methods of the present application can be written in any combination of one or more programming languages. Such program code can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow charts and / or block diagrams are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0207] In the context of the present application, a machine-readable medium can be a tangible medium that can contain or store a program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0208] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or an LCD (liquid crystal display, monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0209] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.
[0210] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact through a communication network. The client-server relationship arises through computer programs running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain.
[0211] It should be noted that the serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0212] In the above embodiments of the present application, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments.
[0213] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only schematic. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of units or modules, which can be electrical or other forms.
[0214] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0215] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0216] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, read-only memory (ROM), random access memory (RAM), mobile hard disk, magnetic disk or optical disk, etc., various media that can store program codes.
[0217] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A host security protection method, characterized in that: Host security products for cloud environments include: Monitoring the authentication password set on the host, wherein the authentication password is used to provide security protection for the host; Determining a security performance index of the authentication password, wherein the security performance index is used to represent the strength of security protection provided by the authentication password to the host; If the security performance index of the authentication password is lower than the index threshold, the bastion host in the cloud environment is called to modify the authentication password.
2. The method according to claim 1, characterized in that The method further comprises: Determining the security performance indicator of the modified authentication password; If the security performance index of the modified authentication password is higher than or equal to the index threshold, the bastion host is called to use the modified authentication password to update the authentication password previously set on the host.
3. The method according to claim 1, characterized in that The method further comprises: Call the bastion host, use the modified authentication password to update the authentication password previously set on the host, and return to continue the step of monitoring the authentication password until the security performance index of the authentication password is higher than or equal to the index threshold.
4. The method according to claim 1, wherein If the security performance index of the authentication password is lower than an index threshold, calling the bastion host in the cloud environment to modify the authentication password includes: If the security performance index of the authentication password is lower than the index threshold, based on the communication connection between the host security product and the interface of the bastion host, the interface of the bastion host is called to modify the authentication password.
5. The method according to claim 4, characterized in that If the security performance index of the authentication password is lower than the index threshold, calling the interface of the bastion host to modify the authentication password based on the communication connection between the host security product and the interface of the bastion host, including: If the security performance index of the authentication password is lower than the index threshold, searching for the bastion host in the cloud environment; Establishing a communication connection between the host security product and the found interface of the bastion host; Utilize the communication connection to call the interface of the bastion host to modify the authentication password.
6. The method according to claim 5, characterized in that If the security performance index of the authentication password is lower than the index threshold, searching for the bastion host in the cloud environment includes: If the security performance index of the authentication password is lower than the index threshold, in the cloud environment, searching for the bastion host that allows the authentication password set on the host to be modified.
7. The method according to claim 1, characterized in that The host security product includes a server, and if the security performance index of the authentication password is lower than an index threshold, calling a bastion host in the cloud environment to modify the authentication password includes: If the server determines that the security performance index of the authentication password is lower than the index threshold, the server is controlled to call the bastion host in the cloud environment to modify the authentication password.
8. The method according to claim 7, characterized in that The method further comprises: Controlling the server to search for the authentication password in an authentication password dictionary, wherein the authentication password dictionary includes at least one authentication password, and a security performance index of each authentication password in the at least one authentication password is lower than the index threshold; If the server finds the authentication password in the authentication password dictionary, the server is controlled to determine that the security performance index is lower than the index threshold.
9. The method according to claim 7, characterized in that The host security product includes a client deployed on the host, and determines the security performance index of the authentication password, including: Controlling the server to obtain the authentication password from the client; The server is controlled to determine a security performance indicator of the obtained authentication password.
10. The method according to claim 9, characterized in that The authentication password set on the monitoring host includes: The client is controlled to monitor the authentication password set on the host.
11. The method according to any one of claims 1 to 10, characterized in that The method further comprises: If the security performance index of the authentication password is lower than the index threshold, generating an authentication password setting policy based on the authentication password, wherein the authentication password setting policy is used to represent rules that the authentication password set on the host needs to satisfy so that the security performance index of the set authentication password is higher than or equal to the index threshold; The authentication password setting policy is sent to the host.
12. A host security protection method, characterized in that: Bastion hosts used in cloud environments include: Monitoring a call instruction from a host security product, wherein the call instruction is triggered when a security performance indicator of an authentication password set on the host falls below an indicator threshold and includes the authentication password, the authentication password is used to provide security protection for the host, and the security performance indicator is used to indicate the strength of the security protection provided by the authentication password to the host; In response to the calling instruction, the authentication password is modified.
13. The method according to claim 12, characterized in that The method further comprises: If the security performance index of the modified authentication password is higher than or equal to the index threshold, the modified authentication password is used to update the authentication password previously set on the host.
14. The method according to claim 12, characterized in that In response to the calling instruction, modifying the authentication password includes: The interface controlling the bastion host modifies the authentication password in response to the calling instruction.
15. The method according to claim 12, characterized in that The host security product includes a server, and monitoring a call instruction from the host security product includes: The calling instruction from the server is monitored.
16. The method according to claim 12, characterized in that The host security product includes a client deployed on the host, and the method further includes: The modified authentication password is sent to the client and monitored as the authentication password set on the host.
17. A host security protection system, characterized in that: Applied in cloud environments, including: A host computer, configured to set an authentication password, wherein the authentication password is used to provide security protection for the host computer; a host security product configured to determine a security performance index of the authentication password, wherein the security performance index represents the strength of security protection provided by the authentication password to the host; and trigger a call instruction if the security performance index of the authentication password is lower than an index threshold, wherein the call instruction includes the authentication password; The bastion host is used to modify the authentication password in response to the calling instruction.
18. An electronic device, characterized in that: include: a memory storing an executable program; A processor, configured to run the program, wherein when the program is run, the method according to any one of claims 1 to 11 or any one of claims 12 to 16 is executed.
19. A computer program product, characterized in that The method comprises computer instructions, which, when executed by a processor, implement the method of any one of claims 1 to 11 or any one of claims 12 to 16.
Citation Information
Cited By
Weak password management method and device for video equipment
CN121125080A