Server cluster security reinforcement system

Through the server cluster security reinforcement system, periodic reinforcement analysis and software hardware evaluation are carried out, targeted management problems of server cluster security reinforcement are solved, strengthening efficiency and accuracy are improved, and the risk of false alarms is reduced.

CN120449162APending Publication Date: 2025-08-08SHANGHAI KUANFAN TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510526106.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-25
Publication Date
2025-08-08

AI Technical Summary

Technical Problem

The existing technology is difficult to manage server clusters with targeted security reinforcement, resulting in a reduced security reinforcement effect, and a risk of false alarms, wasting manpower and resources.

Method used

Through the server cluster security reinforcement system, including the server cluster management center, single evaluation unit, abnormality analysis unit, reinforcement demand unit and reinforcement management unit, periodic reinforcement analysis is carried out, periodic or abnormal reinforcement requests are identified, and targeted reinforcement decisions are made in combination with software and hardware evaluation.

Benefits of technology

It improves the efficiency and reliability of security reinforcement of server clusters, reduces the risk of false alarms, and improves the accuracy and quality of reinforcement.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120449162A_ABST
    Figure CN120449162A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of server cluster management, in particular to a server cluster security reinforcement system, which comprises a server cluster management center, a monomer evaluation unit, an anomaly analysis unit, a reinforcement demand unit, a matching division unit and a reinforcement management unit, according to the method, analysis is preliminarily carried out from the perspective of periodic reinforcement to know whether the server security reinforcement request is a periodic reinforcement request or an abnormal reinforcement request, so that targeted and reasonable management is carried out on the server, and meanwhile, whether the server to be reinforced has the risk of security reinforcement request false alarm is deeply known; when the to-be-reinforced server is subjected to security reinforcement, the security reinforcement demand degree is comprehensively evaluated and analyzed from two points of software and hardware of the to-be-reinforced server, so that the security reinforcement evaluation comprehensiveness of the to-be-reinforced server is improved, and security reinforcement decision matching of different degrees is performed according to feedback characters; the security reinforcement quality of the to-be-reinforced server is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of server cluster management, and in particular to a server cluster security reinforcement system. Background Art

[0002] With the rapid development of technologies such as cloud computing, big data, and artificial intelligence, server clusters have become the core infrastructure for large websites, high-performance computing, and big data processing and analysis. Server clusters consist of multiple servers and use load balancing and distributed storage technologies to handle large traffic and high-concurrency requests. They also provide failover and redundancy mechanisms to ensure service reliability and continuous availability. Each server in a server cluster may have different types of security risks, such as system or application software vulnerabilities, unreasonable permission configuration, and network attacks. When risks arise in a server cluster and security reinforcement measures need to be taken, it is very important to ensure the normal operation of the services in the server cluster. However, in the existing technology, it is difficult to carry out targeted security reinforcement management for each server from a single perspective, which leads to a decrease in the security reinforcement effect of the server. It is also difficult to conduct in-depth information validity analysis on the server that generates the security reinforcement request, which leads to the risk of false positives, resulting in a waste of manpower and resources, and is not conducive to targeted management of the server. In view of the above technical defects, a solution is now proposed. Summary of the Invention

[0003] The purpose of the present invention is to provide a server cluster security reinforcement system to solve the technical defects mentioned above. The present invention initially analyzes from the perspective of periodic reinforcement to understand whether the server security reinforcement request is a periodic reinforcement request or an abnormal reinforcement request, so as to carry out targeted and rational management of the server, and at the same time deeply understand whether there is a risk of false alarm of security reinforcement request for the server to be reinforced, and then carry out targeted verification and management of the server to be reinforced. When performing security reinforcement on the server to be reinforced, a comprehensive evaluation and analysis of the degree of security reinforcement requirements is carried out from the software and hardware points of the server to be reinforced to improve the comprehensiveness of the security reinforcement evaluation of the server to be reinforced, and at the same time, security reinforcement management is carried out in combination with the reinforcement risk, that is, according to the feedback text, different degrees of security reinforcement decision matching is carried out on the server to be reinforced, so as to carry out rational security reinforcement decision matching according to the risk situation of the server to be reinforced, so as to improve the security reinforcement reliability and quality of the server to be reinforced.

