BMC security assessment method and device, equipment, storage medium and program product

By combining static rules and machine learning models, a multi-dimensional dynamic risk assessment of BMC operations is performed, solving the problem that traditional BMC security mechanisms are unable to identify zero-day vulnerabilities and lateral penetration behaviors disguised as legitimate credentials, and achieving effective detection and response to unknown threats.

CN120744940APending Publication Date: 2025-10-03SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202511194740.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2025-10-03

AI Technical Summary

Technical Problem

Traditional BMC security mechanisms are unable to identify zero-day vulnerability attacks and lateral penetration behaviors disguised as legitimate credentials, which allow unauthorized attackers to obtain super management privileges and lack the ability to detect unknown threats.

Method used

By obtaining the behavioral characteristics of user operations, combining static rules and machine learning models, and calculating comprehensive risk weights, we can implement multi-dimensional dynamic risk assessment of BMC operations, including quantitative assessment of user behavioral characteristics, operating environment, and user profiles.

Benefits of technology

It improves the ability to detect unknown threats, solves the detection blind spots and response lag problems of traditional BMC security mechanisms, and enhances security protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120744940A_ABST
    Figure CN120744940A_ABST
Patent Text Reader

Abstract

The invention discloses a BMC security assessment method and device, equipment, a storage medium and a program product. Relates to the technical field of baseboard management controllers. The method comprises the steps that operation of a user on a baseboard management controller (BMC) is obtained, user behavior characteristics corresponding to the operation are obtained, and the user behavior characteristics comprise operation types, operation parameters, operation environments and user portraits; determining a first risk weight of the operation based on the user behavior characteristics and a preset static rule; determining a second risk weight of the operation based on the user behavior characteristics and a machine learning model; determining a third risk weight corresponding to the operation environment and a fourth risk weight corresponding to the user portrait; calculating a comprehensive risk weight of the operation on the BMC based on the first risk weight, the second risk weight, the third risk weight and the fourth risk weight; and based on the comprehensive risk weight, determining security risk assessment information of the operation on the BMC.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of baseboard management controllers, and in particular to a BMC security assessment method, apparatus, device, storage medium, and program product. Background Art

[0002] Against the backdrop of accelerated digital transformation, the baseboard management controller (BMC), as a core component of server hardware management, has a security directly related to the reliability of data centers, cloud computing, and edge computing infrastructure.

[0003] Traditional BMC security mechanisms rely primarily on access control lists (ACLs) or signature-based malicious command detection. However, these security mechanisms only protect against known threats and are unable to identify zero-day exploits and lateral movement attempts disguised as legitimate credentials, which could allow unauthorized attackers to gain super administrator (root) privileges. Summary of the Invention

[0004] In view of this, embodiments of the present application provide a BMC security assessment method, apparatus, device, storage medium, and program product.

[0005] According to the first aspect of the present application, an embodiment of the present application provides a BMC security assessment method, including: Obtaining user operations on a baseboard management controller (BMC) and user behavior characteristics corresponding to the operations, wherein the user behavior characteristics include operation type, operation parameters, operation environment, and user profile; the operations include at least one of BMC command line operations, web interface click operations, intelligent platform management interface call operations, and application programming interface call operations; Determine the first risk weight of the operation based on user behavior characteristics and preset static rules; Determine the second risk weight of the operation based on user behavior characteristics and machine learning models; Determine the third risk weight corresponding to the operating environment and the fourth risk weight corresponding to the user profile; Calculate the comprehensive risk weight of the operation to BMC based on the first risk weight, second risk weight, third risk weight and fourth risk weight; Based on the comprehensive risk weight, determine the security risk assessment information of the operation to the BMC.

[0006] Furthermore, this application also proposes to determine the second risk weight of the operation based on user behavior characteristics and machine learning models, including: Convert user behavior features into corresponding numerical vectors; The input vector is obtained by concatenating the numerical vector with multiple historical numerical vectors corresponding to the user's multiple historical operations; the user's multiple historical operations are the user's multiple operations on the BMC before the operation; The input vector is processed using a machine learning model to obtain the second risk weight of the operation.

[0007] Furthermore, the present application also proposes to concatenate the numerical vector with multiple historical numerical vectors corresponding to multiple historical operations of the user to obtain an input vector, including: Obtain input dimension information corresponding to the input vector; the input dimension information includes the amount of data input each time, the total number of operations processed each time, and the length of the numerical vector of each operation; Based on the total number of operations, multiple historical numerical vectors corresponding to the user's multiple historical operations are obtained; Based on the amount of data input each time and the length of the numerical vector of each operation, the numerical vector and the historical numerical vector are spliced ​​in the order of operation time to obtain the input vector.

[0008] Furthermore, the present application also proposes to determine the first risk weight of the operation based on user behavior characteristics and preset static rules, including: Match the user behavior characteristics with each rule in the static rules to obtain a matching result; each rule in the static rules includes specific behavior characteristics and corresponding risk weights; Based on the matching results of each rule, the first risk weight of the operation is determined.

[0009] Furthermore, the present application also proposes determining a first risk weight of an operation based on the matching result of each rule, including: The risk weights corresponding to the rules whose matching results are matched are summed to obtain the first risk weight of the operation.

[0010] Furthermore, this application also proposes to determine the third risk weight corresponding to the operating environment, including: Based on the operating environment and the correspondence between the operating environment and the risk weight, determine the third risk weight corresponding to the operating environment.

[0011] Furthermore, this application also proposes to determine the fourth risk weight corresponding to the user profile, including: Based on the user portrait and the correspondence between the user portrait and the risk weight, the fourth risk weight corresponding to the user portrait is determined.

[0012] Furthermore, the present application also proposes to calculate the comprehensive risk weight of the operation on BMC based on the first risk weight, the second risk weight, the third risk weight and the fourth risk weight, including: Determine the risk coefficient corresponding to the first risk weight, the second risk weight, the third risk weight, and the fourth risk weight; Based on the risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight, the first risk weight, the second risk weight, the third risk weight and the fourth risk weight are weighted and summed to obtain the comprehensive risk weight of the operation on BMC.

[0013] Furthermore, the present application also proposes obtaining user feedback information, which includes the number of times normal operations are misjudged within a time period and the total number of false alarms; Based on user feedback information, the risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight are updated.

[0014] Furthermore, the present application also proposes to update the risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight, and the fourth risk weight based on user feedback information, including: The risk factor weighting value is determined based on the number of times normal operations are misjudged within a time period, the total number of false alarms, and the preset learning rate; Based on the risk coefficient weighted value, the risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight are weighted respectively to obtain the updated risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight; among which, the updated risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight meet the normalization condition and the upper and lower limit conditions.