[0004] The object of the present invention can be achieved by the following technical solutions: A server cluster security reinforcement system includes a server cluster management center, a single unit evaluation unit, an anomaly analysis unit, a reinforcement requirement unit, a matching and division unit, and a reinforcement management unit; The server cluster management center is used to retrieve the reinforcement information of each server and send the reinforcement information to the single evaluation unit for single-point security reinforcement evaluation analysis to obtain regular servers and servers to be reinforced, and to perform discrimination processing on the reinforcement evaluation values of the servers to be reinforced to obtain regular reinforcement signals or abnormal reinforcement signals; When an abnormal reinforcement signal is generated, the abnormal analysis unit is used to perform false alarm risk assessment feedback analysis on the collected security tool version information of the server to be reinforced to obtain a normal signal or a pseudo abnormal signal; When a conventional reinforcement signal is generated, the reinforcement requirement unit is used to obtain and analyze the reinforcement requirement coefficient of the collected reinforcement requirement information of the server to be reinforced, process the obtained software reinforcement value and hardware reinforcement value to obtain the reinforcement requirement coefficient, and the matching and division unit is used to perform a quantitative matching analysis of the reinforcement decision on the collected reinforcement risk information of the server to be reinforced, compare and analyze the obtained reinforcement evaluation index, and obtain a general reinforcement signal or an advanced reinforcement signal.

[0005] Preferably, the single point security reinforcement evaluation and analysis process is as follows: The running time period of the server cluster is collected, and the running time period of the server cluster is set as the time threshold, each server in the server cluster is set as a node server, and the reinforcement information of each node server within the time threshold is obtained. The reinforcement information represents the reinforcement request instruction code, and the reinforcement information of the node server is judged and processed. If the reinforcement information of the node server is generated, a reinforcement request instruction is generated, and the node server corresponding to the reinforcement request instruction is set as the server to be reinforced. If the reinforcement information of the node server is not generated, a regular instruction is generated, and the node server corresponding to the regular instruction is set as a regular server.

[0006] Preferably, the set reinforcement interval duration of the server to be reinforced within the time threshold is obtained, and at the same time, the duration between the end time of the most recent security reinforcement and the current time of the server to be reinforced within the time threshold is obtained, and the duration between the end time of the most recent security reinforcement and the current time is set as the reinforcement maintenance duration, and the value obtained by subtracting the reinforcement maintenance duration from the set reinforcement interval duration is set as the reinforcement evaluation value, and the reinforcement evaluation value is judged and processed to obtain a normal reinforcement signal or an abnormal reinforcement signal.

[0007] Preferably, the false alarm risk assessment feedback analysis process is as follows: obtain the version information of the security tool in the server to be reinforced within the time threshold, the version information of the security tool includes the version code and the version risk value, extract the characters of the version code, and set the string composed of the extracted characters of the version code as the version information string. At the same time, obtain the latest version code of the security tool, set the string composed of the extracted characters of the latest version code as the latest version string, compare and analyze the version information string with the latest version string, and obtain a feedback instruction or the latest version signal.

[0008] Preferably, when generating a feedback instruction, the version risk value is compared and analyzed with a preset version risk value threshold to obtain a normal signal or a pseudo-abnormal signal; The version risk value represents the product of the total number of security vulnerabilities found in the current security tool of the server to be hardened and the normalized response time for fixing the security vulnerabilities. The vulnerability repair response time represents the time between the time the vulnerability is generated and the time the vulnerability is fixed.

[0009] Preferably, the reinforcement requirement coefficient acquisition analysis process is as follows: Obtain reinforcement requirement information of the server to be reinforced within a time threshold, the reinforcement requirement information including software reinforcement value and hardware reinforcement value, compare and analyze the software reinforcement value and hardware reinforcement value with the preset software reinforcement value threshold and the preset hardware reinforcement value threshold respectively, obtain the number of software reinforcement values and hardware reinforcement values that are greater than or equal to the corresponding preset software reinforcement value threshold and the preset hardware reinforcement value threshold, and set the number of software reinforcement values and hardware reinforcement values that are greater than or equal to the corresponding preset software reinforcement value threshold and the preset hardware reinforcement value threshold as the reinforcement requirement coefficient.