[0015] Furthermore, this application also proposes to determine the security risk assessment information of the operation on the BMC based on the comprehensive risk weight, including: The comprehensive risk weight is compared with the risk values ​​corresponding to multiple preset risk levels to determine the risk level corresponding to the comprehensive risk weight, and obtain the security risk assessment information of the operation on the BMC.

[0016] Furthermore, the present application also proposes responding to operations based on security risk assessment information and preset response strategies.

[0017] Furthermore, this application also proposes responding to operations based on security risk assessment information and preset response strategies, including: If the security risk assessment information indicates that the security risk of the operation to the BMC is at the first risk level, the operation is blocked and two-factor authentication is triggered based on the response policy corresponding to the first risk level; If the security risk assessment information indicates that the security risk of the operation to the BMC is at the second risk level, based on the response strategy corresponding to the second risk level, the operation is delayed and a second confirmation of the user is triggered; If the security risk assessment information indicates that the security risk of the operation to the BMC is at the third risk level, the operation is executed based on the response strategy corresponding to the third risk level; If the security risk assessment information indicates that the security risk of the operation to the BMC is at a fourth risk level, the operation is executed and added to a whitelist based on a response policy corresponding to the fourth risk level.

[0018] According to the second aspect of the present application, an embodiment of the present application provides a BMC security assessment device, including: A behavior collection module is used to obtain user operations on the baseboard management controller (BMC) and obtain user behavior characteristics corresponding to the operations. The user behavior characteristics include operation type, operation parameters, operation environment, and user profile. The operations include at least one of BMC command line operations, World Wide Web interface click operations, intelligent platform management interface call operations, and application programming interface call operations. A first risk assessment module, configured to determine a first risk weight of an operation based on user behavior characteristics and preset static rules; A second risk assessment module is used to determine a second risk weight of the operation based on user behavior characteristics and a machine learning model; The third risk assessment module is used to determine the third risk weight corresponding to the operating environment and the fourth risk weight corresponding to the user profile; a fourth risk assessment module, configured to calculate a comprehensive risk weight of the operation on the BMC based on the first risk weight, the second risk weight, the third risk weight, and the fourth risk weight; The hierarchical policy execution module is used to determine the security risk assessment information of the operation on the BMC based on the comprehensive risk weight.

[0019] Furthermore, the present application also proposes that the second risk assessment module is used to convert the user behavior characteristics into corresponding numerical vectors; The input vector is obtained by concatenating the numerical vector with multiple historical numerical vectors corresponding to the user's multiple historical operations; the user's multiple historical operations are the user's multiple operations on the BMC before the operation; The input vector is processed using a machine learning model to obtain the second risk weight of the operation.

[0020] Furthermore, the present application also proposes that the second risk assessment module is used to obtain input dimension information corresponding to the input vector; the input dimension information includes the amount of data input each time, the total number of operations processed each time, and the length of the numerical vector of each operation; Based on the total number of operations, multiple historical numerical vectors corresponding to the user's multiple historical operations are obtained; Based on the amount of data input each time and the length of the numerical vector of each operation, the numerical vector and the historical numerical vector are spliced ​​in the order of operation time to obtain the input vector.

[0021] Furthermore, the present application also proposes that the hierarchical policy execution module is also used to respond to operations based on security risk assessment information and preset response strategies.

[0022] According to a third aspect of the present application, an embodiment of the present application provides an electronic device, including: At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to cause the at least one processor to perform the BMC security assessment method as described in the first aspect or any embodiment of the first aspect.

[0023] According to a fourth aspect of the present application, an embodiment of the present application provides a computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable a computer to execute the BMC security assessment method as described in the first aspect or any embodiment of the first aspect.

[0024] According to the fifth aspect of the present application, an embodiment of the present application provides a computer program product, including a computer program or instructions. When the computer program or instructions are executed by a processor, the BMC security assessment method of the first aspect or any implementation method of the first aspect is implemented.

[0025] The BMC security assessment method, apparatus, device, storage medium, and program product provided in the embodiments of the present application achieve real-time quantification of the security risks of BMC user operation behaviors by integrating a multi-dimensional dynamic risk assessment mechanism that combines static rule matching, machine learning model reasoning, operating environment analysis, and user profile assessment. This method combines the known threat detection capabilities of static rules with the unknown abnormal sequence recognition capabilities of machine learning models, while introducing environmental factors and user role weights to construct a comprehensive risk assessment system. This overcomes the limitations of traditional static rules, improves the ability to detect unknown threats, and achieves a flexible balance of different risk factors, making risk assessment more comprehensive and accurate. It effectively solves the detection blind spots, response lags, and zero-day attack defense failures caused by the traditional BMC security mechanism's reliance on a single rule, effectively improving the security protection capabilities of BMC.

[0026] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 A flowchart of a BMC security assessment method according to an embodiment of the present application is shown; Figure 2 Schematic diagram of another BMC security assessment method according to an embodiment of the present application; Figure 3 This is a schematic structural diagram of a BMC safety assessment device in an embodiment of the present application; Figure 4 This is a schematic structural diagram of another BMC safety assessment device in an embodiment of the present application; Figure 5 This is a schematic diagram of the hardware structure of an electronic device in an embodiment of the present application. DETAILED DESCRIPTION

[0028] To make the purpose, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.

[0029] This application embodiment proposes a BMC security assessment method, such as Figure 1 Shown, including: S101, obtain the user's operation on the baseboard management controller BMC, and obtain the user behavior characteristics corresponding to the operation, the user behavior characteristics including the operation type, operation parameters, operation environment and user profile; the operation includes at least one of the BMC command line operation, the World Wide Web interface click operation, the intelligent platform management interface call operation, and the application programming interface call operation. S102: Determine a first risk weight of the operation based on user behavior characteristics and preset static rules.

[0030] S103: Determine a second risk weight for the operation based on user behavior characteristics and a machine learning model.

[0031] S104, determining the third risk weight corresponding to the operating environment and the fourth risk weight corresponding to the user profile.

[0032] S105 , calculating a comprehensive risk weight of the operation on the BMC based on the first risk weight, the second risk weight, the third risk weight, and the fourth risk weight.

[0033] S106: Determine security risk assessment information of the operation on the BMC based on the comprehensive risk weight.

[0034] In this embodiment, as shown in Table 1, the operation type may include the command type and the application programming interface (API) call method. The operation environment may include the operation time (e.g., weekday / midnight) and the geographic location of the source network protocol (IP). Operation parameters may include a forced restart flag (force = 1) and the firmware signature verification status. The user profile may include the role permission level (administrator / read-only user) and historical operation frequency. A predefined risk mapping table can be used to encode the operation type, and the operation parameters can be recorded with binary tags. The operation environment can be segmented and encoded using time windows. User profiles can then be constructed based on role weight coefficients to extract multi-dimensional features of user operations.

[0035] Among them, the first risk weight is determined based on user behavior characteristics and preset static rules. Specifically, a rule engine can be used to match user behavior characteristics with known attack patterns in the static rule library, and the risk weight value corresponding to the accumulated matching rules is calculated to quickly identify known threats.

[0036] Table 1 User behavior characteristics

[0037] Among them, the second risk weight is determined based on user behavior characteristics and machine learning models. Specifically, a lightweight LSTM model can be used to convert user behavior characteristics into numerical vectors, and the numerical vectors corresponding to historical operations can be spliced ​​to form a time series input. The abnormal probability is output through model reasoning to solve the problem of insufficient detection ability of unknown attack sequences.

[0038] Among them, the third risk weight is determined based on the operating environment. Specifically, a mapping relationship table between environmental factors and risk weights can be used, and dynamic values ​​can be assigned in combination with the operation time and the geographical location of the source IP to quantify the additive effect of environmental factors on security risks.

[0039] Among them, the fourth risk weight is determined based on the user portrait. Specifically, the user role authority level and historical operation frequency can be used to construct a role weight coefficient table. By querying the preset weight values ​​in the table, a quantitative assessment of the user's inherent risk can be achieved to solve the identity trust problem in the scenario of abuse of legitimate credentials.

[0040] Among them, the comprehensive risk weight is obtained by weighted calculation of the first risk weight, the second risk weight, the third risk weight and the fourth risk weight. Specifically, the normalized weight coefficient can be used to perform linear weighted summation on each risk weight to achieve coordinated evaluation of static rules and dynamic models and improve the accuracy of risk assessment.

[0041] Among them, the security risk assessment information is determined based on the comprehensive risk weight. Specifically, a preset risk level threshold division strategy can be adopted to compare the comprehensive risk weight with the risk value intervals of different levels, and output the corresponding risk level label to provide a decision-making basis for the layered response strategy and solve the problem of delayed response of traditional methods.

[0042] As a preferred embodiment, the solution of this application is specifically implemented as follows: Obtain a firmware update operation initiated by a user on a BMC. Extract the user behavior characteristics of this operation: the operation type is firmware update, the operation parameters include the firmware version number and checksum, the operation environment is non-working hours, and the user profile is a temporary supplier account.

[0043] Matching this user's behavioral characteristics based on a static rule base yields a first risk weight of 0.7. Inputting the operational characteristics into a trained long short-term memory (LSTM) model yields a second risk weight of 0.6. Based on the non-working hours operating environment, a third risk weight of 0.8 is assigned. The user profile for temporary supplier accounts corresponds to a fourth risk weight of 0.6.

[0044] The weighted average method was used to calculate the overall risk weight: 0.3 × 0.7 + 0.3 × 0.6 + 0.2 × 0.8 + 0.2 × 0.6 = 0.67. Based on the pre-defined risk classification, 0.67 corresponds to a medium risk level. The final security risk assessment result for this firmware update operation was determined to be medium risk.

[0045] The embodiment of the present application achieves real-time quantification of security risks of BMC user operation behaviors through a multi-dimensional dynamic risk assessment mechanism that integrates static rule matching, machine learning model reasoning, operating environment analysis, and user portrait evaluation. This method combines the known threat detection capabilities of static rules with the unknown abnormal sequence recognition capabilities of machine learning models, while introducing environmental factors and user role weights to construct a comprehensive risk assessment system. This overcomes the limitations of traditional static rules, improves the detection capabilities of unknown threats, and achieves flexible balancing of different risk factors, making risk assessment more comprehensive and accurate. It effectively solves the detection blind spots, response lags, and zero-day attack defense failures caused by the traditional BMC security mechanism's reliance on a single rule, effectively improving the security protection capabilities of BMC.

[0046] In an optional embodiment, the present application further proposes determining the second risk weight of an operation based on user behavior characteristics and a machine learning model, including: converting the user behavior characteristics into a corresponding numerical vector, concatenating the numerical vector with multiple historical numerical vectors corresponding to the user's multiple historical operations to obtain an input vector, and using a machine learning model to process the input vector to obtain the second risk weight of the operation.

[0047] Among them, numerical vector conversion maps operation types, parameters, environments, and user profiles into multidimensional numerical values ​​through predefined encoding rules; historical numerical vector splicing is based on a time window mechanism, dynamically intercepting historical operation features of a specific number of times before the operation occurs, ensuring that the input vector contains contextual information of continuous operation sequences; the input vector dimension is dynamically adjusted according to the BMC hardware resource constraints, and by setting the total number of operations processed in a single time and the length of the numerical vector for each operation, the model calculation complexity and detection accuracy are balanced.

[0048] Specifically, user behavior features are normalized to form a fixed-length numerical vector. A sliding window algorithm is then used to extract the numerical vectors corresponding to the N previous operations before the current one. These vectors are then concatenated chronologically into a three-dimensional tensor and fed into an LSTM network. The model captures long-term dependencies within the operation sequence through a gating mechanism. The output hidden state is compressed through a fully connected layer to generate a risk probability value, also known as the second risk weight. For example, when processing a firmware update, the model analyzes previous operations for unusual login behavior and, combined with the mandatory flags in the current operation parameters, accurately identifies potential supply chain attacks.

[0049] As a preferred embodiment, the solution of this application is specifically implemented as follows: Convert user behavior features into corresponding numerical vectors. Specifically, for operation type features, a predefined risk mapping table can be used for encoding. For example, mapping the firmware upgrade (firmware_update) operation to 0.9 and the power cycle (power_cycle) operation to 0.7. For operation parameter features, a binary marking method can be used. For example, encoding the forced restart flag force=1 as 1 and force=0 as 0. For contextual environment features, a time window segmentation encoding can be used. For example, encoding the weekday time period as 0.3 and the non-work time period as 0.7. For user profile features, a role weight coefficient can be used. For example, encoding the administrator role as 0.9 and the ordinary user role as 0.5.

[0050] Furthermore, the numerical vector is concatenated with multiple historical numerical vectors corresponding to the user's multiple historical operations to obtain an input vector. Multiple historical operations are the user's multiple BMC operations prior to the current operation. For example, the time window can be set to 10 operations, and the numerical vector of the current operation is concatenated with the numerical vectors of the previous 9 historical operations in chronological order to form an input sequence of length 10.

[0051] Therefore, a machine learning model is used to process the input vector to obtain the second risk weight of the operation. Specifically, an LSTM model can be used to gradually process the input sequence and output a hidden state. The hidden state is then converted into an abnormal probability value between 0 and 1 using a Sigmoid function, which serves as the second risk weight.