[0010] Preferably, the software reinforcement value represents the product obtained by multiplying the network intrusion protection value of the server to be reinforced and its own environment evaluation value after data normalization processing. The network intrusion protection value represents the total number of times the network of the server to be reinforced has been attacked or invaded, and the own environment evaluation value represents the duration of time the network load value exceeds the preset network load value threshold; the hardware reinforcement value represents the product obtained by multiplying the number of corresponding values of the environmental data of the server to be reinforced that exceed the preset threshold and the performance test value of the server to be reinforced after data normalization processing. The performance test value represents the part of the hardware failure rate of the server to be reinforced that exceeds the preset threshold.

[0011] Preferably, the reinforcement decision quantitative matching analysis process is as follows: obtaining reinforcement risk information of the server to be reinforced within a time threshold, the reinforcement risk information representing the asset risk level, multiplying the reinforcement requirement coefficient by the value corresponding to the asset risk level to obtain a value as the reinforcement evaluation index, comparing and analyzing the reinforcement evaluation index with a preset reinforcement evaluation index threshold to obtain a general reinforcement signal or an advanced reinforcement signal; The analysis process of the asset risk level is as follows: obtain the total number of unauthorized accesses to the server to be reinforced within the time threshold, and at the same time obtain the total number of times the vulnerabilities of the server to be reinforced are exploited, and obtain the number of missing vulnerability self-repair patches for the server to be reinforced, and multiply the corresponding values of the total number of unauthorized accesses, the total number of times the vulnerabilities are exploited, and the number of missing vulnerability self-repair patches for the server to be reinforced, and set the product of the total number of unauthorized accesses, the total number of times the vulnerabilities are exploited, and the number of missing vulnerability self-repair patches as the asset risk level.

[0012] The beneficial effects of the present invention are as follows: The present invention initially analyzes from the perspective of periodic reinforcement to understand whether the server security reinforcement request is a periodic reinforcement request or an abnormal reinforcement request, so as to carry out targeted and rational management of the server to improve the security reinforcement efficiency and reliability of the server. At the same time, it deeply understands whether there is a risk of false positives in security reinforcement requests for the server to be reinforced, and then conducts targeted verification and management of the server to be reinforced to improve the security reinforcement efficiency and reinforcement accuracy of the server to be reinforced. When performing security reinforcement on a server to be reinforced, the present invention conducts a comprehensive assessment and analysis of the security reinforcement demand degree from both the software and hardware points of the server to be reinforced, so as to improve the comprehensiveness of the security reinforcement assessment of the server to be reinforced, and at the same time performs security reinforcement management in combination with the reinforcement risk, that is, according to the feedback text, security reinforcement decision matching is performed on the server to be reinforced to different degrees, so as to perform rational security reinforcement decision matching according to the risk situation of the server to be reinforced, so as to improve the reliability and quality of the security reinforcement of the server to be reinforced. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] The present invention will be further described below with reference to the accompanying drawings; Figure 1 It is a flow chart of the system of the present invention; Figure 2 It is a reference diagram for local analysis of the present invention. DETAILED DESCRIPTION

[0014] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0015] References to "embodiments" herein mean that a particular feature, structure, or characteristic described in connection with the embodiment may be included in at least one embodiment of the present invention. The appearance of the phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute a separate or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments; Example