[0052] Through the above technical solution, this application achieves the numerical representation and serialization of user behavior characteristics, effectively capturing the timing information and contextual associations of operations. The use of machine learning models for dynamic risk assessment overcomes the limitations of static rules and improves the ability to detect unknown abnormal behaviors. At the same time, this solution fully utilizes historical operation data, enhancing the accuracy and robustness of risk assessment. Furthermore, the use of a lightweight LSTM model reduces the use of BMC hardware resources and ensures real-time performance.

[0053] In an optional embodiment, the present application further proposes splicing the numerical vector with multiple historical numerical vectors corresponding to the user's multiple historical operations to obtain an input vector, including: obtaining input dimension information corresponding to the input vector, the input dimension information including the amount of data input each time, the total number of operations processed each time, and the length of the numerical vector of each operation; based on the total number of operations, obtaining multiple historical numerical vectors corresponding to the user's multiple historical operations; based on the amount of data input each time and the length of the numerical vector of each operation, splicing the numerical vector and the historical numerical vector in the order of operation time to obtain the input vector.

[0054] The input dimension information constrains the data structure of the input vector through predefined parameters. The total number of operations is used to dynamically truncate the length of the historical operation sequence. The combination of data volume and vector length controls the total dimension after splicing. For example, when the input dimension information is set to the amount of data input per time (batch_size) = 32, the total number of operations per processing (seq_len) = 10, and the length of the numerical vector for each operation (input_dim) = 64, the system automatically truncates the 10 most recent historical operation vectors and splices them with the current operation vector to form 32 sets of 64-dimensional input matrices. The vector splicing process uses zero-padding or truncation strategies to handle dimensional differences and ensure that the input vector meets the model processing requirements.

[0055] Specifically, the batch_size parameter in the input dimension information limits the number of data sets processed at a time to avoid memory overload. The seq_len parameter controls the number of historical operations included in the time window. For example, a setting of 10 retains only the most recent 10 operation vectors. The input_dim parameter specifies the encoding length of each operation vector, for example, a 64-dimensional vector containing features such as the operation type, timestamp, and parameter tags. The system extracts a corresponding number of historical numerical vectors from the historical log based on the total number of operations. If the actual number of historical operations is less than seq_len, the default values ​​are used to fill in the gaps. When concatenating data, the current operation vector and the historical vectors are arranged in reverse chronological order, forming a structured input of [historical operation n, historical operation n-1, ..., current operation], enabling the model to analyze behavioral patterns based on time series. For example, if three consecutive login failures are detected before a firmware update operation, the concatenated input vector will include this anomaly sequence, improving the model's ability to identify potential attack chains.

[0056] Through the above technical solution, this application can construct an input vector containing current and historical operation information, providing complete time series features for subsequent machine learning models. This can capture the temporal correlation of user operations and improve the accuracy of anomaly detection. Furthermore, by pre-defining input dimension information, the scale of input data can be flexibly adjusted to adapt to different hardware resource constraints.

[0057] In an optional embodiment, the present application further proposes determining the first risk weight of an operation based on user behavior characteristics and preset static rules, including: matching the user behavior characteristics with each rule in the static rules to obtain a matching result, each rule in the static rules includes specific behavior characteristics and corresponding risk weights, and determining the first risk weight of the operation based on the matching results of each rule. In an optional embodiment, determining the first risk weight of the operation based on the matching result of each rule includes: summing the risk weights corresponding to the rules with matching results to obtain the first risk weight of the operation.

[0058] In this embodiment, user behavior characteristics are matched against the behavior characteristics in static rules one by one using predefined fields. Each rule is assigned a separate risk weight value, and the matching result is the set of successfully matched rules. The risk weight is calculated by summing the rules to ensure that the risk weight after superimposing the rules can reflect the combined effects of multi-dimensional threats. Each rule in the static rule base corresponds to a specific behavior characteristic and its own risk weight.

[0059] In practice, the static rule base contains combinations of operation types, parameter ranges, and environmental conditions. For example, the rule "Non-administrator role performs firmware update operation during non-working hours" is assigned a risk weight of 0.7, and the rule "Perform sensitive configuration modification after three consecutive failed login attempts" is assigned a risk weight of 0.5. When user behavior characteristics trigger multiple rules simultaneously, the weights of each rule are calculated using arithmetic accumulation.

[0060] Specifically, the operation type, parameters, and environmental conditions in the user behavior characteristics are parsed into structured data and compared one by one with the conditions in the static rules. If the operation type is a firmware update and the user role is a temporary supplier account, the rule match is triggered; if the operation time belongs to the preset high-risk period, the environmental risk weight is further added. The risk weight corresponding to each successfully matched rule is accumulated to form the first risk weight. For example, when the operation matches the two rules of "executing high-authorization commands during non-working hours" and "source IP abnormality" at the same time, the first risk weight is 0.6+0.4=1.0. Through summation processing, missed judgments caused by incomplete coverage of a single rule can be avoided, and the expansion of the rule base can support rapid response to new attack modes.

[0061] For example, suppose the static rule base contains the following three rules: Rule 1: If the operation type is firmware update, the risk weight is 0.8; Rule 2: If the operation time is non-working hours, the risk weight is 0.6; Rule 3: If the user role is a temporary account, the risk weight is 0.5; Furthermore, for a specific user operation, its behavioral characteristics are: Operation type: Firmware update; Operating hours: 3:00 AM; User role: temporary account; Therefore, by matching user behavior characteristics with rules one by one, we can get: Rule 1 is matched successfully, corresponding to a risk weight of 0.8; Rule 2 is matched successfully, corresponding to a risk weight of 0.6; Rule 3 is matched successfully, corresponding to a risk weight of 0.5; Finally, add up the risk weights corresponding to the successfully matched rules: 0.8 + 0.6 + 0.5 = 1.9; Therefore, the first risk weight for this operation is 1.9.

[0062] Through the above technical solution, this application can quickly identify known high-risk operation patterns and improve the efficiency and accuracy of BMC security assessments. Because static rules can be continuously optimized based on historical data and expert experience, this method has strong interpretability and adjustability. In addition, by summing the risk weights of multiple matching rules, multiple risk factors of the operation can be comprehensively considered to obtain a more comprehensive risk assessment result. This rule-based rapid matching and risk accumulation mechanism can achieve real-time risk assessment within the limited computing resources of BMC, providing an important basis for subsequent dynamic response strategies.

[0063] In an optional embodiment, the present application further proposes determining a third risk weight corresponding to the operating environment, including: determining the third risk weight corresponding to the operating environment based on the operating environment and the corresponding relationship between the operating environment and the risk weight.

[0064] Specifically, first establish a mapping table between operating environments and risk weights. For example, the operating environment can be divided into categories such as working hours, non-working hours, and holidays, and a corresponding risk weight can be assigned to each environment category. The risk weight for working hours might be set at 0.3, for non-working hours at 0.6, and for holidays at 0.8.