[0016] See also Figures 1 to 2 As shown, the present invention is a server cluster security reinforcement system, including a server cluster management center, a single unit evaluation unit, an anomaly analysis unit, a reinforcement requirement unit, a matching and division unit, and a reinforcement management unit. The server cluster management center is connected to the single unit evaluation unit and the reinforcement requirement unit in a two-way communication manner, the single unit evaluation unit is connected to the anomaly analysis unit and the reinforcement management unit in a one-way communication manner, the anomaly analysis unit is connected to the reinforcement management unit in a one-way communication manner, the server cluster management center is connected to the matching and division unit in a one-way communication manner, and the matching and division unit is connected to the reinforcement management unit in a one-way communication manner; The server cluster management center is used to retrieve the reinforcement information of each server and send the reinforcement information to the single-point security reinforcement assessment and analysis unit to preliminarily classify the servers from the perspective of security reinforcement requests. At the same time, it is analyzed from the perspective of periodic reinforcement to understand whether the server security reinforcement request is a periodic reinforcement request or an abnormal reinforcement request, so as to carry out targeted and rational management of the server to improve the security reinforcement efficiency and reliability of the server. The specific single-point security reinforcement assessment and analysis process is as follows: The running time period of the server cluster is collected, and the running time period of the server cluster is set as a time threshold, each server in the server cluster is set as a node server, and the reinforcement information of each node server within the time threshold is obtained, the reinforcement information represents a reinforcement request instruction code, and the reinforcement information of the node server is judged and processed. If the reinforcement information of the node server is generated, a reinforcement request instruction is generated, and the node server corresponding to the reinforcement request instruction is set as the server to be reinforced. If the reinforcement information of the node server is not generated, a regular instruction is generated, and the node server corresponding to the regular instruction is set as a regular server; Get the set reinforcement interval of the server to be reinforced within the time threshold, and at the same time get the time between the last security reinforcement end time and the current time of the server to be reinforced within the time threshold, and set the time between the last security reinforcement end time and the current time as the reinforcement maintenance time, and set the value obtained by subtracting the reinforcement maintenance time from the set reinforcement interval time as the reinforcement evaluation value, and perform judgment processing on the reinforcement evaluation value: If the reinforcement evaluation value is less than or equal to the preset reinforcement evaluation value threshold, a regular reinforcement signal is generated; If the reinforcement evaluation value is greater than the preset reinforcement evaluation value threshold, an abnormal reinforcement signal is generated. The reinforcement management unit is used to respond to the regular reinforcement signal or the abnormal reinforcement signal, and immediately display the preset warning text corresponding to the regular reinforcement signal or the abnormal reinforcement signal, that is, the preset warning text corresponding to the regular reinforcement signal is "regular security reinforcement", and the preset warning text corresponding to the abnormal reinforcement signal is "abnormal reinforcement behavior". Through the text display, it is intuitively understood whether there is abnormal security reinforcement request behavior on the current server to be reinforced, so as to carry out targeted and rational management of the server to be reinforced, so as to improve the security reinforcement efficiency and reliability of the server to be reinforced; When an abnormal reinforcement signal is generated, the abnormal analysis unit is used to perform false positive risk assessment feedback analysis on the collected security tool version information of the server to be reinforced. Based on the feedback text, it can intuitively understand whether there is a risk of false positive security reinforcement request for the server to be reinforced. Then, the server to be reinforced is verified and managed in a targeted manner to improve the security reinforcement efficiency and reinforcement accuracy of the server to be reinforced. The specific false positive risk assessment feedback analysis process is as follows: Obtain the version information of the security tool in the server to be reinforced within the time threshold. The version information of the security tool includes a version code and a version risk value. Extract the characters of the version code and set the string composed of the extracted characters of the version code as the version information string. At the same time, obtain the latest version code of the security tool and set the string composed of the extracted characters of the latest version code as the latest version string. That is, by analyzing the security tool version information, determine whether the version information of the security tool is outdated. Among them, security tools include but are not limited to: vulnerability scanners, IDS; The version risk value represents the product of the total number of security vulnerabilities found in the current security tool of the server to be hardened and the normalized response time for vulnerability repair. The vulnerability repair response time represents the time between the time the vulnerability is generated and the time it is repaired. It should be noted that the version risk value is an influencing parameter that reflects the false positive risk of the server to be hardened. The larger the version risk value, the greater the risk of false positives due to vulnerabilities in the current security tool. Compare and analyze the version information string with the latest version string: If the version information string is identical to the latest version string, a feedback instruction is generated. If the version information string does not match the latest version string in a one-to-one comparison, a latest version signal is generated. The hardening management unit is used to respond to the latest version signal and immediately display the preset warning text corresponding to the latest version signal, that is, "Version Normal", so as to analyze from the perspective of the security tool version being outdated and determine whether there is a problem of the security tool version being outdated, which indirectly indicates the risk of false alarm of security hardening; When generating feedback instructions, the version risk value is compared and analyzed with the preset version risk value threshold. If the version risk value is less than the preset version risk value threshold, a normal signal is generated; If the version risk value is greater than or equal to the preset version risk value threshold, a pseudo-exception signal is generated. The reinforcement management unit is used to respond to the normal signal or the pseudo-exception signal, and immediately display the preset warning text corresponding to the normal signal or the pseudo-exception signal. That is, the preset warning text corresponding to the normal signal is "Reinforcement request normal", and the preset warning text corresponding to the pseudo-exception signal is "Reinforcement request abnormal". That is, based on the feedback text, it is intuitively understood whether there is a risk of false alarm of security reinforcement request for the server to be reinforced, and then the server to be reinforced is verified and managed in a targeted manner to improve the security reinforcement efficiency and reinforcement accuracy of the server to be reinforced. Example

[0017] When a conventional reinforcement signal is generated, the reinforcement requirement unit is used to obtain and analyze the reinforcement requirement coefficient of the collected reinforcement requirement information of the server to be reinforced. That is, it comprehensively evaluates and analyzes the security reinforcement requirement degree from both the software and hardware points of view of the server to be reinforced. The specific reinforcement requirement coefficient acquisition and analysis process is as follows: Obtain reinforcement requirement information of the server to be reinforced within a time threshold, the reinforcement requirement information including a software reinforcement value and a hardware reinforcement value, compare and analyze the software reinforcement value and the hardware reinforcement value with a preset software reinforcement value threshold and a preset hardware reinforcement value threshold respectively, obtain the number of the software reinforcement value and the hardware reinforcement value that are greater than or equal to the corresponding preset software reinforcement value threshold and the preset hardware reinforcement value threshold, and set the number of the software reinforcement value and the hardware reinforcement value that are greater than or equal to the corresponding preset software reinforcement value threshold and the preset hardware reinforcement value threshold as the reinforcement requirement coefficient. It should be noted that the larger the value of the reinforcement requirement coefficient, the higher the security reinforcement degree of the server to be reinforced; Among them, the number of software hardening values and hardware hardening values that are greater than or equal to the corresponding preset software hardening value threshold and preset hardware hardening value threshold, that is, if the software hardening value is less than the preset software hardening value threshold and the hardware hardening value is less than the preset hardware hardening value threshold, it is equal to zero; if the software hardening value is greater than or equal to the preset software hardening value threshold, it is equal to 1; if the hardware hardening value is greater than or equal to the preset hardware hardening value threshold, it is equal to 1; if the software hardening value is greater than or equal to the preset software hardening value threshold and the hardware hardening value is greater than or equal to the preset hardware hardening value threshold, it is equal to 2; The software hardening value represents the product of the network intrusion protection value of the server to be hardened and its own environment assessment value after data normalization. The network intrusion protection value represents the total number of times the network of the server to be hardened has been attacked or intruded. The own environment assessment value represents the duration of time the network load value exceeds the preset network load value threshold. It should be noted that the larger the software hardening value, the greater the degree of hardening required. The hardware hardening value represents the product of the number of environmental data values of the server to be hardened exceeding the preset threshold and the normalized performance test value of the server to be hardened. Environmental data includes temperature and humidity values, etc. The performance test value represents the portion of the hardware failure rate of the server to be hardened exceeding the preset threshold. It should be noted that the hardware hardening value is an influencing parameter that reflects the security hardening requirements of the server to be hardened. When a conventional reinforcement signal is generated, the matching and division unit is used to perform a reinforcement decision quantitative matching analysis on the reinforcement risk information collected for the server to be reinforced. Based on the feedback text, different degrees of security reinforcement decision matching are performed on the server to be reinforced, so as to rationalize the security reinforcement decision matching based on the risk situation of the server to be reinforced, thereby improving the reliability and quality of the security reinforcement of the server to be reinforced. The specific reinforcement decision quantitative matching analysis process is as follows: Reinforcement risk information of the server to be reinforced within a time threshold is obtained. The reinforcement risk information represents the asset risk level. The asset risk level analysis process is as follows: the total number of unauthorized accesses to the server to be reinforced within the time threshold is obtained, and the total number of times the vulnerability of the server to be reinforced is exploited, as well as the number of missing self-repair patches for the vulnerability of the server to be reinforced are obtained. The corresponding values of the total number of unauthorized accesses, the total number of times the vulnerability is exploited, and the number of missing self-repair patches for the vulnerability of the server to be reinforced are multiplied together. The product of the total number of unauthorized accesses, the total number of times the vulnerability is exploited, and the number of missing self-repair patches for the vulnerability are set as the asset risk level. The value obtained by multiplying the reinforcement demand coefficient by the value corresponding to the asset risk level is set as the reinforcement assessment index, and the reinforcement assessment index is compared and analyzed with the preset reinforcement assessment index threshold: If the reinforcement evaluation index is less than the preset reinforcement evaluation index threshold, a general reinforcement signal is generated; If the reinforcement evaluation index is greater than or equal to the preset reinforcement evaluation index threshold, an advanced reinforcement signal is generated. The reinforcement management unit is used to respond to the general reinforcement signal or the advanced reinforcement signal and immediately match the security reinforcement decision corresponding to the general reinforcement signal or the advanced reinforcement signal. That is, based on the feedback text, different degrees of security reinforcement decision matching are performed on the server to be reinforced, so as to rationalize the security reinforcement decision matching according to the risk situation of the server to be reinforced, thereby improving the reliability and quality of the security reinforcement of the server to be reinforced; To sum up, the present invention initially analyzes from the perspective of periodic reinforcement to understand whether the server security reinforcement request is a periodic reinforcement request or an abnormal reinforcement request, so as to carry out targeted and rational management of the server to improve the security reinforcement efficiency and reliability of the server, and at the same time, deeply understand whether there is a risk of false alarm of security reinforcement request for the server to be reinforced, and then carry out targeted verification and management of the server to be reinforced to improve the security reinforcement efficiency and reinforcement accuracy of the server to be reinforced. When performing security reinforcement on the server to be reinforced, a comprehensive evaluation and analysis of the degree of security reinforcement requirements is carried out from the two points of view of software and hardware of the server to be reinforced to improve the comprehensiveness of the security reinforcement evaluation of the server to be reinforced. At the same time, security reinforcement management is carried out in combination with reinforcement risks, that is, security reinforcement decision matching of different degrees is carried out on the server to be reinforced based on feedback text, so as to make rational security reinforcement decision matching based on the risk situation of the server to be reinforced, so as to improve the security reinforcement reliability and quality of the server to be reinforced.