[0065] Furthermore, when a user's BMC operation is detected, the time of the operation is extracted. This information can be used to determine the operating environment category of the operation. For example, if the operation occurs between 9:00 AM and 6:00 PM Monday to Friday, it is considered working hours; if it occurs between 8:00 PM and 8:00 AM the following day, it is considered non-working hours; and if it occurs on a statutory holiday, it is considered a holiday.

[0066] Finally, according to the determined operating environment category, the corresponding risk weight value is searched from the correspondence table to obtain the third risk weight corresponding to the operating environment.

[0067] Through the above technical solution, this application achieves a quantitative assessment of the BMC operating environment, improving the accuracy of risk assessment. This allows for more targeted security management of BMC operations based on the security risk characteristics of different time periods, effectively preventing abnormal operational behavior during unconventional times. Furthermore, this solution is easy to implement and maintain, allowing for flexible adjustment of risk weights for different environments and demonstrating strong adaptability.

[0068] In an optional embodiment, the present application further proposes determining the fourth risk weight corresponding to the user portrait, including: determining the fourth risk weight corresponding to the user portrait based on the user portrait and the correspondence between the user portrait and the risk weight.

[0069] Among them, user portraits are broken down into two quantifiable dimensions: role authority level and historical operation frequency. Role authority level is mapped through a predefined weight coefficient table, and the historical operation frequency is generated by comparing the number of operations within the statistical period with the preset threshold to generate a correction factor. The corresponding relationship is stored in the form of configuration files or database tables, and supports dynamic updates to adapt to changes in organizational structure. The role authority level weight coefficient is divided into three categories according to user type: administrator, read-only user, and supplier temporary account, corresponding to baseline values ​​of 0.8, 0.3, and 0.6 respectively; the historical operation frequency correction factor is calculated based on the ratio of the number of operations in the past 30 days to the baseline value of 100 times. When the actual number exceeds the baseline value, the risk weight is reduced, and vice versa.

[0070] Specifically, when a user operation request is received, the role type in the user portrait is first extracted, and the preset role-weight mapping table is queried to obtain the initial risk value. Then the number of operations performed by the user in the past 30 days is retrieved. If the number of operations is 150 times and the baseline value is 100 times, the correction factor is 100 / 150≈0.67, and the initial risk value is multiplied by the correction factor to obtain the final fourth risk weight. For example, the initial risk value of the supplier's temporary account is 0.6, and the fourth risk weight after correction is 0.6×0.67≈0.4. This weight is input into the comprehensive risk calculation module and weighted summed with other risk weights to ensure that the dynamic changes in user behavior patterns and role permissions can be reflected in the risk assessment results in real time, avoiding misjudgments caused by static weight allocation.

[0071] Through the above technical solution, this application achieves precise risk assessment based on user profiles, avoiding misjudgments caused by applying the same standards to all users. This improves the accuracy and flexibility of BMC security assessments, enabling the system to adopt differentiated security strategies based on different user characteristics, effectively reducing false positives and false negatives. Furthermore, by establishing a dynamic mapping between user profiles and risk weights, the system can adapt to changes in user behavior patterns and continuously optimize security assessment results.

[0072] In an optional embodiment, the present application further proposes to calculate the comprehensive risk weight of the operation to BMC based on the first risk weight, the second risk weight, the third risk weight and the fourth risk weight, including: based on the risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight, weighted summing up the above weights to obtain the comprehensive risk weight of the operation to BMC.

[0073] The risk coefficients corresponding to the first, second, third, and fourth risk weights are α, β, γ, and δ, respectively. The risk coefficients must meet the normalization condition, i.e., α + β + γ + δ ≤ 1.0. The upper and lower limits of the risk coefficients are shown in Table 2.

[0074] Table 2 Weight coefficient table

[0075] As a preferred embodiment, the solution of the present application is specifically implemented as follows: During the risk assessment process of the baseboard management controller, the risk coefficient of each risk weight is pre-set to an initial value. The risk coefficient corresponding to the first risk weight is set to 0.4, the risk coefficient corresponding to the second risk weight is set to 0.3, the risk coefficient corresponding to the third risk weight is set to 0.1, and the risk coefficient corresponding to the fourth risk weight is set to 0.2. The sum of the risk coefficients meets the normalization condition. When a user initiates a firmware update operation, the static rule matching calculation obtains a first risk weight of 0.8, the machine learning model outputs a second risk weight of 0.6, the third risk weight corresponding to the operating environment is 0.5, and the fourth risk weight corresponding to the user profile is 0.3. By multiplying each risk weight by the corresponding risk coefficient and then adding them together, the comprehensive risk weight is calculated to be 0.8×0.4+0.6×0.3+0.5×0.1+0.3×0.2=0.32+0.18+0.05+0.06=0.61.

[0076] Through the above technical solution, this application achieves dynamic weight allocation and comprehensive assessment of different risk sources, effectively solving the problem that the fixed weight mechanism in traditional methods is difficult to adapt to complex attack scenarios. Through normalization processing and weighted fusion mechanisms, it is possible to improve the accuracy of quantitative assessment of multi-dimensional risk characteristics while ensuring computational efficiency, and reduce the risk of business interruption caused by misjudgment of a single detection mechanism. Furthermore, through a configurable coefficient adjustment mechanism, this method provides a flexible extension interface for subsequent model optimization and rule updates.

[0077] In an optional embodiment, the present application further proposes obtaining user feedback information, which includes the number of times normal operations are misjudged within a time period, and the total number of false alarms; based on the user feedback information, the risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight are updated.

[0078] Based on user feedback, the risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight, and the fourth risk weight are updated, including: Based on the number of times normal operations are misjudged within a time period, the total number of false alarms and the preset learning rate, a risk coefficient weighted value is determined; based on the risk coefficient weighted value, the risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight are weighted respectively to obtain updated risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight; wherein, the updated risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight meet the normalization condition and the upper and lower limit conditions.

[0079] The calculation of the weighted risk coefficient depends on the ratio of the number of false positives to the total number of false positives, and the learning rate parameter controls the magnitude of coefficient adjustment. The normalization condition ensures that the sum of the risk coefficients does not exceed a preset threshold, and the upper and lower limits restrict the adjustment range of individual coefficients. For example, the update formula for the rule engine weight α is α_{new} = α_{old} - η×{FP_{rule}} / {FP_{total}}, where α_{new} represents the updated value of α, that is, the updated value of the weight coefficient corresponding to the first risk weight; η ranges from 0.05 to 0.2, as shown in Table 3; α_{old} represents the current value of the weight coefficient corresponding to the first risk weight, that is, the α in the above embodiment; FP_{rule} represents the number of false positives generated by the rule engine, and FP_{total} represents the total number of false positives in the system. The coefficient update process must satisfy α_{new} + β_{new} + γ_{new} + δ_{new} ≤ 1.0, and each coefficient must be within a preset range. β_{new} represents the updated value of β; γ_{new} represents the updated value of γ, and δ_{new} represents the updated value of δ.