[0018] The threshold is set to facilitate comparison. The size of the threshold depends on the amount of sample data and the number of bases set by technicians in this field for each set of sample data; as long as it does not affect the proportional relationship between the parameter and the quantized value.

[0019] The above description is only a preferred specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field, within the technical scope disclosed by the present invention, who makes equivalent replacements or changes based on the technical solution and inventive concept of the present invention, should be covered by the scope of protection of the present invention.

Claims

1. A server cluster security reinforcement system, characterized in that: It includes server cluster management center, single unit evaluation unit, abnormality analysis unit, reinforcement requirement unit, matching division unit and reinforcement management unit; The server cluster management center is used to retrieve the reinforcement information of each server and send the reinforcement information to the single evaluation unit for single-point security reinforcement evaluation analysis to obtain regular servers and servers to be reinforced, and to perform discrimination processing on the reinforcement evaluation values of the servers to be reinforced to obtain regular reinforcement signals or abnormal reinforcement signals; When an abnormal reinforcement signal is generated, the abnormal analysis unit is used to perform false alarm risk assessment feedback analysis on the collected security tool version information of the server to be reinforced to obtain a normal signal or a pseudo abnormal signal; When a conventional reinforcement signal is generated, the reinforcement requirement unit is used to obtain and analyze the reinforcement requirement coefficient of the collected reinforcement requirement information of the server to be reinforced, process the obtained software reinforcement value and hardware reinforcement value to obtain the reinforcement requirement coefficient, and the matching and division unit is used to perform a quantitative matching analysis of the reinforcement decision on the collected reinforcement risk information of the server to be reinforced, compare and analyze the obtained reinforcement evaluation index, and obtain a general reinforcement signal or an advanced reinforcement signal.

2. A server cluster security reinforcement system according to claim 1, characterized in that: The single point security reinforcement evaluation and analysis process is as follows: The running time period of the server cluster is collected, and the running time period of the server cluster is set as the time threshold, each server in the server cluster is set as a node server, and the reinforcement information of each node server within the time threshold is obtained. The reinforcement information represents the reinforcement request instruction code, and the reinforcement information of the node server is judged and processed. If the reinforcement information of the node server is generated, a reinforcement request instruction is generated, and the node server corresponding to the reinforcement request instruction is set as the server to be reinforced. If the reinforcement information of the node server is not generated, a regular instruction is generated, and the node server corresponding to the regular instruction is set as a regular server.

3. A server cluster security reinforcement system according to claim 2, characterized in that: Obtain the set reinforcement interval duration of the server to be reinforced within the time threshold, and at the same time obtain the duration between the end time of the most recent security reinforcement and the current time of the server to be reinforced within the time threshold, and set the duration between the end time of the most recent security reinforcement and the current time as the reinforcement maintenance duration, and set the value obtained by subtracting the reinforcement maintenance duration from the set reinforcement interval duration as the reinforcement evaluation value, and perform discrimination processing on the reinforcement evaluation value to obtain a normal reinforcement signal or an abnormal reinforcement signal.

4. A server cluster security reinforcement system according to claim 2, characterized in that: The false alarm risk assessment feedback analysis process is as follows: obtain the version information of the security tool in the server to be reinforced within the time threshold, the version information of the security tool includes the version code and the version risk value, extract the characters of the version code, and set the string composed of the extracted characters of the version code as the version information string. At the same time, obtain the latest version code of the security tool, set the string composed of the extracted characters of the latest version code as the latest version string, compare and analyze the version information string with the latest version string, and obtain feedback instructions or the latest version signal.

5. A server cluster security reinforcement system according to claim 4, characterized in that: When a feedback instruction is generated, the version risk value is compared and analyzed with the preset version risk value threshold to obtain a normal signal or a pseudo-abnormal signal; The version risk value represents the product of the total number of security vulnerabilities found in the current security tool of the server to be hardened and the normalized response time for fixing the security vulnerabilities. The vulnerability repair response time represents the time between the time the vulnerability is generated and the time the vulnerability is fixed.

6. A server cluster security reinforcement system according to claim 2, characterized in that: The reinforcement requirement coefficient acquisition analysis process is as follows: Obtain reinforcement requirement information of the server to be reinforced within a time threshold, the reinforcement requirement information including software reinforcement value and hardware reinforcement value, compare and analyze the software reinforcement value and hardware reinforcement value with the preset software reinforcement value threshold and the preset hardware reinforcement value threshold respectively, obtain the number of software reinforcement values and hardware reinforcement values that are greater than or equal to the corresponding preset software reinforcement value threshold and the preset hardware reinforcement value threshold, and set the number of software reinforcement values and hardware reinforcement values that are greater than or equal to the corresponding preset software reinforcement value threshold and the preset hardware reinforcement value threshold as the reinforcement requirement coefficient.

7. A server cluster security reinforcement system according to claim 6, characterized in that: The software reinforcement value represents the product of the network intrusion protection value of the server to be reinforced and its own environment evaluation value after data normalization processing. The network intrusion protection value represents the total number of times the network of the server to be reinforced has been attacked or invaded. The own environment evaluation value represents the duration of time that the network load value exceeds the preset network load value threshold. The hardware reinforcement value represents the product of the number of times the corresponding values of the environment data of the server to be reinforced exceed the preset threshold and the performance test value of the server to be reinforced after data normalization processing. The performance test value represents the part of the hardware failure rate of the server to be reinforced that exceeds the preset threshold.

8. A server cluster security reinforcement system according to claim 2, characterized in that: The reinforcement decision quantitative matching analysis process is as follows: obtaining reinforcement risk information of the server to be reinforced within a time threshold, the reinforcement risk information representing the asset risk level, multiplying the reinforcement requirement coefficient by the value corresponding to the asset risk level to obtain a value as the reinforcement evaluation index, comparing the reinforcement evaluation index with a preset reinforcement evaluation index threshold, and obtaining a general reinforcement signal or an advanced reinforcement signal; The analysis process of the asset risk level is as follows: obtain the total number of unauthorized accesses to the server to be reinforced within the time threshold, and at the same time obtain the total number of times the vulnerabilities of the server to be reinforced are exploited, and obtain the number of missing vulnerability self-repair patches for the server to be reinforced, and multiply the corresponding values of the total number of unauthorized accesses, the total number of times the vulnerabilities are exploited, and the number of missing vulnerability self-repair patches for the server to be reinforced, and set the product of the total number of unauthorized accesses, the total number of times the vulnerabilities are exploited, and the number of missing vulnerability self-repair patches as the asset risk level.