[0080] Table 3 Weight coefficient update parameter table

[0081] Specifically, when the rule engine generates a high false positive rate, the ratio of FP_rule to FP_total increases, causing the rule engine's weight coefficient α to decrease proportionally and the machine learning model's weight coefficient β to increase accordingly. For example, if α = 0.5 and β = 0.3 initially, and the rule engine's false positives account for 60% of all false positives within a certain period, and the learning rate is set to 0.1, α is updated to 0.5 - 0.1 × 0.6 = 0.44, and the remaining weight of 0.06 is proportionally distributed among the other coefficients. After the updated coefficients are redistributed, the system reduces its reliance on static rules in subsequent risk assessments and strengthens the decision weight of the machine learning model, thereby reducing the impact of false positives on normal operations.

[0082] As a preferred embodiment, the solution of the present application is specifically implemented as follows: During the dynamic weight adjustment process, user feedback information is collected through the log audit interface, specifically including the number of times normal operations are misjudged within a time period and the total number of false alarms. The number of misjudgments is obtained by comparing the conflict records of the operation execution results and the security assessment results, and the total number of false alarms is obtained by the number of all intercepted operations that are finally confirmed as normal operations within the statistical period. The weighted value of the risk coefficient is calculated based on the preset learning rate and the ratio of the number of misjudgments to the total number of false alarms, where the learning rate is dynamically adjusted according to the BMC hardware resources. After the updated risk coefficient is weighted and calculated, a normalization algorithm is used to ensure that the sum of the coefficients does not exceed 1.0, and at the same time, a threshold limit is used to ensure that each coefficient is within the preset recommended range. For example, when normal operations are misjudged 5 times within a time period, the total number of false alarms is 20 times, and the preset learning rate is 0.1, the risk factor weighted value is calculated as 0.1×(5 / 20)=0.025. At this time, the rule engine weight coefficient is updated from 0.5 to 0.5-0.025=0.475, and the machine learning model weight coefficient is updated from 0.3 to 0.3+0.025=0.325. The remaining weight coefficients are adjusted proportionally and normalized.

[0083] Through the above technical solution, the dynamic weight adjustment mechanism can automatically optimize the weight distribution of the rule engine and machine learning model based on actual misjudgment situations, effectively reducing the probability of normal operations being mistakenly intercepted. By quantifying feedback data and normalizing constraints, this solution ensures that the system maintains the accuracy of risk assessment during continuous operation, while also avoiding the increase in the overall misjudgment rate caused by the failure of a single detection mechanism. Furthermore, the adaptive adjustment capability based on the learning rate enables the system to quickly respond to changes in new attack patterns, reducing manual maintenance costs and improving the real-time performance of defense strategies.

[0084] In an optional embodiment, determining security risk assessment information of an operation on a BMC based on a comprehensive risk weight includes: The comprehensive risk weight is compared with the risk values ​​corresponding to multiple preset risk levels to determine the risk level corresponding to the comprehensive risk weight, and obtain the security risk assessment information of the operation on the BMC.

[0085] In this embodiment, the security risk assessment information is risk level information. As shown in Table 4, multiple risk levels can be predefined, such as high risk, medium risk, low risk, and trusted risk. The relationship between risk value ranges and risk level paperwork can also be predefined. For example, if the risk level is high risk, the risk value range is 0.8-1. When the comprehensive risk weight is calculated, for example, 0.9, the risk level corresponding to the comprehensive risk weight is determined to be high risk.

[0086] Table 4 Hierarchical strategy execution logic table

[0087] In this embodiment, by determining the risk level corresponding to the comprehensive risk weight, the security impact of the operation on the BMC can be more accurately understood, which facilitates subsequent defensive actions.

[0088] In an optional embodiment, the present application also proposes responding to the operation based on security risk assessment information and a preset response strategy.

[0089] In some embodiments, responding to an operation based on security risk assessment information and a preset response strategy includes: If the security risk assessment information indicates that the security risk of the operation to the BMC is at the first risk level, the operation is blocked and two-factor authentication is triggered based on the response policy corresponding to the first risk level; if the security risk assessment information indicates that the security risk of the operation to the BMC is at the second risk level, the operation is delayed and a second confirmation of the user is triggered based on the response policy corresponding to the second risk level; if the security risk assessment information indicates that the security risk of the operation to the BMC is at the third risk level, the operation is executed based on the response policy corresponding to the third risk level; if the security risk assessment information indicates that the security risk of the operation to the BMC is at the fourth risk level, the operation is executed and the operation is added to the whitelist based on the response policy corresponding to the fourth risk level.

[0090] In this embodiment, the first risk level is, for example, a high risk level, the second risk level is, for example, a medium risk level, the third risk level is, for example, a low risk level, and the fourth risk level is, for example, a trust level. Figure 2 As shown in the figure, user behavior data is first collected and user behavior characteristics, also known as behavioral feature data, are extracted. Static rules are then used to examine these characteristics and calculate the risk index R1, also known as the first risk weight. Based on these characteristics, a machine learning model evaluates abnormal sequences and calculates the risk index R2, also known as the second risk weight. Based on these characteristics, user and environment detection is performed to calculate additional risk indices, also known as the third and fourth risk weights. A comprehensive risk index, also known as the comprehensive risk weight, is then calculated. The risk level is then determined. If the risk level is high, execution is blocked, 2FA is triggered, and the security team is notified. If the risk level is medium, execution is delayed, triggering a second confirmation. If the risk level is low, execution is allowed, and the operation is logged. If the risk level is trustworthy, the trust level is whitelisted to accelerate subsequent similar operations. User feedback is then obtained to confirm whether the alert is a false positive. If so, the weight coefficient is updated. Otherwise, the process ends.

[0091] In this embodiment, BMC commands are intercepted before parsing based on their risk levels (high / medium / low / trusted), and differentiated defense actions are triggered, including blocking high-risk operations and two-factor authentication (2FA), delaying the execution of medium-risk operations and secondary confirmation, logging low-risk operations, and learning trusted whitelists. This can solve the problem of delayed response.

[0092] The present application also provides a BMC security assessment device, such as Figure 3 Shown, including: Behavior collection module 41 is used to obtain user operations on the baseboard management controller (BMC) and obtain user behavior characteristics corresponding to the operations. The user behavior characteristics include operation type, operation parameters, operation environment, and user profile. The operations include at least one of BMC command line operations, World Wide Web interface click operations, intelligent platform management interface call operations, and application programming interface call operations. A first risk assessment module 42 is configured to determine a first risk weight of the operation based on user behavior characteristics and preset static rules; A second risk assessment module 43 is used to determine a second risk weight of the operation based on user behavior characteristics and a machine learning model; A third risk assessment module 44 is configured to determine a third risk weight corresponding to the operating environment and a fourth risk weight corresponding to the user profile; a fourth risk assessment module 45 for calculating a comprehensive risk weight of the operation on the BMC based on the first risk weight, the second risk weight, the third risk weight, and the fourth risk weight; The hierarchical policy execution module 46 is configured to determine security risk assessment information of the operation on the BMC based on the comprehensive risk weight.

[0093] Furthermore, the present application also proposes that the second risk assessment module 43 is used to convert user behavior characteristics into corresponding numerical vectors; the numerical vector is spliced ​​with multiple historical numerical vectors corresponding to the user's multiple historical operations to obtain an input vector; the user's multiple historical operations are the user's multiple operations on the BMC before the operation; the input vector is processed using a machine learning model to obtain a second risk weight of the operation.

[0094] Furthermore, the present application also proposes that the second risk assessment module 43 is used to obtain input dimension information corresponding to the input vector; the input dimension information includes the amount of data input each time, the total number of operations processed each time, and the length of the numerical vector of each operation; based on the total number of operations, multiple historical numerical vectors corresponding to multiple historical operations of the user are obtained; based on the amount of data input each time and the length of the numerical vector of each operation, the numerical vector and the historical numerical vector are spliced ​​in the order of operation time to obtain the input vector.

[0095] Furthermore, the present application also proposes that the hierarchical policy execution module 46 is also used to respond to operations based on security risk assessment information and preset response strategies.

[0096] When implementing it specifically, Figure 4 As shown, when a user invokes a BMC interface, the behavior collection module collects behavioral data, extracts user behavior characteristics, and logs them. The risk assessment module, consisting of the first, second, third, and fourth risk assessment modules, calculates risk weights to obtain a comprehensive risk weight. Based on the comprehensive risk weights, the hierarchical policy execution model determines the security risk level of the operation to the BMC and, based on the security risk level and pre-set response strategy, responds to the operation and logs it.

[0097] According to an embodiment of the present application, the present application also provides an electronic device.

[0098] Figure 5 A schematic block diagram of an example electronic device 800 that can be used to implement an embodiment of the present application is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described and / or claimed herein.

[0099] like Figure 5 As shown, electronic device 800 includes a computing unit 801, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 802 or a computer program loaded from a storage unit 808 into a random access memory (RAM) 803. RAM 803 may also store various programs and data required for the operation of electronic device 800. Computing unit 801, ROM 802, and RAM 803 are interconnected via a bus 804. An input / output (I / O) interface 805 is also connected to bus 804.

[0100] Multiple components in the electronic device 800 are connected to the I / O interface 805, including an input unit 806, such as a keyboard, a mouse, etc.; an output unit 807, such as various types of displays, speakers, etc.; a storage unit 808, such as a magnetic disk, an optical disk, etc.; and a communication unit 809, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 809 allows the electronic device 800 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0101] The computing unit 801 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 801 performs the various methods and processes described above, such as the BMC security assessment method. For example, in some embodiments, the BMC security assessment method can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 808. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 800 via the ROM 802 and / or the communication unit 809. When the computer program is loaded into the RAM 803 and executed by the computing unit 801, one or more steps of the BMC security assessment method described above can be performed. Alternatively, in other embodiments, the computing unit 801 can be configured to perform the BMC security assessment method through any other suitable means (e.g., via firmware).

[0102] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0103] The program code for implementing the methods of the present application can be written in any combination of one or more programming languages. Such program code can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the program code is executed by the processor or controller, the functions / operations specified in the flow charts and / or block diagrams are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0104] The present invention provides a computer program product or computer program, which includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the BMC security assessment method described above in the present invention.

[0105] An embodiment of the present application provides a computer-readable storage medium storing executable instructions. The computer-readable storage medium stores executable instructions. When the executable instructions are executed by a processor, the processor will execute the BMC security assessment method provided by the embodiment of the present application.

[0106] In some embodiments, a computer-readable storage medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. The computer-readable storage medium may be a machine-readable signal medium or a machine-readable storage medium. The computer-readable storage medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of computer-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0107] In some embodiments, executable instructions may be in the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.

[0108] As an example, executable instructions may, but need not, correspond to a file in a file system, may be stored as part of a file that stores other programs or data, such as in one or more scripts in a HyperText Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple coordinating files (e.g., files storing one or more modules, subroutines, or code portions).

[0109] By way of example, executable instructions may be deployed to be executed on one computing device, or on multiple computing devices at one site, or on multiple computing devices distributed across multiple sites and interconnected by a communication network.

[0110] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0111] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0112] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact through a communication network. The client-server relationship arises through computer programs running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain.

[0113] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this application can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this application can be achieved. This is not a limitation herein.

[0114] Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features being referred to. Thus, a feature defined as "first" or "second" may explicitly or implicitly include at least one such feature. Throughout the description of this application, "plurality" means two or more, unless otherwise specifically defined.

[0115] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A BMC security assessment method, characterized in that: include: Obtaining a user operation on a baseboard management controller (BMC), and obtaining user behavior characteristics corresponding to the operation, the user behavior characteristics including operation type, operation parameters, operation environment, and user profile; the operation including at least one of a BMC command line operation, a World Wide Web interface click operation, an intelligent platform management interface call operation, and an application programming interface call operation; Determining a first risk weight for the operation based on the user behavior characteristics and preset static rules; Determining a second risk weight for the operation based on the user behavior characteristics and the machine learning model; Determining a third risk weight corresponding to the operating environment and a fourth risk weight corresponding to the user profile; Calculating a comprehensive risk weight of the operation on the BMC based on the first risk weight, the second risk weight, the third risk weight, and the fourth risk weight; Based on the comprehensive risk weight, security risk assessment information of the operation on the BMC is determined.

2. The BMC safety assessment method according to claim 1, characterized in that: Determining a second risk weight for the operation based on the user behavior characteristics and the machine learning model includes: Convert the user behavior characteristics into corresponding numerical vectors; The numerical vector is concatenated with multiple historical numerical vectors corresponding to multiple historical operations of the user to obtain an input vector; the multiple historical operations of the user are multiple operations of the user on the BMC before the operation; The input vector is processed using a machine learning model to obtain a second risk weight for the operation.

3. The BMC safety assessment method according to claim 2, characterized in that: The numerical vector is concatenated with multiple historical numerical vectors corresponding to multiple historical operations of the user to obtain an input vector, including: Obtaining input dimension information corresponding to the input vector; the input dimension information includes the amount of data input each time, the total number of operations processed each time, and the length of the numerical vector of each operation; Based on the total number of operations, multiple historical numerical vectors corresponding to multiple historical operations of the user are obtained; Based on the amount of data input each time and the length of the numerical vector of each operation, the numerical vector and the historical numerical vector are spliced ​​in the order of operation time to obtain an input vector.

4. The BMC safety assessment method according to claim 1, characterized in that: Determining a first risk weight of the operation based on the user behavior characteristics and preset static rules includes: Matching the user behavior characteristics with each of the static rules to obtain a matching result; each of the static rules includes a specific behavior characteristic and a corresponding risk weight; Based on the matching result of each rule, a first risk weight of the operation is determined.

5. The BMC safety assessment method according to claim 4, characterized in that: Determining a first risk weight for the operation based on the matching result of each rule includes: The risk weights corresponding to the rules for which the matching results are matched are summed to obtain a first risk weight for the operation.

6. The BMC safety assessment method according to claim 1, characterized in that: Determining a third risk weight corresponding to the operating environment includes: Based on the operating environment and the corresponding relationship between the operating environment and the risk weight, a third risk weight corresponding to the operating environment is determined.

7. The BMC safety assessment method according to claim 1, characterized in that: Determining the fourth risk weight corresponding to the user profile includes: Based on the user portrait and the corresponding relationship between the user portrait and the risk weight, a fourth risk weight corresponding to the user portrait is determined.

8. The BMC safety assessment method according to claim 1, characterized in that: Calculating a comprehensive risk weight of the operation on the BMC based on the first risk weight, the second risk weight, the third risk weight, and the fourth risk weight includes: determining a risk coefficient corresponding to each of the first risk weight, the second risk weight, the third risk weight, and the fourth risk weight; Based on the risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight, the first risk weight, the second risk weight, the third risk weight and the fourth risk weight are weighted and summed to obtain a comprehensive risk weight of the operation on the BMC.

9. The BMC safety assessment method according to claim 8, characterized in that: Also includes: Obtaining user feedback information, including the number of times normal operations were misjudged within a time period and the total number of false alarms; Based on the user feedback information, the risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight, and the fourth risk weight are updated.

10. The BMC safety assessment method according to claim 9, characterized in that: Based on the user feedback information, the risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight, and the fourth risk weight are updated, including: The risk factor weighting value is determined based on the number of times normal operations are misjudged within a time period, the total number of false alarms, and the preset learning rate; Based on the risk coefficient weighted value, the risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight are weighted respectively to obtain the updated risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight; wherein, the updated risk coefficients corresponding to the first risk weight, the second risk weight, the third risk weight and the fourth risk weight meet the normalization condition and the upper and lower limit conditions.

11. The BMC safety assessment method according to claim 1, characterized in that: Determining security risk assessment information of the operation on the BMC based on the comprehensive risk weight includes: The comprehensive risk weight is compared with risk values ​​corresponding to a plurality of preset risk levels to determine the risk level corresponding to the comprehensive risk weight, and obtain security risk assessment information of the operation on the BMC.

12. The BMC safety assessment method according to claim 1, characterized in that: Also includes: Respond to the operation based on the security risk assessment information and a preset response strategy.

13. The BMC safety assessment method according to claim 12, characterized in that: Responding to the operation based on the security risk assessment information and a preset response strategy includes: If the security risk assessment information indicates that the security risk of the operation to the BMC is at a first risk level, blocking the operation based on a response policy corresponding to the first risk level and triggering two-factor authentication; If the security risk assessment information indicates that the security risk of the operation to the BMC is at a second risk level, based on a response strategy corresponding to the second risk level, delaying execution of the operation and triggering a second confirmation of the user; If the security risk assessment information indicates that the security risk of the operation to the BMC is at a third risk level, executing the operation based on a response strategy corresponding to the third risk level; If the security risk assessment information indicates that the security risk of the operation to the BMC is at a fourth risk level, the operation is executed based on a response policy corresponding to the fourth risk level, and the operation is added to a whitelist.

14. A BMC safety assessment device, characterized in that: include: A behavior collection module is configured to acquire user operations on a baseboard management controller (BMC) and obtain user behavior characteristics corresponding to the operations, wherein the user behavior characteristics include the operation type, operation parameters, operation environment, and user profile; the operations include at least one of BMC command line operations, World Wide Web interface click operations, intelligent platform management interface call operations, and application programming interface call operations; a first risk assessment module, configured to determine a first risk weight of the operation based on the user behavior characteristics and preset static rules; a second risk assessment module, configured to determine a second risk weight of the operation based on the user behavior characteristics and the machine learning model; A third risk assessment module, configured to determine a third risk weight corresponding to the operating environment and a fourth risk weight corresponding to the user profile; a fourth risk assessment module, configured to calculate a comprehensive risk weight of the operation on the BMC based on the first risk weight, the second risk weight, the third risk weight, and the fourth risk weight; The hierarchical policy execution module is configured to determine security risk assessment information of the operation on the BMC based on the comprehensive risk weight.

15. The BMC safety assessment device according to claim 14, characterized in that: The second risk assessment module is used to convert the user behavior characteristics into a corresponding numerical vector; The numerical vector is concatenated with multiple historical numerical vectors corresponding to multiple historical operations of the user to obtain an input vector; the multiple historical operations of the user are multiple operations of the user on the BMC before the operation; The input vector is processed using a machine learning model to obtain a second risk weight for the operation.

16. The BMC safety assessment device according to claim 15, characterized in that: The second risk assessment module is used to obtain input dimension information corresponding to the input vector; the input dimension information includes the amount of data input each time, the total number of operations processed each time, and the length of the numerical vector of each operation; Based on the total number of operations, multiple historical numerical vectors corresponding to multiple historical operations of the user are obtained; Based on the amount of data input each time and the length of the numerical vector of each operation, the numerical vector and the historical numerical vector are spliced ​​in the order of operation time to obtain an input vector.

17. The BMC safety assessment device according to claim 14, characterized in that: The hierarchical strategy execution module is further configured to respond to the operation based on the security risk assessment information and a preset response strategy.

18. An electronic device, characterized in that: include: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the BMC security assessment method according to any one of claims 1 to 13.

19. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the BMC security assessment method according to any one of claims 1 to 13.

20. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the BMC security assessment method according to any one of claims 1 to 13 is implemented.

Citation Information

Patent Citations

  • Neural network system, method and device for carrying out risk evaluation on operation event

    CN110705688A

  • Neural network system, method and device for risk assessment

    CN111967565A

  • Risk estimation method and device for operation behavior record

    CN112288329A

  • Baseboard management controller safety protection method, device, equipment and medium

    CN116680686A

  • Security detection method, device and equipment, readable storage medium and program product

    CN120372606A